Introduction

Every domain name ends in a top-level domain, the segment furthest to the right, past the final dot. In example.com, the top-level domain is .com. In example.com.sa, it is .sa, with .com.sa functioning as the registered structure beneath it. This segment is not decorative. It is the entry point into the Domain Name System's root zone, the level at which the internet's naming hierarchy is organized and delegated.

The Internet Assigned Numbers Authority maintains this hierarchy on behalf of the Internet Corporation for Assigned Names and Numbers. Every domain registered anywhere on the internet sits beneath one of the top-level domains recorded in that root zone. How those top-level domains are categorized, and how registration works differently across them, is where a costly and frequently overlooked threat begins.

Top-Level Domain Categories

IANA and ICANN classify top-level domains into three primary categories, plus one reserved for technical infrastructure.

Generic top-level domains, or gTLDs, are not tied to any country or restricted community. The original set, introduced in the 1980s, included .com, .net, and .org, and these remain the most widely registered extensions in use. Since 2012, ICANN's new gTLD program has expanded this category substantially, growing the number of available generic extensions from roughly twenty to well over a thousand, with additions such as .app, .shop, and .tech. These newer extensions are not a separate category sitting alongside gTLDs. They are gTLDs, added through an expansion round rather than a new tier of the DNS hierarchy.

Country-code top-level domains, or ccTLDs, represent specific countries or territories, assigned according to the ISO 3166-1 country code standard. Examples include .sa for Saudi Arabia, .uk for the United Kingdom, and .us for the United States. Each ccTLD is delegated to a local registry operating under policies suited to that country's legal and administrative environment.

Sponsored top-level domains, or sTLDs, serve a defined community under a sponsoring organization that sets registration criteria. Examples include .gov, .edu, and .mil, each restricted to a particular category of registrant rather than open to general registration.

One more exists outside all three. The .arpa domain is reserved for technical infrastructure, administered by IANA in coordination with the Internet Architecture Board. It hosts no public-facing organizational domains and plays no role in brand or domain security planning.

For most organizations, the domain footprint that matters is really just gTLDs and ccTLDs. Between them sits the gap this article is about.

Types of TLD Attacks

Two related but distinct techniques exploit the way top-level domains are registered and perceived: typosquatting and TLD squatting. Both fall under the broader category of domain squatting, where an actor registers a domain resembling an existing one for deceptive or extortionate purposes.

Typosquatting targets errors in how a domain is typed or remembered. An attacker registers a misspelled or visually similar variant, such as exampel.com in place of example.com, betting that some share of users will mistype the address and land on the fraudulent version instead. Large-scale DNS traffic research has found typosquatting to be a persistent source of diverted traffic. A related technique, combosquatting, pairs a brand name with an extra word such as login or support. It now generates more abusive domains, and more click-through traffic, than typosquatting does.

TLD squatting, sometimes called TLD hijacking, works on a different axis entirely. No misspelling occurs. The attacker registers the identical second-level name under a different top-level domain than the one the legitimate organization actually uses. Typosquatting depends on a user's fingers. This one depends on a gap in an organization's own registration coverage, and on a user's uncertainty about which extension the organization actually holds.

The rest of this article stays with that second technique.

What is TLD Hijacking

TLD hijacking occurs when an organization secures its domain under one top-level domain, typically a country-code extension tied to its home market, and leaves the equivalent generic top-level domain unregistered. An attacker registers that open generic domain. Impersonation follows.

The mechanism works because domain registration is not unified across extensions. Ownership of a name under .sa carries no claim to that same name under .com, .net, or anywhere else. Each top-level domain runs its own independent registry. A name being taken in one has no bearing on its availability in another.

Take an organization operating as nationalbank.com.sa; it's a registered and actively used domain within Saudi Arabia. Its operations and customer base are entirely domestic, so it never registers nationalbank.com. The extension seemed unnecessary for a business that has never operated outside the country.

.com.sa secured .com open to anyone

An attacker checks. The domain is open. Registration takes minutes and costs a small annual fee. From that point, the attacker controls a domain sharing the organization's exact brand name, differing only in an extension most users never think to verify.

From there, the attacker can build a site replicating the bank's design, host it at that domain, and configure mail service to send correspondence from addresses such as billing@nationalbank.com. A customer arriving through search results, a social link, or a mistyped bookmark has no reliable way to tell the domain apart from the real one without checking the extension directly, which most people don't do. The organization's domain security on the .sa side, however rigorous, does nothing here. The exposure sits on a domain the organization never owned.

Risks Associated with TLD Hijacking

Phishing attacks. Fraudulent websites resembling the legitimate organization can be used to steal usernames, passwords, and payment details.

Malware distribution happens the same way hijacked domains get used for anything else malicious, whether that's ransomware, spyware, or a drive-by download aimed at whoever trusts the domain enough to visit it.

Reputation damage tends to land regardless of fault. Fraudulent activity conducted through a hijacked domain erodes trust in the brand even when the legitimate organization did nothing wrong.

Traffic redirection sends visitors to competing or malicious sites instead, which shows up eventually as lost revenue or a dent in reputation that's hard to trace back to its source.

Email spoofing and fraud round out the list. Hijacked domains are routinely used to send fraudulent correspondence, impersonating the legitimate organization to deceive customers or partners who have no reason to suspect the sender address.

Preventive Measures for TLD Hijacking

Secure key TLDs first. Register the primary domain across the generic extensions most relevant to the business, particularly .com, .net, and .org, along with the country-code extensions tied to markets where the organization actually operates. Extensions carrying high impersonation risk are worth claiming even in markets the organization doesn't directly serve.

Domain portfolio management comes next: regular audits to catch gaps or unregistered extensions, paired with monitoring tools that can claim newly introduced top-level domains before someone else does.

Monitoring new registrations similar to the organization's primary name is the ongoing version of the same discipline. When something malicious turns up, dispute mechanisms like the Uniform Domain-Name Dispute-Resolution Policy exist to reclaim or challenge it.

Stakeholder education matters more than it gets credit for. Employees, customers, and partners who know to verify a domain before interacting with it catch a lot of what technical controls miss.

And domain locking, simple as it is, prevents unauthorized changes to registration settings on domains already secured. It's the last line, not the first, but it matters.

Real-World Example

Consider again a multinational bank operating under nationalbank.com.sa. The domain is DNSSEC-signed, monitored continuously, locked against unauthorized transfer. By every internal measure, its domain security posture is strong.

None of that extends to nationalbank.com, which the bank never registered. An attacker acquires it and builds a page close enough to the real one to survive casual inspection. Customers searching for the bank, or arriving through a mistyped bookmark, land on the fraudulent domain and hand over credentials the attacker now holds. Partners receiving mail from billing@nationalbank.com have no reason to doubt it. The domain carries the bank's exact name.

The damage traces back to one gap: a top-level domain the bank considered irrelevant to a domestic business, left open for anyone to take.

Conclusion

TLD hijacking isn't a flaw in the domains an organization secures. It's a consequence of the domains it never registers at all. Ownership under one top-level domain grants no protection under any other, so closing this gap means treating domain registration as a portfolio decision, not a single purchase, one that accounts for every extension a customer, partner, or search engine might reasonably associate with the brand.

Securing the domains already in use isn't enough on its own. The organizations most exposed to TLD hijacking are often the ones whose existing domain security looks the strongest, because that strength is exactly what creates the false confidence masking the gap sitting just outside it.

Sources

Internet Assigned Numbers Authority (IANA). "Root Zone Management." iana.org/domains/root

Internet Assigned Numbers Authority (IANA). "Root Zone Database." iana.org/domains/root/db

Internet Corporation for Assigned Names and Numbers (ICANN). "Top-Level Domains (gTLDs)." icann.org/tlds

Internet Corporation for Assigned Names and Numbers (ICANN). "TLD Delegation Practices." archive.icann.org/en/icp/tld-deleg-prac.html

Kintis, Panagiotis, et al. "Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse." Georgia Institute of Technology and Stony Brook University. arxiv.org/pdf/1708.08519

Cloudflare. "What is Cybersquatting?" cloudflare.com/learning/dns/what-is-cybersquatting

Akamai. "The Most Common Combosquatting Keyword Is 'Support'." akamai.com/blog/security-research/combosquatting-keyword-analysis-support

World Intellectual Property Organization (WIPO). "Domain Name Disputes." wipo.int/en/web/amc/domain-name-disputes