In seeking to further monetize Web site traffic on their networks, a number of major Internet service providers may be inadvertently exposing their customers to a greater risk of online attack from identity thieves, according to research released today. Many ISPs have already adopted the controversial practice of serving advertisements when a customer tries to browse to a Web site that does not exist. But a growing number of providers also are serving ad-filled pages when customers request a subdomain of a Web site that does not exist, such as something.example.com. This practice, which experts say potentially introduces new copyright violation claims, also potentially introduces security threats when ISPs outsource the ad-serving process to third parties. The findings come from Dan Kaminksy and Jason Larsen, security researchers from IOActive, a security company based in Seattle, the site of the Toorcon hacker conference where the two are expected to unveil their