Domain Name Scams: Exposing GoDaddy Impersonation and Expired Domain Recovery Tactics
Have you ever received a phone call from someone claiming to be from GoDaddy or ICANN regarding your domain names? You’re not alone. This article delves into the deceptive practices used by scammers targeting domain owners, particularly those who have let their domain names expire. Understanding these tactics is crucial to protecting yourself and your online assets.
The GoDaddy Impersonation Scam: A Growing Threat
Recently, I experienced firsthand the audacity of these scams. I received a call from an individual impersonating a GoDaddy representative. This wasn’t an isolated incident; the previous year, I encountered a similar scam involving someone claiming to be from ICANN. These experiences shed light on the sophisticated methods these scammers employ to exploit unsuspecting domain owners.
In August 2013, I received a phone call from someone who claimed to be working for ICANN. The purported purpose of the call was to verify the contact information associated with a couple of my domain names. However, a red flag immediately arose: the domain names in question had already expired.
The caller’s true intention became clear. He was attempting to gauge my interest in reclaiming these expired domain names. The end goal was to solicit me to re-purchase the domains at an inflated price.
That initial call led to the discovery of a larger scheme that involved click fraud. The scheme prompted individuals to click on PPC (Pay-Per-Click) advertisements on domain names owned by Domain Asset Recovery, a company that specialized in selling expired domain names back to their previous owners.
This seemingly innocuous “whois verification” pretext turned out to be a lucrative tactic for gauging interest in expired domains. Just recently, I received calls similar to the one from the previous year, further highlighting the persistence of this scam.
The Vurgo Connection: A Deeper Dive into Domain Recovery
On March 3rd, I received a phone call from someone claiming to be from GoDaddy’s verification department. The call immediately felt suspicious. The caller claimed they needed to verify my contact information for several domain names. As they recited the list, I recognized them as domain names that had previously expired.
Deciding to play along, I cooperated with the verification process. I confirmed the information previously listed in the whois records for the domains. When asked if I intended to continue using these domain names, I affirmed my interest.
I was certain that it was only a matter of time before I received another call, this time with an offer to sell the domains back to me. My suspicion proved correct the very next day, March 4th.
A woman representing Vurgo.com contacted me, claiming that Vurgo was a web development firm. She stated that they had recently acquired several domain names for upcoming projects. Because I was the previous owner of these domains, they wanted to offer me the opportunity to buy them back for $99 each before they put them to use.
She then recited the same list of domain names that the “GoDaddy” impersonator had used the previous day.
Once again, I decided to play along. Simultaneously, I checked to see if the domain names had actually been registered. Surprisingly, they had not…yet.
I informed her that I was still interested in using one of the domain names, TowerDiamond.com. Moments later, I observed that the domain name TowerDiamond.com was registered at Dynadot in the name of Vurgo LLC.
The caller offered to transfer me to someone who could process the transaction over the phone or to email me instructions. I requested the instructions via email.
On March 7th, I received another verification call, similar to the first one, with the new caller claiming to be from a “verification department that works with GoDaddy.”
The caller once again requested to verify contact details for domain names that I had previously let expire. When I inquired about his location, he responded evasively, stating, “I don’t have that information right now.” He then asked if I planned to keep and renew the domain names (which, of course, had already expired).
True to form, on the next business day, I received a call from Vurgo, informing me that they had recently registered several domain names I previously owned and offering to sell them back to me.
This time, I challenged them a bit. I informed the caller that I had just checked GoDaddy and the domains were still available.
“That’s impossible,” he replied. “They’ve already been registered.” As soon as he said this, he must have taken action, because the domains were suddenly registered. Checking Verisign’s whois timestamp, I confirmed that they registered the domains while I was still on the call.
During the call, I noticed a change in the caller’s voice. It sounded somewhat familiar. When I asked if I was speaking to the same person, the individual claimed to be the supervisor, who had taken over the call because I was asking too many questions and the initial caller was just a “rookie.” This supervisor identified himself as Darren Smith, and he had contacted me a couple of times earlier to confirm that I would pay for TowerDiamond.com.
I questioned “Darren” about why I had received calls about the same domains on Friday (alluding to the GoDaddy impersonator). He denied any involvement, questioning why his company would call on Friday and then wait until Monday to register the domains.
That’s a valid question. It’s understandable why someone might gauge interest with a “verification call” before buying a domain name in the drop market. However, in this case, they waited until I expressed interest in the domains before registering them.
The Web of Deception: Unveiling the Connections
The group that contacted me last August, impersonating ICANN, had a phone number linked to domain names used to perpetrate a click fraud scheme. This scheme involved prompting individuals to click on advertisements on domain names owned by Domain Asset Recovery, which was controlled by the same individual who runs Vurgo. In contrast, the calls I received this March originated from disposable numbers or numbers that do not accept incoming calls.
Regardless of who actually made the calls impersonating GoDaddy, they occurred exactly one business day before the corresponding calls from Vurgo regarding the same domains.
There are several possible reasons for this two-call approach. Perhaps the first call center or team is a lower-cost operation that seeks to identify verified leads for the closers.
One of the key individuals behind Vurgo (and previously Domain Asset Recovery) is John Bonk.
Bonk was also involved with the work-from-home program Wealth Investors. Bonk presented Wealth Investors at DomainFest in 2012. The service essentially charged people for access to knowledge on how to profit from expired domain names.
The Wealth Investors site eventually shut down, but Bonk launched another iteration of the “make money with expired domains” program under the name Click Millions. Its backers heavily promoted the program on NamePros.
Click Millions later ceased operations as well. It was the subject of numerous complaints on NamePros and complaints to the Better Business Bureau.
(While Wealth Investors/Click Millions promoted the idea of making money from parked domain names, at least one of the program’s owners was profiting from domains receiving fraudulent clicks as part of the click fraud scheme.)
I attempted to contact Bonk using the phone number listed in the whois records for many of his domain names. I received a message indicating that the number was temporarily disconnected. After several weeks of trying, I was finally able to reach him via email.
I informed Bonk that I was preparing to publish a story involving him, Vurgo, and the impersonation of GoDaddy to verify domain owner information.
Bonk responded, “Hi Andrew, the campaign you are referring to was terminated last week. Also, we never impersonated GoDaddy – we are a research and development firm at this point.”
I followed up by explaining the two separate calls—one from a GoDaddy impersonator and the next from Vurgo—and asked Bonk if he was aware that the call center or company he hired was engaging in these practices.
Bonk replied:
“I am unaware of that. We did purchase leads from a source that provided us with verified whois information for expiring domain names, and we do reach out to them to offer drop catching services. I never questioned how this information was obtained or what they said since we were only purchasing leads. But as I said before, we don’t use that company anymore.”
The Truth Behind the Lies: Exposing the Deceptive Tactics
Impersonation aside, the calls made on behalf of Bonk’s company, Vurgo, were riddled with falsehoods. The most significant lie was the claim that the company had already registered the domain names for development purposes when, in reality, the domains were still available for registration until the caller believed they had found a willing buyer.
Protecting Yourself from Domain Name Scams
This experience highlights the importance of being vigilant and skeptical when receiving unsolicited calls regarding your domain names. Here are some tips to help you protect yourself:
- **Verify the caller’s identity:** Always independently verify the identity of the caller by contacting GoDaddy or ICANN directly using their official contact information. Do not rely on the information provided by the caller.
- **Be wary of unsolicited offers:** Be cautious of unsolicited offers to buy back expired domain names, especially if they are accompanied by pressure tactics or claims of impending development.
- **Check domain registration information:** Always verify the registration status of your domain names through reputable whois lookup tools.
- **Report suspicious activity:** If you suspect that you have been targeted by a domain name scam, report the incident to the appropriate authorities, such as the Federal Trade Commission (FTC).
By staying informed and taking proactive steps, you can protect yourself from becoming a victim of these deceptive domain name scams.