The research center changed its name. The annual conference moved to a new site. The grant ended and nobody renewed the project domain. Years later, someone else owns it, and every old link in a syllabus, PDF, email signature and search result now points to them.
Infoblox Threat Intel calls these "dropcatch" domains, and its August research shows how big the business has become.
What happened
Infoblox found that about 65,000 previously owned domains are re-registered every day. In the first half of 2026, they made up nearly 20% of all new domain registrations. For .net, the rate was close to 30%; for .com, 24.5%.
Many buyers are harmless. Some are not:
- Sable Squirrel spent more than $7 million on over 10,000 expired domains, using them for illegal streaming sites that also served as command-and-control for malware such as Quasar RAT and HiddenTear ransomware.
- Shady Squirrel partnered with SocGholish, the well-known "fake browser update" operation, to push malware through scareware and call centers.
- Scavengers watch for compromised websites, wait for those domains to expire, then buy them to inherit the victim traffic and redirect it to scams.
Why pay for an old domain? Because it inherits reputation and sometimes connections from its previous life. Email filters, web proxies and search engines treat a 10-year-old name more kindly than a brand-new one.
Why it matters for Texas institutions
Your .edu or .gov domain is hard to lose. The problem is everything else. Universities and agencies register dozens of .com, .org and .net names over the years for conferences, research centers, outreach programs, campaigns and grant-funded projects. They are often bought on a personal credit card and tied to one person's email.
When that person leaves, the renewal notice goes nowhere. The domain drops, and an attacker gets a ready-made, trusted address with years of links from your own pages pointing to it.
What your institution should do
- Inventory every domain you own. Ask departments, centers and communications teams, not just central IT.
- Put renewals on an institutional account. Use auto-renew and a shared mailbox, never a single employee's address.
- Keep important names even after retirement. A few dollars a year is cheap insurance for a domain with years of reputation.
- Scrub old links. Search your own sites and documents for retired domains and remove them.
- Treat age as no guarantee. A long-registered domain is not automatically safe; watch for sudden content or ownership changes.
RSOC is here to help
RSOC can help map domains associated with your institution and flag ones that have lapsed or changed hands. Contact rsoc@utexas.edu.
Sources: Infoblox Threat Intel · Security Affairs · SC Media