Learning from the Past A Detailed Look at Major Domain Hijacking Incidents
- by Staff
Domain hijacking, once considered a relatively rare and obscure form of cybercrime, has become increasingly high-profile in recent years as attackers recognize the power and profitability of seizing control of domain names. These digital assets are often central to a company’s operations, branding, communication, and even intellectual property rights. When they fall into the wrong hands, the impact can be swift and devastating. Examining major incidents of domain hijacking provides crucial insights into the methods used by attackers, the vulnerabilities they exploit, and the steps that organizations must take to defend their online identities.
One of the most notable domain hijacking incidents occurred in 2013, when the Syrian Electronic Army (SEA), a politically motivated hacking group, targeted the New York Times. Through a spear-phishing campaign aimed at a Melbourne IT reseller—then the registrar managing the newspaper’s domain—the SEA was able to obtain login credentials and gain control of the domain. Once inside the registrar’s control panel, they altered DNS settings, redirecting users to a defaced version of the site containing pro-Syrian regime messages. The attack took the New York Times website offline for several hours, disrupted global readership, and triggered a broader conversation about registrar-level security. The fact that a sophisticated publication like the New York Times could fall victim highlighted the potential fragility of DNS infrastructure and the importance of security practices beyond just firewalls and malware prevention.
A similarly impactful incident occurred in 2014 when the domain name for Lenovo was hijacked following a compromise of its domain registrar account at Webnic.cc. Hackers modified the domain’s DNS settings to redirect users to a defaced site that displayed messages criticizing the company, coinciding with public controversy over Lenovo’s pre-installed software on consumer laptops. Investigators later discovered that the attackers used social engineering techniques to manipulate registrar personnel and gain unauthorized access. This attack revealed how human factors—such as trust in seemingly legitimate communication—could be exploited to bypass technical security measures. It also emphasized the need for multi-factor authentication and registrar-level locks to protect domain settings.
In 2017, the Brazilian bank Banco de Brasil faced a highly sophisticated hijack when cybercriminals redirected the domain’s traffic to phishing servers. For over five hours, customers attempting to access the bank’s official website were unknowingly sent to a fake replica designed to steal login credentials and financial data. The attackers achieved this by compromising the domain’s DNS records at a third-party service provider, demonstrating the danger of relying on external infrastructure without adequate security oversight. This incident not only impacted thousands of customers but also caused regulatory scrutiny and long-term damage to the bank’s credibility. It served as a case study in how DNS manipulation, rather than just full domain ownership transfer, can be weaponized for fraud.
Another striking example came in 2018 when MyEtherWallet, a popular cryptocurrency wallet provider, experienced a domain hijacking that resulted in the theft of over $150,000 worth of cryptocurrency. Attackers exploited a vulnerability in the Border Gateway Protocol (BGP), the routing system that directs traffic across the internet. By rerouting traffic through a malicious server, the attackers tricked users into thinking they were accessing the legitimate site when they were actually interacting with a near-identical fake. The domain itself had not been transferred, but the DNS redirection created a similar effect. This incident underscored the layered complexity of domain security, which extends far beyond the registrar and touches the deeper architecture of the internet. It also raised awareness of the need for DNSSEC and BGP monitoring in high-value digital environments.
Perhaps one of the most commercially damaging domain hijacks took place in 2020 when the popular online art marketplace Artsy had its domain redirected by attackers after access to the registrar account was obtained. The attackers changed DNS settings to point to a phishing site that mimicked the real Artsy platform. For several hours, artists and buyers were exposed to a fake interface designed to harvest credentials and financial information. Despite the swift response from Artsy and its registrar, the hijack resulted in significant confusion, lost trust, and a wave of support requests from affected users. The recovery process required coordination between legal teams, cybersecurity experts, and registrar support, revealing how complex and time-sensitive domain recovery efforts can be.
The domain hijacking of Cambodia’s top-level domain (.kh) in 2021 added an entirely different dimension, involving political motivations and misuse of administrative authority. A rogue employee at the country’s domain registry was accused of manipulating registration records to seize domains tied to independent news organizations and human rights groups. This incident illustrated that threats to domain integrity are not limited to external cybercriminals, but can also originate from insiders with privileged access. The fallout included international condemnation, scrutiny of registry practices, and renewed calls for transparency and oversight in managing country-code top-level domains.
These high-profile domain hijacking cases reveal a wide spectrum of attack vectors and consequences. Whether through phishing, social engineering, DNS exploitation, or internal abuse, each incident underscores the immense value of a domain name and the lengths to which attackers will go to compromise it. They also demonstrate that recovery is not a matter of simply flipping a switch—it requires coordination, documentation, often legal intervention, and a hardened understanding of technical infrastructure.
For organizations managing digital assets of any scale, the lessons from these incidents are clear. Domain names are not just addresses; they are lifelines. Securing them requires robust registrar protections, multi-factor authentication, regular audits of DNS settings, and contingency planning for rapid response. Equally important is awareness—of both the methods attackers use and the responsibilities that come with domain ownership. In the world of modern cyber threats, the domain is a crown jewel, and as history shows, failing to protect it can lead to far-reaching and costly consequences.
Domain hijacking, once considered a relatively rare and obscure form of cybercrime, has become increasingly high-profile in recent years as attackers recognize the power and profitability of seizing control of domain names. These digital assets are often central to a company’s operations, branding, communication, and even intellectual property rights. When they fall into the wrong…