What Domain Hijacking Looks Like

You wake up to find your website redirects to a phishing page, your email goes to an attacker's mailbox, and you are locked out of your registrar account. By the time you call support, the domain has been transferred to a different registrar and possibly resold. Recovery takes weeks, sometimes months, and is not always successful.

The good news: every successful hijack uses one of four predictable attack paths, and each one has a known defense.

Attack Path 1: Account Takeover

The attacker gets into your registrar account directly β€” most commonly through a leaked password reused from another breach, or a weak password guessed by an attacker who already knows your email.

Defense:

  • Unique, password-manager-generated password for the registrar account.
  • Hardware-key 2FA (YubiKey, Titan) β€” not SMS. SMS is vulnerable to SIM-swap.
  • Separate email account used only for the registrar, with its own strong password and 2FA.

Attack Path 2: Email Compromise

The attacker takes over the email address listed on your domain. They then use "forgot password" on the registrar to take over the domain account. This is the most common path β€” and it works because the email account is usually the weakest link.

Defense:

  • Your registrar email must have stronger security than your registrar account itself.
  • Enable login alerts in Gmail/Outlook so you see access from new devices.
  • Never use a free email service tied to a phone number you might lose.

Attack Path 3: Social Engineering of Registrar Support

The attacker calls your registrar's support line, claims to be you, and convinces a support agent to reset access. Less common at top-tier registrars but a regular problem at smaller ones.

Defense:

  • Choose a registrar with documented identity-verification procedures for account recovery.
  • Set a security passphrase or PIN on the account (most registrars support this in account settings).
  • Disable "phone-based account recovery" if your registrar offers a way to opt out.

Attack Path 4: Unauthorized Transfer

The attacker uses an EPP/auth code to transfer the domain to their own registrar, where they then have full control. This is the path that turns a temporary compromise into a permanent loss.

Defense:

  • Domain lock (transfer prohibited) β€” every registrar offers this. Turn it on.
  • Registry lock β€” a separate lock at the registry level (the company that runs .com, etc.). Costs $50–200/year per domain but blocks transfers even if the registrar account is compromised. Worth it for any domain that matters to your business.
  • Never share the EPP/auth code by email or chat. Treat it like a password.

The Five-Layer Defense

Stack all of these and a hijack becomes implausible:

  1. Hardware-key 2FA on the registrar account.
  2. A dedicated, hardened email address used only for registrar correspondence.
  3. Domain lock enabled on every domain.
  4. Registry lock on critical domains (your primary brand, auth/login domains).
  5. Annual review of authorized contacts and admin users on the account.

What to Do If You Get Hijacked

Speed matters. The faster you act, the better your chance of recovery.

  1. Contact your registrar immediately by phone, not email. Email queues take hours; phone usually gets a real human in minutes.
  2. Open a UDRP or URS case if the domain is now hosting infringing content. ICANN's dispute mechanisms can recover domains, especially if you have a registered trademark.
  3. File a police report in your jurisdiction. This is required by some registrars to authorize recovery and creates a paper trail.
  4. Document everything β€” screenshots of the hijacked site, transfer notification emails, support tickets. You will need this for the dispute.

Recovery can take weeks. Do not wait until you have been hijacked to learn what your registrar requires β€” read their abuse policy now, while everything is calm.

Related reading: 2FA for Registrars: Setup Guide Β· WHOIS Privacy Protection