// HACKER NEWS — CYBERSECURITY
DNS Abuse and Criminal Infrastructure
Evidence suggests that criminals may control a substantial share of new gTLD registrations. Although the precise scale remains contested, the article asks whether current DNS Abuse measures adequately address wider misuse of domain names.
According to research published by Interisle Consulting Group, cybercriminals registered a significant share of new domain names in 2025, representing a substantial portion of the generic top-level domain (gTLD) market.
The study found that at least 10% of all new gTLD domain names registered during the year had subsequently appeared on security blocklists by the time of analysis. It estimated that, taking account of subsequent blocklisting and associated domains not themselves blocklisted, the share of names registered by malicious actors may be closer to 20%.
In a follow-up presentation at the ICANN 86 Policy Forum, Greg Aaron and Karen Rose of Interisle stated that malicious actors may have registered approximately 20% of gTLD names created in 2025. They further reported that 10% of domains registered during 2025 had already appeared on blocklists and estimated that later blocklisting could raise the directly observed proportion to around 12%. In support of that projection, they cited ICANN research indicating that, for every three domains appearing on blocklists, two additional associated domains may remain unlisted.
Any industry confronted with evidence that a material share of its output may be controlled by bad actors should be seriously concerned. It should examine whether its commercial incentives, operational practices, and contractual arrangements inadvertently enable criminals to acquire, use and profit from its products or services at scale.
ICANN org has since published a blog post by members of its Office of the CTO (OCTO). The post argues, reasonably, that estimates of malicious registrations depend on the definition of "abuse", the standard of evidence applied, and the analytical method used. In particular, it cautions against treating every reported or blocklisted domain as automatically constituting confirmed DNS Abuse.
The post also emphasises that ICANN's contractual definition of DNS Abuse is deliberately limited to botnets, malware, pharming, phishing, and spam when spam serves as a delivery mechanism for one of the preceding harms. It argues that broader categories (including fraud, scams, and spam that does not facilitate these enumerated harms) should be identified separately in analysis. The authors further criticise the Interisle report for referring to methods associated with ICANN and COMAR without sufficiently explaining departures from those methods. They also point to ongoing policy development work concerning associated domain checks and safeguards for high-volume registrations.
Those methodological and definitional questions are important. They affect what can properly be claimed about the scale of confirmed DNS Abuse and the comparability of different studies. However, they do not by themselves resolve the broader concern raised by the Interisle findings: that a substantial proportion of newly registered gTLD names may be under the control of actors engaged in, or supporting, malicious activity.
A domain need not yet appear on a blocklist or satisfy ICANN's narrow contractual definition of DNS Abuse to present a meaningful risk. Domains controlled by criminal actors may be retained for later deployment, used in campaigns not yet detected by reporting systems, or used in technology-facilitated harms falling outside ICANN’s current contractual definition, including fraud, scams, sextortion, and other forms of online deception.
The wider scale of technology-facilitated harm should inform the urgency of this discussion, while not being confused with a claim that every such harm is DNS-enabled. The Global Anti-Scam Alliance estimates that scams caused US$442 billion in global losses during 2025, and reports that the "likelihood of financial loss is nota