Link to home
Start Free TrialLog in
Avatar of isdd2000

asked on

Targeted email attacks

Hi Experts,

I have an issue were my domain is subject to a targeted email attack where they are using a similar domain name to impersonate them for example we are and they use for example. I have contacted the domain registra and they have canceled the account for but the domain will be available for purchase.

How do i stop this from happening.
Avatar of John
Flag of Canada image

Unless you wish to buy up all of domain.xy,tf or whatever, you cannot. People can purchase whatever domain they wish that is not owned. You have to purchase what you do not want sold to others.
Avatar of McKnife
A "targeted e-mail attack" would usually mean, someone of your company is being sent malware specifically appealing to him, like some attachment that has indeed a title that is of interest for his business.

What type of attack are you seeing? What has that to do with the domain name similarity?
Avatar of isdd2000


Hi McKnife,

What we are seeing is someone is using a domain name similar to ours but miss spelled in an attempt to trick our customers in changing the bank details on record for us. So when they go to pay an invoice they pay it to the wrong bank account, the hackers. Using this similar domain name and posing as legitimate staff members.
Ah, right.
You could only tell the authorities about it or, like you already did, the domain registra.
All customers should be aware that e-mail addresses can be faked. So they even could use your name with the correct spelling. If your clients wish to have secured and authenticated communication, use certificates and encrypted mails, no way around it.
Avatar of Dave Howe
Dave Howe
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I managed to get the fraudulent domains block, the domain registrar was asking for a court order to release the info they have on file so waiting on that. I've also reported it to the Australian cyber crimes commission or something like that.