Published
- 22 min read
That Old Web Address May Have a New Owner
Stay Safe Online Without Making It Your Second Job
The Digital Fortress (Second Edition)
A warm, plain-English guide for people with real lives and finite patience. Learn the handful of habits that genuinely protect your money, accounts, and family, and get honest permission to ignore the rest.
For People Who Cannot Afford to Get Privacy Wrong
The Anonymity Playbook (Second Edition)
A practitioner’s field manual for journalists protecting sources, whistleblowers, and activists. It explains how the surveillance actually works, what each technique costs you, and exactly where it fails.
Write, Ship, and Maintain Code Without Shipping Vulnerabilities
Secure Software Development
A hands-on security guide for developers and IT professionals who ship real software. Build, deploy, and maintain secure systems without slowing down or drowning in theory.
Use AI Coding Agents Without Losing Control of Your Codebase
The Secure Harness
A calm, practical guide to letting agents do useful work inside boundaries you set, enforce, and audit. Ships with 15 copy-pasteable artifacts: hook scripts, permission configs, release gates, and MCP templates.
Stop Shipping Demos. Start Shipping Systems.
The AI Native Engineer
Sixteen hands-on chapters, one real product. Grow it from a single model call into a retrieved, tool-using, observable, production-grade system, with evaluation treated as a habit from the first feature.
A web address can outlive the people who ran it. The charity closes, the football club changes its name, or a company retires a campaign. Years of links remain in old articles, browser bookmarks, forum posts, and forgotten pages. Then the registration expires and somebody else buys the address.
That new owner also receives part of the address’s old life. People still click the links. Search engines still know the name. Security systems may remember years of harmless use. A criminal group can buy that history without buying the old organisation, rather like taking over a familiar shop sign after the shop has gone.
Research published by Infoblox on 13 August 2026 describes an unusually large version of this trade. The company says a group it calls Sable Squirrel controls more than 10,000 domains and has spent an estimated $7 million buying expired ones. Infoblox linked some of those addresses to illegal sports streams and gambling sites, while a subset also served as contact points for remote-access malware. Its researchers found more than 31,000 malware samples communicating with the group’s domains. (Infoblox, The Hacker News)
The useful lesson is smaller than the operation. A familiar web address carries history, but history does not prove who owns it today. You do not need to investigate every site before opening it. You do need a little more care when an old bookmark, abandoned blog link, or free streaming page asks you to install something, sign in, pay, or allow notifications.
What the researchers found
Sable Squirrel appears to run a business built around football audiences. Its sites advertise live matches, schedules, chat rooms, and mobile apps. The free stream brings people through the door, then betting promotions and redirects try to make money from that attention. Infoblox says the same operation uses both new lookalike addresses and old addresses bought after their previous owners let them go. (Infoblox)
The old names are the expensive part. Infoblox individually researched about 160 purchases and says it confirmed more than $430,000 in spending on that sample. It then estimated a total above $7 million across the broader collection. That total remains an estimate from Infoblox rather than an audited account of the group’s finances, so it should be read as a measure of scale, not a bank statement. Independent reports from IT Pro and The Hacker News describe the same underlying research and its published method. (IT Pro, The Hacker News)
Some purchases had recognisable previous owners. Infoblox lists a former General Electric health-initiative address, a domain created for the proposed Kroger and Albertsons merger, a former Sony developer-tools company, a French football club, a Brazilian community bank, and a collapsed British advertising company. In August 2026, those examples served the new owner’s streaming material rather than the organisations people might remember. One former advertising-company domain still received calls from thousands of third-party websites each day, according to the researchers. (Infoblox)
The group moved quickly after buying. Among domains where Infoblox could trace both the purchase and first use, 24 percent went live on the same day, three quarters were active within a week, and 94 percent were active within two weeks. Speed matters because the buyer wants the old traffic before links disappear and reputation systems notice the change. The familiar sign goes back above the door while people are still walking toward it.
A more serious finding sat behind some of those signs. Infoblox identified 405 Sable Squirrel domains configured as control servers for malware, with a large setup wave in November and December 2025. It tied more than 31,000 samples to the infrastructure, including several known remote-access tools. A person could see a functioning football stream at an address while an infected computer used the same address to receive instructions. The visible page and the hidden machine traffic could share one domain. (Infoblox, The Hacker News)
That does not mean visiting any expired domain automatically infects a device. Infoblox’s report links malware samples to command servers; it does not claim that every visitor to every listed stream received malware. Some domains supported streaming, some redirection, some gambling, and a subset had the additional control-server role. Keeping those distinctions matters. The story shows how old trust can be bought and reused, rather than proving that every forgotten link is a trap.
How a web address changes hands
A domain name is rented for a period, usually through a registrar. The person or business pays to keep the registration and points the name toward its website, email service, or other systems. If the registration is renewed, ordinary visitors see continuity. If it is allowed to expire and passes through the recovery process, the name can eventually return to the market.
There is a buffer. ICANN’s current policy for many common endings such as .com requires registrars to send notices roughly one month and one week before expiry, followed by another notice shortly after expiry when the name has not been renewed. The policy also provides a 30-day redemption period after deletion for most generic top-level domains, during which the former holder can ask the registrar to restore the registration. Country-code domains can follow different rules. (ICANN)
Once those chances have passed, specialised buyers compete for valuable names. Services watch for the precise moment a registration becomes available and send rapid purchase attempts. When several buyers want one domain, an auction may decide who gets it. The Hacker News reported that about 50,400 expired domains were re-registered each day across common generic endings during the first half of 2026, rising to roughly 65,000 when country-code endings were included. Those figures come from Infoblox’s data and include legitimate buyers as well as harmful ones. (The Hacker News, IT Pro)
Buying an expired name is legal and often ordinary. A baker may buy a concise address that another business no longer wants. A preservation group may rescue an old community site. A defensive buyer may keep a discontinued brand name away from fraudsters. The risk comes from what remains attached to the name and what the new owner chooses to do with it.
Imagine a local theatre that ran a summer festival at riverlightweekend.example for ten years. Newspapers linked to schedules there, volunteers used email addresses at the domain, schools bookmarked the ticket page, and hundreds of social posts still point toward it. The festival ends and the renewal card expires. Two years later, another buyer can put a completely different page behind the same address, while the newspaper links and family bookmarks remain unchanged.
The browser does not remember the theatre’s intentions. It asks the domain-name system where the address points today, then opens whatever the current owner placed there. The padlock beside the address only says that the connection to today’s site is encrypted. A new owner can usually obtain a valid certificate for a domain they legitimately control. The padlock protects the conversation from interception; it does not certify that the person behind the site is the organisation you remember.
This explains why the old name has value. The buyer receives a queue of visitors who made their decision in the past. They trusted a newspaper article, saved a bookmark, scanned a printed code, or followed a link from a club page months or years earlier. The click happens today, but the judgement behind it may be stale.
The address carries more than a name
An old domain can bring several kinds of inheritance. The easiest one to picture is a backlink, which is simply another page pointing toward it. A university page may link to an old research project. A newspaper archive may link to a company announcement. A forum answer may point to a download that was helpful in 2019. Nobody has to hack those pages; they keep sending visitors because their links were never removed.
Bookmarks create the same effect in private. A family may have a favourite free-streaming address saved on the television browser. An employee may use an old supplier portal from autocomplete. A volunteer may open last year’s event link from a message thread. The name feels familiar because the human remembers it, even though ownership changed out of sight.
Reputation systems can also trail behind. Security products often consider how old a domain is, what content it has served, who has linked to it, and whether harmful activity has been seen there. A newly registered jumble of letters deserves more suspicion than a name with a decade of quiet history. That is a useful shortcut most of the time. Sable Squirrel’s spending shows that criminals understand the shortcut and will pay for names that begin with a cleaner record.
Residual traffic has commercial value even without a scam. If an expired address still receives ten thousand curious visits a month, a buyer can show advertising or redirect those people elsewhere. Harmful operators can use the same flow for fake updates, unwanted browser notifications, gambling pages, or download prompts. The original organisation built the road; the new owner places a toll booth on it.
Email creates a different concern. People may continue writing to old addresses printed on invoices, business cards, public documents, or account records. A new domain owner can set up mail service for addresses at that domain. Whether any useful messages arrive depends on the old organisation’s habits and the services involved, but the possibility is why businesses should treat domain retirement as a security project rather than an accounting chore.
There may also be forgotten technical connections. An old website can be loaded inside another page for an image, script, font, or tracking file. A mobile app may call an address that its maker no longer maintains. A document may contain a live link. Infoblox says one expired domain in the Sable Squirrel collection still received requests from thousands of third-party websites each day. That is inherited traffic with no need to persuade a person to type anything. (Infoblox)
None of these signals belongs permanently to the old owner. They attach to a string of characters, and control of that string can move. We are used to a telephone number changing hands, yet web addresses often feel like permanent buildings. They behave more like rented shopfronts with old directions scattered all over town.
The mistake is treating familiarity as current proof. A domain can be old while its owner is new. A link can come from a reputable newspaper while its destination has changed. A valid padlock can protect a conversation with the wrong shopkeeper. Each clue still tells you something, but none can carry the whole decision when the page asks for a password, payment, download, or permission.
How this reaches an ordinary household
Most people will meet this problem while trying to watch a match, reopen an old craft tutorial, download a printer tool, or follow a link from a five-year-old article. The page may look polished and may even contain the content expected. Trouble begins when it asks for one extra step that the old site never required.
Consider Amir, who searches a family chat for the football-streaming link his cousin sent last season. The address is unchanged, and the page shows team names and a countdown. A large box says the video player needs an update. Amir is already late for kickoff, so installing a file feels like part of watching rather than a separate security decision.
That moment is the real boundary. The stream itself may be poor, illegal, harmless, or some mixture that changes by region and visit. The downloaded “player” receives far more trust than a web page because it can run on the computer. A notification permission can keep sending deceptive alerts after the tab closes. A sign-in form can collect a reused password. A card form can turn a supposedly free stream into an expensive lesson.
An old address makes those requests feel less strange. Amir remembers using the site before. Search results may show old descriptions. Forum posts may recommend it. The browser displays an encrypted connection. Every clue refers to some part of the address’s history or present connection, but none answers the practical question: should this page receive new authority on the device today?
You can lower the risk without becoming suspicious of every old article. Reading a page asks little of your device. Installing an application, enabling a browser extension, accepting notifications, signing in, and paying are larger steps. Pause when the site crosses one of those lines, especially if you arrived through an old bookmark or old content rather than the organisation’s current home page.
A simple check is to search for the organisation separately and compare its current official address. Open a fresh tab, type the organisation’s name, and look at a recent trusted listing, official social profile, current printed material, or account app. For a bank, government service, retailer, or software maker, use the address you already know or reach it through a saved official app. Do not let the questionable page choose the source that confirms it.
Dates help too. A glowing recommendation from 2018 proves that the writer liked whatever occupied the address in 2018. It says very little about the operator in August 2026. If the destination now asks for a download or sign-in, look for current confirmation. The older the route, the less weight its endorsement should carry.
You may decide that checking a free stream or abandoned-tool download is too much work, which is a perfectly good answer. You do not owe an unfamiliar page a forensic examination. Close it and spend your evening on the match rather than the domain’s ownership history.
What to do when an old link asks for something
The useful response depends on the request. A page that only displays an old article can usually be read and left alone. A page asking for control, secrets, or money deserves an independent check. The following sequence keeps the work proportional.
-
Stop at the new request: If an old bookmark suddenly asks for a player, browser extension, notification permission, password, or card, do not continue from habit. The address may be identical while the owner or page has changed. Closing the tab costs less than proving the request safe under time pressure.
-
Find the current organisation through a route you choose: Open a new tab or official app. Search for the business, club, charity, or software project by name and confirm its present address from a recent source. If it has moved, use the new site and remove the old bookmark.
-
Treat the padlock as encryption, not identity history: A padlock means the browser has an encrypted connection to the domain shown. Read the full address and ask whether that current domain belongs to the organisation. Do not use the padlock alone as permission to pay or sign in.
-
Decline surprise downloads and notifications: A video page should not need a special player from an unknown site, and a news article does not need permission to send alerts. Use the browser’s built-in controls to deny the request. If a service genuinely requires an app, get it from the device’s official store or the organisation’s verified current site.
-
Use a password manager as a warning light: A password manager usually fills credentials only on the exact address where they were saved. If it refuses to fill on a page that looks familiar, stop and inspect the domain rather than copying the password manually. The refusal may be telling you that the page is on a different address.
-
Leave small payments to a trusted route: A low fee is still a card request. Pay for tickets, subscriptions, deliveries, or donations through the organisation’s current account page or app. A familiar old domain does not earn an exception.
-
Clean up the route afterward: Delete the stale bookmark, correct the link in a family chat when practical, and tell the owner of the page that still points there. One repaired link can stop many future visits. You do not need to chase every copy across the internet.
If you only opened the page and left, there is usually no reason to panic. Update the browser and device in the normal course, then move on. A visit becomes more concerning when you ran a file, installed an extension, granted unusual permissions, entered a password, entered card details, or approved a bank prompt.
If you downloaded and ran something, disconnect the computer from the internet and ask a trusted technical person or security service to examine it. Use another device to change any password you entered, beginning with email if that password was reused. Contact the bank through its official app or the number on the physical card if you supplied payment details or approved a transaction.
Browser notifications deserve a quieter fix. Open the browser’s site-permission settings and remove notification access for the unfamiliar address. Do not click the warning banners it sends, even when they claim the device has a virus. A notification can imitate a system alert while remaining only a message from a website you once permitted.
A password manager and official app stores remove much of the guesswork here. They will not make every old link safe, but they narrow the dangerous moments. You have my blessing to ignore domain-age lookup tools unless you enjoy that sort of work. Protect the handover of authority instead: installs, passwords, payments, and permissions.
Site owners need a retirement plan
For a family, closing the tab is enough. A business, charity, club, or project that owns domains has a larger responsibility because other people may keep trusting those names. Letting a registration lapse without checking what still depends on it can transfer years of accumulated attention to the next buyer.
The safest default is often boring: keep important former domains registered. Renewal costs money each year, but the fee can be modest beside the cost of a convincing fake site, lost email, or a poisoned download link. This matters most for names that held customer accounts, staff email, software downloads, payment pages, memorable campaigns, or links printed on products that remain in circulation.
Automatic renewal helps only if its foundations work. The registrar needs a valid payment method and a contact address outside the domain being renewed. ICANN specifically recommends a secondary contact that does not depend on the expiring domain, because an expiry can interrupt mail to the very address receiving the warning. Use more than one responsible contact, and test that renewal notices reach them. (ICANN)
Registrar-account security matters as well. Protect it with a unique password and strong two-step verification. Limit who can change contact details, name servers, transfer settings, and renewal choices. Record where each domain is registered, who pays for it, what it serves, and which team owns the decision. A spreadsheet that nobody reviews once a year is a false comfort, so put the review on a calendar with a named person.
Before retiring a domain, inventory the connections. Search your own websites and code for the address. Check email aliases, sign-in recovery addresses, cloud accounts, social profiles, printed codes, mobile apps, API calls, image links, advertising campaigns, and supplier portals. Ask staff where they still use addresses at that domain. The forgotten dependency is usually less glamorous than the main website and more expensive to discover after ownership changes.
Move people deliberately. Put a clear notice on the old site, redirect expected pages to their new homes, update important third-party listings, and contact partners that send customers through the old address. Keep the old domain through a long quiet period while watching web and mail traffic. A name that still receives meaningful visits or sensitive messages is still doing security work, even if marketing considers it retired.
Email needs particular patience. Change recovery addresses on services before shutting old mailboxes. Tell regular senders about the move, remove the address from public documents where possible, and keep a controlled catch-all only if the privacy and workload are acceptable. Do not assume every supplier will update its records after one announcement.
Some names can eventually be released. A temporary internal test domain with no public links carries less risk than a customer-facing brand used for a decade. Base the decision on residual trust rather than sentiment, and document why the name is safe to drop.
If renewal has already failed, act quickly through the registrar rather than an unsolicited “recovery” service. ICANN’s policy provides notice and redemption steps for many generic domains, but timing and fees vary. Confirm the status through the registrar’s official site. Once another party legitimately acquires the name, recovery becomes slower and uncertain.
Small clubs and family businesses can keep this manageable. List the handful of public domains, turn on renewal, use an outside contact email, secure the registrar account, and review the list twice a year. You do not need an enterprise domain-management platform for three names. You need one owner, working payment details, and a calendar reminder that somebody actually opens.
What security teams should change
The research also exposes a weakness in simple blocking rules. A security product may pay close attention to domains registered yesterday because new names are frequently used in scams. Sable Squirrel paid for older names precisely because age and history could reduce that suspicion. A clean past belongs to the name, while current intent belongs to today’s owner.
Teams protecting a school, office, or home-filtering service should therefore notice ownership and behaviour changes, not merely the original registration date. A long-standing address that changes registrar details, name servers, hosting, certificates, content, and traffic pattern in a short window deserves a fresh assessment. The question is whether today’s destination still resembles the reason people and machines trust it.
Protective domain-name filtering can block known harmful control servers before an infected device reaches them. Infoblox naturally sells such a service, so its product recommendations should be read with that commercial interest in mind. The underlying control is still sensible when it uses current threat information and produces logs that someone can review. It should support device updates, limited permissions, and endpoint protection rather than replace them.
Web filters should avoid a lazy rule that declares every expired and re-registered domain harmful. IT Pro notes that many of the roughly 65,000 daily registrations in Infoblox’s first-half 2026 figure are legitimate commercial or personal purchases. Blocking the whole category would damage ordinary sites and train users to work around warnings. A change of ownership is a reason to reconsider trust, not an automatic conviction. (IT Pro)
Developers have their own cleanup job. When a project retires a domain, remove it from package metadata, documentation, update mechanisms, sample configuration, mobile applications, and remote asset calls. A forgotten script reference can cause another website to execute content from the new owner. Pinning important resources, serving them locally, and reviewing external dependencies reduces that inheritance.
Organisations should also search their public pages for outbound links to domains they no longer control. Universities, newspapers, councils, and charities often keep valuable archives, which means their old pages continue sending trust for years. A periodic broken-link and ownership-change review is unglamorous work with a clear payoff. At minimum, repair links on high-traffic pages and pages that direct readers toward downloads, donations, logins, or health advice.
Incident responders should preserve the date of change. If a familiar domain starts serving malware in August 2026, an old allow-list entry from 2024 should not settle the case. Compare current ownership, name servers, certificates, page captures, and network behaviour with earlier records. That timeline can separate compromise of the former owner from misuse by a later buyer.
The goal is not to erase history from security decisions. History remains useful. It should expire as proof when control changes. Treat a major ownership or infrastructure change like a new tenant moving into an old building: keep the street address, but change the assumptions about who has the keys.
A familiar name is only a starting point
Sable Squirrel’s scale makes the point easy to see. According to Infoblox’s August 2026 research, the group assembled more than 10,000 domains, spent an estimated $7 million on expired names, and used some of the estate for both public streaming pages and malware control. The operation bought old traffic and old reputation, then attached new purposes to them. (Infoblox)
Most expired domains will never become part of a criminal network. They may sit parked, host an honest new business, or return as a personal project. The practical change is in your standard of proof. A name you recognise can help you orient yourself, but a sensitive request still has to make sense for the current owner and the route you chose.
For ordinary browsing, pause at the handover of authority. A page wants to install software, send notifications, receive a password, or take payment. That is where you check the organisation’s current home through another route. If the check is annoying and the page offers nothing essential, close it.
For site owners, renew the names that still carry trust. Use contact details that survive the domain, secure the registrar account, and retire addresses only after their links, mail, and technical dependencies have gone quiet. An unused website can remain an active security boundary for years.
The internet does not forget directions at the same speed that organisations close. Old articles, printed codes, bookmarks, and software keep pointing long after the sign above the door changes hands. Keep that picture in mind, protect the few moments that matter, and skip the rest.
If you want calm, practical security notes without the daily panic cycle, the newsletter is one email per month.
Sources
- Infoblox Threat Intel: $7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret, accessed 2026-08-15
- The Hacker News: Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware, accessed 2026-08-15
- IT Pro: Expired domains are a goldmine for hackers, and some cyber crime groups are investing millions, accessed 2026-08-15
- ICANN: Expired Registration Recovery Policy, accessed 2026-08-15