Skip to main content

Introduction to Typosquatting

Understand what typosquatting is and why it represents a security risk for your organization.

Written by Hugo

What is Typosquatting?

Typosquatting is the exploitation of typing mistakes by attackers to mislead users, redirect traffic, or impersonate your organization.

Instead of using your legitimate domain, attackers register or use similar-looking domain names to mislead users, redirect traffic, or impersonate your organization.


How does it work?

Attackers rely on common human errors to exert typosquatting such as:

  • Missing or added characters

  • Swapped letters

  • Incorrect domain extensions (e.g. .com vs .co)

  • Slight variations of your brand or domain name

For example, a user trying to access example.com could accidentally land on:

  • exmaple.com

  • example.co

  • examp1e.com

These variations can be used maliciously to impersonate your brand and mislead users.


Why is it a security risk?

Your brand is the primary door to your attack surface, and attackers use typosquatted domains for:

  • Phishing attacks (stealing credentials or sensitive data)

  • Brand impersonation

  • Malware distribution

  • Traffic redirection to malicious websites

As compromised variations can be exploited at any given moment, a continuous detection and risk priorisation of typosquatted domains is essential to protect your brand reputation.


How does Patrowl detect typosquatting ?

Patrowl automatically generates and monitors permutations of the top domains identified as part of your external attack surface.

Within our dashboard, you can:

  • Identify suspicious domain variations

  • Assess associated risk using evidence

  • Monitor and categorize permutations

  • Track related vulnerabilities and actions

Did this answer your question?