Expired Domains Are Becoming a New Cybersecurity Threat
Cybercriminals are increasingly acquiring expired domains to exploit their old reputation, backlinks and digital history for malware, phishing, scams and other malicious operations.
On this page
A domain name can look abandoned and still carry years of history.
That history is becoming a valuable target on the Internet.
Recent research highlighted by Infoblox and reported by multiple security publications shows that cybercriminals are increasingly acquiring expired domains, not simply because the names are available, but because these domains can inherit reputation, backlinks, traffic patterns and existing trust from their previous owners. Infoblox's analysis found that roughly 50,400 expired domains were being re-registered each day across generic top-level domains during the first half of 2026, rising to about 65,000 per day when country-code domains are included.
One particularly striking case involves a threat group identified as Sable Squirrel, which reportedly spent more than $7 million acquiring over 10,000 domains. The domains were subsequently associated with activities including illegal streaming, gambling infrastructure and malware operations.
This creates a much bigger Internet-security problem than simply βhackers buying domains.β It exposes a weakness in one of the Web's oldest assumptions: that a domain's reputation roughly follows its current owner.
The Hidden Value Inside an Expired Domain
When a domain expires, its name eventually becomes available to someone else. To an ordinary buyer, it may look like a blank domain that happens to have a desirable name.
Technically, however, the domain may have a long history.
It may previously have hosted a company website, an online publication, a university project, a community forum, a software product or an e-commerce store. Other websites may still link to it. Search engines may have previously indexed it. Security systems may have encountered it thousands of times. Users may recognize the name from somewhere they visited years earlier.
That historical footprint is what makes some expired domains attractive.
A newly registered domain has no history. An expired domain can arrive with one.
Infoblox describes these re-registered domains as βdropcatchβ domains and warns that their previous reputation and connections can make them more useful to threat actors than newly registered domains. Security products and reputation-based systems may treat a domain differently when it already has an established history.
What Exactly Is a Dropcatch Domain?
The term sounds complicated, but the underlying process is relatively simple.
Imagine a business registers example-site.com and operates it for ten years. During that time, hundreds of websites link to the domain. Search engines crawl it. Users bookmark it. Other services reference it.
The business eventually stops operating and forgets to renew the registration.
After the applicable expiration and deletion process is completed, the domain becomes available again. Another party can register it.
The new owner now controls the same Internet address that previously belonged to the old organization.
The domain's ownership has changed, but its historical footprint does not automatically disappear.
This is the opportunity attackers are exploiting.
ICANN explains that if an expired domain is not renewed or restored, it can eventually be released for registration by another party. Depending on the registrar's policies, an expired domain can also pass through an Auto-Renew Grace Period and, after deletion, a 30-day Redemption Grace Period before becoming available again.
Why Would a Criminal Pay for an Old Domain?
The answer is trust inheritance.
Suppose an attacker creates a completely new domain such as random-security-update-example.com. Security systems, browsers, search engines and users have very little reason to trust it.
Now compare that with a domain that existed for eight years, received legitimate backlinks and previously hosted a respected website.
The second domain may have significantly more useful history.
This does not mean every expired domain automatically retains search rankings or security reputation. Nor does it mean security systems blindly trust old domains. The advantage is contextual rather than magical.
An attacker can potentially inherit useful signals that would otherwise take years to build.
That makes the domain itself part of the attack infrastructure.
The Attack Is Not Really About the Domain Name
The most important conceptual change is to stop thinking of these domains as websites.
For attackers, a domain can be infrastructure.
It can redirect visitors, host malicious files, support phishing campaigns, distribute fake software updates, operate as a command-and-control endpoint, or act as a disposable address in a larger criminal operation.
Infoblox's research linked dropcatch domains to several types of malicious activity, while reporting on the research identified malware families including Quasar RAT, AsyncRAT and HiddenTear among infrastructure associated with the activity.
The same domain may also be useful for activities that do not immediately look like conventional hacking.
Researchers observed expired domains being used for illegal streaming and gambling operations. That matters because the infrastructure economy surrounding cybercrime is increasingly interconnected. A domain acquired for one purpose can later become part of another criminal campaign.
The Scale Is What Makes This Story Important
One compromised domain is not particularly unusual.
The scale of the re-registration ecosystem is.
According to the Infoblox analysis reported this month, approximately 50,400 dropcatch domains were being re-registered every day in generic top-level domains during the first half of 2026. Including country-code top-level domains increased the figure to around 65,000 per day. The research indicated that dropcatch registrations represented nearly one in five daily domain registrations across the analyzed categories.
That does not mean one in five newly registered domains is malicious.
Most expired domains are not necessarily being purchased by criminals. Businesses, domain investors, developers and legitimate organizations can have perfectly valid reasons for acquiring an expired domain.
The important finding is that the pool is large enough to create an attractive ecosystem for abuse.
Why Old Backlinks Can Become a Security Problem
Backlinks are normally discussed as an SEO topic.
In this context, they become an infrastructure-security issue.
Imagine an old technology website that accumulated hundreds of links from other sites. Years later, its domain expires. A malicious buyer acquires it and starts redirecting selected visitors to a scam.
The external websites may still contain links pointing to the domain.
The links themselves have not changed.
What changed is the entity controlling the destination.
This creates an uncomfortable weakness in the architecture of the Web: links generally point to names, not to the people who currently control those names.
That is one reason abandoned domains deserve more attention from organizations that manage websites, old projects and large collections of Internet properties.
Search Reputation Is Not the Same as Trust
There is an important misconception worth clearing up.
An old domain having backlinks does not mean Google or another search engine will automatically rank malicious content highly.
Search engines evaluate many signals, and a domain changing ownership can produce significant changes in how its content is evaluated.
However, attackers do not necessarily need a domain to rank at the top of Google.
They may simply want users to recognize the domain, follow an existing link, trust an email containing the address, or pass through a security system that considers the domain less suspicious than a completely new registration.
That distinction is crucial.
The value of an expired domain can exist even when traditional SEO value has disappeared.
The Domain Lifecycle Creates the Opportunity
Domain expiration is not an instant event in which a website disappears and the name becomes available five minutes later.
There can be several stages between expiration and final deletion.
ICANN says registrars may offer an Auto-Renew Grace Period of between one and 45 days, depending on their policies. If a domain is deleted, generic TLD registries must provide a 30-day Redemption Grace Period during which the previous registrant can restore the domain, although restoration can involve additional fees.
After those recovery opportunities have ended, the domain can eventually return to the available registration pool.
That is the moment domain-catching systems become relevant.
Automated systems monitor domains approaching release and attempt to register valuable names extremely quickly after they become available.
The process is highly automated because popular domains may attract multiple potential buyers at almost exactly the same moment.
Why Automation Changes the Economics
Humans are not particularly good at competing for domain names that become available at unpredictable times.
Machines are.
A domain-catching service can monitor large numbers of names, evaluate their history and attempt registrations automatically.
For a legitimate domain investor, this may be a business tool.
For a criminal organization, the same infrastructure can become a way to acquire large numbers of domains with desirable historical properties.
This creates an interesting parallel with modern cyberattacks: the attacker does not necessarily need to compromise an existing server if it is cheaper to acquire the identity of the infrastructure itself.
The $7 Million Example Shows How Industrialized It Can Become
The Sable Squirrel case provides a useful illustration of the economics.
According to reporting based on Infoblox's research, the group spent more than $7 million to acquire more than 10,000 domains. The domains were used across illegal streaming, gambling and malicious infrastructure, demonstrating that the objective was not simply to obtain a few attractive domain names.
That scale changes the nature of the problem.
When attackers acquire thousands of domains, defenders cannot reasonably inspect each one manually.
The defense therefore has to become automated too.
What Makes a Recycled Domain Suspicious?
A previously registered domain is not automatically dangerous.
Security teams therefore need to look at combinations of signals rather than simply blocking every expired domain.
Potential warning signs can include a sudden change in the domain's content, a new hosting environment, unexpected DNS changes, unusual traffic patterns, newly associated mail infrastructure, suspicious redirects or a domain that suddenly begins serving software downloads unrelated to its historical purpose.
For example, imagine a domain that previously belonged to a local community organization and had a simple informational website. If that same domain suddenly begins serving executable files or redirecting visitors through multiple unfamiliar websites, the change in behavior is far more meaningful than the domain's age alone.
What Website Owners Should Do Before a Domain Expires
The problem is not limited to security companies.
Ordinary website owners can unintentionally create the infrastructure that someone else later abuses.
If an organization abandons a domain but continues to own it, the safest option is often to maintain control rather than simply allowing it to expire.
This is particularly important for domains that have been used for:
- Company websites
- Product documentation
- Software downloads
- Public APIs
- Email addresses
- Customer portals
- Marketing campaigns
- Educational resources
- Old subdomains
- Developer documentation
An organization should also review old DNS records, email configurations, certificates, API integrations and third-party references before retiring a domain.
Simply deleting the website does not necessarily mean the digital identity has disappeared.
Old Subdomains Can Create a Separate Problem
There is another issue that organizations should consider: subdomains.
A company may have hundreds of addresses such as old.example.com, campaign.example.com or project.example.com.
If those subdomains point to services that no longer exist, the organization may accidentally leave behind dangling infrastructure references.
This is different from buying an expired domain, but the underlying lesson is similar: ownership and configuration must be reviewed together.
A domain can remain under an organization's control while pointing toward infrastructure that no longer belongs to it.
That is why domain retirement should be treated as a security process rather than simply a billing decision.
Why Email Makes Expired Domains Even More Dangerous
Web traffic is only one side of the problem.
Email can make an abandoned domain significantly more sensitive.
Suppose an organization previously used support@example.com and later allowed example.com to expire.
A new registrant could potentially control the domain and therefore create new addresses under it.
That does not automatically grant access to historical email, but it can create serious impersonation risks.
Someone receiving an email from a familiar-looking domain may not realize that ownership has changed.
Organizations retiring domains should therefore consider whether the domain has appeared in customer communication, authentication systems, password-reset workflows, invoices, contracts or software documentation.
The Problem Is Bigger Than Malware
Malware receives much of the attention because it provides an obvious security threat.
But recycled domains can support a much broader range of abuse.
They can be used for phishing, fake software updates, fraudulent advertising, scam pages, illegal streaming, gambling infrastructure, traffic redirection and command-and-control systems.
That makes the problem relevant to Internet infrastructure, SEO, web development, security operations and even brand management.
In other words, this story belongs to the broader Internet & Web ecosystem, not only to traditional cybersecurity.
Why Reputation-Based Security Has a Difficult Job
Many security systems need to make decisions quickly.
When a browser requests a domain, an email arrives, or an endpoint connects to a server, a security product may have only milliseconds or seconds to decide whether the activity looks suspicious.
Historical reputation can be useful in that process.
But attackers understand that reputation systems exist.
That creates an adversarial game.
If a malicious actor can obtain infrastructure with an existing history, they may be able to make malicious activity look less unusual than it would coming from a completely new domain.
This does not mean reputation systems are broken. It means reputation cannot be the only security signal.
Security Teams Need to Watch Ownership Changes, Not Just New Domains
Traditional monitoring often focuses heavily on newly registered domains.
That remains useful, but the current research highlights another question:
Who owns this domain now, and what changed?
A domain that has existed for years can still become dangerous if its ownership or infrastructure changes.
For enterprise security teams, historical DNS data, domain-registration intelligence, certificate history, passive DNS and content changes can therefore become important parts of threat detection.
The strongest defense is not simply asking whether a domain is old. It is understanding whether its current behavior makes sense given its history.
What This Means for SEO Professionals
SEO professionals should also pay attention to this development.
Expired domains have long been traded because buyers may value their existing backlinks, brandability and historical authority.
But purchasing an old domain without investigating its history can create problems.
A domain may have previously been associated with spam, malware, adult content, scams, manipulated links or unrelated industries.
Even when the buyer's intentions are completely legitimate, the historical profile can affect how the domain behaves after redevelopment.
A proper expired-domain evaluation should therefore examine more than domain age and backlink count.
Historical content, anchor-text patterns, previous ownership, redirects, indexing history, DNS history and suspicious activity all deserve consideration.
A Simple Example for Website Owners
Consider a fictional company called NorthStar Tools.
The company launches northstartools.com and operates it for seven years. During that period, hundreds of suppliers and industry blogs link to the website.
The company eventually changes its brand and decides not to renew the old domain.
Two years later, someone else registers the domain.
The new owner now controls an Internet address that appears in old articles, documents and links.
If the new owner uses that domain for unrelated content, visitors following old links may initially assume they have reached the original company.
If the domain is used maliciously, the old identity can become part of the deception.
This example is fictional, but it demonstrates why domain retirement should be treated as an asset-management and security decision.
What Users Can Do to Protect Themselves
Individual users cannot control the entire domain-registration ecosystem, but they can reduce the risk created by deceptive recycled domains.
Do not assume a domain is legitimate simply because it looks old.
Be particularly cautious when a familiar website suddenly asks you to download software, enter sensitive credentials or install a browser update.
When receiving important links by email, verify the destination rather than relying solely on the appearance of the message.
For software updates, use the application's official update mechanism or visit the vendor's known website manually rather than downloading an executable from a random redirect.
The goal is not to distrust every old website. It is to recognize that domain age and domain ownership are different things.
What Businesses Should Put on Their Domain Security Checklist
- Inventory every domain: Know which domains the organization owns, including old campaign and product domains.
- Track expiration dates: Do not allow important domains to expire accidentally.
- Protect registrar accounts: Use strong authentication and limit administrative access.
- Review DNS records: Remove obsolete records and investigate unexpected changes.
- Audit email dependencies: Identify systems that still reference retired domains.
- Review old subdomains: Check for services that were abandoned but remain referenced.
- Monitor ownership: Track important domains and related infrastructure for unexpected changes.
- Secure domain retirement: Decide deliberately whether a domain should be retained, redirected or released.
ICANN itself advises registrants to understand their registrar's renewal policies, keep contact information current and renew important domains before expiration.
The Internet's Identity Layer Is More Fragile Than It Looks
The deeper lesson from the dropcatch phenomenon is that the Internet is built around persistent identifiers.
URLs, domains, email addresses and links allow the Web to function because users assume that an address continues to identify roughly the same destination over time.
But domain registration is fundamentally a lease of an identifier, not permanent ownership of an identity.
When that lease ends, another party can eventually obtain the same name.
That creates a gap between technical ownership and human memory.
A user may remember that a domain was trustworthy five years ago. The DNS system only knows who controls it today.
That gap is precisely where recycled-domain abuse becomes powerful.
Why This Trend Could Get More Important
The number of websites, applications, APIs and digital services continues to grow, which means the Internet accumulates an enormous amount of historical infrastructure.
Every abandoned project creates another potential identifier that can eventually return to the registration pool.
At the same time, automated domain acquisition makes it possible to monitor and register large numbers of names without human intervention.
That combination creates a long-term security challenge.
The Web's historical memory can become an attacker's resource.
And as organizations increasingly depend on external links, cloud services, APIs and automated systems, the consequences of an ownership change can extend far beyond a single website.
What the Current Research Actually Proves
There is an important distinction between what has been observed and what can be predicted.
Confirmed by the reporting: Infoblox has identified large-scale re-registration of expired domains and documented malicious use of some of those domains. Reporting based on the research describes tens of thousands of dropcatch registrations occurring daily and a threat group that spent millions acquiring domains.
Confirmed about the domain lifecycle: ICANN documents the expiration, renewal, redemption and eventual release process for generic domains.
What should not be assumed: An expired domain is not automatically malicious, and an old domain does not automatically retain high search rankings or universal security trust.
The risk comes from the combination of historical identity, residual connections and malicious intent.
The Bigger Picture
The story of expired domains reveals a part of Internet infrastructure that most users never think about.
When a website disappears, the domain name does not necessarily disappear with it. The address can eventually return to the market, carrying a history that may still be visible through links, DNS records, certificates, reputation systems and user expectations.
That makes abandoned domains a form of digital real estate with a potentially valuable history.
For legitimate buyers, that history can represent opportunity.
For attackers, it can represent camouflage.
The reported $7 million investment by Sable Squirrel demonstrates that at least some criminal groups see enough value in this ecosystem to spend heavily on it.
For website owners, the lesson is simple: do not treat an unused domain as worthless just because the website is gone.
For security teams, the lesson is more technical: do not judge a domain solely by how old or familiar it looks.
And for the wider Web, the lesson is perhaps the most important one:
A domain name may remain familiar long after the person behind it has changed.
That small weakness in the Internet's identity model is becoming a surprisingly valuable resource for modern cybercrime.
Written by


