Desk live·
ForensicPost
Cloud/Identity/File 24-0710

Squarespace Migration Dropped Two-Factor, Crypto Domains Hijacked

Domains moved from Google to Squarespace arrived in accounts that had never been claimed, with two-factor authentication switched off. Between 9 and 12 July 2024 attackers claimed several and redirected them.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSquarespace domain customers
ActorUnattributed
D. Kennedy9 min readConfidence: high2 sources reviewed

Following the migration of domain registrations from Google Domains to Squarespace, researchers found that migrated accounts which had not yet been claimed could be taken over by supplying an email address associated with the domain. Reporting also describes two-factor authentication being disabled on migrated accounts, including those that previously had it enabled.

Between 9 and 12 July 2024 attackers used this to hijack domains belonging mainly to cryptocurrency businesses, redirecting some to sites built to drain visitors’ wallets.

A Migration Is A Security Event

Moving millions of registrations between providers means reconstructing the account state for each one. Whatever does not survive the move is silently removed, and nobody is notified that a protection they configured has gone.

We recorded the same category at CloudNordic in 2023, where a datacentre move merged backup networks into the environment they protected. The migration is where the assumptions get rebuilt, usually by people working to a deadline.

The Domain Is The Account

Control of a domain is control of its email, which is control of password resets everywhere else. A hijacked domain is not one compromised asset; it is the root of the recovery tree for everything hanging off it.

The targets here were cryptocurrency platforms, where redirecting a site to a wallet drainer converts that control into money within hours. It is the fastest route from a registrar problem to a financial loss that we have on file.

How we reported this

Compiled from published research and public reporting, listed below. The number of hijacked domains and any total loss have not been established. Corrections: corrections@forensicpost.com.

Sources
  1. Researchers: Weak Security Defaults Enabled Squarespace Domains HijacksKrebs on Security
  2. DNS hijacks target crypto platforms registered with SquarespaceBleepingComputer
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary