Brand abuse on the web: fending off typosquatting & fake shops
Protect your brand name against typosquatting and fake online shops. Learn how criminals exploit typing errors and how you can secure your domains effectively.

Typosquatting explained: how typing errors become a gateway for fraud
Advancing digitalisation offers criminals ever more subtle attack surfaces on the internet. A particularly insidious and often underestimated method is what is known as typosquatting (also called typo domain squatting). Here, fraudsters register domains that look confusingly similar to your established brand name in order to hijack the reputation your company has painstakingly built. The 2025 economic protection study by the industry association Bitkom shows how tense the overall situation in the digital space is: it extrapolates the total damage to the German economy from theft, espionage and sabotage at 289.2 billion euros, of which 202.4 billion euros are attributable to cyber attacks. 87 percent of the companies surveyed were affected. The figures are based on self-reported data from 1,002 companies with 10 or more employees and are an extrapolation, not official statistics. That makes it all the more important for managing directors and IT managers in mid-sized companies to understand the exact mechanisms of this threat and to fend it off.
The anatomy of a typing error and common tricks
Attackers deliberately bank on the hectic pace of digital working life and the psychological factor of convenience. Instead of copying a web address precisely or calling it up from a bookmark, customers, suppliers or even your own employees often type it hastily from memory straight into the address bar. A single wrong keystroke is enough and the browser unnoticeably heads for a foreign, manipulated web address. Because cyber attacks on mid-sized companies frequently start with such lapses of human attention, fraudsters systematically exploit this unconscious carelessness in everyday life in order to distribute malware or capture sensitive login credentials.
- Transposed letters: swapping adjacent characters on the keyboard leads visitors to counterfeit sites.
- Omitted characters: leaving out a letter when typing quickly often goes completely unnoticed by the user.
- Additions and filler words: fraudsters add terms such as login or portal in order to feign trustworthiness.
- Homoglyph attacks: criminals replace individual letters with visually almost identical special characters from foreign character sets.
The fake shop scam: how criminals abuse your good name
The abuse of established identities is one of the most insidious methods in modern online fraud. Criminals systematically copy the name, the legal notice and even the visual design of your company in order to build deceptively realistic fake online shops on the internet. These fraudulent platforms are often operated under slightly altered web addresses that look confusingly similar to your real domain. Customers who order in good faith from these supposed representatives of your brand usually only notice far too late that they have fallen into the hands of fraudsters.
- Identity theft from real companies: fraudsters hijack your good reputation, copy logos and legal data from your legal notice and place them on a fraudulent domain in order to feign absolute respectability.
- The advance payment scam: customers are lured with apparently unbeatable prices and deliberately pushed towards payment in advance, after which the ordered goods are never delivered.
- Loss of trust as the greatest collateral damage: although your company bears no blame for the fraud, the anger of cheated customers often falls back directly on your brand and damages your reputation lastingly.
Recent surveys show that these are long since no longer isolated cases. According to the 2025 consumer report by the Federation of German Consumer Organisations (vzbv), for which forsa surveyed 1,503 people on a representative basis, nearly one in eight online shoppers in Germany (12 percent) has fallen for such a fake online shop in the past two years. The number of unreported cases and the economic consequences are enormous. Cyber attacks on SMEs have long since stopped affecting only your own IT infrastructure, they increasingly also hit the external digital identity of your brand. To prevent this abuse, classic IT security at your own network perimeter is no longer sufficient. Proactive protection through modern cybersecurity is essential in order to detect trade mark infringements in the digital space early.
A billion-euro risk for SMEs: why German mid-sized companies are targets too
If you believe that brand abuse and counterfeit online shops only affect world-famous corporations, you are underestimating the current threat situation for German mid-sized companies. Criminals deliberately exploit the good reputation of established regional SMEs. The damage is considerable: according to the 2025 study by the digital association Bitkom, the damage from theft, espionage and sabotage reported by the companies surveyed adds up, when extrapolated, to 289.2 billion euros per year, of which 202.4 billion euros are due to cyber attacks. How much of that is specifically attributable to brand abuse or fake online shops is not broken out in the study.
Mid-sized businesses are in the attackers' focus for three reasons above all:
- Lower security barriers: many SMEs do not have their own IT security department staffed around the clock, which makes them easier targets for attacks such as typosquatting.
- High trust capital: German mid-sized companies enjoy extremely high trust among customers and partners, which fraudsters abuse for fake online shops and forged invoices.
- Hidden follow-up costs: alongside the direct loss of revenue, there is a risk of long-term reputational damage, expensive legal disputes and the permanent loss of hard-won customer trust.
For managing directors and IT managers this means that IT security and brand protection have to be thought of as inseparable. If criminals hijack your brand name, limiting the damage after the fact is not enough. Effective protection requires proactive monitoring of all digital channels. Through the seamless integration of cybersecurity and proactive brand protection, forged identities and domains can be detected early, before customers are harmed and your reputation suffers.
Proactive domain management: the first line of defence for your brand
When fraudsters abuse your brand name for fake online shops, your customers' trust is at stake. As the German Federal Office for Information Security (BSI) stresses in its 2025 situation report, digital attack surfaces are growing continuously in the course of advancing digitalisation. One of the most insidious methods is what is known as typosquatting: attackers deliberately register web addresses that differ from your original domain only by tiny typing errors. To prevent this abuse before the first counterfeit shop goes online, proactive and defensive domain management is essential.
- Defensive domain registration: systematically register common transposed letters, omissions or typo variants of your brand name in order to get ahead of attackers.
- Secure top-level domains: alongside the classic .de ending, secure important alternative country endings (such as .at or .ch) as well as generic TLDs that are relevant for your industry.
- Automated brand monitoring: establish continuous monitoring that searches the internet fully automatically for newly registered domains that look deceptively similar to your brand.
For managing directors and IT managers in mid-sized companies, this prevention is an essential building block of a holistic security strategy. Only those who monitor their digital perimeter completely can protect their own brand effectively against reputational damage and lost revenue. CAVRIX supports you in integrating this protection seamlessly into your existing cybersecurity. With continuous monitoring and automated alerts you keep full control over your digital footprint and can nip attacks in the bud.
Legal countermeasures: how to have fake sites taken down quickly
When fraudsters abuse your brand name for fake online shops, you have to act quickly in order to avert damage to your image and financial losses. German companies have proven legal instruments at hand for this in order to have abusive domains blocked or transferred to them. Proactive protection through our cybersecurity service helps you to detect such threats early, before any damage occurs at all.
The DENIC dispute entry for German addresses
For .de domains, the free DISPUTE entry from DENIC eG is the first instrument of choice. If, as the holder of name or trade mark rights, you credibly demonstrate that a domain infringes your rights, DENIC blocks it for administrative changes. The current holder can then no longer transfer the domain to a third party. As soon as the unauthorised holder deletes or loses the domain, it passes to you automatically. The entry initially applies for one year. It is only extended if you submit a new form in the original in good time and demonstrate that the dispute with the domain holder is still ongoing (DENIC eG).
The UDRP procedure for international domains
For international domain endings such as .com or .org, ICANN's dispute resolution procedure applies, the Uniform Domain-Name Dispute-Resolution Policy (UDRP). Through organisations such as the WIPO Arbitration and Mediation Center you can initiate a structured procedure. The prerequisite is proof that the domain is similar to your trade mark, that the holder has no legitimate interest and that the domain was registered in bad faith. For IT managers and technical directors in mid-sized companies this is often the most efficient way to stop international piracy websites on a sound legal basis.
Cease-and-desist letters and civil law steps
In addition, you can issue a cease-and-desist letter through a lawyer and obtain preliminary injunctions in order to force providers or hosters to shut down the site immediately. Because fraudsters abroad are often hard to get hold of, the combination of fast blocking and technical protection is the most effective. For managing directors in mid-sized companies, IT security is therefore very much a matter for the top, in order to align legal and technical defensive measures optimally with each other.
Digital verification in practice: protecting invoices, documents and emails
These days criminals not only forge websites, they also intrude directly into your everyday communication. Forged emails and manipulated invoices in your company's name not only damage your revenue, they also lastingly destroy the trust of your customers and partners. According to the German Federal Office for Information Security (BSI), countless new malware variants are discovered in Germany every day, often distributed via heavily manipulated email traffic. Without effective protective mechanisms, your company's identity can be abused in everyday digital business.
To keep your outgoing emails safe from abuse, standardised authentication procedures have to be implemented. The Sender Policy Framework (SPF) defines which servers are allowed to send emails in your name. DomainKeys Identified Mail (DKIM) adds a cryptographic signature that proves the content was not altered in transit. DMARC (Domain-based Message Authentication, Reporting and Conformance) links both protocols and gives recipients clear instructions on how to handle unauthorised emails. This effectively protects your brand against email spoofing and ensures that your customers only receive genuine messages.
- Email authentication with DMARC, DKIM and SPF protects your sender address against fraudulent abuse.
- Digital verification of invoices exposes manipulated bank details and payment requests before damage occurs.
- Integrity checks on documents ensure that contracts and attachments in PDF format have not been manipulated after the fact.
As part of a comprehensive security strategy, digital verification is therefore indispensable for preserving the integrity of your business communications. This is a decisive protective measure especially for managing directors and IT managers in German mid-sized companies. Our cybersecurity service protects your organisation proactively against identity theft and secures your sensitive business processes.
Holistic protection with CAVRIX: cybersecurity and fraud prevention combined
Effective protection against digital brand abuse requires a seamless security strategy that combines technical barriers with proactive monitoring. For managing directors and IT managers in German mid-sized companies this means looking beyond the classic network perimeter to external threats such as fake online shops. The vzbv consumer report 2025 shows how widespread the danger is: 12 percent of online shoppers in Germany have fallen for a fake online shop within two years. The integrated offering from CAVRIX starts precisely at this interface and unites the internal protection of your IT infrastructure with proactive fraud prevention on a single platform.
- Managed IT for endpoints: automated patching and proactive hardening of your workstations prevent malware from forged emails sent in your brand's name from entering your corporate network and causing damage there.
- Round-the-clock security: through the integrated cybersecurity module, CAVRIX provides continuous monitoring around the clock. This helps to detect fraudulent domain registrations and brand abuse on the internet early.
- Simple control in the Command Center: through this intuitive, AI-native interface you manage your entire security status and pending compliance tasks by chat, directly in your everyday communication channels such as Microsoft Teams or Slack.
In addition, the integrated compliance module ensures that your company meets and fully documents all requirements of modern rules such as the NIS2 security requirements. If you have questions about proactive fraud prevention, brand protection or the general security of your IT infrastructure, the CAVRIX team is available at any time at info@cavrix.de for personal advice. That way you build a resilient digital identity and protect the trust of your customers and partners sustainably.
Frequently asked questions
What exactly is meant by typosquatting?
Typosquatting refers to the deliberate registration of internet addresses (domains) that look deceptively similar to well-known brand names but differ by small typing errors. Criminals hope that users will mistype the URL and then redirect them to counterfeit websites or fake online shops in order to capture sensitive data or sell inferior goods.
How do you recognise a fraudulent fake online shop?
Fake online shops frequently stand out through extremely low prices, missing or incorrect legal notice details and payment in advance as the only payment method at checkout. Often the design and the logo of established companies are copied one to one in order to fake respectability and deliberately abuse the good reputation of well-known brands among German mid-sized companies.
How high is the economic damage from cybercrime in Germany?
The threat is immense. According to the economic protection study by the industry association Bitkom for 2025, the extrapolated total damage from theft, espionage and sabotage stands at 289.2 billion euros, of which 202.4 billion euros are due to cyber attacks. The figures are based on self-reported data from the companies surveyed; the study contains no separate breakdown for brand abuse or fake online shops.
What can I do if my brand name is abused for a fake online shop?
You should act immediately. For German .de domains you can apply for a dispute entry with DENIC in order to prevent the domain from being passed on. It is also advisable to send a legal cease-and-desist letter to the domain holder and to initiate a fast UDRP arbitration procedure for international domains in order to have the fraudulent website taken down.
How does CAVRIX protect my company against domain abuse and fake online shops?
CAVRIX provides comprehensive protection as part of cybersecurity and the new modules for digital verification. This includes continuous domain monitoring for the early detection of suspicious registrations, the hardening of your email infrastructure through DMARC and SPF, and the proactive analysis of suspicious documents and invoices via the intuitive Command Center.
Which preventive measures are most important for mid-sized companies?
Companies should pre-emptively register the most important typo variants and alternative top-level domains (.com, .de, .net) of their core brand themselves. In addition, automated monitoring of the domain name space protects against unauthorised new registrations. Consistent staff training as part of security awareness programmes also minimises the risk of internal phishing victims.