Combosquatting: When Scammers Add 'login' or 'secure' to Your Brand Name
Some convincing fake web addresses do not misspell your name at all. They spell it correctly and add an official-sounding word, like "yourbrand-login.com" or "yourbrand-support.com". This tactic is called combosquatting, and it can fool people who are expecting to sign in or pay. This guide explains how it works and what a business can do about it.
What Combosquatting Means
Combosquatting is a blend of "combination" and "squatting". Instead of altering your brand name, the fraudster combines it with an extra word to create a new web address, usually joined by a hyphen or run together. Your brand stays correctly spelled, which is exactly what makes the fake feel legitimate.
Common examples take a real business name and add words such as "login", "secure", "account", "billing", "support", "verify", "payments" or "update". So a business at "coretubes.co.uk" might be targeted with "coretubes-login.com", "secure-coretubes.com" or "coretubes-billing.com". This is one of the forms of the broader problem covered in our guide to lookalike domains.
Why Combosquatting Is So Convincing
Combosquatting works because the added word matches what the victim is already expecting. If someone receives an email asking them to sign in, a link to "yourbrand-login.com" looks entirely reasonable. If they are expecting an invoice, "yourbrand-billing.com" fits the story. The extra word does not raise suspicion, it reduces it, because it sounds like the kind of address a real company might genuinely use for that purpose.
It is also harder to dismiss than a misspelling. Your brand name is spelled correctly, so the usual advice to "check the spelling" does not help. Many legitimate businesses really do use addresses like "login.theirbrand.com", which blurs the line further and makes the fakes even more believable.
The important distinction is where the brand appears. In "login.yourbrand.com", the registered domain is normally "yourbrand.com" and "login" is a section controlled by that domain owner. In "yourbrand-login.com", the registered domain is the entire different name. Reading from the end of the address before the first single slash is a useful habit when a message asks you to sign in or pay.
How Combosquatting Is Used Against You
A combosquatting address is typically the destination in a scam message. The fraudster sends an email or text that appears to come from you, or from a service your customers use, urging them to log in, confirm a payment or update their details. The link leads to a fake page on the combosquatting address, built to look like your genuine site, where the victim hands over their login details or card information.
Because the word in the address matches the action being requested, these campaigns can be highly effective. They are used against customers, but also against your own staff, who may receive a convincing message pointing to something like "yourbrand-hr-portal.com".
How to Protect Your Business from Combosquatting
There are three practical steps, and they work best together.
Be consistent about your real addresses. Decide which web addresses your business genuinely uses for signing in and paying, publish them clearly, and tell customers that anything else is not you. The fewer legitimate variations you use, the easier the fakes are to call out.
Register the most tempting combinations yourself. You cannot own every word combination, but buying a few of the most dangerous, such as your name with "login", "secure" or "pay", takes the obvious ones off the table. Our guide to defensive domain registration explains how to prioritise.
Watch for the rest as they appear. Because the range of possible word combinations is huge, the practical safety net is to be alerted whenever someone registers your brand combined with a suspicious word. Checking for this by hand is not realistic, since you would have to imagine and test countless combinations continually. This is one of the patterns Impostor Watch watches for automatically.
How Impostor Watch Helps
Impostor Watch uses public Certificate Transparency logs, newly registered domain feeds and generated variations to look for your brand combined with words such as "login", "secure", "billing" and "support". When it finds a match, it checks for a live website, mail records and signs such as a copy of your site's small browser icon (its favicon), then explains the apparent risk in plain English.
That saves you from having to guess and repeatedly check a large set of word combinations, and it helps prioritise matches with stronger evidence. If a combosquatting domain is being used for abuse, you can ask us to handle the reporting process.
Frequently Asked Questions
How is combosquatting different from typosquatting?
Typosquatting misspells your name to catch typing mistakes. Combosquatting spells your name correctly and adds an extra word, such as "login" or "secure", to build a fake that looks like an official part of your business.
Why are combosquatting addresses so effective?
Because the added word matches what the victim expects to be doing, such as signing in or paying, so the address looks reasonable rather than suspicious. The correct spelling of your brand also defeats the usual "check the spelling" advice.
Can I stop combosquatting completely?
You cannot register every possible word combination, but you can buy a few high-priority ones and monitor for the rest. A service such as Impostor Watch can alert you when it detects a risky combination so you can assess how it is being used.
Want to see if your brand has already been combined with a suspicious word? Run a free scan with Impostor Watch and find out.
