Friday, 25 September 2026

The top GenAI tactics used by counterfeiters and the importance of IP (Original Version)

Generative artificial intelligence ('GenAI') is a general term used to describe automated systems able to generate complex content of a variety of types - which may include natural language, images or audio - in response to an input prompt. Many GenAI systems are built using models which have been trained using very large volumes of pre-existing content, with the aim of learning statistical patterns in this material. GenAI applications have become extremely accessible and popular in mainstream use, with over 60% of the population in the US (for example) now utilising such services[1], which include familiar examples such as OpenAI's ChatGPT, Google Gemini, image generators such as Midjourney, and coding assistants like GitHub Copilot.

In the world of online brand protection, AI capabilities are now extensively used both by infringers and by brand protection service providers. For bad actors, GenAI can readily be used in the creation of highly convincing infringing content, such as phishing e-mails[2], fake websites, and malicious files. Whilst GenAI can significantly lower the technical entry barrier to (and increase the speed of) the generation of fraudulent content, in many cases it does not necessarily change the types of infringements which are produced. However, some newer areas, such as the generation of 'deepfake' content (i.e. artificially generated video or audio content intended to impersonate a trusted individual), or the creation of highly convincing fake identity documents, are only possible through the use of GenAI. Such content has extensively been observed as being utilised in executive impersonations and payment-transfer scams[3], and in identity theft.

AI-generated content is increasingly being seen to be utilised by bad actors in a wide variety of other ways. For example, in the counterfeit goods trade, imagery containing legitimate product features, serial numbers and other relevant characteristics can readily be generated for use in marketplace listings or in product packaging, as a means of falsely creating an appearance of authenticity and bypassing basic legitimacy verification checks. AI image generation and automated listing tools are also being used in the creation of merchandise featuring protected intellectual property, via print-on-demand services[4].

One of the trickiest areas to address by brand owners and service provides is the use of deepfake videos and voice clones for the promotion of counterfeit items. This issue is particularly relevant given the popularity of influencer partnerships in promoting branded goods, and can be applied across multiple popular emerging channels increasingly used for e-commerce, including short-form video platforms and messaging apps.

In general, the maintenance of a robust portfolio of intellectual property (IP) is key to an effective enforcement programme, with a demonstration of rights being essential for successfully actioning the takedown of infringing content - and, conversely, proactive brand protection can often be a prerequisite for retaining IP protection. IP traditionally encompasses a range of different types of rights, including trademarks (in relevant product and service classes, and in specific jurisdictions), copyright, patent and design rights. Trademarks - which are signs, designs, etc. serving as an identifier of product origin - can themselves be of a number of types; most commonly they cover word-marks or logos, but it is also possible for other distinctive characteristics such as colours, sounds and even smells to be covered.

Many celebrities and other key figures are increasingly becoming aware of the value of their personal 'brands' - particularly in the era of deepfake threats - and are beginning to explore the process of registering distinctive personal characteristics as trademarks. High-profile examples include the registrations by Taylor Swift of a range of marks including her stage name, album titles, lyrics, sound snippets, voice and likeness[5], and applications by footballer Cole Palmer for a portrait mark and a celebration mark (comprising a video of his goal celebration[6], already registered as a motion mark[7]), in addition to his name, nickname and signature, intended to prevent commercial misappropriation and open up possibilities for licensing deals[8,9]. These developments follow on from other previous noteworthy stories, such as the registrations by footballers Jude Bellingham, Kylian MbappĂ© and Gareth Bale of their names and celebrations, and the gaining of IP protection by athlete Usain Bolt of his 'lightning bolt' pose.

These concepts are of particular relevance in the absence of dedicated image rights laws in jurisdictions such as the UK, resulting on a reliance for protection from impersonation on (generally lower reliability) concepts such as passing off (which applies only to high-profile individuals), privacy, data protection, and copyright (which applies only to e.g. a photograph, rather than the individual portrayed).

Whilst the stories discussed above do highlight an increasing appreciation of the key role of IP protection, they do raise some questions on the enforceability of non-traditional trademarks, their ability to function as an indicator of origin (rather than simply being descriptive), and on the circumstances in which these types of rights might be exercised. However, the attempts by various celebrities to protect specific personal characteristics has proven valuable in increasing public awareness of their reputations and profiles, and highlights the importance of a carefully considered approach to the construction of a robust but effective portfolio of rights.

References

[1] https://www.genaiadoptiontracker.com/

[2] https://www.vectra.ai/topics/ai-scams

[3] https://www.ic3.gov/PSA/2024/PSA241203

[4] https://snapdragon-ip.com/black-friday-brand-protection-guide-resource/

[5] https://esquiretrademarks.com/how-many-trademarks-does-taylor-swift-have/

[6] https://www.youtube.com/shorts/jDzJ7QECUzo

[7] https://trademarks.ipo.gov.uk/ipo-tmcase/page/Results/1/UK00004129108

[8] https://www.lawinsport.com/topics/item/cold-palmer-trade-marks-image-rights-and-the-business-of-being-an-athlete

[9] https://www.taylorwessing.com/en/insights-and-events/insights/2026/01/bu-cole-palmers-trade-mark-strategy-are-faces-and-celebrations-registrable

This article was first published on 25 September 2026 at:

https://www.linkedin.com/pulse/top-genai-tactics-used-counterfeiters-importance-ip-david-barnett-dfhxe/

A modified version was originally published on on 25 August 2026 at:

https://snapdragon-ip.com/the-top-generative-ai-tactics-used-by-counterfeiters-and-why-ip-matters/

Tuesday, 15 September 2026

Black Friday domains: an out-of-season look forward to the holiday shopping period (Original Version)

Prior to the start of the build-up to the holiday shopping period, we conduct an 'out-of-season' analysis of the current state of the landscape relating to Black Friday domains. The research follows on from SnapDragon's 2025 overview of brand protection threats associated with the Black Friday season, and serves as a start point for ongoing analyses as the 2026 period moves closer.

The history of registration activity for domain names connected to Black Friday unsurprisingly shows a strong annual cycle, peaking in Q4 of each year. As of June 2026, a pre-existing 'baseline' of around 4,100 such domains were found to be registered. The domains encompass a range of naming patterns and styles, with significant numbers featuring additional keywords explicitly relating to e-commerce or special offers, specific product types, or explicitly targeting particular country markets. Around half of the domains were found to feature live associated websites - comprising a range of content types including active e-commerce or the promotion of other product and service areas, such as payday loans, cryptocurrency and gambling. Over one in three of the domains in the dataset also have active e-mail functionality, and the registrations cover a wide range of domain extensions (TLDs), including significant numbers hosted on higher-risk TLDs.

* * * * *

Following SnapDragon's 2025 overview of brand protection threats associated with Black Friday and the holiday shopping period[1], and in advance of the build-up to this year's season, we have investigated the related domain name landscape, in order to gain an overview of the current scale of potential infringement risks (and to serve as a start point for ongoing analysis this year). 

Black Friday - the day after the US Thanksgiving holiday, which falls on the fourth Thursday of November - has become increasingly popular for holiday shopping (and associated promotions) in recent years. Accordingly, as a result of this heightened awareness, it has in parallel also been hijacked by bad actors to drive consumers to their own online material, with the intention of selling counterfeit or otherwise infringing goods, or promoting other damaging content. 

As has been noted in a number of previous studies[2,3,4,5], levels of elevated activity of this type are often reflected in patterns of related domain registrations. As an illustration of how this trend has continued to the current time, it is instructive to consider the dataset of domains with names containing 'black(-)friday' (i.e. with an optional hyphen) which are currently registered. This analysis was carried out using data from domain zone-files, giving comprehensive coverage across all gTLD (generic top-level domain) extensions. 

As of June 2026, there were around 4,100 such domains. Excluding the approximately 300 which are most likely to be legitimate registrations by brand owners (on the basis of the explicit use of a corporate domain name registrar), Figure 1 shows the registration history of the remaining 3,800, grouped by their original month of registration.

Figure 1: Numbers of registered gTLD domains with names containing 'black(-)friday', by original month of registration (from 2001 to 2026)

The figures show a striking annual cycle, with numbers of registrations (unsurprisingly) peaking markedly in the fourth quarter (Oct - Dec) of each year (i.e. centred on the Black Friday period). A subsequent search in September showed that this figure had already grown to 5,453 registered 'black(-)friday' domains, an increase of 32% in 15 weeks.

In addition, there is some suggestion in an overall growth of levels of activity over time, although this may in part be an artefact caused by the fact that the analysis considers only those domains which are currently still registered, and will therefore exclude any historical registrations which were registered but have subsequently lapsed - i.e. the (potentially large numbers of) examples which may have been registered for just a short period (of, say, a year) and intended only for use in a particular individual season. 

It is also instructive to look for other trends and patterns in the set of approximately 3,800 Black Friday domains of potential interest or concern. The first observation is that relatively few of these domain names themselves as explicitly brand-specific. For example, only nine of the domains (0.2% of the total) include the name of any of the top ten global luxury brands[6], and only a further 22 (0.6%) feature the name of any of the top ten global retail brands[7]. The conclusion is therefore that - even where specific brands are being targeted through the use of infringing websites - the registration of generic Black-Friday-related domain names is a much more popular tactic by bad actors. (This is despite the fact that some brand owners - notably including (from the sub-dataset of approximately 300 probably legitimate domains) Beats (with 91 registrations) and Lululemon (23) - have taken the proactive approach of registering portfolios of brand-specific domains defensively, to prevent their potential registration and use by bad actors.)

Indeed, the dataset of general Black Friday domain registrations is dominated by examples containing generic e-commerce terms ('shop', 'sale', 'outlet', etc.) or keywords relating to special offers ('deals', 'vouchers', 'coupons', 'giftcards', etc.), references to specific product types ('clothing', 'watches', 'tablets', etc.), or country names. These types of names are more amenable to a wider range of uses by bad actors, including websites targeting either single ('mono-brand') or multiple ('multi-brand') brands, or promoting other types of products or services - in addition, of course, to the potentially large numbers of sites associated with legitimate brand promotions by official parties. 

Other general observations from the data include the facts that: 

  • 1,934 of the domains (50.9%) return a live website response (i.e. some sort of active content) 
  • 1,415 (37.2%) have active MX (mail exchange) records, indicating that they have been configured to be able to send and receive e-mails and - even in the absence of any associated live website - could be associated with active e-mail or phishing campaigns 
  • The top ten domain extensions (TLDs) represented in the dataset are: com (2,738 domains), shop (171), net (137), info (102), org (98), xyz (54), world (36), sbs (34), click (30), store (26). Whilst the presence of some of these extensions in the list is unsurprising, in view of the large numbers of domains they host generally (such as .com and .net), or their clear relevance to e-commerce (.shop and .store), others are more noteworthy - particularly some of the new-gTLDs in the list such as .xyz, .world, .sbs and .click - many of which have been previously noted as being disproportionately frequently associated with infringing activity[8,9,10]. 

Amongst the live domains, a range of content types were identified. Examples include sites promoting sales across multiple brands or platforms, or featuring material relating to any of a diverse range of other products or service types, including payday loans (a trend previously noted in 2024), cryptocurrency and gambling. Examples of some of these sites are shown in Figure 2. 

Figure 2: Examples of live websites associated with Black Friday domains 

These observations highlight the scale of the pre-existing Black Friday domain and website landscape even outside the holiday shopping season, at a point where numbers are only set to grow as the year continues. Many of the identified infringements utilise generic, rather than brand-specific domain names, highlighting the need for a flexible monitoring approach rather than the use of exact-brand matching. 

Additionally, of course, domain names comprise only one specific content type in an online environment where activity is becoming ever more increasingly interconnected across channels. This is especially true in the e-commerce sphere, where alternative areas such as short-form video content and messaging apps are becoming ever more relevant. 

Overall, these trends, coupled with the observed range of types of content of particular concern, provide compelling illustrations of the importance of proactive monitoring and enforcement by brand owners – particularly at times of heightened activity. However, the substantial scale of the risk even out-of-season shows that brand protection should be treated as an ongoing requirement, rather than just being considered a short-term campaign issue. For programmes to be truly effective, brand owners must also be mindful of the importance of a joined-up approach, with collaboration between multiple teams, including marketing, legal, digital, and security. 

References

[1] https://snapdragon-ip.com/black-friday-brand-protection-guide-resource/

[2] https://www.cscdigitalbrand.services/blog/how-will-black-friday-ecommerce-domains-trend/ (2020)

[3] https://www.cscdigitalbrand.services/blog/holiday-shopping-events-part-2/ (2020)

[4] https://www.iamstobbs.com/opinion/web-dot-coms-but-once-a-year-holiday-shopping-activity-part-1-black-friday-domains (2023)

[5] https://www.iamstobbs.com/opinion/its-beginning-to-look-a-lot-like-domain-patterns-in-the-approach-to-the-holiday-shopping-season-2024 (2024)

[6] https://www.kantar.com/campaigns/brandz/global

[7] https://en.wikipedia.org/wiki/List_of_largest_retail_companies

[8] 'Patterns in Brand Monitoring' (D.N. Barnett, Business Expert Press, 2025), Chapter 5: 'Prioritization criteria for specific types of content'

[9] https://circleid.com/posts/towards-a-generalised-threat-scoring-framework-for-prioritising-results-from-brand-monitoring-programmes

[10] https://circleid.com/posts/20230117-the-highest-threat-tlds-part-2

This article was first published on 15 September 2026 at:

https://www.linkedin.com/pulse/black-friday-domains-why-brands-should-preparing-etgtf/

Tuesday, 8 September 2026

Black Friday domains: why brands should be preparing now, and not later

by David Barnett and Jane Jarosz

Black Friday has become one of the biggest moments in the retail calendar. So much so that this year is projected to expand beyond a single day to a 'Black Week' and surpass $25 billion in US e-commerce sales, representing an 8.7% year-over-year increase. For consumers, it means deals, discounts and an increasingly early start to holiday shopping. For brands, it represents a major opportunity to drive sales, acquire customers and build momentum going into the crucial end-of-year period.

The attention that makes Black Friday so valuable to brands makes it equally valuable to bad actors - giving counterfeiters, scammers and unauthorised sellers a ready-made opportunity to hijack consumer demand. Counterfeiters, scammers and other infringers can exploit the event's familiarity to direct consumers towards websites, products and services that have nothing to do with the legitimate brands they may believe they are interacting with.

Most importantly, this activity does not begin when Black Friday begins. Our latest analysis of Black Friday-related domains suggests that a significant online landscape is already in place well ahead of the 2026 shopping period. 

We analysed domain zone-file data to look at currently registered domains containing 'blackfriday' or 'black-friday' across generic top-level domains (gTLDs). As of June 2026, we identified around 4,100 registered domains.

Figure 1: Numbers of registered gTLD domains with names containing 'black(-)friday', by original month of registration (from 2001 to 2026).

Approximately 300 appear to be legitimate registrations by brand owners, based on the use of corporate domain registrars. That leaves around 3,800 domains that warrant potential interest or concern. And this is before the traditional Black Friday build-up has even begun.

The registration data shows a striking annual pattern: activity consistently peaks during Q4, around the Black Friday period. There is also evidence suggesting that overall activity may be increasing over time, although this needs to be treated with some caution because the current analysis only captures domains that remain registered today. Short-lived domains that were registered for a single shopping season and subsequently allowed to lapse are therefore excluded. In other words, the 4,100 figure is not the full historical picture. It is the existing landscape that remains visible today.

The biggest risk may not have your brand name in the domain. One of the most interesting findings from the research is what these domains don't contain. Only nine domains in the dataset - 0.2% - include the name of one of the top ten global luxury brands[1]. A further 22 - 0.6% - feature the name of one of the top ten global retail brands[2]. At first glance, that might sound reassuring. It isn't. It tells us something important about how bad actors can use Black Friday domains. Rather than registering domains containing a specific brand name, they can use generic, commercially attractive terminology that creates the appearance of a legitimate Black Friday shopping destination.

For example:

  • 'shop'
  • 'sale'
  • 'outlet'
  • 'deals'
  • 'vouchers'
  • 'coupons'
  • 'giftcards'

Put alongside product categories such as clothing, watches or tablets, or country-specific terms, these domains can then potentially be used to target individual brands, multiple brands, or entirely different products and services.

If you are utilising a brand protection strategy based purely on exact brand-name matching, or even mis-spelt brand names, it could well miss these threats entirely. A domain doesn't need to say your brand's name to create a problem for your brand. Plus, more than half of these domains are already live.

The scale becomes even more significant when we look at what these domains are actually doing. Of the approximately 3,800 domains we discovered and felt were of potential interest or concern, 1,934 - 50.9% - return a live website response. That means there is already some form of active content associated with more than half of the domains. And the content is not limited to obvious Black Friday e-commerce sites. The analysis identified websites promoting sales across multiple brands and platforms, alongside sites associated with other products and services, including payday loans, cryptocurrency and gambling. This is an important reminder that a Black Friday domain is not automatically a counterfeit site - but neither should it automatically be dismissed as harmless. Context matters.

There is another finding from our research that deserves particular attention.1,415 domains - 37.2% of the total - have active MX records. In simple terms, these domains have been configured to send and receive e-mail. Even where there is no live website, that capability could potentially be associated with active e-mail or phishing campaigns. For brand owners, this broadens the risk considerably. The threat is not necessarily just: "Could someone use this domain to sell counterfeit products?"; It can also be: "Could someone use this domain to make consumers believe an e-mail, promotion or communication is connected to a legitimate Black Friday offer?". That makes domain monitoring relevant not only to brand and e-commerce teams, but potentially to security, digital and marketing teams too. It is also a reflection of what consumers reported in the 2024 research study by Hostinger[3] where 59.2% of respondents said that email offers were the top method of marketing that influenced their Black Friday and Cyber Monday purchases.

The discovered domains span a wide range of Top Level Domains (TLDs). The ten most represented in the dataset are:

  • .com - 2,738
  • .shop - 171
  • .net - 137
  • .info - 102
  • .org - 98
  • .xyz - 54
  • .world - 36
  • .sbs - 34
  • .click - 30
  • .store - 26

Some of these numbers are unsurprising. For example, .com and .net, are widely used generally, while .shop and .store have an obvious ecommerce relevance. Others are more noteworthy. Several newer gTLDs - including .xyz, .world, .sbs and .click - have previously been associated disproportionately with infringing activity[4,5,6]. This doesn’t mean that every domain using one of these extensions is malicious. It does mean that TLD can be one useful signal when assessing risk.

The real lesson: don't wait for Black Friday. The most important finding from this research may actually be the simplest. The Black Friday threat is not seasonal. Yes, registration activity follows a strong annual cycle, with significant peaks in Q4. But the existence of around 4,100 Black Friday-related domains in June - months before the main shopping period - demonstrates that the digital landscape is already established before consumers start searching for deals. And as the year progresses, the number of registrations is likely to increase. Waiting until November to start monitoring therefore means starting long after the activity has already begun.

The research points towards a few practical actions.

  1. Start monitoring before your Black Friday campaign starts - Don't make Black Friday monitoring a two-week exercise. Establish a baseline early, identify suspicious domains and track how the landscape changes as Q4 approaches. That gives you something much more valuable than a snapshot: a picture of how the threat is developing.

  2. Don't search only for your brand name - Generic domains are a significant part of the landscape. Your monitoring strategy should therefore consider combinations of: brand + Black Friday + e-commerce terminology + product terminology + relevant markets, rather than relying solely on exact brand-name matches.

  3. Look beyond the website - A domain is only one part of a wider digital ecosystem. The research itself highlights how e-commerce activity is increasingly interconnected with short-form video and messaging apps and e-mail capability. That means a suspicious domain could be just one component of a broader campaign. Monitoring should therefore connect the dots between domains, websites, e-mail, marketplaces, social content and other relevant channels on an ongoing basis.

  4. Prioritise rather than simply collect data - Thousands of domains can quickly become an overwhelming dataset. The objective shouldn't be to investigate every suspicious domain equally. Instead, look for signals such as:

    • Is there a live website?
    • Is e-commerce activity taking place?
    • Is the brand being referenced?
    • Are products being offered?
    • Is there active e-mail functionality?
    • Does the domain connect to other suspicious activity?
    • Is the site targeting a particular market?
    • Is there evidence of phishing or consumer deception?

    The goal is not more alerts. It's better intelligence.

  5. Make Black Friday a cross-functional exercise - Brand protection shouldn't sit in isolation during high-risk periods. The findings from this research point towards the need for collaboration between marketing, legal, digital and security teams.

    • Marketing knows what legitimate campaigns are planned.
    • e-commerce knows where consumers are expected to shop.
    • Legal understands the available enforcement options.
    • Security can help assess phishing and other technical risks.

    Bringing these perspectives together can make it much easier to distinguish legitimate promotional activity from activity that threatens the brand or its customers.

The question isn't "What happens on Black Friday?". It's "What is already happening before Black Friday?". Thousands of Black Friday-related domains already exist. More than half of those of potential concern have live websites. More than a third have active e-mail functionality. And many of the domains are generic rather than explicitly tied to a particular brand.

That combination makes one thing clear: brands cannot afford to treat Black Friday brand protection as a short-term campaign. The strongest approach is proactive, continuous and connected across channels. Start by identifying the domains, websites and wider digital activity already associated with the event. Establish your baseline. Identify the highest-risk activity. And put an enforcement plan in place before consumer attention reaches its peak. When millions of consumers are searching for the best deal, the last thing you want is for someone else to control where they end up.

Figure 2: Examples of live websites associated with Black Friday domains

References

[1] https://www.kantar.com/campaigns/brandz/global

[2] https://en.wikipedia.org/wiki/List_of_largest_retail_companies

[3] https://www.hostinger.com/in/tutorials/black-friday-statistics/

[4] 'Patterns in Brand Monitoring' (D.N. Barnett, Business Expert Press, 2025), Chapter 5: 'Prioritization criteria for specific types of content'

[5] https://circleid.com/posts/towards-a-generalised-threat-scoring-framework-for-prioritising-results-from-brand-monitoring-programmes

[6] https://circleid.com/posts/20230117-the-highest-threat-tlds-part-2

This article was first published on 7 September 2026 at:

https://snapdragon-ip.com/black-friday-domains-why-brands-should-be-preparing-now-and-not-later/

The top GenAI tactics used by counterfeiters and the importance of IP (Original Version)

Generative artificial intelligence ('GenAI') is a general term used to describe automated systems able to generate complex content o...