HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Hackers Spend $7M on Expired Domains to Redirect Web Traffic to Scams and Malware

In H1 2026, attackers spent nearly $7 million acquiring expired domains, then used the inherited traffic to funnel users to phishing sites and malware. The tactic highlights a gap in DNS and web‑filtering controls that SOC 2 audit programs must address.

LiveThreat™ Intelligence · 📅 August 17, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Hackers Spend $7M on Expired Domains to Redirect Web Traffic to Scams and Malware

What Happened — Threat actors spent close to $7 million in the first half of 2026 buying expired domains. By “drop‑catching” these names, they inherit residual traffic and search‑engine reputation, then use the domains to redirect visitors to phishing pages, ransomware loaders, and other malware. Infoblox reports that more than 50 400 domains were repurposed in this way.

Why It Matters for Compliance & Audit Readiness

  • The scenario illustrates a classic phishing supply‑chain gap that SOC 2 Security (CC6.1) controls are designed to mitigate: untrusted external URLs must be filtered and incident response documented.
  • Continuous monitoring of domain reputation and DNS changes provides audit‑ready evidence that your organization is actively managing third‑party risk.
  • Our Security Awareness Training capability helps staff recognize malicious redirects, satisfying the Personnel criteria (CC7.1) and reducing reliance on purely technical controls.

Who Is Affected – SaaS providers, financial services platforms, e‑commerce sites, and any organization that drives inbound web traffic.

Recommended Actions

  • Map the phishing‑prevention controls (CC6.1, CC7.1) to your SOC 2 audit plan and collect evidence of email/web filtering logs.
  • Deploy a domain‑watch service or DNS‑threat feed to flag newly registered look‑alike domains.
  • Conduct a targeted security‑awareness session on “expired‑domain hijacking” and test with simulated phishing.

Source: The Hacker News

Technical Notes – Attack vector: malicious domain registration and DNS redirection. No specific CVE; the threat leverages reputation inheritance rather than software flaw. Data exposed includes credential harvest pages and malware payloads. Source: same as above

📰 Original Source
https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →