Combosquatting is the practice of attaching extra words to a real brand name in a domain, such as support, login, or secure, to create a convincing look-alike address. It works because the added term feels plausible to hurried users even when the domain is not legitimate.
Expanded Definition
Combosquatting is a domain abuse technique that appends a common trust cue to a real brand name, such as support, security, or login, to make a look-alike domain feel legitimate at a glance. It is distinct from typosquatting, which relies on misspellings, and from outright brand impersonation because the base brand remains visible while the extra word supplies the deception.
In security operations, combosquatting matters because the visual deception is subtle enough to bypass casual review, especially in phishing, credential theft, and fraud campaigns. It is also used to stage fake portals that mirror brand workflows, then route users to malicious content or collection pages. Under the NIST Cybersecurity Framework 2.0, this risk sits squarely in governance, protection, and detection practice rather than in any one technical control.
The most common misapplication is treating combosquatting as a branding nuisance only, which occurs when teams ignore it until a user reports a phishing page or a payment diversion attempt.
Examples and Use Cases
Implementing monitoring and response rigorously often introduces more alert volume and investigation overhead, requiring organisations to weigh faster takedown and user protection against operational fatigue.
- A threat actor registers a domain that combines a bank name with secure and sends password-reset emails that link to a credential harvest page.
- An attacker creates a fake login portal for a payroll or HR service so employees enter credentials during routine access.
- A fraudulent support domain uses the brand plus support to impersonate helpdesk workflows and capture MFA codes or remote-access approvals.
- An NHI-focused campaign targets service accounts by imitating vendor or cloud console names, then using the fake domain to distribute malware or steal API keys.
- Security teams register look-alike domains defensively to measure user susceptibility and improve brand protection, detection tuning, and takedown workflows.
Why It Matters for Security Teams
Combosquatting is important because it turns brand familiarity into an attack surface. Users do not need to make a spelling error for the deception to work; they only need to trust a word that looks operationally normal. That makes detection harder for both people and controls that rely on simple string matching or keyword blocks.
For security teams, the issue spans phishing defense, domain monitoring, mail security, web filtering, and incident response. It also intersects with identity security because combosquatting is often the first step in credential theft, session hijacking, or abuse of NHI secrets such as API keys and service tokens. Defenders need a process for monitoring newly registered domains, assessing brand-risk patterns, and responding quickly when a fake portal is used in a campaign. The control lens in NIST CSF is useful here because it pushes teams toward continuous detection, coordinated response, and user protection rather than relying on registration takedowns alone.
Organisations typically encounter the real impact only after a user submits credentials or approves a fraudulent request, at which point combosquatting becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV, PR.AA, DE.CM, RS.MA | CSF 2.0 covers governance, access, monitoring, and response needed to manage this domain-abuse risk. |
| NIST SP 800-63 | AAL2 | Credential phishing from combosquatting often targets authenticators governed by digital identity assurance. |
| NIST SP 800-53 Rev 5 | SI-4 | System monitoring supports detection of malicious domains, redirects, and user compromise indicators. |
| OWASP Non-Human Identity Top 10 | NHI-07 | Look-alike domains often steal NHI secrets such as API keys, tokens, and service credentials. |
| NIS2 | NIS2 raises expectations for incident handling and risk management when phishing threatens critical services. |
Use CSF governance, monitoring, and response practices to detect look-alike domains and contain abuse quickly.
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org