Type it fast, pay for it later

You go to log into your bank. You type the address from memory, hit enter, and the page looks exactly like it should. Same logo, same colors, same login box. You put in your username and password. Nothing happens, so you try again. Second time it works.

Except that first site wasn’t your bank. It was a copy sitting on a domain one letter off from the real one. And you just handed your login to whoever set it up.

This is typosquatting, and it’s one of the oldest tricks that still works because it relies on something nobody can turn off: we all type too fast and trust what looks familiar.

How the con actually works

Scammers register domains that are almost your bank, your vendor, or a big service everyone uses. They bank on human error. A few of the common tricks:

  • Swapped letters. Your bank is at ‘chase.com’ but the fake is ‘chsae.com’. Read it fast and your brain fills in the blank.
  • Missing letters. ‘microsft.com’ instead of ‘microsoft.com’. You’ve typed the real one a thousand times, so you don’t proofread it.
  • Wrong ending. The real site ends in .com but the fake ends in .co or .net. Same name, different tail.
  • Look-alike characters. A lowercase L and the number 1 look identical in a lot of fonts. So does a capital I. ‘paypa1.com’ can fool a tired person at 9pm.

Once you land on the copy and log in, they capture your credentials in real time. Some of these fake pages even pass your login straight through to the real site so you never notice anything went wrong. You’re in your account, everything looks normal, and they’re already changing your password from their end.

Why small businesses get hit harder

Big companies register the misspelled versions of their own names to block this. When you fat-finger ‘gooogle.com’ with three Os, Google owns that too and quietly redirects you. A local business with one main domain almost never does this. So a scammer can grab the version of your name that’s one letter off, spin up a login page or an invoice, and go after your customers and your staff.

Picture this. A client goes to pay you and types your domain wrong. They land on a copycat page a scammer built with your logo pulled straight off your real site. It shows a payment portal. They pay. The money’s gone, and your business gets the angry call even though you did nothing wrong.

Or it hits from the inside. An employee gets an email that looks like it’s from your accounting software. They click, the link goes to a look-alike domain, they log in, and now the attacker has the keys to your billing.

What this means for you

You don’t need to be paranoid. You need a few habits and a couple of small setups.

Stop typing addresses from memory

Bookmark the sites you use for money and email. Your bank, your payroll, your accounting tool, your Microsoft or Google login. Click the bookmark, don’t type the name. This one change kills most typosquatting attacks before they start, because you’re never typing the address that could go wrong.

Slow down on login pages

Before you enter a password, glance at the address bar. Read the whole domain, not just the part your brain expects. Check the ending. If your bank is a .com and you’re looking at a .co, close it.

Turn on MFA everywhere

If a scammer grabs your password on a fake page, multi-factor authentication is your backstop. It’s not perfect against every attack, but for the majority of these credential-stealing pages, the second factor stops them cold. If you haven’t turned it on for your email and banking, do it this week.

Register the obvious typos of your own domain

This is the move most owners skip. Domains cost about 12 dollars a year. Grab the two or three most likely misspellings of your business name and the .net and .co versions. Point them at your real site. Now a customer who types it wrong still lands on you, and a scammer can’t grab the easy fakes.

Train your team to hover

Before anyone clicks a link in an email, they should hover their mouse over it and read where it actually goes. The text can say one thing while the link points somewhere else entirely. On a phone, press and hold the link to preview it. Ten seconds of checking beats a week of cleaning up a breach.

Typosquatting works because it hides in plain sight. There’s no scary popup, no obvious red flag. Just a page that looks right and a name that’s off by one letter. Once your team knows to look, the trick loses most of its power.

Want us to check which look-alike versions of your business domain are sitting out there unregistered, and lock them down before someone else does? That’s a quick job for us and a real gap for you. Reach out and we’ll take a look. Always happy to troubleshoot.