Phishing Landscape 2026 – Proportion of Phishing Domains by Namespace Segment
Colin Strutt
In previous years, Interisle published comprehensive annual reports on phishing. This year, we’re taking a different approach and showing just the significant results of our analysis as a series of posts.
You can refer to previous full reports (such as Phishing Landscape 2025) for more details about our methodology and definitions of terms.
In the previous post, we grouped Top-level Domains (TLDs) by “market segments” - the legacy gTLDs (e.g., .COM, .NET, .ORG), the TLDs operated by countries, sovereign states or designated territories (ccTLDs), and TLDs introduced since 2012 (new gTLDs) - and examined how the proportion of registered domains compared to the proportion of domains reported for phishing for each segment.
In this post we look at the phishing activity over time for the same market segments to see how the proportions of phishing domains by market segment have changed.
Since the demise of commercial ccTLD operator Freenom (2021-2023), the proportion of phishing domains reported in the ccTLDs dropped dramatically. The proportion of phishing domains reported in the gTLDs has grown significantly over the years. The new gTLD space is clearly attracting a very high proportion of cybercriminal activity. In both segments, TLDs that offer unrestricted domain registrations (open to all) remain the most attractive to cybercriminals.
In the next post, we will look at the TLDs with the most phishing this past year.


