NiceNIC:s granskning av 2026 års nätfiskemätningar: branschroller, verifierade resultat och missbrukskontroller

Visningar:27 Tid:2026-08-27 11:38:35 Författare: windy Kontakt suppellert email

Quick Answer

Two 2026 publications reported a significant concentration of phishing domains for which NICENIC INTERNATIONAL GROUP CO., LIMITED was identified as the sponsoring registrar.

NiceNIC recognizes that phishing can cause credential theft, fraud, account compromise, financial loss, and service disruption. The reported concentration and growth are serious operational and security signals that require attention.

Registrar attribution does not mean that NiceNIC operated the reported websites, controlled their content, hosted their files, provided their authoritative DNS, delivered their email, or operated their CDN. Those services may be provided by different parties.

This division of roles does not remove NiceNIC’s registrar responsibilities. When actionable evidence shows that a NiceNIC-sponsored domain is being used for DNS Abuse, NiceNIC is responsible for investigating the matter and applying appropriate registrar-level mitigation where supported.

This review explains what the publications reported, how industry responsibilities are divided, what NiceNIC can verify from its registrar-side records, and how NiceNIC approaches evidence, mitigation, and transparency.

What the Two Publications Reported

This review addresses two public publications:

  • the Cybercrime Information Center's May 1 to July 31, 2026 quarter-over-quarter registrar comparison;
  • the annual publication titled Phishing Landscape 2026, Domain Registrars, published through Interisle Insights.

The annual publication reported NiceNIC as first in its study for:

  • the number of phishing domains reported;
  • the number of domains classified by the researchers as attacker-created malicious phishing registrations.

It also stated that 85% of the NiceNIC-associated phishing domains in the annual study were classified by the researchers as attacker-created.

The later quarterly comparison reported the following changes:

Measurement
Reported change from February-April to May-July 2026
Domains under management
+27%
Reported phishing domains
+66%
Phishing domain score
+31%
Domains classified as malicious registrations
+71%

The reported phishing and malicious-registration measurements increased faster than the reported growth in NiceNIC’s domain portfolio.

NiceNIC treats this trend as a material risk signal requiring closer attention.

Source note: The quarterly changes above are reproduced from the May 1 to July 31, 2026 registrar comparison published by the Cybercrime Information Center. The annual statements are from Phishing Landscape 2026, Domain Registrars, published through Interisle Insights. NiceNIC has not independently validated every domain-level classification included in the aggregate measurements.

What NiceNIC's Role as Registrar Means

The two publications identify NICENIC INTERNATIONAL GROUP CO., LIMITED as the sponsoring registrar for the associated domain names.

A registrar relationship does not automatically mean that the registrar also provides all other services used by a domain.

A domain may use NiceNIC services, third-party services, or a combination of different providers. The configuration varies from one domain to another.

Industry role
Typical responsibility
Registrant or website operator
Determines the intended use of the domain and typically controls or authorizes the website, application, and content
Hosting provider
Stores and serves website files, databases, applications, and other hosted content
Authoritative DNS provider
Publishes the DNS records that direct users and services to the relevant infrastructure
CDN or reverse-proxy provider
Routes, proxies, caches, filters, or protects website traffic
Email provider
Sends, receives, or processes email associated with the domain
Registrar
Manages the registration, customer relationship, transfer status, registrar-level statuses, and applicable registrar responsibilities
Registry
Operates the authoritative registration database and DNS zone for the top-level domain and manages registry-level policies and statuses

Registrar attribution therefore does not establish that NiceNIC:

  • operated the reported website;
  • created or controlled the reported content;
  • hosted the website on NiceNIC-operated infrastructure;
  • provided the authoritative DNS;
  • operated the CDN or reverse proxy;
  • sent the reported phishing email;
  • controlled the registrant's server or application.

At the same time, registrar responsibility remains important.

When NiceNIC has actionable evidence that a domain it sponsors is being used for DNS Abuse, NiceNIC must investigate and apply an appropriate registrar-level measure where supported.

Depending on the circumstances, stopping the harmful activity may also require action by:

  • the registrant or website operator;
  • the hosting provider;
  • the authoritative DNS provider;
  • the CDN or reverse-proxy provider;
  • the email provider;
  • the registry;
  • law enforcement or another relevant authority.

NiceNIC explains these responsibilities in more detail in its guide to how the domain industry works and how responsibilities are divided.

How the Published Measurements Should Be Understood

The publications use external threat-intelligence data to measure phishing activity associated with registrars.

The Cybercrime Information Center states that threat records may include:

  • domains;
  • URLs;
  • discovery dates;
  • targeted brands;
  • registrar information;
  • DNS information;
  • infrastructure information;
  • threat classifications.

These records are combined with registration, DNS, hosting, and classification information to produce aggregate measurements.

Reported Phishing Domains

This measurement represents domains attributed to a registrar that appeared in the phishing data used during the reporting period.

It should not be interpreted as the number of complaints submitted directly to NiceNIC.

A domain may appear in external threat intelligence:

  • before a report reaches the registrar;
  • after registrar review has begun;
  • after a registrar-level restriction has been applied;
  • after the domain has expired, transferred, or changed status;
  • in more than one threat-intelligence source.

The measurement is useful for identifying concentration and trends. It does not provide the complete registrar-side history of every domain.

Phishing Domain Score

The quarterly publication calculates the registrar phishing domain score by dividing the number of reported phishing domains by the registrar’s domains under management and multiplying the result by 10,000.

The score is intended to compare registrars with different portfolio sizes.

It does not, by itself, establish:

  • the current status of each domain;
  • when NiceNIC first became aware of the domain;
  • when the initial assessment occurred;
  • when mitigation occurred;
  • which infrastructure providers were involved;
  • whether multiple observations belonged to one campaign;
  • whether a domain was intentionally registered for abuse or was later compromised.

Malicious Registration Classification

The published research distinguishes domains believed to have been intentionally registered for phishing from legitimate domains that were later compromised.

The research methodology states that a domain blocklisted within 90 days of registration is treated as maliciously registered for the purpose of the study.

Additional indicators may include:

  • deceptive terms such as "login" or "security";
  • brand names and close misspellings;
  • related domains registered in batches;
  • common nameservers or infrastructure;
  • recurring or algorithmically generated naming patterns.

These research classifications are useful risk indicators.

They do not replace the domain-level evidence, investigation, and case history required before a registrar makes an individual mitigation decision.

What the Aggregate Data Shows

The publications show that:

  • a large number of domains attributed to NiceNIC appeared in the phishing data used by the researchers;
  • the reported concentration increased between the two quarterly periods;
  • a large proportion was classified as likely malicious registrations;
  • reported phishing activity grew faster than the reported domain portfolio;
  • automated and bulk registration risks require continued attention.

NiceNIC does not dismiss these findings.

What the Aggregate Data Does Not Show by Itself

The public aggregate data does not provide a complete registrar-side case record for every associated domain.

It does not, by itself, show:

  • whether each domain is currently active, restricted, expired, deleted, or transferred;
  • when NiceNIC first became aware of each domain;
  • whether awareness came from external threat intelligence, a direct report, a registry notice, or internal review;
  • when NiceNIC completed the initial assessment;
  • whether registrar action occurred before or after a later external observation;
  • whether several records relate to the same campaign or repeated observations;
  • whether the reported website used NiceNIC-operated or third-party infrastructure;
  • whether the registrar was also the DNS, hosting, CDN, or email provider;
  • whether every domain was attacker-created or whether some legitimate domains were compromised;
  • whether an individual mitigation action was timely and proportionate.

These limitations affect how the aggregate totals should be interpreted.

They do not make the reported concentration irrelevant.

Registrar Responsibility and ICANN Requirements

NiceNIC is operated by NICENIC INTERNATIONAL GROUP CO., LIMITED and is listed in the ICANN directory of accredited registrars, IANA ID 3765.

Accreditation confirms NiceNIC’s registrar identity and contractual role. It does not, by itself, prove how an individual abuse case was handled.

The ICANN Advisory on DNS Abuse Obligations explains that registrars must investigate reports involving domains they sponsor and promptly apply appropriate mitigation when actionable evidence confirms DNS Abuse.

The appropriate measure may depend on:

  • the available evidence;
  • the severity and immediacy of the harm;
  • whether the domain appears intentionally abusive or compromised;
  • whether legitimate websites, email, or services could be affected;
  • which service provider is best placed to stop or disrupt the harmful activity.

ICANN also explains that registrars and registries are only part of the broader DNS ecosystem. In some cases, the party best placed to detect, verify, remove, or disrupt the activity may be another service provider.

A public article does not prove compliance in a specific case. Case-specific handling must be supported by investigation records, evidence, chronology, and documented mitigation decisions.

Verified NiceNIC Findings from a Separate Case Review

The public aggregate publications do not contain the complete registrar-side history of every domain included in their totals.

NiceNIC therefore does not claim that it has independently validated every domain-level classification behind those measurements.

A separate NiceNIC case review does provide relevant evidence concerning current registrar-level status.

On August 18, 2026, NiceNIC published a registrar-side review of 50 domains identified in Google Threat Intelligence's UNC6671 report.

That review recorded:

Verified NiceNIC finding
Result
Domains reviewed
50
Domains subject to hold status as of August 18, 2026
50
Domains recorded with clientHold
49
Domains recorded with both serverHold and clientHold
1

This separate case review is not a statistical sample of the larger aggregate publications.

The current hold status records the status on August 18, 2026. It does not, by itself, prove when each restriction was applied or whether every historical case was handled within the same timeframe.

Its purpose is to provide verifiable registrar-side status information that an external threat-intelligence table cannot provide.

NiceNIC's Published Abuse-Handling Process

NiceNIC's abuse handling methodology describes a structured case-management workflow.

The published process includes:

Area
Published process
Case logging
Submitted abuse complaints are recorded in an internal case-management system
Case identification
Each complaint is assigned a case identifier
Evidence capture
The domain, suspected abuse type, submitted evidence, date, time, and reporter information are recorded where available
Preliminary analysis
Automated tools may assist with initial technical analysis and prioritization
Classification
Reports are categorized according to the suspected abuse type
Operational reporting
NiceNIC publishes monthly information about complaint intake, involved domains, mitigation, and recovery

The NiceNIC July 2026 Abuse Report is the latest monthly report referenced in this review.

NiceNIC’s operational data and the external threat-intelligence measurements use different definitions and data sources. They should not be treated as directly interchangeable.

Contextual Review of Relevant Signals

When actionable evidence indicates that a NiceNIC-sponsored domain is being used for DNS Abuse, NiceNIC may consider information reasonably accessible to the registrar as part of the investigation.

Relevant context may include:

  • registration date and timing;
  • registration method;
  • nameservers;
  • related infrastructure;
  • account activity;
  • domain history;
  • repeated naming patterns;
  • prior confirmed abuse;
  • information supplied by registries, researchers, authorities, or affected parties.

These signals can help NiceNIC understand the circumstances surrounding a reported domain.

They do not, by themselves, establish that another domain is abusive.

Any registrar-level action involving an additional domain should be supported by actionable evidence relating to that domain and should consider the severity of the harm and the possibility of collateral damage.

Automated and API Registration

Automated registration and API access are legitimate services used by:

  • hosting providers;
  • domain resellers;
  • agencies;
  • developers;
  • domain portfolio operators;
  • other customers requiring automated provisioning.

API use by itself is not evidence of abuse.

NiceNIC does not treat ordinary automated registration as suspicious and does not propose blanket restrictions on legitimate API or reseller activity.

Additional review may be appropriate when automated activity is combined with multiple credible indicators, such as:

  • confirmed phishing or another form of DNS Abuse;
  • abnormal registration behavior;
  • recurring impersonation terms;
  • repeated security reports;
  • related infrastructure;
  • previous confirmed abuse involving the same activity.

Controls should remain evidence-based, risk-based, and proportionate.

External Threat Intelligence Can Initiate Review

A direct complaint is an important source of information, but it is not the only possible trigger for review.

NiceNIC may consider:

  • credible external threat intelligence;
  • reports from affected users;
  • security researcher submissions;
  • registry notifications;
  • law-enforcement reports;
  • internal account information;
  • registration activity;
  • DNS and nameserver information;
  • other information reasonably accessible to the registrar.

Where external information provides actionable evidence, NiceNIC may begin registrar-side review without waiting for a separate customer complaint.

Evidence That Helps an Abuse Review

Reporters should provide the strongest evidence reasonably available to them.

Useful information may include:

  • the domain name;
  • the exact abusive URL;
  • the legitimate website, organization, or brand being impersonated;
  • screenshots;
  • timestamps and time zones;
  • phishing emails and full headers;
  • transaction or victim information where appropriate;
  • technical logs;
  • device, browser, or country information where content is conditionally displayed.

NiceNIC may request additional information when it is necessary to reproduce or verify reported activity.

Reporters can review the step-by-step evidence guide for domain abuse reports and submit evidence through the official NiceNIC Report Abuse channel.

Malicious Registration and Compromised Domains

An attacker-created domain and a compromised legitimate domain may both be used for phishing, but they can require different mitigation decisions.

A malicious registration may show evidence that the domain was acquired primarily for:

  • phishing;
  • malware;
  • botnet activity;
  • pharming;
  • another abusive purpose.

A compromised domain may belong to a legitimate organization whose:

  • website was hacked;
  • hosting account was compromised;
  • credentials were stolen;
  • CMS or plugin was exploited;
  • DNS settings were changed without authorization;
  • email system was abused.

NiceNIC's guide to compromised domains and malicious registrations explains why this distinction affects the appropriate response.

Where evidence supports an intentionally abusive registration, domain-level action may be appropriate.

Where a legitimate domain has been compromised and the harmful activity can be stopped without unnecessary collateral damage, remediation may be more appropriate.

The decision should consider:

  • available evidence;
  • severity and ongoing harm;
  • available mitigation options;
  • the roles of the service providers involved;
  • the risk of disrupting legitimate websites, email, and services.

Scope of This Review

This review does not claim that:

  • every domain-level classification in the aggregate publications has been independently validated by NiceNIC;
  • ICANN accreditation means abuse cannot occur;
  • registrar attribution means NiceNIC operated, hosted, or controlled the reported websites;
  • the separate UNC6671 review represents the full datasets used in the two publications;
  • current hold status proves that every historical action was timely;
  • every complaint should automatically result in domain suspension;
  • API use, registration method, account information, domain naming, or automation alone proves malicious intent;
  • publication of this article demonstrates compliance in an individual case.

This review confirms that:

  • the reported concentration is serious;
  • the reported growth requires attention;
  • sponsoring registrar, hosting provider, DNS provider, CDN, email provider, and website operator are different roles;
  • NiceNIC remains responsible for appropriate registrar-level investigation and mitigation where actionable evidence supports it;
  • credible external threat intelligence can support or initiate review;
  • specific case histories require registrar-side records;
  • mitigation decisions must remain evidence-based and proportionate;
  • future reporting should use clearer high-risk DNS Abuse measurements and case-event definitions.

How Progress Should Be Measured

NiceNIC’s response should be evaluated through measurable outcomes rather than general statements.

Relevant indicators include:

  • time from receipt of actionable information to initial assessment;
  • time from confirmed actionable evidence to mitigation;
  • number of active phishing cases disrupted;
  • repeat-abuse rates;
  • remediation and false-positive outcomes;
  • reduction in externally reported abusive registrations over comparable periods;
  • clearer documentation of why action was or was not taken;
  • better coordination with hosting, DNS, CDN, registry, security, and other relevant providers where necessary.

The objective is to achieve:

  • fewer abusive registrations;
  • faster assessment of active threats;
  • proportionate registrar-level action;
  • effective cooperation across the domain and hosting ecosystem;
  • protection for legitimate domain owners;
  • clearer and more comparable case outcomes.

Frequently Asked Questions

Does registrar attribution mean NiceNIC hosted or operated the reported phishing website?

No.

Registrar attribution means that NiceNIC was identified as the sponsoring registrar for the domain registration.

It does not, by itself, establish that NiceNIC hosted the website, operated the authoritative DNS, provided the CDN, delivered the email, controlled the content, or operated the reported activity.

NiceNIC nevertheless remains responsible for investigating actionable DNS Abuse involving domains it sponsors and taking appropriate registrar-level measures where supported.

Does NiceNIC dispute the two publications?

NiceNIC has not independently validated every domain-level classification behind the aggregate publications.

NiceNIC treats the reported concentration and growth as serious risk signals and is responding through registrar-side review, evidence-based mitigation, and clearer operational measurement.

Are the published rankings an ICANN compliance finding?

No. They are independent threat-intelligence measurements.

ICANN compliance is assessed under the Registrar Accreditation Agreement using applicable obligations and case-specific records. The published measurements remain relevant to NiceNIC’s operational risk review.

Does NiceNIC wait for a direct complaint before reviewing a domain?

No.

Credible external threat intelligence, registry notifications, internal records, and other reasonably accessible evidence may also support or initiate review.

Does NiceNIC consider all API registrations suspicious?

No.

API registration is a legitimate and important business tool. Additional review should depend on multiple credible indicators, not automation alone.

Will every abuse complaint result in suspension?

No.

The appropriate measure depends on the evidence, severity, ongoing harm, domain history, whether the domain is maliciously registered or compromised, the roles of the providers involved, and the possibility of collateral damage.

How can suspected phishing or DNS Abuse be reported?

Submit the domain, exact URL, description, and strongest available evidence through the NiceNIC Report Abuse channel.

Continuing Review and Transparency

The two publications identify a serious concentration that NiceNIC cannot responsibly dismiss.

They identify NiceNIC as the sponsoring registrar. They do not establish that NiceNIC operated the reported websites or provided every service used by those domains.

NiceNIC’s responsibility is to combine credible external signals with registrar-side records and to take appropriate action within its role.

That includes continued improvement in:

  • prevention;
  • investigation;
  • mitigation;
  • high-risk case prioritization;
  • responsible automation controls;
  • communication with reporters;
  • coordination with other infrastructure providers;
  • protection for legitimate domain owners;
  • transparency.

Progress should be judged by measurable results: faster assessment of active threats, effective registrar-level mitigation, appropriate cooperation across the wider internet ecosystem, fair remediation, and a sustained reduction in externally reported abuse over time.

NiceNIC Security and Reporting Resources

For additional registrar-side information, review the following NiceNIC resources:

Copyright © 2006-2026 NICENIC INTERNATIONAL GROUP CO., LIMITED Alla rättigheter förbehållna