Domain hijacking, or domain theft, refers to the loss of control over a registered domain name due to unauthorized access, abuse of procedures, or fraudulent modifications at the registrar, registry, or associated systems. The person who gains control may alter nameservers, transfer the registration, modify contact details, or attempt to move it to another account. Consequences can include website and email outages, user redirection to deceptive pages, and misuse of the domain owner's identity. This is a security incident involving administrative control over the domain, not merely a DNS failure or forgotten password.
How It Happens
A registrar account protected by reused or stolen passwords may be compromised through phishing, malware, or breaches of third-party services. The attacker can intercept administrative emails and then initiate credential resets, making recovery more difficult. Other risks include SIM theft or use of the authentication number, unprotected email accounts, identity verification errors, social engineering attacks on support teams, and shared access without oversight. In some cases, issues stem from reseller accounts or insecure transfer procedures.
Not every suspicious DNS change constitutes hijacking. Operational errors, domain expiration, site compromise, or authorized collaborator changes can produce similar symptoms. The distinction must be made by reviewing activity logs, access records, contact information, domain status, and provider communications. A rushed response may erase evidence or worsen an outage; it is useful to document times, screenshots, emails, and ticket identifiers while keeping data private.
Prevention
Protection begins with securing the registrar account and email accounts that can reset it. Unique passwords stored in a password manager, strong multi-factor authentication, individual accounts, and minimal privileges reduce risk. Registrars should offer transfer locks and, for high-value domains, optional registry lock procedures with out-of-band verification. Owners must keep contact details updated, monitor change and renewal notices, and restrict access to domain management. DNS API keys should be separated by purpose and revoked when no longer needed.
It is helpful to maintain an updated card with registrar, registrant, expiration date, nameservers, recovery procedures, and authorized contacts, avoiding inclusion of passwords or tokens in unprotected documents. Alerts for owner changes, nameserver updates, DNSSEC, locking, and transfers allow early response before abuse consolidates. An internal policy should define who approves changes and how urgent requests are verified: instructions received via email should be confirmed through independent channels, especially when they involve transfers or access changes.
Incident Response
If domain hijacking is suspected, immediately contact the registrar using known official contact methods, not those in suspicious messages. Request to block changes or transfers and preserve logs, following the official dispute procedure. Meanwhile, secure administrative emails, identity, and devices, and revoke compromised sessions or credentials. Emergency DNS changes must be carefully evaluated to avoid erasing evidence and ensure service continuity. Legal consultants, law enforcement, or extension-specific resolution procedures may be required for international damage or transfers.
After recovery, verify ownership, contacts, lock status, DNS delegation, records, certificates, email accounts, and linked services. Reconstruct the timeline, rotate credentials and keys, and update the response plan. In short, domain hijacking is a compromise of domain control; prevention combines identity and registrar protection, timely alerts, and pre-defined recovery procedures.
← Full glossary