Police Investigate Fraudulent Domain Registrations Targeting Icelandic Companies
Authorities in Iceland are dealing with a growing problem: foreign fraudsters have been buying domain names that closely mimic those of local companies. The copycat domains are built to look convincing, with the apparent aim of exploiting unsuspecting businesses.
Steinarr Kristján Ómarsson, a police officer in the computer investigation department for the capital area, says the people behind this are doing their homework. They are reportedly lifting the names of CEOs, managing directors, and other company representatives to make their approach seem credible.
The Mechanics of the Scam
Contact from these fraudsters typically comes through fabricated email addresses. Police have not yet found evidence that fake social media profiles are being created to impersonate company representatives. Most of the fraudulent domain registrations have occurred in two foreign countries.
The goal seems to be placing orders with legitimate foreign suppliers while pretending to be the Icelandic companies — invoices sent to Iceland, goods shipped somewhere else entirely. No confirmed cases of direct losses to local businesses have emerged so far, but Steinarr is urging caution. “There’s a reason for caution,” he said.
Confidentiality in Action
The companies involved have chosen to stay anonymous, and police are supportive of that. With no clear public interest in naming them, keeping things quiet makes sense. As Steinarr put it: “We’re keeping this confidential because it can be sensitive for these companies as well.”
The situation first came to light in mid-October, when reports came in involving three separate companies. A fourth case followed on November 11. Icelandic police have since been in contact with authorities in the countries where the fraud originated, working through both national channels and Europol.
Ongoing Monitoring Without Major Investigation
There is no large-scale investigation underway at this point. Steinarr was clear that the focus right now is on keeping an eye on developments. “This is mostly a preventive measure, as we are following up on any new information that arises.” Tracing the fraud is difficult — anonymous email services and foreign domains make it hard to pin anything down.
“We’re not expending too much energy on this at the moment. Our priority is to monitor and alert companies,” Steinarr said. His advice to business representatives is straightforward: stay alert, keep close tabs on supplier communications, and treat anything out of the ordinary with a healthy dose of scepticism. “Be vigilant. Scrutinize all supplier communications and take note of the details.”






























