Phishing Landscape 2025: An In-Depth Analysis of Domain Abuse
The digital world faces a constant barrage of threats, and phishing remains one of the most prevalent and damaging. Interisle, a respected internet security and cybercrime research firm, has released its annual Phishing Landscape 2025 report, providing critical insights into the domains and registrars most frequently exploited for phishing attacks. This report is an essential resource for anyone seeking to understand and combat the evolving landscape of online fraud.
This comprehensive study, analyzing over four million phishing reports collected between May 2024 and April 2025, meticulously identifies the top-level domains (TLDs) and registrars that are disproportionately associated with malicious activities. The findings provide a clear picture of where phishing attacks originate and offer valuable data for developing effective countermeasures.
The Most Abused Top-Level Domains: A Per Capita Analysis
Interisle’s report introduces a metric called the “Phishing Score,” which provides a per capita assessment of TLD abuse. This metric normalizes the data, allowing for a fair comparison between TLDs of varying sizes. The Phishing Score reveals which TLDs are most likely to host phishing websites relative to their overall size, offering a more accurate representation of the risk associated with each domain extension.
According to the Phishing Landscape 2025 report, the following five TLDs exhibit the highest Phishing Scores, indicating a significant prevalence of phishing activity:
- .xin
- .bond
- .help
- .win
- .cfd
The prominence of these TLDs in phishing attacks highlights the importance of understanding the factors that contribute to their exploitation. Cheap registration prices, lax enforcement policies, and the perception of novelty or legitimacy can all make these TLDs attractive to cybercriminals.
.xin: A Hotspot for Unpaid Toll Scams
The .xin TLD stands out significantly in the report, primarily due to its association with unpaid toll scams. Interisle’s analysis indicates that nearly all .xin domains involved in phishing schemes were registered through Dominet, a company owned by Alibaba. This concentration of abuse at a single registrar suggests a potential weakness in enforcement or a targeted exploitation of Dominet’s services.
The sheer scale of .xin abuse is alarming. The report assigns a staggering Phishing Score of 10,810 to .xin, far exceeding the score of 1,759 for .bond, the second most abused TLD. This vast disparity underscores the severity of the problem and the urgent need for targeted interventions to mitigate the risk associated with .xin domains.
.com: A Benchmark for Comparison
In contrast to the high-risk TLDs, the .com domain serves as a benchmark for comparison. Despite being the most popular TLD globally, .com has a Phishing Score of only 30. This relatively low score demonstrates that popularity alone does not necessarily correlate with a high risk of phishing abuse. The mature security infrastructure and robust enforcement mechanisms surrounding .com likely contribute to its resilience against phishing attacks.
The Correlation Between Cost and Phishing: A Driving Factor
The Interisle report reveals a strong correlation between the cost of domain registration and the prevalence of phishing activity. The most abused domains typically share a common characteristic: they are inexpensive to register. This cost-effectiveness makes them attractive to phishers who operate on a large scale, registering numerous domains to maximize their chances of success.
The following image from the report illustrates this correlation, visually demonstrating the relationship between domain cost and Phishing Score:

This correlation underscores the need for a multi-faceted approach to combating phishing. While cost is a significant factor, it is not the only determinant. Registrars must also implement robust verification procedures, actively monitor for suspicious activity, and promptly respond to abuse reports to mitigate the risk of phishing attacks.
The Shifting Landscape of Subdomain Abuse
Last year’s Interisle report highlighted the increasing use of free subdomains for phishing attacks. This trend has shifted somewhat in the current report. While subdomain abuse remains a concern, its prevalence has decreased in certain areas due to proactive measures taken by major platforms like Google.
Google’s efforts to reduce abuse on domains like blogspot.com have had a noticeable impact, leading to a decline in phishing activity on those platforms. However, this has also resulted in a displacement effect, with phishers shifting their focus to other platforms offering free subdomains. The report notes an increase in abuse of subdomains at webflow.io and vercel.app, indicating that the problem is not eradicated but rather redirected.
This dynamic highlights the ongoing cat-and-mouse game between security professionals and cybercriminals. As security measures improve on one platform, phishers adapt and seek out new vulnerabilities elsewhere. Continuous monitoring and adaptive security strategies are essential to stay ahead of these evolving threats.
The Registrars with the Highest Incidence of Phishing Domains
The Interisle report identifies the registrars with the highest incidence of phishing domains. These registrars play a crucial role in the ecosystem, as they are the gateway through which phishers acquire the domains used in their attacks. The report names the following five registrars as having the highest association with phishing domains:
- NiceNic
- Aceville
- Dominet
- Webnic
- OwnRegistrar
The inclusion of these registrars in the report does not necessarily imply malicious intent or direct involvement in phishing activities. However, it does highlight the need for these registrars to加强 their security measures and actively combat abuse on their platforms. This includes implementing stricter verification processes, monitoring for suspicious domain registrations, and promptly responding to abuse reports from security organizations and the public.
ICANN’s Warning on DNS Abuse Rankings
ICANN (Internet Corporation for Assigned Names and Numbers), the organization responsible for coordinating the global DNS (Domain Name System), recently warned that DNS abuse rankings can vary significantly depending on the blocklist sources used. This variability arises from the different methodologies, coverage, and biases inherent in each blocklist.
Interisle’s Phishing Landscape 2025 report sources its data from a combination of reputable anti-phishing organizations, including the Anti-Phishing Working Group (APWG), OpenPhish, PhishTank, and Spamhaus. By drawing data from multiple sources, Interisle aims to provide a more comprehensive and representative view of the phishing landscape. However, it is important to acknowledge that the findings may still be subject to the limitations inherent in the underlying data sources.
Conclusion: A Call for Collaborative Action
The Phishing Landscape 2025 report from Interisle provides invaluable insights into the ever-evolving world of phishing attacks. By identifying the most abused TLDs and registrars, the report helps stakeholders prioritize their efforts and develop targeted strategies to combat online fraud.
The report highlights the importance of factors such as domain cost, enforcement policies, and the proactive measures taken by platforms like Google in shaping the phishing landscape. It also underscores the need for continuous monitoring, adaptive security strategies, and collaboration between security organizations, registrars, and domain registries.
Ultimately, combating phishing requires a collective effort. By working together, stakeholders can create a safer and more secure online environment for everyone.