Data Security, Privacy, Phishing, Threat Intelligence, Malware

Kaspersky warns of parked domain data harvesting risks

Fraudsters are exploiting parked domains to harvest sensitive private data from unsuspecting users, according to Kaspersky. These deceptive sites often masquerade as error pages or ad-filled placeholders, exposing users to privacy breaches and potential identity theft every day, based on information published by TahawulTech.

A parked domain, a registered web address without a developed website, can silently collect sensitive user data, including IP addresses, geolocation, User-Agent details, and cookie identifiers. Fraudsters can also gather unique browser fingerprints like Canvas, WebGL, or Audio-fingerprinting to track devices and build targeted profiles without consent. Beyond covert tracking, these domains pose direct security threats through malicious redirections and typosquatting.

Threat actors embed scripts to redirect visitors to fraudulent platforms, adult content, or online casinos. A simple typo can lead users to phishing websites where cybercriminals may steal credentials and financial information, or infect devices with malware via drive-by-downloads. Kaspersky recommends avoiding suspicious links, using security software with anti-tracking and anti-fingerprinting features, and immediately closing and clearing cache/cookies if a parked domain is accidentally visited.

Source: TahawulTech

You can skip this ad in 5 seconds