Abuse takes its “toll” on .top: But who is paying the price?
ID: 4a12ca52-aced-50dd-991e-7c1bb0dd39b3
STIX ID: report--4a12ca52-aced-50dd-991e-7c1bb0dd39b3
Feed Name: The Spamhaus Project
Threat Score
Spamhaus researchers observed a 50% increase in abuse of the .top gTLD (211,406 detections over six months), highlighting smishing toll-road scams that send SMS messages with phishing links to fake E‑ZPass/FasTrak payment portals (examples: e-zpass.com-txzy.top, bayareafastrak.com-fzxb.top) which harvest payment credentials; the report describes the SMS→fake-site→data theft flow and notes at least one malicious site was taken down on May 4, 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
