Throughout 2024, attackers conducted a campaign researchers named "Sitting Ducks" to describe the scale and nature of the attack. The name is apt. Over the course of the year, Russian-linked threat actors hijacked tens of thousands of legitimate domains and used them to run phishing campaigns, sell counterfeit products, and distribute malware. The victims were not breached through password theft or sophisticated hacking. They were simply sitting ducks—owners of domains with weak or outdated security configurations that nobody was monitoring.
The attack worked because most businesses treat their domain as something you register once and never think about again. The registrar keeps it renewing. The DNS servers point to your hosting. Everything works, so there is no reason to look at the security settings. Then one day, attackers access the registrar account (often through an old email that isn't checked, or a password shared years ago), change the DNS records to point to their servers, and your domain is no longer yours. Your email stops working. Your website goes offline. Customers trying to reach you land on a fraud site bearing your domain.
The scale in 2024 was shocking because it revealed how many domains had been neglected. Attackers also compromised DNS servers managing roughly seventy thousand domains through direct compromise, altering records at the DNS level itself. That is a different vector—if your DNS provider was breached and you had weak API credentials or no IP whitelisting, your domain could be redirected without touching your registrar account at all.
The human element is what made "Sitting Ducks" possible. A domain registered five years ago might have an associated email address that belonged to a now-departed employee. That email account has been compromised in a third-party breach (credentials floating on the dark web). An attacker tries those credentials against your domain registrar and they work. Two-factor authentication isn't enabled, so there is no second barrier. The domain changes hands.
Other cases involved even simpler negligence. A business registered a domain with a DNS provider, pointing it to their website. Years later, they moved to a different DNS provider but never updated the DNS records at the original provider. The old records sat dormant, unchanged, unmonitored. Attackers noticed and claimed the dormant domain through the registrar, creating subdomains that worked like the real thing.
Later in 2024, after Google Domains migrated to Squarespace, new victims emerged. Domain owners reported that attackers had taken over their accounts during or after the migration because Squarespace's transfer process left accounts partially unverified or dormant, creating an opening for account takeover.
The common thread across all these cases is the same: neglect. Not compromised passwords or sophisticated attacks, but abandoned or forgotten security basics. No regular audits of DNS settings. No IP whitelisting on registrar API access. No two-factor authentication on registrar accounts. Old DNS servers still holding records. Duplicate DNS setups with one serving as a backdoor. Outdated contact information on registrar accounts.
For a business whose brand and customer communication flow through a domain, hijacking is catastrophic. You lose access to your email. Your website goes offline or worse, serves malware. Customers cannot reach you. Attackers use your reputation to commit fraud.
Where WebAcumen fits in
We audit domain security as part of our security review process. That includes checking DNS configurations, verifying registrar security settings, ensuring two-factor authentication is enabled, reviewing DNS change logs, and recommending hardening steps. For critical domains, we also monitor for unauthorized changes so you know if someone attempts an unauthorized modification.
Your domain is your online identity. It deserves the same security rigor you apply to anything else valuable.