Business Wire

Holiday Shopping Warning: Simple Typos Can Lead Consumers and Brands to Online Fraud, Counterfeit Goods, and Cyber Crime

Share

CSC, a world leader in business, legal, tax, and domain security, today released new research from their Digital Brand Services (DBS) division warning consumers that simple URL typos could lead to significant online fraud, counterfeit goods, and cyber crime during the holiday shopping season. The company identified and analyzed registered domain typos (misspellings) associated with the 10 largest online shopping brands in the world and found that over 70% of the 1,553 registered domain typos appear to be owned by third parties.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20201117005233/en/

To view this piece of content from mms.businesswire.com, please give your consent at the top of this page.

(Graphic: Business Wire)

According to CSC’s new research, these third-party owned domains receive over five million visitors annually. In addition, 40% of these domains are using domain privacy services to mask or hide their ownership and identity, and close to 48% are configured with MX (mail) records that can be used for phishing and to intercept email. In its blog, CSC offers tips to both brand owners and consumers to protect themselves against fraudulent web properties and content.

A deep dive of the top 100 most visited typo domains shows they are being used in this manner:

  • 38% are pointing to advertising-related and pay-per-click web content, which can be used to spread malware via domain parking services
  • 27% had no live web content, yet 37% were configured to send and receive email with MX records
  • 15% were engaged in affiliate referrals, which means the brand owner could be targeted for unauthorized affiliate activity resulting in loss of revenue
  • 12% were pointing at shopping-related web content, which indicates that consumers could engage with nefarious retailers selling counterfeit goods while brand owners lose revenue
  • 8% were pointing toward malicious web content e.g., malware

During the holiday shopping season, just one hour of downtime can cost a business over $500,000 in lost revenue*. Despite this, many global eCommerce and shopping companies are still lacking basic domain security measures that could prevent this from happening. For instance, only 16% of the top 500 global eCommerce and shopping domains leverage domain name system (DNS) hosting redundancy, which could secure their online presence from a distributed denial of service (DDoS) attacks. In addition, only 18% use registry locks that prevent DNS hijacking attacks that could redirect consumers to alternate websites. Lastly, 40% of retailers do not use enterprise-class domain registrars. This is partially explained by the fact that 40% of the observed domains still rely on retail registrars that typically don’t provide advanced domain security features.

In light of the global pandemic, both consumers and leading brands have embraced online shopping as we head into the 2020 holiday season. As such, we wanted to call attention to how brands and consumers are at increased risk for a multitude of threat vectors associated with online fraud, counterfeits, revenue leakage and many other cyber criminal activities this year,” says Ihab Shraim, chief technology officer for CSC. “As evidenced by the sheer number of mail-in votes in the U.S. election, consumers are looking for safe alternatives to in-person interactions, and it’s important for brands to not only provide those digital channels, but also ensure they are secure from online threat vectors.”

“We’re delighted that companies like CSC are advocating for companies and online brands to put the necessary security protocols in place to protect not only their brand reputation, but their consumers, from online fraud and cyber crime,” says Daniel Eliot, director of Education and Strategic Initiatives at the National Cyber Security Alliance (NCSA). “The NCSA's mission is to educate consumers and businesses about these credible risks, and the importance of using recommended cyber security best practices. CSC’s research is also an important part of advocating for consumers, and showing the pervasive risk of these cyber attacks and fraudulent domains.”

Additional resources:

*gremlin.com/ecommerce-cost-of-downtime/

About CSC

CSC is the trusted provider of choice for the Forbes Global 2000 and the 100 Best Global Brands® in enterprise domain names, domain name system, digital certificate management, as well as digital brand and fraud protection. As global companies make significant investments in their security posture, CSC can help them understand known security blind spots that exist and help them secure their digital assets. By leveraging CSC’s proprietary solutions, companies can get secure to protect against cyber threats to their online assets, helping them avoid devastating revenue loss, brand reputation damage, or significant financial penalties because of policies like the General Data Protection Regulation (GDPR). CSC also provides online brand protection—the combination of online brand monitoring and enforcement activities—taking a holistic approach to digital asset protection, along with fraud protection services to combat phishing. Headquartered in Wilmington, Delaware, USA, since 1899, CSC has offices throughout the United States, Canada, Europe, and the Asia-Pacific region. CSC is a global company capable of doing business wherever our clients are—and we accomplish that by employing experts in every business we serve. Visit cscdbs.com.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

Christine Blake
W2 Communications
703-877-8114
CSC@w2comm.com
CSC News Room

About Business Wire

Business Wire
Business Wire
24 Martin Lane
EC4R 0DR London

+44 20 7626 1982http://www.businesswire.co.uk

(c) 2018 Business Wire, Inc., All rights reserved.

Business Wire, a Berkshire Hathaway company, is the global leader in multiplatform press release distribution.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Bureau Veritas: Strong Start to the Year; 2024 Outlook Confirmed25.4.2024 09:20:00 CEST | Press release

Q1 2024 Key figures1 › Revenue of EUR 1,439.5 million in the first quarter of 2024, up 2.5% year-on-year and up 8.0% organically › Strong organic growth from Industry +16.3%, Certification +13.7%, Marine & Offshore +13.6%, compared to the first quarter of 2023; growth of +6.1% for Consumer Products Services, +3.6% for Buildings & Infrastructure and +3.2% for Agri-food & Commodities › The scope effect was a positive 0.1%, reflecting bolt-on acquisitions offset by a small disposal › The currency impact was negative by 5.6% mainly due to the depreciation of some emerging countries’ currencies against the euro Q1 2024 Highlights › New strategy LEAP | 28, announced on March 20, 2024, to deliver a step change in growth and performance, built around three pillars: Focused Portfolio, Performance-led execution and Evolved People model › Strong growth in every region (Americas, Middle East, Africa, Asia-Pacific and Europe), outperforming many underlying markets › Growth momentum maintained for s

New CPS Protection Platform: TXOne Networks Presents SageOne in Hannover25.4.2024 09:04:00 CEST | Press release

TXOne Networks, a leading company in the field of cyber-physical systems (CPS) security, will be presenting its new CPS security platform during the Hannover Messe from 22nd to 26th April 2024 at stand B06 in hall 16: SageOne, which means Wise Man Number One. This central management console provides an overview of the CPS attack surface of the OT environment. All three TXOne product lines can be centrally controlled, namely Stellar for endpoint protection, Element for security inspection and Edge for network defense. The platform offers integrated OT security across the entire lifecycle of the objects to be protected and enables reliable detection and response to threats. SageOne essentially covers three main pillars: CPS Attack Surface Management: Visibility is a cornerstone for cybersecurity. A clear view of the overall security posture helps identify security focal points in an OT environment. SageOne focuses on operational security by honing in on assets and illuminating the securi

Infobip becomes an Oracle Independent Software Vendor partner25.4.2024 09:00:00 CEST | Press release

Infobip, a global cloud communications platform and a member of Oracle PartnerNetwork (OPN), today announced it has enhanced its relationship with Oracle, becoming an Independent Software Vendor (ISV) with access to Oracle Integration Cloud. Businesses using any Oracle solution can access Infobip’s omnichannel platform through Oracle Cloud Marketplace (OCM). They can quickly orchestrate powerful interactions, help increase customer satisfaction, boost sales, and improve campaign performance. Oracle Cloud Marketplace is a one-stop shop for Oracle customers seeking trusted business applications and services offering unique solutions, including ones that extend Oracle Fusion Cloud Applications. Infobip’s communication channels will enable businesses to deliver conversational experiences across many sectors including banking and financial services, retail and ecommerce, and hospitality and leisure. Through Infobip’s collaboration, Oracle users will gain customer insights, enabling them to

Global CIOs geared up to scale AI but organizations aren’t as ready25.4.2024 05:00:00 CEST | Press release

AI is the CIO’s top priority, according to findings of Lenovo’s third annual global CIO report. Inside the Tornado: How AI is Reshaping Corporate IT Today, reveals that while CIOs need to adopt and scale AI urgently, their ambitions are threatened by speed, security, and other organizational functions lagging in AI readiness. In a stark contrast to previous years, CIOs are tabling non-traditional responsibilities to sharpen their focus on core IT functions. Slightly more than half (51%) of CIOs feel AI/ML is an urgent priority to address, matched only by cybersecurity. This urgency is directly correlated to the pressure that CIOs are under to drive business impact, rather than operational maintenance and preservation. 84% of CIOs revealed they are being evaluated on business outcome metrics more than ever before. “Today’s CIOs are working in a tornado of innovation. After years of IT expanding into non-traditional responsibilities, we’re now seeing how AI is forcing CIOs back to their

Mundipharma acquires all assets and rights related to REZZAYO ® (rezafungin) , reinforcing continued commitment to management of infectious diseases and specialty care therapeutic area24.4.2024 22:01:00 CEST | Press release

Mundipharma* today announced the acquisition of all assets and rights related to rezafungin globally from Cidara Therapeutics. This provides Mundipharma with global ownership of rezafungin including ongoing development and distribution. Rezafunginis a novel once-weekly echinocandin indicated for the treatment of invasive candidiasis in adults.1 Invasive candidiasis, is a severe, life-threatening infection of the bloodstream and/or deep/visceral tissues.2,3 It affects seriously ill people, especially those with a weakened immune systemand the mortality rate can be 40%4 or more.5,6 It can place a large burden on the healthcare system, with the potential for extended treatment regimens and long hospital stays.6 Over the last 15 years, there have been no new treatments and morbidity and mortality rates remain largely the same, indicating the need for alternative treatment options.7,8 “This acquisition places Mundipharma in the best position to realise the full potential of rezafungin inclu

HiddenA line styled icon from Orion Icon Library.Eye