DNS abuse and criminal infrastructure

Research from the Interisle Consulting Group suggests that up to 20% of new generic top-level domain registrations in 2025 may be linked to malicious actors. The report highlights concerns regarding current DNS abuse measures and the potential for criminal exploitation of domain infrastructure.
Why it matters
This indicates a significant security vulnerability in the internet's naming infrastructure that could facilitate large-scale cybercrime and phishing operations.
Evidence suggests that criminals may control a substantial share of new gTLD registrations. Although the precise scale remains contested, the article asks whether current DNS Abuse measures adequately address wider misuse of domain names.
According to research published by Interisle Consulting Group , cybercriminals registered a significant share of new domain names in 2025, representing a substantial portion of the generic top-level domain (gTLD) market.
The study found that at least 10% of all new gTLD domain names registered during the year had subsequently appeared on security blocklists by the time of analysis. It estimated that, taking account of subsequent blocklisting and associated domains not themselves blocklisted, the share of names registered by malicious actors may be closer to 20%.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in