Reported phishing domains have grown sharply since 2020, and the headline figures now circulating in domain-industry and cybersecurity coverage are genuinely large: more than 1.5 million domain names reported for phishing in a recent 12-month period, according to data Interisle Consulting Group presented to ICANN’s Governmental Advisory Committee, an increase of more than 425% since mid-2020. Those numbers deserve to be taken seriously. They also deserve a more careful reading than they typically receive, because a parallel and less-publicized debate about how this data is compiled has direct implications for what the numbers can and cannot justify — including which registries, registrars, and hosting providers should be held responsible for what, and what kind of intervention is actually appropriate for each type of abuse.

What the Headline Numbers Show

Interisle’s fifth annual phishing report, Phishing Landscape 2025, released in September 2025, analyzed nearly four million phishing reports collected between May 2024 and April 2025 and found reported phishing attacks approaching two million for the period — an increase of more than 180% since 2021. The report’s authors, Dave Piscitello and Karen Rose, describe an environment in which criminals continue to exploit permissive registration and hosting practices largely unchecked. A companion presentation Interisle gave to ICANN’s GAC in June 2025 sharpened the picture further: 77% of phishing domains identified in the data were assessed as maliciously registered — meaning the domain was set up specifically to phish, rather than being a legitimate website subsequently compromised by an attacker — and phishing activity was estimated to impose roughly $18,000 in direct financial loss globally every minute. The same presentation found phishers concentrating in the cheapest, easiest-to-register corners of the market: registrations priced at $2 or less accounted for a disproportionate share of abuse, and 51% of maliciously registered phishing domains were found in new generic top-level domains introduced since 2012, compared with 32% in the long-established .com and .net.

Interisle’s research has also documented how concentrated some categories of abuse are at the infrastructure level. A case study of the “Unpaid Toll Scam” — a widespread scheme impersonating state tollway authorities to collect payment information — found that in a sample of roughly 37,000 related domains, 65% were registered through a single Chinese registrar, with 49% relying on a single top-level domain and 33% hosted through a single China-based provider. That kind of concentration is important because it identifies a small number of specific points in the supply chain where intervention could plausibly disrupt a large share of a specific scam, rather than requiring an industry-wide response to address one narrow abuse pattern.

The Monthly Data Is Volatile, and That Matters

Interisle has shifted in 2026 to publishing more frequent updates through its Cybercrime Information Center rather than relying solely on an annual report, and the resulting monthly figures show how much short-term volatility sits underneath the multi-year growth trend. Reported phishing activity for March 2026 rose 28% compared with February, while reported malware activity increased 189% month over month, driven partly by a 440% jump in endpoint malware targeting user devices. Separately, Interisle’s reporting on the February-to-April 2026 window flagged the .GARDEN top-level domain as a notable new source of phishing activity despite having little to no prior history of abuse, with the increase traced to the practices of specific registrars rather than a structural property of the extension itself. Read in isolation, any single month’s spike could look like an alarming acceleration; read against Interisle’s own multi-year data showing a repeating pattern of peaks and valleys layered on top of long-term growth, these figures are better understood as evidence that abuse concentrates opportunistically, sometimes shifting quickly between registrars, hosting networks, and even entire extensions, rather than as evidence of a single accelerating crisis.

A related attribution problem shows up in Interisle’s hosting-network rankings, where Cloudflare has repeatedly appeared at the top of the list for phishing domains reported by IP address or autonomous system. Interisle’s own commentary on this ranking, published through its Insights channel, has noted the irony directly: because Cloudflare’s reverse-proxy service masks the true origin server behind its own network addresses, a large share of the phishing traffic attributed to Cloudflare in raw hosting statistics is actually occurring on entirely different infrastructure that the proxy is simply concealing from view. That does not necessarily exonerate Cloudflare of any responsibility as an intermediary, but it does mean that a raw ranking of “phishing by hosting network” conflates the network that happens to be visible in the data with the network actually serving the malicious content — a distinction with real consequences if such rankings are used to assign blame or set enforcement priorities.

A Methodological Debate That Deserves More Attention

The more consequential story for anyone using this data to guide policy or enforcement decisions is a critique of Interisle’s methodology published on CircleID, which argues that the widely cited “DNS Abuse” totals conflate categories that matter enormously in practice. The core of the critique is definitional: Interisle counts every domain flagged by any of the numerous reputation blocklists it draws on as a “problem domain,” including listings the blocklist providers themselves do not attribute to any specific abuse type. That sweeps in suspected scam and fraud sites, domains referenced in spam messages, and other undifferentiated listings — a legitimate research scope for measuring the broader universe of harmful web activity, but a materially broader category than what ICANN’s own contractual framework defines as “DNS Abuse”: specifically malware, botnets, phishing, pharming, and spam only where spam serves as a delivery mechanism for one of those other harms.

That distinction is not merely semantic. Registries and registrars have domain-level tools available to them — suspending a domain, deleting a registration, or locking a transfer — but they have no ability to remove a specific harmful page from an otherwise legitimate website, or to distinguish, at the level of a shared hosting account or a subdomain-reselling platform, one abusive customer from thousands of legitimate ones. The CircleID analysis notes that Interisle’s methodology counts only the second-level domain in its totals, which avoids inflating raw counts through subdomain proliferation, but this convention can still place large legitimate platforms into TLD and registrar abuse rankings for activity that occurred on a single customer’s subdomain or web page — precisely the scenario in which suspending the entire domain would harm large numbers of innocent users to stop one bad actor, and in which the appropriate point of intervention is the hosting provider or law enforcement rather than the domain registrar at all.

None of this means the underlying phishing and malware trends Interisle documents are exaggerated or unreal — the report’s core finding of sustained, multi-year growth in reported phishing is corroborated across several years of the organization’s own historical data and is broadly consistent with independent cybersecurity industry reporting on phishing volume. What the methodological critique adds is a caution against treating a single aggregated “abuse” number as a precise measure of which specific registries, registrars, or hosting networks are performing poorly, or as a mandate for registrar-level content policing that current tools and legal authority do not actually support.

What This Means for Domain Industry Stakeholders

For registries and registrars, the practical implication is to engage with abuse data at the level of granularity it actually supports: using concentration patterns like the Unpaid Toll Scam case study to identify and disrupt specific criminal supply chains is a defensible, targeted use of the data, while treating an aggregated abuse score as a general reputation metric risks incentivizing indiscriminate suspensions that punish legitimate subdomain and shared-hosting customers alongside genuine bad actors. For brand owners and enterprises whose domains or subdomains are flagged in abuse reports because of a compromised customer account or a third-party abuse of a shared platform, understanding this distinction is directly useful: it clarifies why a registrar may be unable, rather than unwilling, to unilaterally remove specific infringing or malicious content, and why escalation to the hosting provider or a law enforcement channel is often the more appropriate — and faster — path to resolution.

More broadly, as ICANN and the wider domain-industry community continue to debate contractual DNS Abuse obligations, the choice of measurement methodology is likely to shape policy outcomes as much as the raw scale of the abuse problem itself. Data that conflates confirmed malicious registrations with undifferentiated blocklist entries will tend to support broader, blunter interventions; data that distinguishes maliciously registered domains from compromised legitimate ones, and second-level domain abuse from subdomain or hosted-content abuse, supports more targeted responses that are both more effective against criminal infrastructure and less likely to harm innocent registrants. Both Interisle’s raw data and the methodological critique of it are worth following closely — not as competing claims about whether phishing is a serious problem, which by any measure it clearly is, but as an ongoing and unresolved disagreement about how to count it in a way that actually points toward workable solutions.

For readers who follow domain-industry policy debates primarily through headline abuse statistics, the practical lesson is to ask a simple follow-up question whenever a large “DNS Abuse” or “phishing domains” figure is cited: does this number represent domains registered for the purpose of abuse, or does it also include legitimate domains and platforms where a small number of bad actors hosted harmful content that the underlying registry or registrar has no direct tool to remove? The answer changes not just how alarming a given statistic should be considered, but which part of the internet’s infrastructure is actually in a position to fix it.

By Dasoly

Dasoly

Leave a Reply

Your email address will not be published. Required fields are marked *