{"id":5147,"date":"2022-12-09T12:11:16","date_gmt":"2022-12-09T12:11:16","guid":{"rendered":"https:\/\/adex.com\/?p=5147"},"modified":"2026-04-23T10:50:24","modified_gmt":"2026-04-23T10:50:24","slug":"another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website","status":"publish","type":"post","link":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/","title":{"rendered":"Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website"},"content":{"rendered":"\n<p><em>Shortly after Adex specialists discovered a <a href=\"https:\/\/adex.com\/blog\/adex-discovers-potential-dns-vulnerability-and-3rd-party-fraud-on-fc-barcelonas-official-website\/\" target=\"_blank\" rel=\"noreferrer noopener\">potential fraud case on FC Barcelona\u2019s website<\/a>, a similar issue was identified on another popular website \u2013 Carmax.com.<\/em><\/p>\n\n\n\n<p>Adex provides anti-ad fraud services to one of the biggest global ad platforms \u2013 PropellerAds. The company pays close attention to the quality of ad campaigns launched via its platform and also carefully verifies that URLs provided, in fact, belong to advertisers.<\/p>\n\n\n\n<p>During a standard automated campaign check, Adex\u2019s staff was alerted about a suspicious link leading to a well-known vehicle retailer \u2013 Carmax.&nbsp;<\/p>\n\n\n\n<p>Apart from being a top-rated company in the USA and one of the country\u2019s largest retailers of used cars, the Carmax domain is also a tidbit for fraudsters, with over 13M monthly organic visits.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/\/wp-content\/uploads\/2022\/12\/Adex-SemRush-Carmax.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" width=\"1794\" height=\"534\" src=\"https:\/\/adex.com\/blog\/\/wp-content\/uploads\/2022\/12\/Adex-SemRush-Carmax.png\" alt=\"Adex - Semrush - Carmax\" class=\"wp-image-5148\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-SemRush-Carmax.png 1794w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-SemRush-Carmax-300x89.png 300w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-SemRush-Carmax-1024x305.png 1024w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-SemRush-Carmax-768x229.png 768w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-SemRush-Carmax-1536x457.png 1536w\" sizes=\"(max-width: 1794px) 100vw, 1794px\" \/><\/a><figcaption class=\"wp-element-caption\">Data from SemRush<\/figcaption><\/figure>\n\n\n\n<p>Having in mind the <a href=\"https:\/\/adex.com\/blog\/adex-discovers-potential-dns-vulnerability-and-3rd-party-fraud-on-fc-barcelonas-official-website\/\">previous case with subdomain takeover<\/a>, the specialists instantly began investigating the matter.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/\/wp-content\/uploads\/2022\/12\/Adex-carmax-potential-subdomain-takeover.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" width=\"1364\" height=\"1084\" src=\"https:\/\/adex.com\/blog\/\/wp-content\/uploads\/2022\/12\/Adex-carmax-potential-subdomain-takeover.png\" alt=\"Adex - carmax - suspicious subdomain\" class=\"wp-image-5149\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-potential-subdomain-takeover.png 1364w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-potential-subdomain-takeover-300x238.png 300w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-potential-subdomain-takeover-1024x814.png 1024w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-potential-subdomain-takeover-768x610.png 768w\" sizes=\"(max-width: 1364px) 100vw, 1364px\" \/><\/a><figcaption class=\"wp-element-caption\">A suspicious subdomain<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/\/wp-content\/uploads\/2022\/12\/Adex-potential-fraud-on-carmax-subdomain-closeup.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" width=\"1361\" height=\"248\" src=\"https:\/\/adex.com\/blog\/\/wp-content\/uploads\/2022\/12\/Adex-potential-fraud-on-carmax-subdomain-closeup.png\" alt=\"Adex - carmax - suspicious subdomain\" class=\"wp-image-5150\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-potential-fraud-on-carmax-subdomain-closeup.png 1361w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-potential-fraud-on-carmax-subdomain-closeup-300x55.png 300w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-potential-fraud-on-carmax-subdomain-closeup-1024x187.png 1024w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-potential-fraud-on-carmax-subdomain-closeup-768x140.png 768w\" sizes=\"(max-width: 1361px) 100vw, 1361px\" \/><\/a><\/figure>\n\n\n\n<p>While the root domain\u2019s content centers on car reselling, the subdomain focuses on gambling, an improbable combination of topics for multiple reasons, starting from SEO to legal complications.<\/p>\n\n\n\n<p>Once the NS records had been compared, it came out that the root domain was hosted on Akamai DNS, and the subdomain was managed with Microsoft Azure.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-root-domain-1.png\"><img decoding=\"async\" width=\"1102\" height=\"777\" src=\"https:\/\/adex.com\/blog\/\/wp-content\/uploads\/2022\/12\/Adex-carmax-root-domain-1.png\" alt=\"Adex - carmax - root domain dig\" class=\"wp-image-5154\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-root-domain-1.png 1102w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-root-domain-1-300x212.png 300w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-root-domain-1-1024x722.png 1024w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-root-domain-1-768x542.png 768w\" sizes=\"(max-width: 1102px) 100vw, 1102px\" \/><\/a><figcaption class=\"wp-element-caption\">Root domain<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/adex.com\/blog\/\/wp-content\/uploads\/2022\/12\/Adex-carmax-subdomain.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" width=\"1095\" height=\"595\" src=\"https:\/\/adex.com\/blog\/\/wp-content\/uploads\/2022\/12\/Adex-carmax-subdomain.png\" alt=\"Adex - carmax - potential fraud - subdomain\" class=\"wp-image-5152\" srcset=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-subdomain.png 1095w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-subdomain-300x163.png 300w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-subdomain-1024x556.png 1024w, https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-subdomain-768x417.png 768w\" sizes=\"(max-width: 1095px) 100vw, 1095px\" \/><\/a><figcaption class=\"wp-element-caption\">Subdomain<\/figcaption><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"fake-subdomain\"><strong>Fake subdomain<\/strong><\/h2>\n\n\n\n<p>What is peculiar about this case is the name of the potentially fraudulent subdomain &#8211; <strong><em>expresstestdrives-qa.carmax.com<\/em><\/strong> \u2013 thematically matched with the root domain; it would be harder for website owners to detect.<\/p>\n\n\n<div class=\"block__bord\"><div class=\"block__bord_desc\"><p>As it\u2019s typical for subdomain takeover scenarios, the indexation was turned off, so no one could simply Google the page, and the traffic spikes most probably went unnoticed for domain owners as the subdomain was hosted on a different server.<\/p>\n<\/div><\/div>\n<style>\n.block__bord { margin: 32px 0; padding: 1.25em 2.375em;\tborder-radius: 24px; background: rgba(0, 220, 200, 0.20); }\n.block__bord_desc {font-size: 16px !important;font-weight: 400 !important;color: #606060 !important;}\n<\/style>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"a-pattern-emerging\"><strong>A pattern emerging<\/strong><\/h2>\n\n\n\n<p>Adex specialists emphasize that subdomain takeover doesn\u2019t threaten only big websites; smaller businesses are also at risk:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201c It\u2019s becoming more and more common to see hijacked subdomains, and definitely there is a pattern here. Potentially illegal gambling companies are stealing subdomains, hosting them on different servers, and taking advantage of companies\u2019 reputation and domain ranking. We recommend using anti-ad fraud tools and regularly checking your NS records to prevent fraud.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>Adex has already contacted the Carmax website and will add any comments should they follow.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Shortly after Adex specialists discovered a potential fraud case on FC Barcelona\u2019s website, a similar issue was identified on another popular website \u2013 Carmax.com.<\/p>\n","protected":false},"author":4,"featured_media":5158,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-5147","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-current_risks"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website.<\/title>\n<meta name=\"description\" content=\"Shortly after Adex specialists discovered a potential fraud case on FC Barcelona\u2019s website, a similar issue was identified on another popular website \u2013 Carmax.com.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website.\" \/>\n<meta property=\"og:description\" content=\"Shortly after Adex specialists discovered a potential fraud case on FC Barcelona\u2019s website, a similar issue was identified on another popular website \u2013 Carmax.com.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/\" \/>\n<meta property=\"og:site_name\" content=\"ADEX\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/adexsaas\/\" \/>\n<meta property=\"article:published_time\" content=\"2022-12-09T12:11:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-23T10:50:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-subdomain-takeover.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Content Team\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website.\" \/>\n<meta name=\"twitter:description\" content=\"Shortly after Adex specialists discovered a potential fraud case on FC Barcelona\u2019s website, a similar issue was identified on another popular website \u2013 Carmax.com.\" \/>\n<meta name=\"twitter:creator\" content=\"@adexsaas\" \/>\n<meta name=\"twitter:site\" content=\"@adexsaas\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Content Team\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\\\/\"},\"author\":{\"name\":\"Content Team\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#\\\/schema\\\/person\\\/2bf2469195f0e5bffe2e1d5b2ef12b61\"},\"headline\":\"Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website\",\"datePublished\":\"2022-12-09T12:11:16+00:00\",\"dateModified\":\"2026-04-23T10:50:24+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\\\/\"},\"wordCount\":341,\"publisher\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/Adex-carmax-subdomain-takeover.png\",\"articleSection\":[\"Current risks\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\\\/\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\\\/\",\"name\":\"Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website.\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/Adex-carmax-subdomain-takeover.png\",\"datePublished\":\"2022-12-09T12:11:16+00:00\",\"dateModified\":\"2026-04-23T10:50:24+00:00\",\"description\":\"Shortly after Adex specialists discovered a potential fraud case on FC Barcelona\u2019s website, a similar issue was identified on another popular website \u2013 Carmax.com.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/adex.com\\\/blog\\\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\\\/#primaryimage\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/Adex-carmax-subdomain-takeover.png\",\"contentUrl\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/Adex-carmax-subdomain-takeover.png\",\"width\":1200,\"height\":628,\"caption\":\"Adex - carmax subdomain takeover\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/adex.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/\",\"name\":\"ADEX - Ad Fraud & Invalid Traffic Prevention Platform\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#organization\"},\"alternateName\":\"ADEX\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/adex.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#organization\",\"name\":\"ADEX - Ad Fraud & Invalid Traffic Prevention Platform\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/CDD2258_copy-48-1.svg\",\"contentUrl\":\"https:\\\/\\\/adex.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/CDD2258_copy-48-1.svg\",\"width\":148,\"height\":30,\"caption\":\"ADEX - Ad Fraud & Invalid Traffic Prevention Platform\"},\"image\":{\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/adexsaas\\\/\",\"https:\\\/\\\/x.com\\\/adexsaas\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/adex.com\\\/blog\\\/#\\\/schema\\\/person\\\/2bf2469195f0e5bffe2e1d5b2ef12b61\",\"name\":\"Content Team\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc59bc385c83827a6549fd86c717ef334484d083fba0e770f9b2365acdf272f2?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc59bc385c83827a6549fd86c717ef334484d083fba0e770f9b2365acdf272f2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/cc59bc385c83827a6549fd86c717ef334484d083fba0e770f9b2365acdf272f2?s=96&d=mm&r=g\",\"caption\":\"Content Team\"},\"sameAs\":[\"https:\\\/\\\/adex.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website.","description":"Shortly after Adex specialists discovered a potential fraud case on FC Barcelona\u2019s website, a similar issue was identified on another popular website \u2013 Carmax.com.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/","og_locale":"en_US","og_type":"article","og_title":"Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website.","og_description":"Shortly after Adex specialists discovered a potential fraud case on FC Barcelona\u2019s website, a similar issue was identified on another popular website \u2013 Carmax.com.","og_url":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/","og_site_name":"ADEX","article_publisher":"https:\/\/www.facebook.com\/adexsaas\/","article_published_time":"2022-12-09T12:11:16+00:00","article_modified_time":"2026-04-23T10:50:24+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-subdomain-takeover.png","type":"image\/png"}],"author":"Content Team","twitter_card":"summary_large_image","twitter_title":"Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website.","twitter_description":"Shortly after Adex specialists discovered a potential fraud case on FC Barcelona\u2019s website, a similar issue was identified on another popular website \u2013 Carmax.com.","twitter_creator":"@adexsaas","twitter_site":"@adexsaas","twitter_misc":{"Written by":"Content Team","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/#article","isPartOf":{"@id":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/"},"author":{"name":"Content Team","@id":"https:\/\/adex.com\/blog\/#\/schema\/person\/2bf2469195f0e5bffe2e1d5b2ef12b61"},"headline":"Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website","datePublished":"2022-12-09T12:11:16+00:00","dateModified":"2026-04-23T10:50:24+00:00","mainEntityOfPage":{"@id":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/"},"wordCount":341,"publisher":{"@id":"https:\/\/adex.com\/blog\/#organization"},"image":{"@id":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/#primaryimage"},"thumbnailUrl":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-subdomain-takeover.png","articleSection":["Current risks"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/","url":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/","name":"Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website.","isPartOf":{"@id":"https:\/\/adex.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/#primaryimage"},"image":{"@id":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/#primaryimage"},"thumbnailUrl":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-subdomain-takeover.png","datePublished":"2022-12-09T12:11:16+00:00","dateModified":"2026-04-23T10:50:24+00:00","description":"Shortly after Adex specialists discovered a potential fraud case on FC Barcelona\u2019s website, a similar issue was identified on another popular website \u2013 Carmax.com.","breadcrumb":{"@id":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/#primaryimage","url":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-subdomain-takeover.png","contentUrl":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/12\/Adex-carmax-subdomain-takeover.png","width":1200,"height":628,"caption":"Adex - carmax subdomain takeover"},{"@type":"BreadcrumbList","@id":"https:\/\/adex.com\/blog\/another-case-of-subdomain-takeover-detected-potential-fraud-on-carmax-website\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/adex.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Another Case of Subdomain Takeover Detected: Potential Fraud on Carmax Website"}]},{"@type":"WebSite","@id":"https:\/\/adex.com\/blog\/#website","url":"https:\/\/adex.com\/blog\/","name":"ADEX - Ad Fraud & Invalid Traffic Prevention Platform","description":"","publisher":{"@id":"https:\/\/adex.com\/blog\/#organization"},"alternateName":"ADEX","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/adex.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/adex.com\/blog\/#organization","name":"ADEX - Ad Fraud & Invalid Traffic Prevention Platform","url":"https:\/\/adex.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/adex.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/05\/CDD2258_copy-48-1.svg","contentUrl":"https:\/\/adex.com\/blog\/wp-content\/uploads\/2022\/05\/CDD2258_copy-48-1.svg","width":148,"height":30,"caption":"ADEX - Ad Fraud & Invalid Traffic Prevention Platform"},"image":{"@id":"https:\/\/adex.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/adexsaas\/","https:\/\/x.com\/adexsaas"]},{"@type":"Person","@id":"https:\/\/adex.com\/blog\/#\/schema\/person\/2bf2469195f0e5bffe2e1d5b2ef12b61","name":"Content Team","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/cc59bc385c83827a6549fd86c717ef334484d083fba0e770f9b2365acdf272f2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/cc59bc385c83827a6549fd86c717ef334484d083fba0e770f9b2365acdf272f2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/cc59bc385c83827a6549fd86c717ef334484d083fba0e770f9b2365acdf272f2?s=96&d=mm&r=g","caption":"Content Team"},"sameAs":["https:\/\/adex.com"]}]}},"_links":{"self":[{"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/posts\/5147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/comments?post=5147"}],"version-history":[{"count":3,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/posts\/5147\/revisions"}],"predecessor-version":[{"id":5503,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/posts\/5147\/revisions\/5503"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/media\/5158"}],"wp:attachment":[{"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/media?parent=5147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/categories?post=5147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/adex.com\/blog\/wp-json\/wp\/v2\/tags?post=5147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}