Brand phishing domains are concentrated in new generic extensions: according to Interisle Consulting Group’s Phishing Landscape 2026 data, published on 30 June, new gTLDs held 13% of registered domains but 46% of the domains reported for phishing between May 2025 and April 2026, while country-code domains had the best ratio. For brand owners, that means domain monitoring cannot stop at .com and the ccTLDs of their markets; it has to cover the new gTLDs where attackers actually register.
Key takeaways
- New gTLDs: 13% of registrations, 46% of phishing domains. Legacy gTLDs such as .com: 52% and 40%. ccTLDs: 35% and 14%.
- Interisle says new gTLDs have had the worst ratio in every study period since 2021.
- Phishing attacks in its dataset rose 117%, to 4,251,720, and maliciously registered phishing domains rose 92%, to 2,295,824.
- Most phishing domains are registered by the attackers themselves, so watching new registrations is the earliest point of defence.
What did Phishing Landscape 2026 find about TLDs?
Interisle, a consultancy that has published annual phishing studies for several years, is releasing its 2026 results as a series of posts. In the post of 30 June 2026, Colin Strutt groups top-level domains (TLDs) into three market segments and compares each segment’s share of registered domains with its share of domains reported for phishing:
| Segment | Share of registered domains | Share of phishing domains |
|---|---|---|
| Legacy gTLDs (.com, .net, .org) | 52% | 40% |
| ccTLDs (country codes) | 35% | 14% |
| New gTLDs (introduced since 2012) | 13% | 46% |
The study period runs from May 2025 to April 2026. Interisle concludes that the ccTLD segment has the best ratio of registered domains to phishing domains and that, as in every period since 2021, new gTLDs have the worst.
The summary post of 24 June 2026 puts that in context. Compared with the previous 12 months, the attacks recorded rose from 1,963,390 to 4,251,720, unique domain names reported for phishing from 1,542,922 to 3,103,438, and maliciously registered domains (registered by the attacker, rather than legitimate sites that were hacked) from 1,192,794 to 2,295,824. Phishing attacks using subdomain providers rose 114%.
What does this mean for brand phishing domains?
Three practical conclusions follow for brand owners.
First, monitoring that covers only .com and your own country codes misses the segment where almost half of phishing domains sit. A watch service should cover new gTLDs as a whole, not a hand-picked list.
Second, ccTLDs are not risk-free. A 14% share of a dataset of more than three million phishing domains is still a large number, and the ccTLDs of the corridor (.es, .mx, .co, .com.br) each have their own registry rules and dispute procedures.
Third, because most phishing domains are registered for the purpose, the fastest response starts the day the name appears, before it is used against your customers or staff. Lookalike domains are often used for email fraud rather than websites: in a 2025 case highlighted by WIPO, a domain imitating General Electric was used in a scheme that almost diverted USD 800,000.
Which tools take down a phishing domain?
| Tool | Where it applies | What it achieves |
|---|---|---|
| Abuse report to registrar or registry | gTLDs, under ICANN’s 2024 contract amendments | Mitigation, such as suspension, where there is actionable evidence of phishing |
| Uniform Rapid Suspension (URS) | New gTLDs | Suspension for the rest of the registration period |
| UDRP | gTLDs and ccTLDs that have adopted it | Transfer to the brand owner |
| ccTLD procedures | Each country code (for example, the .es procedure) | Transfer or cancellation under local rules |
Since 5 April 2024, ICANN’s amended registrar and registry agreements define DNS abuse to include phishing and require registrars with actionable evidence to “promptly take the appropriate mitigation action(s)”. The URS procedure requires clear and convincing evidence, locks the domain within 24 hours of notice, gives the registrant 14 days to respond and aims for a determination within three business days of examination.
What this means for your business
- Extend domain monitoring to all new gTLDs and to the ccTLDs of every market where you sell or hire.
- Prepare an evidence kit in advance: trade mark certificates, screenshots and email headers, so abuse reports are actionable from day one.
- Use the right tool for the goal: abuse reports and the URS to stop the attack, the UDRP or the ccTLD procedure to take the name.
- Brief finance and customer teams: lookalike domains are often used for payment fraud by email.
If you want monitoring and takedowns run from one place, our domain monitoring and anti-phishing enforcement service covers gTLDs and the corridor’s ccTLDs.
Where brands get phishing response wrong
- Monitoring a short list of extensions while attackers use the whole namespace.
- Sending vague abuse reports. Registrars act on actionable evidence; a report without proof of phishing may sit unanswered.
- Using the UDRP when speed matters. Transfer takes weeks; suspension or mitigation can stop the attack sooner.
- Ignoring ccTLDs. ICANN’s contracts do not bind country-code registries, which follow their own rules.
Frequently asked questions
Why are new gTLDs used so often for phishing?
Interisle’s 30 June post does not analyse the causes; it reports that new gTLDs held 13% of registered domains but 46% of phishing domains from May 2025 to April 2026, the worst ratio of the three segments in every period since 2021. For brand owners, the practical point is to include new gTLDs in monitoring.
How quickly can a phishing domain be suspended?
It depends on the route. An abuse report to the registrar can lead to mitigation as soon as it has actionable evidence. In new gTLDs, the URS locks the domain within 24 hours of notice and targets a determination within three business days after examination starts, following a 14-day response period.
Can IP Global Guard monitor and take down phishing domains for us?
Yes. We set up monitoring across gTLDs and the ccTLDs of your markets, prepare evidence and abuse reports, and file URS, UDRP or ccTLD complaints where needed. For country-code procedures with local rules, we coordinate qualified correspondents across Europe, Latin America and Africa from a single point of contact.
How IP Global Guard can protect your brand online
Phishing domains move faster than most brand protection programmes. IP Global Guard, the IP services line of META Channel Corporation Limited, combines domain monitoring, enforcement and trade mark protection with one strategy across more than 25 jurisdictions in Europe, Latin America and Africa.
Tell us which brands and markets you need covered and any lookalike domains you have already seen. We will propose a monitoring scope and a response plan. Contact our brand protection team.
This article is general information, not legal advice, and reflects the data available on the date of publication.
Sources
- Interisle Consulting Group, Phishing Landscape 2026: comparing phishing activity across TLD market segments (30 June 2026)
- Interisle Consulting Group, Phishing Landscape 2026: summary findings (24 June 2026)
- ICANN, 2024 global amendments to the RAA and base gTLD Registry Agreement (effective 5 April 2024)
- ICANN, Uniform Rapid Suspension (URS) procedure (updated 21 February 2024)
- WIPO, 2025 record year for domain name disputes (14 January 2026)







