Site icon techcoffeehouse.com

Kaspersky Warns Parked Domains Hide Data Risks

Advertisements

Fraudsters are exploiting so-called “parked domains” — registered web addresses without a fully built website — to quietly harvest visitors’ private data, Kaspersky has warned.

A parked domain typically displays a blank page, a “Coming Soon” placeholder, or a “Domain for Sale” notice. According to Kaspersky, these seemingly harmless pages can run hidden scripts that silently collect a visitor’s IP address, geolocation, User-Agent details and cookie identifiers. Fraudsters can also harvest unique browser fingerprints, such as Canvas, WebGL or Audio-fingerprinting, to track users across the internet without relying on cookies. This data can then feed into advertising networks to build detailed profiles without a user’s consent.

Redirects and typosquatting risks

Beyond covert tracking, Kaspersky said parked domains can pose direct security threats through malicious redirections and typosquatting, where a small typo lands a user on a domain resembling a popular brand by just one or two letters. Threat actors can embed scripts that automatically redirect visitors to fraudulent platforms, adult content or online casinos. Landing on a phishing site through a typo can expose users to credential theft, financial fraud, or malware installed via drive-by downloads.

“While most users may believe that an empty webpage is completely harmless, it is a dangerous misconception. A blank page or a standard ‘Domain for Sale’ placeholder can secretly scan your device’s digital footprint, collecting data for ad networks without your knowledge,” said a Kaspersky expert.

How to stay protected

Kaspersky recommends users take the following precautions:

Author

Exit mobile version