Domain hijacking is the unauthorized transfer or takeover of a domain, usually through a compromised registrar account rather than any weakness in DNS itself.
Common attack paths
- Phishing the registrar account’s email or credentials
- Exploiting a weak or reused password with no two-factor authentication
- Social-engineering the registrar’s support team into an unauthorized transfer
- An expired domain being re-registered by someone else (technically not "hijacking" but has the same effect)
Prevention
- Enable two-factor authentication on your registrar account — the single highest-impact step
- Enable a registrar/registry transfer lock so the domain can’t move without extra verification
- Keep registrant contact information current so ownership disputes can be resolved
- Monitor domain and DNS records for unexpected changes
FAQ
Can domain hijacking happen even with a strong password?
Yes, if two-factor authentication isn’t enabled — social engineering of registrar support staff has succeeded even against accounts with strong passwords.