A groundbreaking report by ONESECURE reveals that for every legitimate organization, there are an average of 151 lookalike domains online, threatening global digital trust.

  • A median of 151 lookalike domains were found for every reference organization domain.
  • 82% of these lookalike domains possess active internet or email infrastructure.
  • Risk exposure spans multiple sectors including finance, healthcare, and education.

In an era where digital interaction is the primary touchpoint for consumers, the line between an official presence and a sophisticated imitation is blurring. The inaugural ONESECURE report, 'The State of Digital Trust in Singapore 2026', has uncovered a massive gap between organizational control and consumer trust. While companies focus on securing their own assets, a vast landscape of external identities is emerging under their names.

The study, which analyzed over 120,000 distinct lookalike domains associated with 448 reference organizations, found a startling trend: each organization is associated with a median of 151 similar-looking domains across the public internet. Crucially, 82% of these domains are not just idle; they possess the technical infrastructure—such as email or web hosting—needed to appear legitimate to an unsuspecting user.

Why This Matters

BozokMedia analysis shows that this is not merely a technical IT issue, but a fundamental crisis of perception. Trust is not built on ownership records or complex security certificates; it is built on familiarity. When a consumer sees a name, an email, or a link that looks identical to their trusted provider, they act on instinct. This creates a massive vulnerability where external actors can exploit the reputation of established brands without ever touching the brand's actual servers.

People don't experience organisations through asset inventories or security diagrams. They experience them through names, emails, websites and links.

The implications are widespread. The report highlights that external identity exposure is prevalent across critical sectors, including financial services, healthcare, education, and public services. This suggests that the phenomenon is a systemic digital risk rather than an isolated industry problem.

Historical Background: The Evolution of Identity Spoofing

Historically, identity theft was focused on individual credentials. However, as organizations moved to the cloud, the target shifted to 'Brand Spoofing.' From early 'typosquatting' (registering domains with common typos) to today's sophisticated infrastructure mirroring, the ability to mimic a brand's digital footprint has become highly accessible, necessitating a shift from reactive to proactive identity governance.

FeatureOfficial Brand AssetsLookalike Domains
OwnershipDirectly controlled by the OrgExternal/Third-party controlled
Trust FactorVerified and LegitimateUnverified and Potentially Deceptive
VisibilityHigh (Managed)Hidden (Shadow Identity)
Did You Know?: Lookalike domains are often used in 'Brandjacking,' where attackers use a brand's visual identity to gain trust before launching a scam.

Frequently Asked Questions

1. Are lookalike domains always used for phishing?
No. While they pose a risk, the report notes that having infrastructure does not automatically mean malicious intent; however, they warrant close monitoring.

2. How can companies protect their brand reputation?
Companies must move beyond securing their own perimeter and start monitoring the wider 'identity landscape' that exists around their brand.