Rogue Domains: When a University Isn’t a University

An inquiry into typo-squatting, invisible trust markers, and the fragility of the research ecosystem.

Author

Leslie McIntosh

Published

December 11, 2025

Our natural world is full of creatures that mimic other creatures or objects for survival – either to escape predators or to prey on other life. In predatory publishing, fake journals mimic legitimate ones to prey on unsuspecting researchers. So what, then, should we make of a university website – and its associated email addresses – that mimics a real institution?

This case began as a routine review of a paper, which rapidly escalated into something else. One detail stood out: all the authors on that paper used email addresses ending in uok.edu.gr. At first glance, nothing glaringly suspicious – just an unfamiliar Greek institutional domain attached to the authors’ email addresses. Except that each of the authors listed Chinese research affiliations in the paper.

That tiny mismatch was enough to pull a thread. And, as with most investigations in forensic scientometrics, one tug was all it took to unravel the entire garment.

A Domain Out of Place

The domain could have been the University of Crete, but that institution is uoc.gr, not uok.edu.gr. The difference looks trivial — but isn’t. The research ecosystem is full of invisible trust markers we rely on without realizing it – country-level domains (e.g., gr = Greece), institutional naming conventions (e.g., edu = educational institution), and other email patterns. When one of those markers drifts out of alignment, it raises flags.

At first, nothing about the domain activated any instinctive alarms. But I did what any curious person would do before attributing concern: I visited the uok.edu.gr website.

That is when things moved from seemingly ordinary to undeniably odd.

First Impressions: The November 2025 Website Version

As of November 2025, the website looked like a student project (see Figure 1) – a few images, some social media icons, and contact pages. Not all the images loaded. The enrolment date was outdated by over a year. Broken links. Oh, and the html code was annotated with Chinese, not Greek writing.

Figure 1: Previous homepage of uok.edu.gr (until ~November 2025)

The December 2025 Revision

When I checked in again in early December 2025, the website had been further refined, with celebrating graduates tossing their caps into their future (Figure 2). Links connected to other pages, so one could consider the multiple possible “programs” at the University of Krete (spelling intentional). There were far fewer Chinese characters in the html code. The date to enrol at the non-existent university remained over a year out of date. And the landing page with graduates hailed from a stock image with iconic Singapore in the background.

And yet, the contact page still pointed back to the legitimate University of Crete. It appeared more polished, but not more credible. A surface-level improvement that did nothing to correct the internal inconsistencies.

What is not clear is why the website was updated. Was it because they noticed more traffic to the site? Did they have more plans for the domain? Perhaps this will be clearer in the future. But perhaps we will never know.

And one week later, that refined version vanished as abruptly as it had appeared.

Figure 2: Revised homepage of uok.edu.gr with stock image of Singapore as the background. (from December 2025 for ~one weeks)

Figure 3: The real University of Crete website (Hellenic and English versions)

Early Theories and the Reality of edu.gr Domains

Initially, I was concerned this was a domain hack. After all, Greece’s domain authority (EEET) states that edu.gr domains are restricted to educational institutions. In practice, however, this operates more as an honor system. Much of the global research ecosystem operates on honor systems. Trust embedded through norms rather than enforced by verification.

A representative from EEET later confirmed the domain had been purchased by a “natural person”, but due to privacy laws no identifying information could be shared.

That alone told me this was far less likely to be a hack and far more likely to be something else.

Domain Analysis

Whois records indicate that uok.edu.gr was historically connected to the same administrative entity managing uoc.gr, but the technical infrastructure told a different story:

  • UOK DNS originally points to Cloudflare servers in the United States.

  • The associated IP leads to a Chinese-owned site.

  • The domain appears to have been purchased on 15 December 2024.

  • Evidence suggests either a dormant domain being repurposed or a case of typo-squatting that mimicked a Greek educational domain just closely enough to pass casual inspection.

This is not hacking. This is the acquisition of a domain to mimic a legitimate institution.

Forensic Scientometrics Inspection and Reflection

What “Normal” Looks Like and Why It Matters

When forensically examining the science of science, the baseline question is deceptively simple: What is normal?

What patterns do genuine institutional websites follow – URL structure, naming conventions, content density, visual identity? What signals do legitimate scholars give when they list affiliations and provide contact information? None of this is formally codified. These are invisible markers of trust we instinctively use and rarely articulate.

And those invisible markers are precisely what misuse exploits.

Publications

There is no semblance of hiding. The first known publication using a uok.edu.gr email address appears in January 2025. Remarkably fast, assuming peer review, revision, and typesetting processes. More followed.

Within 12 months, there were:

  • 57 publications

  • 44 individual authors with identifiers

  • 48 institutions

  • 5 very different fields of research

  • 2 countries

  • 0 legitimate ties to Greece

Not all authors had identifiers; they are not tied to an affiliation or have no ORCiD, for example. All publications had authors with Chinese names and Chinese institutional affiliations. One person who cannot be verified claimed an affiliation in Malaysia. One person openly claimed an affiliation with the University of Crete – but had no co-authors from Greece and no publication history connected to the region. Naturally, that person’s email at uok.edu.gr bounces.

The authors do not cite one another. That does not preclude a citation cartel, but currently, there is no evidence of one. These publications also hail from different fields of research, from commerce to computer science to data science (Figure 4).

Figure 4: The top five Fields of Research represented in the publications (one publication could have more than one category).

The people are either a cluster of independent actors using the same purchased domain – or a coordinated effort operating with plausible deniability.

Typo-Squatting vs. Brandwashing

Typo-squatting is typically defined as purchasing a domain that looks deceptively close to an established one: for example, uoc-edu.gr. In cases where a second-level domain is tightly controlled, typo-squatting is the easiest path to mimicry.

But Greece’s edu.gr second-level domain does not appear to be meaningfully enforced. That made it simple: just purchase edu.gr, attach any name you like to it, and suddenly you possess a domain that appears to be an educational institution in Greece.

If an editor checks an email address such as academic@uok.edu.gr, it is easy – and understandable – to assume legitimacy.

That is the essence of brandwashing: using institutional resemblance, however superficial, to project credibility.

And it works because institutions, publishers, and platforms still rely on assumptions that once were safe.

Why Would Anyone Do This?

That is the persistent question.

Possibilities include:

  • To gain credibility for personal reasons (e.g., job promotion, visa acquisition).

  • To bypass affiliation verification procedures during submission.

  • To obfuscate institutional accountability.

  • To exploit trust gaps in a system that has not adapted to sophisticated misuse.

  • To probe vulnerabilities in global scholarly credentialing – an angle relevant for states with strategic interest in information manipulation.

We must also admit that we cannot verify all of the people as real. There could be fictitious names used to offer another step removed from culpability.

If governments or institutions are aware yet inactive, one must ask whether the inaction is strategic. When you know precisely what is untrustworthy, you can infer what is trustworthy. In an age where AI depends on clean data to benchmark “truth,” this knowledge is powerful.

What We Are Not Seeing

This does not appear to be:

  • A hack of the University of Crete.

  • A convincing spoof intended to deceive the public.

  • A website designed to harvest data.

  • A coordinated attempt to impersonate Greek academic authorities.

If anything, the sloppy early version argues against a sophisticated impersonation campaign. But the later polished version complicates that narrative. Someone felt it worthwhile to improve the façade, even briefly.

As of the first week of December, the website is gone, and the domain is no longer available. Uok.edu.gr appears (not confirmed) to be back in the hands of the Greeks.

Implications for Integrity and Security

This incident exposes the quiet intersection of integrity and security. They are not separate domains; they are braided strands. If integrity is compromised, security collapses. If security is neglected, integrity becomes optional.

Neglected subdomains, unenforced domain rules, and unverified affiliations create a perfect environment for exploitation. The fact that 57 peer-reviewed publications in a single year used a rogue domain illustrates how quickly misuse can scale.

Recommendations

The research community cannot continue relying on honor systems built for a pre-digital era. We need:

  1. Routine audits of neglected or dormant subdomains.

  2. Investment in maintenance, not just new digital infrastructure.

  3. Publisher-level verification of affiliations and identities before acceptance.

  4. Researcher-level responsibility to verify their own identities and institutional ties.

  5. Policy evaluation, particularly under EU digital identity and cyber-fraud frameworks, to determine when misuse becomes a crime.

Buying authorship is not a crime in most jurisdictions. Misrepresenting affiliation might be. Using deceptive domains to obtain editorial trust certainly should be.

What the UOK Case Reveals About Global Trust Markers

Global top-level domains are governed by local rules. The United States tightly controls .edu. The United Kingdom does likewise with .ac.uk. But edu.gr demonstrates the fragility of assuming consistency across borders.

The global scientific community cannot rely on domain appearance as a credentialing mechanism. Yet, that is precisely what many workflows – editorial, institutional, and algorithmic – continue to do.

This case is a reminder that trust markers are attack surfaces.

Final Thoughts

This entire case began with a small anomaly – an email domain that did not appear to belong. But anomalies are how unraveling begins. This is the work of forensic scientometrics: noticing what others overlook, articulating what others assume, and interrogating what others accept.

There will be more cases like this. Perhaps many more. The question is whether we learn from this one.

Methods

This investigation used both open-source intelligence and scientometric tools:

Open Source Tools

  • Terminal-based whois and dig

  • Developer console inspection of the UOK website

  • Independent analysis by three IT experts

  • PubPeer

  • ORCiD

  • Wayback Machine

  • General web searching

Scientometric and Bibliometric Tools

  • Dimensions: publication patterns, institutional ties, author histories

  • Dimensions Author Check: cross-author anomalies

  • Dimensions Research Security

  • Altmetric: attention traces

Each method reinforced the same conclusion: this domain was purchased, repurposed, and leveraged to create an aura of academic legitimacy.

Disclaimers

I work at Digital Science and advise the development of their product Dimensions Author Check, which originated from my company acquired in 2020. I now advise VeriMe, an identity verification initiative for the scholarly community. Digital Science is a for-profit company. VeriMe is a cooperative.

Reuse

Citation

For attribution, please cite this work as:
McIntosh, Leslie. 2025. “Rogue Domains: When a University Isn’t a University.” FoSci Blog, December 11. https://fo-sci.org/blog/2025-12-11/.