
Phishing Domains Surge in 2025
Phishing and domain abuse continue to rise, and recent data from Interisle Phishing Landscape report 2025, confirms that attackers are registering domains specifically for malicious use, at scale.
In the past year alone:
- ~1.96 million phishing attacks were recorded
- Over 1.5 million domains were used in phishing
- 77% of those domains were deliberately registered for abuse
TLDs Showing Elevated Risk
The report shows certain newer gTLDs have disproportionately high phishing rates relative to their size, including:
.xin
.bond
.help
.win
.cfd
These extensions show high abuse concentration per registered domain.
At the same time:
- .com remains the most abused TLD by total volume, simply due to its global scale.
- Certain ccTLDs such as .ru and .es have also seen spikes in phishing campaigns.
Why These TLDs?
The common drivers are:
Low Cost
Cheap promotional pricing reduces the barrier for attackers to register domains in bulk.
Bulk Registration Access
Automated bulk purchasing allows threat actors to deploy hundreds or thousands of domains quickly.
Limited Verification
TLDs with minimal vetting processes tend to experience higher concentrations of abuse.
What This Means for Brands
Monitoring should prioritise:
- 1. High-abuse new gTLDs
- 2. Legacy extensions by volume (.com)
- 3. Emerging ccTLD spikes
Risk isn’t just about how popular a TLD is. It’s about how much it’s abused. Knowing which domains attackers target, helps brands focus their monitoring, enforcement, and protection efforts where they matter most.
About brandsec
brandsec is a team of highly experienced domain name management and online brand protection experts. We provide corporate domain name management and brand enforcement services, helping brands eliminate phishing platforms across the internet. Supporting some of the largest brands in the region, we offer innovative solutions to combat threats across multiple industries.
Niluka W
Operations Director
Niluka is a results-driven Operations leader at Brandsec with over 15 years' experience in domain name management, online brand protection, and cybersecurity. Known for her strong relationship management and operational expertise, she plays a key role in leading Brandsec’s Operations and Account Management teams. From onboarding to service delivery, Niluka ensures high standards and smooth execution, fostering a culture of excellence. Her leadership and dedication make her a standout figure in the industry.


