Criminals Spent Almost $7 Million Buying Expired Web Domains to Push Scams and Malware
Infoblox says 50,400 'dropcatch' domains were scooped up in the first half of 2026 to inherit the trust of the sites that came before them.

Key points
- Infoblox, a DNS threat intelligence firm, tracked 50,400 expired domain names bought by criminals in the first half of 2026.
- The buyers spent close to $7 million snapping the domains up the moment previous owners let them lapse.
- Infoblox calls the practice 'dropcatch': grabbing a name the instant it drops back onto the market.
- The reused domains send unsuspecting visitors to scam pages and malware downloads while borrowing the old site's search ranking and reputation.
- The finding lands as regulators keep pressing registrars for stronger checks on who buys what, though no binding federal rule yet targets dropcatching directly.
A domain name is the address you type into a browser, like example.com. When the owner stops paying for it, the name expires and eventually becomes available again for anyone to register.
Criminals have turned that quiet moment into a business.
According to research from Infoblox, a company that watches the internet's address system for signs of abuse, hackers spent nearly $7 million in the first half of 2026 buying up expired names. The count reached 50,400 domains. Infoblox has a term for the tactic: 'dropcatch', meaning the domain is caught the second it drops back onto the market.
The appeal is simple. An expired domain often carries years of built-up trust: inbound links from other websites, a spot in Google's search results, and email addresses that people still write to. A new owner inherits all of that on day one.
Why would a criminal want an old, expired domain?
Because an old domain looks legitimate to both people and machines. A freshly registered site raises red flags with spam filters and browser warnings. A domain with a long history usually does not.
Buyers use the reputation to send visitors to fake shopping sites, investment scams, and pages that quietly install malware, meaning software designed to steal data or take over a device. Search engines may still list the old site's pages, so a shopper clicking a familiar link ends up somewhere very different from what they expected. Emails sent from the domain are more likely to land in inboxes rather than spam folders.
The original reporting on the Infoblox findings came from The Hacker News.
How does dropcatching actually work?
Registrars, the companies that sell domain names, release expired names back to the pool on a predictable schedule. Specialist services monitor that schedule and fire off automated registration requests the instant a name becomes available, often winning it in milliseconds.
Those services are legal and have legitimate uses. Investors trade domains the way others trade property. The problem is that the same speed and automation let criminals win valuable names before anyone else notices they were up for grabs.
| Metric | Figure |
|---|---|
| Dropcatch domains bought by criminals | 50,400 |
| Period | H1 2026 |
| Estimated spend | close to $7 million |
| Source | Infoblox DNS threat intelligence |
What can ordinary internet users do about it?
Treat a familiar-looking link with a little more suspicion than you used to, especially if the page it loads feels off. Look for sudden design changes, spelling mistakes, or requests for payment details on a site that never asked before. If a bookmarked shop or service suddenly redirects to something unfamiliar, close the tab and search for the company fresh.
For businesses, the lesson is quieter but sharper: do not let your own domains expire. A lapsed marketing site or old campaign URL can be bought within hours and pointed at anything the new owner wants, with your customers still trusting the address.
Common questions
Is buying an expired domain illegal?
No. Buying a domain that has been released back to the market is legal. What the new owner then does with it, running a scam, hosting malware, impersonating the old brand, can be illegal on its own terms.
How can a company keep its old domains safe?
Pay for auto-renewal, keep contact details current with the registrar, and keep a written inventory of every domain the business owns, including ones no longer in active use.



