Reverse WHOIS Finds 1,621 Sister Domains for the S&P 500 — Three Quarters Have Never Been Scored for Bounty Coverage, and 11 Companies Have a Critical CVE Sitting on One Right Now
Our seventh cross-reference. This one doesn't touch the primary domain at all — it's built entirely from domains a company owns but that the main attack-surface conversation never looks at.
NullBlocks Research — August 2026
Our last six reports each found the same shape of gap on a company's known, obvious infrastructure — subdomain takeover candidates, exposed GraphQL schemas, archived legacy pages, critical CVEs, exposed database ports, expired TLS certificates. All of that lives on domains everyone already knows to look at: the primary corporate domain and its subdomains.
This report is different. It asks a simpler question: what domains does this company own that nobody's watching because nobody thought to look?
Methodology, up front
Every company in our index has a primary domain and a WHOIS record with a registrant organization on file. We took that registrant org string and ran it through a free reverse-WHOIS lookup — a public tool that answers "what other domains are registered to this same organization?" — then cross-checked each result against our own scan data to confirm it's a real, live, independently-owned asset (not a false-positive registrant-name collision), and checked whether that sister domain shows up anywhere in HackerOne's public bounty-scope data.
The result is a list of domains a company owns and actively operates that sit completely outside the "main website" conversation: acquired-brand sites, regional storefronts, contractor portals, internal tooling with a public front door, and old marketing microsites nobody decommissioned.
1. 25 companies, 1,621 confirmed sister domains, live infrastructure on every one
Across the S&P 500 index, 25 companies have at least ten reverse-WHOIS-matched sister domains that our scanner confirmed are live and actively serving infrastructure (not a parked placeholder or an unconfirmed candidate — every domain counted here has real subdomains, real HTTP responses, real technology fingerprints behind it). Three companies dominate the raw count — Airbnb, Hilton Worldwide, and Booking Holdings — and we address that directly in the next section before showing the ranked table.
| Company | Ticker | Confirmed sister domains | Has any bounty coverage? |
|---|---|---|---|
| Charles Schwab Corporation | SCHW | 175 | Yes |
| eBay Inc. | EBAY | 158 | No |
| CVS Health | CVS | 146 | No |
| Workday, Inc. | WDAY | 134 | No |
| Public Storage | PSA | 126 | No |
| Amgen | AMGN | 113 | No |
| Domino's | DPZ | 94 | No |
| PPG Industries | PPG | 84 | No |
| Teledyne Technologies | TDY | 76 | No |
| Airbnb | ABNB | 63 | Yes |
| Intuit | INTU | 56 | Yes |
| Cardinal Health | CAH | 53 | No |
| Lam Research | LRCX | 50 | No |
| American Electric Power | AEP | 45 | No |
| Best Buy | BBY | 35 | No |
| Hilton Worldwide | HLT | 32 | Yes |
| Humana | HUM | 29 | Yes |
| Alphabet Inc. (Class C) | GOOG | 17 | Yes |
| Booking Holdings | BKNG | 13 | Yes |
| Fortinet | FTNT | 10 | Yes |
| Johnson Controls | JCI | 10 | No |
(20 of the 25 ranked companies shown; the remaining 5 each carry 10–35
confirmed sister domains and are included in every aggregate total below.
Two entries with clean company-name matches but unresolved ticker mapping —
astrazeneca.com and worldpay.com, carrying 13 and 4 confirmed sister
domains respectively — are omitted from the ranked table pending a cleaner
company-ID match but included in the aggregate totals.)
A note on the three largest entries — Airbnb, Hilton, and Booking Holdings
An earlier version of this analysis omitted three companies that, once verified, turned out to carry the largest sister-domain footprints in the index: Airbnb (63 confirmed), Hilton Worldwide (32 confirmed), and Booking Holdings (13 confirmed) — plus an even larger set of unconfirmed candidates still pending live-infrastructure verification (Booking Holdings alone has 237 candidate domains queued). We checked these specifically before publishing, because a jump this large from prior data warranted scrutiny rather than a straight republish.
The registrant-org match for each is clean and unambiguous: every domain
counted for Airbnb matched registrant org "Airbnb, Inc." exactly (e.g.
airbnb-cn.com, airbnb.ae), every domain for Hilton matched "Hilton
International Holding LLC" (e.g. 1800bookhilton.com,
beverlyhilton.com), and every domain for Booking Holdings matched
"Booking.com B.V." (e.g. 1-booking.com, activebooking.com). This is
consistent with these companies' actual business models — global hotel and
travel-booking brands routinely register hundreds of city-, brand-, and
campaign-specific domains (regional hotel sites, promotional booking
portals, brand-variant defensive registrations) — not a repeat of the
registrant-org collision bug found and fixed elsewhere in our pipeline this
week (see the caveat section below for what that bug looked like and how we
checked for it here).
2. 17 of these 25 companies have zero bounty coverage anywhere — on any domain
17 of the 25 companies with 10+ confirmed sister domains have no matched HackerOne program on file for any of their domains — not just the sister domain, the whole company. Across the full set of 25, 1,226 of the 1,621 confirmed sister domains (75.6%) belong to a company with zero bounty coverage anywhere; across our entire confirmed dataset of 50 companies with any reverse-WHOIS sister domains at all, that's 1,303 of 1,755 (74.2%).
The eight companies that do have bounty coverage (Charles Schwab, Airbnb, Intuit, Hilton, Humana, Alphabet, Booking Holdings, and Fortinet) are the same small set of mature-program operators our prior reports keep finding — but a program covering the main domain doesn't automatically extend to every acquired brand or regional storefront a company owns, which is exactly what the next finding shows.
3. 11 companies have a version-matched CRITICAL CVE sitting on a sister domain right now
Cross-referencing confirmed sister domains against our existing CVE-matching pipeline: 11 companies have at least one CRITICAL-severity, version-matched CVE on a sister domain (37 distinct affected domains, 744 individual finding rows). 8 of those 11 companies have zero bounty coverage anywhere.
| Company | Sister domain | CVE | CVSS | Bounty coverage |
|---|---|---|---|---|
| American Electric Power | aepcontractorsafety.com |
CVE-2026-21962 | 10.0 | No |
| American Electric Power | aepcontractorsafety.com |
CVE-2026-49257 | 10.0 | No |
| American Electric Power | aeptexas.com |
CVE-2026-41679 | 10.0 | No |
| Domino's | dominos.com.pe |
CVE-2026-21962 | 10.0 | No |
| Domino's | dominospizzatracker.ie |
CVE-2026-21962 | 10.0 | No |
| Evergy | evergy.com |
CVE-2026-41679 | 10.0 | No |
| Workday, Inc. | myworkday.com |
CVE-2026-21962 | 10.0 | No |
| Workday, Inc. | myworkday.com |
CVE-2026-49257 | 10.0 | No |
| Fortinet | fortinet.net |
CVE-2026-21962 | 10.0 | Yes |
| Hilton Worldwide | corpratesathilton.com |
CVE-2026-34047 | 9.9 | Yes |
| Johnson Controls | johnsoncontrols.com |
CVE-2026-34047 | 9.9 | No |
| Amgen | amgencare.co.uk |
CVE-2019-1365 | 9.9 | No |
Note the shape of the domain names carrying this risk: a contractor-safety portal, an international brand-owned "corporate" microsite, a regional pizza-tracking app, and a regional utility's own apex domain registered under a different corporate entity name. None of these look like "the company's website" to a casual observer — which is exactly why they don't get the security attention the primary domain does, and exactly why a researcher scanning only the obvious domain would miss all of them.
An honest caveat
Reverse-WHOIS-by-registrant-org has real false-positive risk: two unrelated entities can share a registrar's privacy-proxy organization name, or a common-word org string can pull in unrelated matches. We only counted a sister domain as "confirmed" here if our scanner independently found live, resolvable infrastructure on it — a much stronger bar than a raw WHOIS-string match — but registrant-organization data itself is occasionally inconsistent or stale, and a small number of matches in any large-scale run like this could reflect a shared registrar service rather than true common ownership.
We take this caveat seriously enough that it changed this exact report:
while finalizing these numbers we found and fixed a real seeding bug
elsewhere in our pipeline where ~12 companies' primary domain (not their
reverse-WHOIS matches) had been seeded to an unrelated organization's
domain via a TICKER.com heuristic — one casualty was a company
previously shown in this report's first draft with "97 confirmed sister
domains" that were, on inspection, actually Netflix's domain portfolio
being queried under the wrong company's name. That company no longer
appears in this version. Every company and CVE finding shown above was
re-verified against the corrected dataset before publishing, and the three
largest entries (Airbnb, Hilton, Booking Holdings) were individually
spot-checked against their own registrant-org strings for exactly this
failure mode — see the note above.
Treat this as a strong starting signal for investigation, the same caveat we've given on every report in this series.
What this means if you hunt bug bounties
- Don't stop at the primary domain. A company's own reverse-WHOIS footprint — acquired brands, regional storefronts, internal tooling with a public face — routinely carries real, unaddressed risk, and it's systematically under-scrutinized because it doesn't look like "the target" at a glance.
- A bounty program on the main domain doesn't mean the sister domain is in scope — check explicitly. Several of the CRITICAL-CVE findings above belong to companies that DO run a bug bounty program, just not one that covers the specific asset carrying the risk.
- This is a seventh independent confirmation of the same pattern this series keeps finding: real, verifiable risk concentrates almost entirely outside the small cluster of companies running continuous external scrutiny via HackerOne — this time on an asset class (owned-but-forgotten sister domains) that most researchers never think to enumerate at all.
Check your own footprint
Everything above came from the same free tool anyone can run right now: domrecon.com — enter a domain, get a plain-English risk grade, full subdomain data, technology stack, and TLS/port intelligence. No signup required.
If you want the aggregate, cross-company view instead of one domain at a time — the kind of query that produced this report — that's what we built next: Graph Explorer, continuous scanning of the S&P 500's public attack surface as one interactive graph. See what's in it →
Data as of 2026-08-23, one point-in-time snapshot from our reverse-WHOIS and CVE-matching pipeline — not continuous monitoring, and re-verified against a corrected dataset the same day after fixing an unrelated primary-domain seeding bug elsewhere in our pipeline. Spot an error, or want the underlying query for a specific company? Reply — we read every message.
NullBlocks Systems — domrecon attack-surface intelligence.