A research demo by Have I Been Squatted

Look
again

This is not apple.com

The first five characters of this address are Cyrillic. They look like Latin characters, but they spell a different domain.

A research demo by Have I Been SquattedRead more
A Latin e made of tiny e characters and a Cyrillic ө made of tiny ө characters.

The address, character by character

Realapple.com
Lookalikeаррӏө.com

Your device's interface font, the same one as the address bar

Large size

To a computer, Cyrillic ө and Latin e are as different as a and b. Swap all five characters and you get a separate domain that anyone can register. We registered this one for the research.

Domain names can only contain basic Latin characters, digits, and hyphens, so your computer looks this one up as xn--80a6aa68c8d.com. Chrome shows that form instead when it decides a name is imitating another. This one passes the check, and the research explains why.

What is typosquatting?

How lookalike domains work

Typosquatting is registering a domain that looks like a real one, so people visit it by mistake or trust it at a glance. There are several ways to build one, from a simple misspelling to letters from another alphabet. The cases below are real, public incidents, in date order.

  1. 2006

    Misspellings

    A domain one typing mistake away from the real one.

    1. 2006A character replaced by a different one, as in exemple.com

      Google

      Realgoogle.com
      Lookalikegoggle.com

      One letter off: the second o is a g

      People who mistyped Google's address landed on a site that used a Windows image-file exploit to install SpySheriff, a fake anti-spyware program that demands payment to remove threats it invents.

  2. 2013–2016

    Misleading names

    The brand name appears in the address, but someone else owns the domain.

    1. 2013–2015Posing as a known company. No lookalike domain is on record

      Google and Facebook

      Posed asQuanta Computer, a real supplier
      DomainNot on record
      $121M
      paid out: $23M by Google in 2013, $98M by Facebook in 2015

      A Lithuanian man and accomplices posed as Quanta Computer, a hardware supplier both companies used. Fake email addresses, invoices, and corporate stamps were enough to get the payments approved. The court record does not name the email domains.

    2. March 2016The real name placed in front of a domain someone else owns, so it reads like the real site

      John Podesta

      Realmyaccount.google.com
      Lookalikemyaccount.google.com-securitysettingpage.tk

      The highlighted part is the domain the attacker registered. Everything before it is a subdomain they chose

      A fake Google alert said someone in Ukraine had used the password of Hillary Clinton's campaign chairman. Its shortened link opened a password page on this address. His Gmail account was taken, and its emails were later published.

  3. 2017–2019

    Lookalike characters

    A letter from another alphabet, or with a small mark, replaces a Latin letter.

    1. September 2017A character swapped for one that looks the same, often from another alphabet, as in еxample.com

      Adobe

      Realadobe.com
      Lookalikeadoḅe.com
      Punycodexn--adoe-x34a.com

      ḅ is Latin small letter b with dot below, U+1E05

      A fake Flash Player update on this domain installed Betabot, a backdoor that turns off security software and steals what people type into web forms.

    2. Early 2018A character swapped for one that looks the same, often from another alphabet, as in еxample.com

      EOS and MyEtherWallet

      Realeos.com
      Lookalikeẹos.com
      Punycodexn--os-g7s.com

      ẹ is Latin small letter e with dot below, U+1EB9

      Realmyetherwallet.com
      Lookalikemyethẹrẇallet.com
      Punycodexn--myethrallet-zk9e6w.com

      Fake EOS token airdrops sent people to a copy of the MyEtherWallet page, which asked for their private key. Whoever holds a private key controls the wallet and everything in it.

    3. January–March 2018A character swapped for one that looks the same, often from another alphabet, as in еxample.com

      Binance

      Realbinance.com
      Lookalikebịnạnce.com
      Punycodexn--bnnce-k11b2l.com

      Binance's own description: “2 dots at the bottom of 2 characters”

      2 min
      of automated buying on 7 March

      Phishing pages collected logins from early January and peaked around 22 February. The attackers made API keys for each stolen account and waited. On 7 March they used them to buy Viacoin from accounts they controlled at a pumped price. Binance's risk system halted withdrawals.

    4. May 2018A character swapped for one that looks the same, often from another alphabet, as in еxample.com

      Jet Airways

      Realjetairways.com
      Lookalikejetaırways.com
      Punycodexn--jetarways-ypb.com

      ı is Latin small letter dotless i, U+0131

      A WhatsApp message offered two free tickets for the airline's 25th anniversary. The page behind the link asked for personal details. Jet Airways warned customers that it ran no such offer.

    5. August 2018A character swapped for one that looks the same, often from another alphabet, as in еxample.com

      Delta, easyJet, and Ryanair

      Realdelta.com
      Lookalikedeǀta.com
      Punycodexn--deta-1kb.com

      ǀ is Latin letter dental click, U+01C0, standing in for l

      Realeasyjet.com
      Lookalikeeasyjeṭ.com
      Punycodexn--easyje-n17b.com
      Realryanair.com
      Lookalikeryanaiṛ.com
      Punycodexn--ryanai-1x7b.com
      15
      WhatsApp contacts each visitor had to share the offer with

      The same free-ticket script moved from brand to brand. Visitors answered four questions and forwarded the link, then landed on another site that likely asked for card details.

    6. August 2018

      British Airways

      Realbritishairways.com
      Attackerbaways.com

      No swapped letters. The name reads as BA plus airways

      429,612
      customers and staff whose data was exposed
      £20M
      UK data-protection fine, October 2020

      Attackers got in with a supplier's stolen remote-access login, not through this domain. They changed a script on BA's website and app, and from 21 August to 5 September 2018 it copied card details from the payment form to baways.com.

    7. October 2018–February 2019

      Bank of Valletta

      Realamf-france.org
      Lookalikeamf-fr.org

      amf-france.org belongs to France's financial markets regulator, the AMF

      €13M
      in fraudulent transfers sent abroad

      Emails posing as the AMF sent bank staff in France and Malta to Word documents on this domain. On 13 February 2019, attackers inside Bank of Valletta's network sent about €13 million in fraudulent international transfers. The bank took its branches, ATMs, and website offline to stop them. Public reports do not say which email gave the attackers access. In 2021, the US Justice Department tied the heist to North Korean military hackers.

  4. 2022–2026

    Phishing and supply chains

    Lookalike domains registered quickly and aimed at employees, developers, and the software they ship.

    1. July–August 2022A related word added to the name, as in secureexample.com

      0ktapus: Twilio, Cloudflare, and 130+ more

      Realtwilio.com
      Lookaliketwilio-sso.com
      Realcloudflare.com
      Lookalikecloudflare-okta.com

      Registered less than 40 minutes before the texts went out

      9,931
      credentials
      5,441
      one-time codes
      136
      organizations

      Text messages told employees their password had expired and linked to a copy of their company's Okta sign-in page. The page passed one-time codes to the attackers as people typed them. At Twilio they reached data of 125 customers, which exposed about 1,900 Signal users' phone numbers. At Cloudflare, three employees entered their passwords, but hardware security keys blocked the sign-in.

    2. September–October 2022A hyphen added inside the name, as in exam-ple.comA character replaced by a different one, as in exemple.comA related word added to the name, as in secureexample.com

      CircleCI, GitHub, and Dropbox

      Realcircleci.com
      Lookalikecircle-ci.com

      A hyphen added

      Lookalikecircle-cl.com

      A hyphen added, and l for i

      Lookalikeemails-circleci.com

      A word added in front

      130
      private repositories copied from Dropbox's GitHub

      Emails posing as CircleCI asked developers to sign in with GitHub to accept new terms. A proxy passed their password and one-time code to the attackers. A Dropbox employee typed in a code from a hardware key. The copied code held some API keys and a few thousand names and email addresses.

    3. July 2024–September 2025Letters replaced by others that read the same, such as rn for m or nn for m, as in exannple.com

      Microsoft 365: RaccoonO365

      Realmicrosoft.com
      Lookalikernicrosoft.com

      No Unicode: r and n set close together read as m

      5,000+
      Microsoft credentials
      94
      countries
      338
      domains seized

      A phishing kit rented by subscription cloned Microsoft 365 sign-in pages. Anyone could pay to run a campaign. Microsoft obtained a court order and seized the domains in September 2025.

    4. July 2025A character replaced by a different one, as in exemple.com

      npm: eslint-config-prettier

      Realnpmjs.com
      Lookalikenpnjs.com

      n for m. The email's support links went to the real npmjs.com

      30M+
      weekly downloads of eslint-config-prettier

      An email that looked like it came from npm support asked package maintainers to log in at a copy of the npm website. The maintainer of eslint-config-prettier did. With the stolen npm token, the attackers published new versions of that package and others by the same maintainer. Installing them on Windows ran a script that loaded malware.

    5. March 2026Two neighbouring characters swapped, as in eaxmple.comThe real name placed in front of a domain someone else owns, so it reads like the real siteThe same name with a different ending, as in example.org instead of example.com

      TeamPCP: Trivy, Checkmarx KICS, and LiteLLM

      Realaquasecurity
      Attackerscan.aquasecurtiy.org

      Two letters swapped. aquasecurity is the GitHub organization that publishes Trivy

      Realcheckmarx.com
      Attackercheckmarx.zone

      Same name, different ending

      Reallitellm.ai
      Attackermodels.litellm.cloud

      Same name, different ending, with a plausible subdomain

      2 days
      between registering aquasecurtiy.org and the first malicious release
      3
      open-source projects hit in six days

      Attackers used stolen credentials to push malicious code into Trivy, a popular security scanner, and its GitHub Actions, and published a malicious Trivy release. Pipelines that ran it sent their secrets to the lookalike domain. Credentials taken that way opened Checkmarx's KICS and LiteLLM's release pipeline, where a malicious PyPI release, litellm 1.82.8, sent credentials to models.litellm.cloud. The lookalike domains were not the way in; they served the malicious code and received the stolen data.

How to protect yourself

In each case above, someone trusted how an address looked. These habits do not depend on reading the address.

  • Do not trust how an address looks Browsers, email, and chat apps can all display this name as apple.com.
  • Go to sites directly Use a bookmark or type the address yourself instead of following links in messages.
  • Let a password manager fill in logins It matches the domain, not how it looks, so it will not fill your Apple Inc. password on this page.
  • Use passkeys or security keys where you can They only sign in to the domain they were made for. Security keys stopped the 0ktapus sign-in at Cloudflare. A typed one-time code did not stop the attacks at Twilio or Dropbox.
  • Keep your browser up to date Updates add to the checks browsers use to catch lookalikes. This name shows those checks still miss some.