It has been a year since we last discussed fraudulent domain name registrar scams and we wanted to let people know that this scam continues unabated.
In a nutshell, a message is sent to a publicly-visible email address listed on your website (sales, support, the CEO's office, a public relations contact, et cetera) from a Chinese company purporting to be a domain name registrar. The warning states that another business is attempting to register your existing domain name in Asia with various country-code specific top level domains (ccTLD). For example, since ESET has the eset.asia, eset.hk, eset.org.cn or other domain names in use in China, Hong Kong, India, Taiwan and so forth. The message then goes on to warn that you have a short amount of time to purchase the domains yourself before they are offered to the other party.
This is, of course, a scam; the other party is fictional and some of the domains you are being "offered" may already be registered and in use by your company.
If you do receive such a message, here are steps you can take to minimize the damage:
Scams like these existed long before the Internet, and will continue to exist long after the Internet as we know it has been replaced. A little caution and a little common sense, though, go a long ways to protecting you from them.
For more information, including the reason for the name of the article, see ESET Threat Blog articles The Tits Alternative and There’s More to Jacques Tits than Meets the Eye, as well as an article here from our friends at Norman from March, 2009. Our friends at anti-spam vendor Firetrust also discussed domain registration scams extensively here in their blog in March, 2008.
Regards,
Aryeh Goretsky, MVP, ZCSE
Distinguished Researcher