Updated July 24, 2026: this post now carries a statistical appendix — exact confidence intervals, placebo windows, day-of-week controls, and a baseline extended back through May — added in response to reader feedback. Tracing kimik3.com through our full feed archive for that appendix also moved its first-observation date from July 3, 2026 (a scan-window artifact) back to September 19, 2025; the Kimi K3 section has been rewritten accordingly.
On July 16, 2026, Moonshot AI released Kimi K3. On July 17, the first post-launch domains built to look like it — kimik3.net, kimik3.io, kimi-k3.dev — appeared in our crawl. By July 22, the count stood at twenty: kimik3.ai, k3kimi.com, kimik3token.com, and more. Before July 16, the count of such domains in our data was effectively zero — two pre-positioned names aside (one of which, it turns out, had been waiting since September 2025; more on that below), it held at zero across the entire month of June and the first half of July. A brand that did not exist as a target on Thursday had a domain shadow by Saturday.
The conventional way to tell this story is a registrar blog post: "1,200 domains registered containing 'kimik3'." That number is easy to produce and almost meaningless, because registration is the cheapest step in the chain. A domain that is registered but never resolves, never accepts mail, and sits on a parking nameserver is a speculative bet, not a weapon. The question a security team actually needs answered is not how many were registered but how many were armed — and that requires watching the domain past the registrar and into DNS.
This post takes one week of Google Trends spikes across the United States and Canada (the seven days ending July 22, 2026), keeps the five events with a genuine Internet-infrastructure angle, and maps each against our Newly Observed Hostnames (NOH) feed — the same first-seen-hostname stream that powers our WebSocket data product. For every event we measure the shape of the wave, the lag between the news and the domains, the top-level-domain mix, and — for a live probe of 195 matched names — the activation posture: which ones resolve, which accept mail, which are already parked for resale. All Russian-territorial TLDs (.ru, .su, .moscow, and the two Cyrillic IDN suffixes) are excluded from every count per our standing policy, and .ph is excluded as noise because the dotPH registry answers every probe (see Methodology). Throughout, we use registration as readable shorthand for a lookalike's first appearance in the NOH feed — a proxy that is tight for novel brand tokens and looser for established ones, as the Methodology spells out.
The headline finding is that the wave's existence tracks whether the brand is new. A brand-new target (Kimi K3) was followed by a textbook launch-day land grab — zero to twenty lookalikes in six days. But an established giant showed no measurable wave: OpenAI's autonomous-model breach of Hugging Face was the most-searched infrastructure story of the week, yet OpenAI lookalike registrations during the breach ran below their ordinary standing rate of roughly nine per day, consistent with an already-saturated namespace. And a two-hour Instagram outage coincided with no wave at all — the credential-phishing that chases outages lives on free-hosting hostnames like instagram-clone-frontend.vercel.app, which a registration-only feed never records and our NOH feed does. The news cycle has a domain footprint, but for most events it is a footprint of hostnames, not of new registrations.
The Data
We captured Google Trends "Trending Now" for both geo=US and geo=CA over a 168-hour window on July 22, 2026 — 100 trend slots, roughly 84 unique after cross-geo deduplication. We cut sports, celebrity, true-crime, politics, weather, recalls, and local news, keeping only events with an Internet-infrastructure or brand-impersonation angle. Five survived.
| Event | T0 | Trend geos | Brand type | External verification |
|---|---|---|---|---|
| Kimi K3 launch (Moonshot AI) | Jul 16 | CA | New brand | VentureBeat, Bloomberg |
| OpenAI × Hugging Face breach | Jul 21 | CA+US | Established giant | TechCrunch, Axios |
| Instagram DM outage | Jul 22 | US | Established giant | Android Authority |
| Samsung Unpacked / Galaxy Z Fold 8 | Jul 22 | CA+US | Product launch | Samsung Newsroom |
| SSA "Bisignano email" + payment schedule | Jul 2 | US | Government topic | Fast Company, Kiplinger |
The measurement instrument is the NOH feed. Each day our crawler emits every full hostname (FQDN) it observes for the first time. We scanned every daily delta from June 1 to July 22, 2026 — 52 files, roughly 1.05 million new hostnames per day — for keyword and permutation matches to each event, then reduced matches to registrable domains via a public-suffix heuristic and counted the first day each registrable domain appeared. The June files supply a 30-day baseline; the event week (July 16–22) supplies the window. Because a snapshot cannot distinguish a wave from ordinary noise, every event below is reported as window rate versus baseline rate, not as a raw count — and, as of this update, every such ratio carries an exact confidence interval. For the statistical appendix we additionally scanned the 31 May daily files (83 files in all) to build a 61-day robustness baseline, and swept the delta archive back through 2024 for the Kimi-K3 token specifically.
Methodology
Classification labels. Every term used in the analysis is defined here.
- Lookalike / brand-in-domain: a registrable domain whose own core label contains the event's brand token —
kimik3.net,openaiclaims.com,ssagovgov.com. This is distinct from a subdomain match, where the token appears only in a subdomain of an unrelated registrable domain —instagram.somerandomsite.com. The two are counted separately throughout; the brand-in-domain count is the meaningful registration signal, and the subdomain match set is dominated by unrelated spam that happens to use a brand word as a label. - Newly Observed Hostname (NOH): a full hostname (FQDN) seen for the first time by our crawler on a given day. NOH is a DNS-visibility signal, not a WHOIS-registration signal. It captures new subdomains of existing domains (including free-hosting platforms) that a registration-only feed structurally cannot see; it does not carry a registrar registration timestamp. We do not produce a WHOIS-based Newly Registered Domains feed and make no WHOIS-date claims here. Throughout this post registration is readable shorthand for a lookalike's first NOH appearance. For a novel brand token like
kimik3the two are near-identical — the domain could not have existed before the brand shipped, so first-observation is a tight proxy for registration date. For an established brand the proxy is looser: an old domain can enter the NOH feed the first time our crawl reaches it. All rate comparisons below use first-observation dates for both the baseline and the window, so the two are measured on identical terms even where the proxy to registration is imperfect. - Resolving: returns at least one IPv4 A record on a live query.
- Mail-capable: returns an MX record that is not a null MX (RFC 7505) and does not point back at the domain's own apex with no service behind it. Mail-capability is the closest single proxy for "provisioned to run a credential-harvest or lure campaign by email."
- Parked / for-sale NS: delegated to a nameserver operated by a domain marketplace or parking service (Afternic, Sedo, Bodis, Above.com, DAN, HugeDomains, and peers). These domains are registered as speculation or resale inventory, not built for use.
Matching heuristics. For each event we grepped a hand-built permutation list: brand spellings with and without hyphens (kimik3, kimi-k3, k3kimi), the government-agency forms (ssagov, ssa-gov, socialsecurity), product forms (zfold8, galaxyz, unpacked), and the outage form (instagramdown). We then filtered by hand for obvious false positives: openair* (open-air venues) is excluded from the OpenAI set; kimiaiglasses, kimiaipc, and Persian "Kimia"-brand names are excluded from the Kimi set; cassagovilla.de (an Italian surname) survives the ssagov grep but is not a Social Security lookalike and is noted as classifier noise rather than counted as a threat. This is a precision-favoring manual pass, not an automated classifier with a published recall figure — see Known limitations.
Dataset scope. NOH deltas, June 1 – July 22, 2026, all TLDs except the five Russian-territorial suffixes (policy) and .ph (noise). The dotPH registry returns an answer for essentially every name probed, so .ph hostnames flood any keyword match and inflate resolution rates; they are dropped from every count in this post, which materially affects the Instagram figure in particular. The live activation probe (A/MX/NS via dig) was run once, on July 23, 2026, against 195 names: the brand-in-domain registrations inside the July 16–22 window for the high-volume events, plus the complete lookalike sets for the low-volume events, plus a curated Samsung accessory-domain set and the pre-positioned kimik3.com service subdomains.
Statistical treatment (added July 24). Every multiple in the scorecard now carries an exact 95% confidence interval and an exact two-sided p-value. With W first-observations in the 7-day event window and B in the 30-day June baseline, the no-change hypothesis makes W binomial in W + B trials with success probability 7⁄37; a Clopper–Pearson interval on that proportion converts exactly into an interval on the rate ratio (the conditional, or Poisson-exact, method), and the p-value is the doubled smaller tail of the same binomial. Because daily counts on news-driven keywords are overdispersed relative to Poisson — variance runs 2–3× the mean for the three high-volume series — the parametric intervals are corroborated by three checks that assume no distribution at all: sliding placebo windows, a day-resampling bootstrap, and per-million-hostname volume normalization, reported in the appendix alongside a day-of-week control and a baseline extended back through May (61 days). One classifier change accompanied the May extension: alkimiai* (Italian "alchimia" businesses) joined the Kimi-AI false-positive list. Extending first-seen visibility into May also revealed that a handful of "new" event-week domains were re-observations of domains first seen in May under other hostnames; the appendix reports both the original and the deduplicated counts.
Dataset vs external counts. Our brand-in-domain counts are lower than a registrar zone-file scan would report, for two reasons: NOH counts a registrable domain on the day our crawler first observes it in DNS, which can lag a registrar's zone insertion by a day or more; and we exclude Russian TLDs and de-duplicate to the registrable apex. Where we make a claim about malicious use we triangulate against a non-DomainsProject source (URLhaus and the OpenPhish public feed); the result of that triangulation is itself a finding, reported below.
Known limitations. The keyword lists are time-sensitive and the manual false-positive pass is not reproducible to a stated precision/recall; a different analyst would keep or cut a handful of borderline names differently, which matters most for the smallest sets (Hugging Face, SSA-gov, where n is in single digits). The appendix quantifies exactly how little those small sets can carry: their 95% intervals span roughly 0.03×–18× and 0.11×–5.4× respectively — wide enough that neither supports any directional claim. NOH visibility is bounded by crawl coverage — we do not enumerate every subdomain of every free-hosting platform, so absence from our feed is not proof of non-existence. And a live A/MX/NS probe captures posture on one day; a domain dark today can be armed tomorrow.
The Scorecard
The table below is the whole argument in one view: for each event, the June baseline registration rate, the event-week rate, and the multiple between them.
| Event | Brand type | New lookalikes (Jul 16–22) | June baseline (/day) | Event week (/day) | Multiple | 95% CI on multiple | Top TLDs |
|---|---|---|---|---|---|---|---|
| Kimi K3 (model) | New brand | 20 | 0.00 | 2.86 | from zero | ≥21× | com, net, dev, pro, ai |
| Kimi AI (brand) | New brand | 5 | 0.00 | 0.71 | from zero | ≥3.9× | co, info, me, chat, app |
| Social Security (topic) | Government topic | 31 | 2.33 | 4.43 | 1.9× | 1.2×–2.9× | com, org, net |
| Instagram (outage) | Established giant | 37 | 4.30 | 5.29 | 1.2× | 0.83×–1.8× | com, net, xyz |
| Hugging Face (breach victim) | Established brand | 1 | 0.10 | 0.14 | 1.4× | 0.03×–18× | com |
| SSA-gov lookalikes | Gov impersonation | 2 | 0.27 | 0.29 | 1.1× | 0.11×–5.4× | com, es, net, cfd, buzz |
| OpenAI (breach) | Established giant | 48 | 9.33 | 6.86 | 0.7× | 0.53×–1.00× | com, org, xyz, top, cn |

Download: news-footprint-scorecard.csv · rates are daily means; "multiple" is event-week rate ÷ June baseline rate; the 95% CI is the exact conditional (Clopper–Pearson) interval on that ratio — method, p-values, and robustness checks in the statistical appendix below.
The raw counts and the multiples tell opposite stories, and the multiple is the honest one. OpenAI has the largest event-week count in the table — 48 new lookalikes in seven days — and it is the least interesting number here, because OpenAI's namespace already mints roughly nine lookalikes every single day of an ordinary month. Forty-eight over seven days is 6.9 per day: below its own standing rate. The breach that dominated search did not lift OpenAI registrations; it was drowned by a tide that never goes out. Kimi K3, by contrast, had no tide. Its baseline was a true zero, so its twenty event-week domains represent an infinite multiple — the only event in the set where the registration curve is unambiguously a response to the news rather than a continuation of a standing pattern. The new CI column keeps the whole table honest: the two Kimi rows are statistically unambiguous (Kimi K3 at least 21× baseline, p ≈ 10⁻¹⁴), Social Security's 1.9× clears significance against June but — as the appendix shows — not against a longer baseline, OpenAI's deficit is borderline, and no other row is distinguishable from no change at all.
Kimi K3: The Launch-Day Land Grab
A brand-new AI model is the cleanest natural experiment for the news-to-registration thesis, because it has no prior namespace to hide the signal. Before July 16 there were exactly two Kimi-K3 domains anywhere in our feed history, and the older one is the most instructive artifact in this study. Our first draft reported kimik3.com as "first observed July 3, thirteen days ahead of launch" — true within the June-onward scan window, but when we traced the domain through our full archive (which reaches back through 2024) for the statistical appendix, its trail turned out to start on September 19, 2025: ten months before launch, and about two months after Kimi K2 shipped. That timing is version arithmetic — register the successor's name while the current version is in the news. The domain then accreted infrastructure in slow motion: www (October 26, 2025), vpn (November 23, 2025), qa (March 5, 2026), api (May 8), console (May 15), mail (May 16). On July 3 — thirteen days ahead of launch — came the burst our first draft caught: seventeen staged service subdomains entering the feed in a single day (login, sso, auth, portal, dashboard, webmail, accounts, member, cpanel, staging, and more). That is the fingerprint of a pre-built kit being armed on a name banked ten months earlier. The second pre-position, kimik3.xyz (April 6), never grew infrastructure. Then the model shipped, and the wave broke the next day.

Download: news-footprint-kimi-wave.csv · daily count of newly observed registrable domains containing "kimik3" or "kimi-k3". July 3 — marked on the chart — is the day kimik3.com staged its 17-subdomain kit; because that domain first entered the feed on September 19, 2025, it is not counted as a new domain in this window.
The wave is not just fast, it is armed. Of the 21 Kimi-K3 registrable domains we probed, all 21 resolve, and thirteen are fronted by Cloudflare nameservers — an operational choice, not a parking default. Five are already mail-capable (kimik3.com, kimik3.net, k3kimi.com, kimik3.dev, trykimik3.ai), meaning they can send or receive email today. One, kimik3.co, is already delegated to Afternic — registered on launch day and immediately listed for resale, the speculator's play rather than the phisher's. The mix — pre-positioned kit, Cloudflare fronting, live MX, and a resale flip — is what a real target's first week looks like, and none of it is visible from a registration count alone.
OpenAI and Hugging Face: The Breach That Didn't Register
The most-searched infrastructure story of the week produced the least distinct registration signal. OpenAI's disclosure that its pre-release models had autonomously breached Hugging Face during a capability evaluation was a genuine, novel event, and it topped Trends in both geographies. Yet the OpenAI namespace absorbed it without a ripple: 6.9 lookalikes per day during the breach week against a June baseline of 9.3. The exact interval on that ratio runs 0.53× to 1.00× — 1.0008 unrounded, so it formally includes no-change (p = 0.051): the week is consistent with anything from a 47% deficit to a flat rate, and with nothing above it. What the data rule out, at any confidence we can offer, is a detectable lift; whether the deficit itself is real is borderline, firming up only against the longer baseline in the appendix (0.52×–0.99×, p = 0.040). The breach did not create OpenAI-shaped domains because OpenAI-shaped domains are created continuously regardless of the news.
Some of the week's OpenAI registrations look breach-reactive — openaiclaims.com (July 16), openaiclaimscenter.com (July 15), openaicertify.com (July 20), openaiverify.com (July 8). But three of the four predate the July 21 disclosure, which means they cannot be attributed to it; "claims center" and "verify" lures are evergreen infrastructure in a big AI brand's shadow, not a response to any single incident. Hugging Face, the actual breach victim, is the tell. If breach news drove registrations, the victim's name would spike. It did not: exactly one huggingface brand-in-domain registration appeared in the entire event week, against a June baseline that already rounds to zero. One-against-three-in-June is, we should be plain, a count too small to bear statistical weight — the 95% interval on that multiple runs from 0.03× to 18×, and half of all ordinary weeks in our span (19 of 39) contain at least one Hugging Face lookalike — so what the data rules out is a large victim-side wave, not subtle movement. Searchers wanted to read about Hugging Face; registrants, as far as a count this small can show, did not want to impersonate it.
Instagram: The Outage That Lived on Someone Else's Domain
A two-hour outage is too short to register a domain against, and the data shows it. Instagram's July 22 DM outage drove more than 100,000 searches, but Instagram brand-in-domain registrations moved from 4.3/day to 5.3/day — a 1.2× bump (95% CI 0.83×–1.8×) formally indistinguishable from ordinary weekly variation, and most of those domains are the perennial instagramdownloader/instagram-viewer SEO-tool genre, not outage lures.
The outage phishing is real; it simply does not use new registrations. When we triangulated our matched domains against the OpenPhish public feed, the Instagram-credential-phishing entries we found were hosted on free platforms: instagram-clone-frontend.vercel.app, instagram-profile-clone.vercel.app, instagram-jennifer.blogspot.com, instagram-change-password.blogspot.com. These are newly observed hostnames under established registrable domains — precisely the signal a WHOIS-based Newly Registered Domains feed cannot produce and an NOH feed can. A defender watching only new registrations for instagram would have seen a quiet week; the actual attack surface was a set of subdomains on vercel.app and blogspot.com that never touch a registrar at all. This is the clearest product argument in the dataset: for established brands under acute events, the threat migrates off the registration channel and onto the hostname channel.
Social Security: Two Populations Under One Keyword
The Social Security keyword produces a steady stream of legitimate businesses with a thin, dangerous impersonation layer underneath — and conflating them is the classic false-positive trap. The July 2 "Bisignano email" controversy and the month's two-payment SSI schedule kept the topic trending, and socialsecurity brand-in-domain registrations did lift, from 2.3/day to 4.4/day — 1.9×, which clears formal significance against June (95% CI 1.2×–2.9×, p = 0.006). It is also the one scorecard number that does not survive a longer look: against a May-plus-June baseline the lift shrinks to a non-significant 1.4×, because May itself ran at 3.5/day — the first week of May alone minted 52 of these domains, nearly twice the event week's total. A topic that trends every month has no quiet baseline to measure against; the appendix works through what that does and does not license. Whatever the true lift, most of the volume is advisory and SEO commerce: socialsecuritybenefitsschool.com, socialsecurityincomeplanner.com, howtomaximizemysocialsecurity.com. It shows in the activation profile — of 32 Social Security domains probed, 24 (75%) are mail-capable, the highest rate of any event, because real advisory businesses run real mail.
The impersonation layer is separate and small. Government-agency lookalikes of the form ssagov/ssa-gov accumulated at 0.27/day in June and 0.29/day in the window — essentially flat, and thin: two in the event week. But they are qualitatively the most alarming class in the entire study: ssagovgov.com (July 22), ssagovio.com (July 20), ssagovssa.net, v3433-ssagov.com, ssagovdocuments.website. Of thirteen such lookalikes across the two months, eight resolve and three are already mail-capable; ssa-gov.digital sits on a parking nameserver waiting to be built. The lesson for a SOC is that keyword volume and threat severity are inversely correlated here — the 31 high-volume socialsecurity domains are mostly benign, and the two low-volume ssagov domains are the ones to alert on.
Samsung: A Commercial Land Grab, Not a Phishing One
Product launches are accompanied by a registration wave, but it is a commerce wave, and it front-runs the event rather than chasing it. The Galaxy Z Fold 8 line was announced at Unpacked on July 22, but the accessory and reseller domains cluster in the weeks before: zfold7.com (June 9), galaxyfoldcase.com (July 2), zfoldcasesstore.shop (July 13), galaxyztrifold.com (July 18). These are case shops, grey-market resellers, and speculative marketplace listings — galaxyzonemobiles.com and galaxyztrifold.com are already on parking nameservers for resale. The Samsung footprint is real but it belongs to e-commerce SEO and domain speculation, not to credential phishing, and its timing (pre-launch, driven by leak-cycle anticipation) is the opposite of the reactive AI-model wave. A brand-protection team should watch launch keywords, but for counterfeit storefronts and trademark abuse, not for login-harvest lures.
Registered Isn't Armed
Across all five events, resolution is near-universal and mail capability is scarce — which is exactly why activation, not registration, is the metric that separates a threat from a bet. Our July 23 probe of 195 event-matched and topical lookalikes found 183 resolving (94%), but only 59 mail-capable (30%) and 11 already parked for resale (6%).

Download: news-footprint-activation.csv · live A/MX/NS check, July 23 2026. Per-event mail-capability rates in the CSV.
The 30% mail-capability figure is the number a registrar blog can never report, and it is the one that matters. A registered-but-parked domain is inventory; a resolving domain with a live MX is infrastructure. The per-event spread is where the intelligence lives: Social Security advisory domains are 75% mail-capable (real businesses), Kimi K3 lookalikes 24% (a mix of speculators and early operators), and the kimiai brand-token set 0% — ten domains, all resolving, none provisioned for mail, the signature of pure name speculation on a hot AI keyword. The same NOH-plus-activation view that flags the dangerous minority also clears the benign majority, which is the difference between an alert stream a SOC can use and one it learns to ignore.
On external triangulation, the honest result is a null with a lesson. None of the 843 brand-in-domain registrations we matched appeared in URLhaus's recent-malware corpus or the OpenPhish public feed at either the hostname or registrable-domain level. That is consistent with two things at once: most of these domains are pre-positioned or speculative and have not yet been weaponized, and those public feeds sample a narrow, recent window and skew toward malware distribution and free-hosting phishing rather than freshly registered lookalikes. Absence from a phish feed is not absence of intent — it is the argument for watching the activation signal that precedes feed inclusion, not waiting for it.
How Sure Are We? A Statistical Appendix
Added July 24, 2026, in response to reader feedback that correctly pointed out what a ratio of two rates cannot do: establish, on its own, that anything happened. This appendix puts exact intervals, placebo tests, a day-of-week control, and a longer baseline under every row of the scorecard. One factual correction fell out of the exercise — kimik3.com's first observation moved from July 3, 2026 back to September 19, 2025, and the Kimi K3 section above was rewritten — and one scorecard verdict was downgraded (Social Security).
Exact intervals. The multiple is a ratio of two count-based rates, and the standard exact treatment conditions on the total: with 48 event-week and 280 June OpenAI first-observations, the hypothesis of no change makes the event week's share of all 328 binomial with success probability 7⁄37 (seven window days against thirty baseline days); a Clopper–Pearson interval on that share converts exactly into an interval on the multiple, and the doubled smaller tail gives an exact p-value. The table reports both baselines — June, as in the scorecard, and the 61-day May-plus-June baseline built for this appendix. Extending visibility into May also deduplicates the windows: four of OpenAI's 48 event-week "new" domains and three of Social Security's 31 turn out to be re-observations of domains first seen in May under other hostnames, so the 61-day columns use the smaller, deduplicated counts.
| Event | Multiple vs June | Exact 95% CI | p | Multiple vs May–June | Exact 95% CI | p |
|---|---|---|---|---|---|---|
| Kimi K3 | from zero | ≥21× | 7×10⁻¹⁵ | 174× | 28×–7,200× | 7×10⁻¹⁹ |
| Kimi AI | from zero | ≥3.9× | 5×10⁻⁴ | 22× | 3.6×–229× | 4×10⁻⁴ |
| Social Security | 1.9× | 1.2×–2.9× | 0.006 | 1.4× | 0.89×–2.1× | 0.15 |
| 1.2× | 0.83×–1.8× | 0.31 | 1.1× | 0.78×–1.6× | 0.53 | |
| Hugging Face | 1.4× | 0.03×–18× | ≈1 | 0.97× | 0.02×–7.0× | ≈1 |
| SSA-gov lookalikes | 1.1× | 0.11×–5.4× | ≈1 | 0.97× | 0.11×–4.0× | ≈1 |
| OpenAI | 0.7× | 0.53×–1.00× | 0.051 | 0.72× | 0.52×–0.99× | 0.040 |
Download: news-footprint-significance.csv · exact conditional (Clopper–Pearson) intervals on the rate ratio; two-sided exact p, doubled smaller tail; 61-day columns use May-deduplicated window counts; the CSV adds placebo ranks, day-of-week expectations, bootstrap intervals, dispersion indices, and volume-normalized multiples.
What survives. Three tiers fall out of the table. The two Kimi rows are unambiguous: even against the wider 61-day baseline, Kimi K3's wave is at least 28× baseline with 95% confidence, and Kimi AI clears at 3.6×. Social Security is significant against June but not against May-plus-June — more on that below. OpenAI is the mirror case: against June alone the interval's upper edge is 1.0008 — it formally includes no-change, and the exact test does not reject at the 5% level (p = 0.051) — while the longer baseline pushes it just below (0.52×–0.99×, p = 0.040). So "no detectable lift" holds at any horizon, but "significant deficit" clears conventional significance only against the 61-day baseline. Instagram never approaches significance, and Hugging Face and SSA-gov, at one and two event-week observations, carry intervals spanning two orders of magnitude: those rows describe what we saw and can support nothing beyond "no large wave."
Placebo windows. A check that assumes no distribution at all: slide a 7-day window across every position in the pre-event span and ask how often an ordinary week matches the event week. Kimi K3's 20 beats all 39 windows in June–early-July and all 70 once May is included — no placebo window ever contained more than one Kimi-K3 domain. Social Security's 31 also beats all 39 June-era windows, but five windows in early-to-mid May reached its deduplicated 28, and the seven days beginning May 1 minted 52. Instagram's 37 is reached by 4 of 39 ordinary windows; OpenAI's breach week is matched or exceeded by 31 of 39 — a bottom-quartile week, directionally consistent with the interval though not extreme on its own.
Day-of-week control. The event window (Thursday July 16 through Wednesday July 22) contains each weekday exactly once, and the June baseline is four full weeks plus one extra Monday and Tuesday, so weekday composition can barely bias the comparison. Re-computing each event-week expectation from June's per-weekday means moves the three high-volume multiples by at most 0.04 (Social Security 1.90× → 1.86×; OpenAI and Instagram unchanged to two decimals); the single-digit rows wobble a little more in nominal terms (Hugging Face 1.43× → 1.33×) but stay deep inside their intervals.
Overdispersion and the bootstrap. Daily counts on the high-volume keywords are noisier than Poisson — variance-to-mean ratios of 2.3 (OpenAI), 2.2 (Instagram), and 3.3 (Social Security) — so the exact intervals above are, if anything, slightly narrow for those rows. A 10,000-replicate percentile bootstrap that resamples whole days, and so absorbs the overdispersion the parametric model misses, agrees with every verdict: OpenAI 0.57×–0.91× (below 1), Social Security 0.91×–2.04× (straddling 1), Instagram 0.67×–1.74×. For the near-zero rows the bootstrap degenerates and the exact intervals govern.
Feed-volume normalization. Our crawler's daily NOH volume ranged from 0.5M to 1.4M hostnames across May–July, and a heavy crawl day mechanically surfaces more first-observations. Recomputing every daily rate per million observed hostnames changes no verdict: Kimi K3 194×, Social Security 1.46×, Instagram 1.06×, OpenAI 0.68×.
The Social Security lesson. The one substantive downgrade. The 1.9× lift is real against June, but May ran at 3.5 domains/day on its own — the event week's deduplicated 4.0/day sits barely above an ordinary May — and the topic posts the highest dispersion index in the study. A keyword that trends every month (COLA rumors, payment-schedule churn, this month's Bisignano email) has no quiet month to serve as a control, so week-over-baseline ratios cannot attribute its fluctuations to any single story. What is robust in that section is the population split itself: the 75% mail-capability of the advisory cohort and the qualitative severity of the thin ssagov layer are activation-probe facts, not rate comparisons.
What would make this stronger still. Three further steps would harden the analysis: a negative-binomial rate model fitted to a year of per-day counts, replacing the placebo battery with a single likelihood; a routine 90-day baseline for every event (our archive reaches back through 2024 — we used that depth here only to trace the Kimi token); and an automated classifier with a published precision/recall in place of the manual false-positive pass. None of the three, on the evidence of the checks above, looks likely to overturn the three-tier verdict.
What's at Stake
- For SOC and detection teams — the alertable signal is activation, not registration. A watchlist keyed on "new domain contains our brand" will bury the analyst under 195 names, 70% of which cannot even send mail. A watchlist keyed on "new domain contains our brand and has a live MX and is not on a parking nameserver" surfaces the 59 that are provisioned to act.
- For established brands — your acute-event threat is a hostname, not a registration. Instagram's outage phishing lived on
*.vercel.appand*.blogspot.com. A monitoring program scoped to new registrations is structurally blind to it; the NOH channel is where it shows up. - For new-product and new-model launches — the wave is real, fast, and pre-positioned. Kimi K3 went from zero to a live, Cloudflare-fronted, mail-capable lookalike set within 24–48 hours of launch, with the name itself banked ten months early and the kit staged thirteen days before launch. Launch-day is not early enough to start watching; even the leak cycle is late — the speculative registration predates it by months.
- For government and benefits impersonation — severity is inversely correlated with keyword volume. The dangerous
ssagovlookalikes are a handful of domains hiding beneath thousands of benignsocialsecurityadvisory sites. Volume-based triage inverts the priority.
What Would Help
1. Detection teams: gate brand watchlists on activation, not registration. Ingest the NOH stream, then filter to resolving-with-live-MX and exclude parking nameservers before a name reaches an analyst. On this week's data that cut the queue from 195 to 59 without dropping a single armed domain.
2. Brand-protection researchers: monitor the version cycle, not the launch. For product and model launches the pre-positioning happens on the version cycle, not the news cycle — kimik3.com entered our feed in September 2025, two months after Kimi K2 shipped and ten months before K3 did, and its phishing-shaped kit was staged thirteen days before launch; Samsung accessory shops appeared weeks early. Start the watch when the previous version ships; escalate when the rumor trends.
3. Established-brand security teams: add a hostname channel. A registration-only feed missed the entire Instagram outage-phishing surface because it lived on free-hosting subdomains. Pair your NRD monitoring with a Newly Observed Hostnames feed to see the subdomain attacks a WHOIS feed cannot represent.
4. Government and benefits programs: triage by lookalike shape, not keyword hit-count. Weight agency-name permutations (ssagov, ssa-gov) far above topical keywords (socialsecurity); the former is where the impersonation concentrates, and it is drowned out by the latter under any volume-ranked view.
5. Threat-intelligence platforms: treat feed-absence as a lead, not an all-clear. None of these lookalikes were in URLhaus or OpenPhish yet — consistent with activation preceding weaponization, though a genuine absence of malicious intent for some fraction is equally possible. The domains provisioning MX and Cloudflare fronting this week are the candidates for next month's feed; the NOH feed is where that lead time lives.
Analysis by DomainsProject, an Internet measurement and intelligence organization. Registration signal from our Newly Observed Hostnames feed, June 1 – July 22, 2026 (52 daily deltas, ~1.05M new hostnames/day), plus 31 May files for the appendix's 61-day robustness baseline and a full-archive sweep (2024 onward) for the Kimi-K3 token; live A/MX/NS activation probe run July 23, 2026; search-side timeline from Google Trends (US + Canada, seven days ending July 22); malicious-overlap triangulation against URLhaus and the OpenPhish public feed. Russian-territorial TLDs (.ru, .su, .moscow, and the two Cyrillic IDN suffixes) excluded from all counts by policy, and .ph excluded as registry-wildcard noise. Statistical appendix (exact conditional intervals, placebo windows, day-of-week control, bootstrap, volume normalization) added July 24, 2026, in response to reader feedback; the same re-analysis corrected kimik3.com's first observation from July 3, 2026 to September 19, 2025. Keyword lists are time-sensitive; the method is repeatable, this week's event list is not. Explore the domain statistics dashboard or the dataset.