Can see this being exploited in some fashion for phishing attacks..
If domain-owning organization fails to prevent a third party from hosting a phishing site under a path or a subdomain, that third party is likely well-positioned to deface the existing pages. With a subtle alteration (scripts that capture credentials and transmit them out), the existing pages grant an attacker all of the users with no extra effort—as opposed distributing a link to a fake page, convincing the user that the page is legit, and in the end getting a fraction of the user base.
I can even argue that if you take away the path from the URL, then it's actually easier to spot a phishing website since all you see is the domain if you don't hover over the address bar.