Following the migration of domain registrations from Google Domains to Squarespace, researchers found that migrated accounts which had not yet been claimed could be taken over by supplying an email address associated with the domain. Reporting also describes two-factor authentication being disabled on migrated accounts, including those that previously had it enabled.
Between 9 and 12 July 2024 attackers used this to hijack domains belonging mainly to cryptocurrency businesses, redirecting some to sites built to drain visitors’ wallets.
A Migration Is A Security Event
Moving millions of registrations between providers means reconstructing the account state for each one. Whatever does not survive the move is silently removed, and nobody is notified that a protection they configured has gone.
We recorded the same category at CloudNordic in 2023, where a datacentre move merged backup networks into the environment they protected. The migration is where the assumptions get rebuilt, usually by people working to a deadline.
The Domain Is The Account
Control of a domain is control of its email, which is control of password resets everywhere else. A hijacked domain is not one compromised asset; it is the root of the recovery tree for everything hanging off it.
The targets here were cryptocurrency platforms, where redirecting a site to a wallet drainer converts that control into money within hours. It is the fastest route from a registrar problem to a financial loss that we have on file.
Compiled from published research and public reporting, listed below. The number of hijacked domains and any total loss have not been established. Corrections: corrections@forensicpost.com.