Phishing Landscape 2026 – Malicious Phishing Domains
Colin Strutt and Dave Piscitello
In previous years, Interisle published comprehensive annual reports on phishing. This year, we’re taking a different approach and showing just the significant results of our analysis as a series of posts.
You can refer to previous full reports (such as Phishing Landscape 2025) for more details about our methodology and definitions of terms.
In the previous post, we showed the five TLDs with the highest number of phishing domains and the five TLDs with the highest phishing domain scores. We also saw how the top TLDs in each have changed over the years.
Now we turn our attention to the topic of phishing domains that we believe were attacker-created: registered intentionally (maliciously) for the purpose of phishing. If a phishing domain is not determined to be malicious, we consider the domain to have been compromised.
First, let’s look at the breakdown between attacker-created (maliciously registered) and compromised for the TLD market segments that we described in an earlier post:
Historically, malicious domain registrations in the new gTLD market segment have been highly concentrated in fewer than 50 gTLDs. In our 2026 data, nearly all of the domains reported for phishing in the following gTLDs were attacker-registered:
We found that some of the ccTLDs have very high proportions of maliciously registered phishing domains – here are the top five:
The proportion of maliciously registered to compromised phishing domains has changed over our six years of reporting. But not for the better.
The trendline is disturbing… In recent years about three quarters of all phishing domains were registered maliciously.
The TLDs with the highest number of maliciously registered phishing domains in this year’s data were:
With so many registered domains, it’s not surprising that .COM has most maliciously registered phishing domains, though its overall percentage is significantly lower than the next five TLDs. Still, the sheer number of malicious domains is concerning.
Next we look at how the top 5 has changed over six years of reporting:
You can see the full list of TLD tables at the Cybercrime Information Center for both the data for the year and for the year-over-year comparisons.
In the next post, we will look at phishing using free web hosting (subdomain) providers.
Articles in this series (to date):
Phishing Landscape 2026 – Summary Findings
Phishing Landscape 2026 – Six Years of Phishing, Six Years of Growth
Phishing Landscape 2026 – Comparing Phishing Activity Across TLD Market Segments
Phishing Landscape 2026 – Proportion of Phishing Domains by Namespace Segment
Phishing Landscape 2026 – Phishing Activity in Top-level Domains
..






