A CSC domain security study reported that many large enterprises continue to leave domain names and DNS underprotected, creating an exploitable gap outside traditional perimeter controls. The research highlights how attackers leverage domain weaknesses—such as lookalike registrations, domain hijacking, and reuse of lapsed or forgotten domains—to enable phishing, business email compromise (BEC), malware delivery, impersonation, and traffic redirection, particularly when registrar accounts are compromised.
The report found 67% of Global 2000 organizations have implemented fewer than half of recommended domain security measures, despite improvements in email authentication: DMARC adoption is near 80%, influenced by regulatory pressure including the EU’s NIS2 directive. Other protections remain uncommon, including DNSSEC (~11%) and registry lock (<25%), increasing exposure to unauthorized domain changes and DNS integrity attacks. DNS availability was also flagged as a resilience risk, with many organizations consolidating on a single cloud DNS provider and limited use of DNS redundancy (notably among unicorns, where reliance on single-cloud infrastructure is high), while CSC cautioned that using non-enterprise registrars can elevate the risk of hijacking and impersonation.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Coverage of the CSC findings emphasized that DMARC adoption had risen to nearly 80%, partly due to regulatory pressure including the EU NIS2 directive, while many firms remained exposed to domain hijacking, spoofing, and business email compromise. The reporting also noted growing risk from reliance on single cloud DNS providers and weaker security at consumer-grade registrars.
Corporation Service Co. published research on the Forbes Global 2000 and top private unicorns finding that most Global 2000 firms had implemented fewer than half of recommended domain security controls. The study highlighted low adoption of protections such as DNSSEC, registry lock, and DNS redundancy, despite improved DMARC uptake.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.