unphish
unphish unphish

One Domain, Twelve Brands Targeted

One Domain, Twelve Brands Targeted

Anatomy of a live subdomain-abuse campaign and what security teams should do about it

In early April 2026 a single parent domain – offcialonlinee.com – quietly began impersonating more than a dozen well-known consumer brands. Each brand was given its own third-level label: yeti.offcialonlinee.com, pandora.offcialonlinee.com, hoka.offcialonlinee.com, crocs.offcialonlinee.com, and more. Same infrastructure, same discount banner, same store template – different logo. It is one of the cleanest live examples of subdomain abuse we have seen this quarter, and a useful reminder that brand impersonation is now an economies-of-scale business.

What is subdomain abuse?

Subdomain abuse is a phishing and counterfeit-storefront technique where a single registered domain is used as a launchpad to attack many brands at once. Instead of registering twelve separate domains – twelve WHOIS records, twelve TLS certificates, twelve takedown targets – the attacker registers one “base” domain and spins each brand up as a subdomain underneath it.

Three things make this pattern attractive to attackers:

Case study: offcialonlinee.com

The parent domain is a classic typosquat of “official online” with two deliberate misspellings designed to survive a casual glance at a URL bar or an email preview. Our passive-DNS monitoring has surfaced the following subdomains over roughly six weeks – each one staged as a fully-themed counterfeit storefront:

Subdomain Impersonated brand First seen Last update
www.offcialonlinee.comStaging / template shell16 Mar 202623 Mar 2026
cs.offcialonlinee.comPlaceholder (“Velora” / shop-2)3 Apr 20264 Apr 2026
hoka.offcialonlinee.comHOKA (footwear)5 Apr 20265 Apr 2026
laneige.offcialonlinee.comLaneige (beauty)7 Apr 20267 Apr 2026
jonesroad.offcialonlinee.comJones Road (cosmetics)7 Apr 20267 Apr 2026
buffcitysoap.offcialonlinee.comBuff City Soap7 Apr 20267 Apr 2026
necessaire.offcialonlinee.comNécessaire (body care)7 Apr 20267 Apr 2026
owalalife.offcialonlinee.comOwala (drinkware)13 Apr 202613 Apr 2026
yeti.offcialonlinee.comYETI (drinkware)14 Apr 202614 Apr 2026
on.offcialonlinee.comOn (running footwear)15 Apr 202616 Apr 2026
pandora.offcialonlinee.comPandora (jewellery)15 Apr 202615 Apr 2026
gymshark.offcialonlinee.comGymshark (apparel)15 Apr 202618 Apr 2026
crocs.offcialonlinee.comCrocs (footwear)17 Apr 202618 Apr 2026

Every subdomain uses the same visual template: an “Up to 30% off & Free Shipping” sale banner, a centred brand logo pulled from the genuine brand, a headline marketing image, and a checkout flow that collects card details. Chrome Safe Browsing flags most of them as “Dangerous” in the address bar, so Google has already correlated several.

Two observations worth calling out:

Underneath the visual theming the plumbing is boring and reusable. A single wildcard TLS certificate issued against .offcialonlinee.com is enough to serve every brand page with a valid padlock. The same IP, the same Apache or Nginx configuration, the same payment-capture form and the same WooCommerce-style /product-category/ path structure appear across every subdomain we inspected. That reuse is the whole point: the operator has reduced the marginal cost of attacking a new brand to roughly the time it takes to swap a logo and a hero image.

Why it works

From a consumer perspective the attack is simple and highly convincing. The brand name in the subdomain label (“yeti”, “pandora”, “hoka”) matches the brand in the logo, and most users do not parse hostnames right-to-left. A quick glance at “yeti.offcialonlinee.com” reads as “YETI.” Mobile browsers, email clients and chat apps make this worse by truncating or hiding the full hostname entirely.

From a defender perspective the architecture exploits a gap in how we are organised. Brand teams monitor mentions of their brand and typically only see yeti. Security teams monitor their own domains, not other brands’. Unless someone is watching the parent domain – or watching Certificate Transparency for wildcard issuances under it – the victim brands end up fighting twelve separate, overlapping battles.

Detection and response for security teams

Signals worth monitoring:

For takedown and response:

The takeaway

Subdomain abuse is not new, but offcialonlinee.com is a useful snapshot of how mature the tradecraft has become. One registration, one template, one operator, twelve brands – and almost certainly more before the infrastructure is taken down. Defending against it means moving the monitoring target one level up: from your own domain to any domain capable of becoming the parent for yours.

This article was prepared by the unphish team based on live monitoring data collected between 16 March and 24 April 2026.

About unphish

Protect Your Brand with unphish

unphish is a threat detection and disruption platform built to identify and take down phishingscams, and digital impersonation at scale. We combine intelligence-led detection with automated enforcement to help organisations protect their brand, customers, and digital ecosystem.

See unphish in Action

Detect, Validate, and Take Down Threats Automatically

unphish combines intelligence-led detection with automated enforcement so you can protect your brand, customers, and digital ecosystem without the manual effort.

Create your account