logo

Abuse takes its “toll” on .top: But who is paying the price?

ID: 4a12ca52-aced-50dd-991e-7c1bb0dd39b3

STIX ID: report--4a12ca52-aced-50dd-991e-7c1bb0dd39b3

Feed Name: The Spamhaus Project

Threat Score
50/100

Date Published: 2025-05-08

Date Updated: 2026-04-30

Author: The Spamhaus Team

...
...

Spamhaus researchers observed a 50% increase in abuse of the .top gTLD (211,406 detections over six months), highlighting smishing toll-road scams that send SMS messages with phishing links to fake E‑ZPass/FasTrak payment portals (examples: e-zpass.com-txzy.top, bayareafastrak.com-fzxb.top) which harvest payment credentials; the report describes the SMS→fake-site→data theft flow and notes at least one malicious site was taken down on May 4, 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.