Domain hijacking: what it is and how to protect yourself
Imagine this: you type in the URL of your company website, but instead of your site a page belonging to someone else appears. Or worse: a page telling you that you can "buy back" your own domain name for thousands of euros. This is the nightmare of domain hijacking, and it happens to more companies and individuals than you might think. In this article we explain what a domain hijacker is, how domain hijacking works and, most importantly, how you can protect yourself against it.
What is domain hijacking?
Domain hijacking is the unlawful takeover of a domain name. A domain hijacker gains control, in an illegal or unethical way, over a domain name that does not belong to them. This can happen in several ways, from hacking the account at the domain registrar to abusing expired domain names.
The difference with simply registering an available domain name is that with domain hijacking the name already has an owner, or has just expired, and the hijacker deliberately abuses the situation. The consequences can be devastating: loss of online identity, customers who can no longer find you, reputational damage and, in the worst case, financial loss through extortion.
Domain hijacking is a serious problem in the digital world. According to ICANN (the international organisation that manages the domain name system), thousands of disputes about domain name matters are filed every year. And those are only the cases that are officially reported; the real number is probably much higher.
How does domain hijacking work?
A domain hijacker can strike in several ways. Here are the most common methods:
Social engineering at the registrar
The hijacker poses as the rightful owner and convinces the domain registrar to transfer the domain name. This can be done by phone, email or a forged proof of identity. Registrars with weak verification processes are vulnerable to this. The hijacker might, for example, request a password reset or claim that the contact details have changed.
Phishing attacks
The hijacker sends an email that looks like a message from your domain registrar. This email asks you to log in through a link that leads to a fake website. As soon as you enter your login details, the hijacker has access to your account and can transfer the domain name to another registrar.
Hacked email account
If a hijacker gains access to the email address linked to your domain registration, they can reset passwords and take over control. Many people use the same email address for everything, which increases the risk. A hacked email account opens the door to all your online accounts, including your domain registrar.
Taking over an expired domain (domain sniping)
If you forget to renew your domain name, it becomes available for registration again after a waiting period. Specialised companies and individuals actively monitor which domain names are expiring and register them the moment they become free. This is technically legal, but is often seen as unethical, especially when the hijacker then asks an astronomical sum to sell the domain back.
Exploiting registrar vulnerabilities
Sometimes the systems of domain registrars contain security holes that can be exploited by hackers. This can range from SQL injection to cross-site scripting (XSS) attacks. In larger attacks, thousands of domain names have been hit at once in the past.
Well-known cases of domain hijacking
Domain hijacking is not a theoretical risk; it has happened many times, sometimes with spectacular consequences:
Sex.com (1995-2003)
The most famous case of domain hijacking ever. Stephen Michael Cohen managed to take the domain sex.com away from its rightful owner Gary Kremen through a forged letter to the registrar Network Solutions. The domain was worth millions of dollars in advertising revenue. After years of legal proceedings, Kremen got the domain back in 2003, together with damages of 65 million dollars. Cohen fled to Mexico to avoid payment.
Panix.com (2005)
The New York internet provider Panix temporarily lost control over panix.com when someone had the domain transferred to an Australian registrar through a fraudulent transfer request. The incident lasted only a week, but it led to stricter security rules at ICANN for domain transfers.
Perl.com (2020)
The domain perl.com, for decades the unofficial home address of the programming language Perl, was hijacked in January 2020 and redirected to an IP address associated with malware distribution. It took the Perl community weeks to get the domain back.
Types of domain abuse: the differences
Not all forms of domain abuse are the same. It is important to understand the differences:
Domain hijacking
The actual theft of a domain name through unlawful takeover of the registrar account or through fraud at the registrar. The rightful owner loses all control over the domain.
Cybersquatting
Registering domain names that are identical or very similar to well-known brand names, with the aim of reselling them at a profit to the brand owner. For example: registering cocacola-netherlands.nl without any relation to Coca-Cola, in the hope that they will want to buy it.
Typosquatting
Registering domain names that look a lot like popular websites, but with a typo. Examples: gooogle.com, facebok.com or amazom.com. Visitors who make a typo end up on the typosquatter's website, which is often full of adverts or even malware.
Domain sniping (expired domains)
Systematically monitoring and registering domain names that have just expired. This is technically legal but is considered unethical when the goal is to make the previous owner pay to get their domain back.
Reverse domain hijacking
A less well-known but growing form: a (often large) company tries, through a UDRP procedure or legal pressure, to take a domain name away from a rightful owner who registered the domain earlier. This is abuse of the dispute process.
How do you protect yourself against domain hijacking?
Fortunately there are many measures you can take to protect your domain name. Here are the most important ones:
Use strong, unique passwords
It sounds obvious, but weak passwords are still the number one cause of account compromise. Use a strong, unique password for your domain registrar account: at least 16 characters, with a mix of letters, numbers and special characters. Use a password manager such as LastPass, 1Password or Bitwarden to store your passwords safely.
Enable two-factor authentication (2FA)
2FA adds an extra layer of security. Besides your password, you need a second factor to log in, such as a code from an authenticator app (Google Authenticator, Authy) or a hardware key (YubiKey). Even if a hijacker knows your password, they cannot log in without this second factor.
Activate domain lock (registrar lock)
A domain lock (also called registrar lock or transfer lock) prevents your domain name from being transferred to another registrar without your permission. As long as the lock is active, all transfer requests are automatically refused. This is one of the simplest and most effective protective measures. At most registrars you can enable it with a single click.
Use WHOIS privacy
When you look up a domain name via WHOIS, the contact details of the owner are often visible: name, address, phone number and email address. This information can be used by hijackers for social engineering or phishing. WHOIS privacy (also called WHOIS protection or ID protect) hides your personal details and instead shows the details of a privacy service.
Renew your domain name on time
One of the easiest ways to lose your domain is by forgetting to renew it. Enable automatic renewal at your registrar so that your domain is renewed automatically before it expires. Also make sure that the credit card or payment method linked to your account is up to date.
Keep your contact details up to date
Make sure that the email address linked to your domain registration is always current and that you have access to it. If your registrar sends a verification email and you do not respond, this can lead to problems. Preferably use an email address on a different domain than the one you are protecting; if that domain is hijacked, you still have access to your email.
Choose a reliable registrar
Not all domain registrars offer the same security measures. Choose a registrar that supports 2FA, offers domain lock, has WHOIS privacy and has a proven track record in the area of security. At Theory7 you can register your domain name with all these security features included.
What to do if your domain name is hijacked
Should it unexpectedly happen anyway, follow these steps:
- Contact your registrar immediately: report the hijacking as soon as possible. The faster you react, the greater the chance that the transfer will be reversed.
- Gather evidence: screenshots of your registration information, proof of payment, earlier WHOIS data, anything that proves that you are the rightful owner.
- Contact the receiving registrar: if the domain has been transferred to another registrar, contact them too and report the fraud.
- File a UDRP complaint: through ICANN's Uniform Domain-Name Dispute-Resolution Policy you can start a dispute procedure. This costs around $1,500-5,000 and takes 2-4 months.
- SIDN dispute settlement (for .nl domains): for .nl domain names, SIDN (the manager of .nl) offers its own dispute settlement. This is faster and cheaper than a UDRP procedure and is governed specifically by Dutch law.
- Legal steps: in serious cases you can engage a lawyer and file a court case. This is the most expensive option but may be necessary in the event of major financial damage.
- Report it to the police: domain hijacking is a criminal offence in the Netherlands as computer trespass (article 138ab of the Dutch Criminal Code). Report it, even if the chance of catching the culprit seems small.
Protecting your domain name at Theory7
At Theory7 we take the security of your domain name seriously. As standard we offer:
- Domain lock: automatically activated on all domain names to prevent unauthorised transfers.
- WHOIS privacy: your personal details are protected and not publicly visible.
- Secured account: our control panel supports strong passwords and two-factor authentication.
- Renewal reminders: we send multiple reminders before your domain expires, so you are never caught off guard.
- Automatic renewal: the option to renew your domain automatically so that it never expires by accident.
- Dutch support: if you suspect abuse, you can contact our Dutch-speaking team directly.
Do you want to register a domain name or transfer your existing domain to a safer registrar? Take a look at our domain offers or get in touch for personal advice. Our specialists are happy to help you choose the perfect domain name and secure it as well as possible.
Frequently asked questions about domain hijacking
How quickly should I react if my domain is hijacked?
As fast as possible, preferably within 24 hours. The longer you wait, the harder it becomes to get the domain back. A domain transfer can be final within a few days if you do not react in time.
Is domain hijacking a criminal offence in the Netherlands?
Yes, domain hijacking can fall under computer trespass (article 138ab of the Dutch Criminal Code), fraud or identity theft. The chance of catching the culprit is small in the case of international hijacking, however. For .nl domains you can also start a dispute procedure through SIDN.
What does it cost to recover a hijacked domain?
Through a UDRP procedure at ICANN: $1,500-5,000. Through the SIDN dispute settlement for .nl domains: around €1,500. Through a court case: thousands to tens of thousands of euros. In some cases it is cheaper to pay the hijacker, however frustrating that may be.
Does domain lock protect against all forms of hijacking?
Domain lock protects against unauthorised transfers to another registrar. It does not protect against all forms of hijacking, such as a hacked registrar account. So always combine domain lock with strong passwords and 2FA.
Can I claim a domain name that resembles my brand name?
Yes, if you own a registered trademark you can, through a UDRP procedure or the SIDN dispute settlement, claim a domain that is identical or confusingly similar to your brand name. The condition is that the current holder registered or used the domain in bad faith.
How do I know whether my domain is safe?
Check regularly whether domain lock is active, whether you have enabled 2FA, whether your contact details are current and whether automatic renewal is switched on. Also run a periodic WHOIS check on your own domain to verify that the details are correct.
A domain hijacker can take over your online identity in the blink of an eye, with all the consequences that entails. Fortunately, with relatively simple measures (strong passwords, 2FA, domain lock, WHOIS privacy and timely renewal) you can reduce the risk considerably.
Your domain name is one of your most important digital assets. Protect it as if it were your physical business premises. And if you are looking for a reliable registrar that takes security seriously, take a look at the domain registration options at Theory7.
Protection against a domain hijacker
| Protective measure | Protects against a domain hijacker | Difficulty |
|---|---|---|
| Registry Lock | Prevents a domain hijacker from transferring your domain | Easy |
| Two-factor authentication | Blocks a domain hijacker during login attempts | Easy |
| WHOIS privacy | Hides your details from a potential domain hijacker | Easy |
| Strong password | Makes it harder for a domain hijacker to break in | Easy |
| Domain monitoring | Detects when a domain hijacker becomes active | Medium |
By combining these measures you considerably reduce the chance that a domain hijacker will succeed.
Protection against domain hijacking: advanced security measures
Besides the basic tips, there are advanced measures you can take to protect yourself against a domain hijacker. Professional domain security goes beyond just a strong password.
Setting up Registry Lock
Registry Lock is the strongest protection against unauthorised domain transfers. Unlike an ordinary Registrar Lock, a Registry Lock is set directly at registry level. Every change requires manual verification by the registry, often with telephone confirmation. For .nl domains, SIDN offers this under the name Domeinslot. The cost is higher than a standard lock, but for business-critical domains it is worth the investment.
Monitoring and alerting
Set up monitoring so that you are warned immediately of changes to your domain. Use services that alert you to DNS changes, WHOIS changes, nameserver changes and certificate issuance for your domain. You can monitor Certificate Transparency logs through tools such as crt.sh. That way you know immediately if someone requests an SSL certificate for your domain, a possible sign of domain hijacking.
What to do if your domain is hijacked
- Contact your registrar immediately - report the hijacking and ask for an immediate freeze of the domain
- Gather evidence - take screenshots of WHOIS data, DNS records and all communication
- File an ICANN complaint - through the Transfer Dispute Resolution Policy (TDRP) process
- Legal steps - engage a specialised lawyer for a UDRP procedure or summary proceedings
- File a police report - domain hijacking is a criminal offence; always report it
Want to know more about how to keep your domain safe? Also read our extensive guide on protecting your domain name.
Recognising a domain hijacker: warning signs
To protect yourself against a domain hijacker, you need to know the warning signs. Phishing emails claiming to come from your registrar and asking you to log in are a classic attack method; always check the sender address and log in directly through the official website. Unexplained changes in your DNS records, such as new A records or altered MX records, can indicate unauthorised access. If you suddenly no longer have access to your registrar account, or if you receive password reset emails you did not request, someone may be trying to take over your domain. Check your WHOIS data regularly to spot unauthorised changes to contact information early.
A domain hijacker: legal consequences
A domain hijacker risks serious legal consequences. In the Netherlands, domain hijacking is a criminal offence under cybercrime legislation. Victims can demand the return of the domain through summary proceedings, often with an award of legal costs against the hijacker. International procedures through ICANN (UDRP) cost the claimant around 1,500 dollars but have a high success rate when bad faith is proven. The cost of legal procedures underlines the importance of preventive measures.
Protect your domain today against a domain hijacker by applying the security measures from this article. Prevention is always better than cure.
Want to know whether a domain name is still available? Use our free domain name checker to check this instantly.