Typosquatting is a cyberattack in which malicious actors register misspelled or lookalike domains to impersonate legitimate websites and deceive unsuspecting users. It is also known as URL hijacking, cousin domain, sting site, or fake URL.
Typosquatting
Typosquatting is a type of impersonation attack. If you were to set up a website that mimics somebody else's website, and the domain is really closely related, so it looks like the illegitimate website, that would be an example of typosquatting.
The key to this is the term typo right there. Typo as in you misspelled something. So if I'm trying to go to www.microsoft.com but I misspelled something right here, I put a T instead of an R right there, and suddenly I find myself on this typosquatted site, this site that's been mimicked. It represents itself as being Microsoft, but actually it's the scammer.
This type of attack goes by many different names besides just typosquatting. You could call it URL hijacking, a sting site, a cousin domain, or a fake URL.
Very similar concepts that have a lot of overlap would be cybersquatting, where once again you're impersonating another brand, and brandjacking, where you're using their trademarks and their logos and different aspects of the company to represent or misrepresent yourself and who you are.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →