Neurobyte Technologies

The Domain That Looks Like Yours: How Brand Impersonation Works

Attackers register a domain one character from yours, copy your login page and phish your customers in your name. How the sequence works, why the gap between registration and campaign is your only window, and what to do inside it.

The Domain That Looks Like Yours: How Brand Impersonation Works

There is a category of attack where your systems are never touched, your network is never entered, and your security controls are never tested — and you still absorb the entire cost of it.

Someone registers a domain that looks like yours. They copy your login page. They send messages to your customers. The customers, who have no realistic way to tell the difference, enter their credentials. The money moves. And when it goes wrong, it is your brand in the complaint, your call centre handling the volume, and your name in the story.

Nothing about this requires access to anything of yours. It requires only that your brand is worth impersonating.

The sequence, in order

Brand impersonation follows a predictable pattern, which is fortunate, because predictability is what makes it detectable.

It begins with registration. An attacker registers a domain visually or typographically close to yours. The techniques are well worn: a character substitution that reads correctly at a glance, a doubled or dropped letter, a hyphen inserted or removed, a different top-level domain, or a plausible-sounding subdomain-as-domain construction — something along the lines of a bank name followed by "-online" or "-secure" — which is particularly effective because it looks like the kind of thing an organisation would legitimately register.

Then comes the certificate. Free certificate authorities issue in minutes, so the impersonating site gets the padlock. This matters more than it should, because a generation of security awareness training taught people to check for the padlock, and the padlock now means only that the connection is encrypted — not that the destination is honest.

Then the content. Your login page is copied, usually by an automated tool that pulls your stylesheets and images directly from your real site, so it matches perfectly and updates when you change your branding. Sometimes the copy is hosted on infrastructure that proxies your genuine site in real time, which makes it flawless and lets the attacker intercept a session token as well as a password.

Then the campaign. Messages go out — email, SMS, WhatsApp, sponsored search results — directing people to the domain. This is the first moment you are likely to hear about any of it, and by then the mechanism has been in place for days.

The window between the second and fourth stages is the whole opportunity. A domain that has been registered and given a certificate but has not yet been used in a campaign is a loaded weapon that has not been fired. Everything you can do — takedown, blocking, warning customers, alerting the registrar — is dramatically more effective in that window than after.

Why this is worse for financial brands here

Any brand can be impersonated, but the return on the effort is highest where money moves quickly and irreversibly, which is the environment mobile money has created across Kenya and East Africa.

Two local factors compound the problem. The first is that people are habituated to transactional messages about money arriving on their phones, frequently and legitimately, from many different institutions. A well-crafted fraudulent notification does not have to overcome scepticism; it has to blend into a stream of messages that look broadly similar and are usually genuine.

The second is that the transfer mechanisms are fast and difficult to reverse. Where fraud in slower payment systems can sometimes be interrupted between initiation and settlement, here the window is often minutes. Detection speed and settlement speed are in direct competition, and settlement usually wins.

There is a further wrinkle for institutions with agent networks or field staff, which describes a great many SACCOs, microfinance institutions and insurers. Impersonation of your organisation to your own agents is as damaging as impersonation to your customers, and considerably less likely to be reported quickly, because an agent who has been deceived is often unsure whether they have made an error and may hesitate before escalating.

Why you find out last

The uncomfortable structural feature of this attack is that every part of it happens outside your visibility.

The domain is registered on somebody else's registrar. The certificate is issued by somebody else's authority. The site is hosted on somebody else's infrastructure. The messages are sent through somebody else's channels to your customers' devices. At no point does any of it generate a log entry, an alert, or a single packet on your network.

Your SIEM sees nothing, because nothing happened on your systems. Your endpoint protection sees nothing, for the same reason. The first signal in most organisations is a customer complaint, which arrives only after someone has lost money and worked out why — typically well into the campaign, and often days after it began.

The only way to see it earlier is to look outward, at the same public sources the attacker's own preparation leaves traces in.

What is actually watchable

The good news is that most of the preparation is a matter of public record, if someone is watching for it.

Domain registrations are public, and permutations of your brand can be enumerated and monitored continuously — checking whether each variation has been registered, whether it resolves, and whether anything is being served on it.

Certificate transparency logs are public and, by design, record every certificate issued by a participating authority. A certificate issued for a domain resembling yours, by an authority you do not use, is a strong signal and frequently the earliest one available.

Content similarity can be checked. When a newly registered look-alike domain begins serving a page that pulls images and stylesheets from your real site, the relationship is not subtle, and it can be detected automatically.

Watching those three sources together is what look-alike domain monitoring means in practice. It is not exotic, it does not require access to anything hidden, and it can compress the time from registration to detection from weeks to roughly a day. That compression is the entire product.

What to do when you find one

Confirm it is real before escalating. Similar domain names are sometimes coincidental, sometimes registered defensively by someone in your own organisation years ago, and occasionally belong to an unrelated business with a legitimate claim to a similar name. Check what is actually being served before treating a registration as hostile.

Preserve evidence properly. Screenshots with visible timestamps, the full URL, the certificate details, the hosting and registrar information, and copies of any messages directing people to it. Takedown requests are processed considerably faster when they arrive complete, and slowly or not at all when they require the recipient to investigate.

Report to the hosting provider and the registrar in parallel rather than in sequence. Most have abuse processes and the phishing case is usually clear cut. Submit to the browser blocklists as well — Google Safe Browsing and Microsoft SmartScreen — because getting the site flagged in browsers often protects more people faster than a takedown does, and takes minutes.

Warn your customers through a channel you already control and they already trust, and do it before the complaint volume builds. Say plainly what your real domain is and what you will never ask for. Organisations frequently delay this out of concern about appearing compromised, which is understandable and usually the wrong call — the reputational damage from customers being defrauded silently is worse than the damage from a proactive warning that demonstrates you are watching.

Then decide about the defensive registrations. Registering the most obvious permutations of your own domain is cheap, and it removes the easiest options from the attacker's list. It does not remove all of them, since the permutation space is effectively unbounded, but taking the twenty most plausible variants off the table for the cost of twenty domain registrations is straightforwardly good value.

The uncomfortable summary

You cannot prevent someone registering a domain that looks like yours, and you cannot secure infrastructure you do not own. What you can control is the interval between their preparation and your knowledge of it.

Left to the default, that interval ends when a customer calls to ask why their money is gone. Watched properly, it ends within a day or so of the certificate being issued, while the site is still being built and before a single message has gone out.

That difference — days of warning versus a complaint after the fact — is not a marginal improvement in a metric. It is the difference between a takedown request and a fraud investigation.

Frequently asked questions

What is a look-alike domain?

A look-alike domain is one registered to resemble a legitimate organisation's domain closely enough to deceive at a glance. The common techniques are character substitution using visually similar letters, doubling or dropping a letter, adding or removing a hyphen, registering the same name under a different top-level domain, or appending a plausible word such as "secure" or "online". They are also called typosquatted or cousin domains, and they are the standard foundation for phishing that targets a specific brand's customers.

How quickly can we detect one?

With monitoring of domain registrations and certificate transparency logs, typically within about a day of the certificate being issued — which is usually before any campaign has launched. Without monitoring, detection normally comes from a customer complaint, which arrives after the campaign is running and after someone has lost money. That gap between roughly a day and roughly a week is the practical value of the monitoring, because almost every response option works far better before the messages go out.

Can we get an impersonating domain taken down?

Frequently yes, though speed varies by registrar and host. Clear phishing cases are usually actioned, particularly when the report includes complete evidence — timestamped screenshots, the URL, certificate details, and copies of the messages directing victims to it. Report to the hosting provider and the registrar in parallel, and submit to Google Safe Browsing and Microsoft SmartScreen at the same time, since browser blocking often protects more people faster than takedown and takes only minutes to request.

Should we defensively register domains similar to ours?

Registering the most obvious permutations is cheap and worth doing, because it removes the easiest options from an attacker's list. It cannot be comprehensive — the space of possible variations is effectively unbounded, and defensive registration of everything is neither affordable nor useful. Register the twenty or so most plausible variants, then monitor for the rest rather than attempting to buy your way to safety.

Does an SSL certificate mean a site is legitimate?

No, and this is one of the more damaging pieces of outdated security advice still in circulation. A certificate confirms only that the connection is encrypted and that whoever controls the domain proved they control it. Free certificate authorities issue in minutes with no verification of who the requester is or whether the name resembles someone else's brand, so essentially every phishing site now has a padlock. Customer guidance should focus on checking the domain name character by character, not on looking for the padlock.

Would our SIEM or firewall catch this?

No, and this is why the category needs a different tool. Every stage of a brand impersonation attack happens on infrastructure you do not own — someone else's registrar, certificate authority, hosting and messaging channels — so none of it produces a log entry, an alert or any network traffic on your systems. Inward-looking tools like a SIEM, firewall or endpoint agent are structurally incapable of seeing it. Detection requires outward-looking monitoring of public sources such as domain registrations and certificate transparency logs, which is what brand-protection capability within a threat intelligence platform provides.