Kaspersky warns that fraudsters are exploiting the so-called ‘parked domains’ to harvest sensitive private data from unsuspecting users. These deceptive sites often masquerade as error pages or ad-filled placeholders, exposing users to privacy breaches and potential identity theft every day.
A parked domain is originally a registered web address that does not yet host a fully developed website. At first glance, these pages appear harmless, often displaying a blank screen, a "Coming Soon" placeholder, or a "Domain for Sale" notice. However, beneath the surface, these pages can execute aggressive hidden scripts.
Simply visiting one of these sites can lead to the silent collection of a user’s sensitive data, including IP addresses, geolocation, User-Agent details (a piece of text a web browser or app sends to websites that acts as an ID card), and cookie identifiers.
Fraudsters can also collect unique browser fingerprints, such as Canvas, WebGL, or audio fingerprinting, which they can use instead of cookies to identify a user across the Internet and track their device by the unique way a user’s hardware creates pictures and sounds. This data may be subsequently funnelled into advertising networks to build detailed, targeted profiles without the user’s consent.
Beyond covert tracking, parked domains may pose direct security threats through malicious redirections and ‘typosquatting’ (when a user ends up on domains that differ from popular brand names by just one or two letters). Threat actors can embed scripts that automatically redirect visitors to fraudulent platforms, adult content, or online casinos. The danger is also that a simple typo can land a user on a malicious or phishing website, where cybercriminals may steal login credentials and financial information, or stealthily infect the user’s device with malware via drive-by downloads (malicious files or software that may automatically install on your device without your knowledge or consent).
To stay safe from the hidden threats of parked domains, Kaspersky recommends users:
• Avoid clicking on suspicious links from unknown sources, whether via email, messaging apps, or social media. Always double-check the URL for typos before entering any sensitive information.
• Be equipped with reliable software to block web tracking and unwanted content.
• If you realise you have accidentally navigated to a parked domain, an empty page, or a placeholder site, do not click on any banners or submit any contact information. Close the page immediately and clear the browser’s cache and cookies.
For more information contact Kaspersky SA,
© Technews Publishing (Pty) Ltd. | All Rights Reserved.