Skip to content

How Typosquatters Trick Holiday Shoppers

December is a peak online shopping season, with Cyber Monday alone reaching billions of dollars in sales. Because the internet is flooded with deals, many shoppers let their guards down and become susceptible to typosquatters, who trick consumers into buying counterfeit products or giving away sensitive information. It's important for payment service providers to be aware of these merchants entering their portfolios at this time of year.

 

What is Typosquatting?

Typosquatting is a deceptive tactic typically intended to trick internet users into visiting websites they believe are operated by a trusted entity. Instead, the websites may attempt to steal a user's information, sell counterfeit products or services, or engage in other forms of illicit activity that can harm consumers and damage brands.

Typosquatters capitalize both upon genuine typographical errors that an unwitting user might enter - for example facebook.cm or faceboook.com - as well as visually deceptive domain names an internet user might not immediately recognize as falsified.

 

What Are Some Typosquatting Tactics?

There are many methodologies typosquatters use to mimic an authentic domain name. Often a typosquatter will make use of a typo, such as disneyy.com, or will use an alternative top level domain (TLD), such as disney.om.  Other cybercriminals trick consumers using trailing text, such as disney-official.com. There are more sophisticated techniques as well; see our typosquatting guide for some real examples.

 

What to Watch Out For

While consumers should carefully scrutinize every new website they visit, payment service providers can also take action to prevent typosquatters from appearing in their portfolios. They can:

  • Watch out for merchants applying for merchant accounts with domain names that are suspiciously similar to well-known brands.
  • Carefully scrutinize merchants using domain names that include common typosquatting techniques, such as starting a domain name with "www-."
  • Invest in merchant monitoring services, such as those provided by LegitScript, to quickly flag suspicious merchants who may be engaged in phishing, IP infringement, or other problematic activity.

 

Want to learn more? Download our Typosquatting Guide for more examples and a case study of an offshore internet service provider operating as a cybersquatting safe haven.

person typing on a mobile phone

 

Recent Blog Articles

Why LegitScript Certification Is Your Passport in 2025: A Recap for Healthcare Businesses

In a dynamic regulatory landscape where risk, reputation, and compliance increasingly determine access to financial services, healthcare businesses face a unique challenge. A recent webinar hosted by LegitScript - featuring Rob Bast, chief sales officer at Corepay, and Angela Salter, director of sal...

LegitScript & Special Guest Marketplace Risk Panel Recap: How to Stay Ahead of Global Regulations and Trends: Using Deep Intelligence to Shape Policy and Mitigate Risk

At Marketplace Risk, experts tackled the challenges of content moderation and platform responsibility, focusing on drug-related content, evolving evasion tactics, and the balance between AI and human oversight. Transparency and proactive safety measures took center stage. Listen below to an excerpt...
FDA updates REMS program for common abortion drug mifepristone.

Key Takeaways from LegitScript’s Webinar: Navigating Risks and Regulations in Online Abortion Pill Sales

The online sale of abortion medication is at the center of a rapidly evolving regulatory and risk environment. In LegitScript's June 2025 webinar, Online Abortion Pill Sales: Navigating Regulations and Problematic Activity, experts outlined how recent legal changes are reshaping access to medication...

Merchant Onboarding Essentials: What You Need to Know

Modern merchant onboarding involves much more than collecting documents - it's about building a smart, scalable risk management process that can keep up with changing technology and fraud tactics. Whether you're launching a payments platform or refining your underwriting approach, getting onboarding...