TL;DR:

  • Domain hijacking can silently redirect your website visitors and intercept your business emails — without you knowing for hours or days.
  • The fix is straightforward: enable two-factor authentication on your registrar account, turn on Registrar Lock, and check who actually controls your DNS records.
  • A joint NCSC/FBI advisory in early 2026 attributed large-scale DNS hijacking operations to state-backed attackers — but the same techniques are used against small businesses every day.

Your business domain — the name people use to find your website and send you emails — is one of your most valuable digital assets. Lose control of it and you lose everything that depends on it: your website, your email, any customer trust built up in that name.

Domain hijacking doesn’t require hacking your website directly. It means taking control of your domain registration — the account at a registrar like GoDaddy, Namecheap, or 123-reg — so attackers can redirect traffic wherever they want.

How Domain Hijacking Actually Happens

There are three common routes attackers take:

1. Registrar account compromise. Your registrar account has a username and password. If attackers get hold of those credentials — through phishing, a data breach on another site where you reused the password, or a password reset email they’ve intercepted — they can log in to your registrar and change where your domain points.

2. Social engineering the registrar. Attackers call or email your registrar’s support team, impersonating you as the domain owner, and request a domain transfer or DNS change. Support staff at some registrars have been deceived into making changes without proper identity verification. This is harder than it sounds, but it happens — and the NCSC has documented state-backed groups using forged identity documents to execute this at scale.

3. Compromised DNS settings via router or hosting. If your router or web hosting control panel is compromised separately, attackers may be able to change DNS records without touching your registrar at all. A joint NCSC/FBI advisory in April 2026 warned specifically about APT28 (a Russian state-sponsored group) modifying SOHO router DNS settings to intercept traffic. The same technique works against small businesses at a fraction of the sophistication.

What Happens When Your Domain Is Hijacked

Once attackers control your DNS records, they can:

  • Redirect your website to a fake version that harvests customer data or installs malware on visitors’ computers
  • Redirect your email to their own servers, intercepting every incoming email — including password resets, invoices, and customer enquiries
  • Transfer the domain to another registrar, making recovery much harder
  • Set up convincing phishing pages that appear to be your legitimate site

The worst part: your actual website and servers are completely untouched. There’s nothing wrong with your hosting. The attack is invisible to you until customers start reporting that your site looks different — or until you notice email isn’t arriving.

Five Things to Do This Week

1. Enable two-factor authentication (2FA) on your registrar account. This is the single most important step. If your registrar supports 2FA (most do), turn it on immediately. Use an authenticator app rather than SMS if possible — SMS 2FA can be defeated by SIM-swapping attacks.

2. Enable Registrar Lock (Transfer Lock). Most registrars offer a “Registrar Lock” setting that prevents any domain transfer request from succeeding without you explicitly unlocking it first. Check your registrar’s control panel under “Domain Settings” or “Security.” This stops the most common method of domain theft outright.

3. Use a strong, unique password for your registrar account. Do not reuse any password from any other site. A breach at any other service you use with the same password is a breach of your domain. Use a password manager (Bitwarden and 1Password are both good options) and generate a long random password specifically for your registrar.

4. Check who controls your DNS and what they point to. Log into your registrar and review your DNS records. Your “A” record should point to your web hosting IP. Your “MX” records should point to your email provider. If anything looks unfamiliar or has recently changed and you didn’t make the change, treat it as a potential incident.

5. Keep your contact details up to date at the registrar. Registrars use the email address on your account to send security alerts and to verify ownership if you need to recover the account. Make sure the email address on your registrar account is one you actively check and that someone at your business has access to.

DNSSEC: Worth Enabling?

DNSSEC (Domain Name System Security Extensions) cryptographically signs DNS records so that resolvers can verify they haven’t been tampered with in transit. It doesn’t prevent account compromise, but it does protect against certain types of DNS poisoning attacks where records are intercepted and forged during lookup.

DNSSEC is supported by most major registrars and is free to enable. For most small businesses, it’s a useful additional layer once you’ve done the basics above. Check your registrar’s help documentation for their specific setup steps.

Domain Name Monitoring

If you want an early warning system, a few free and low-cost services will alert you if your domain’s DNS records change unexpectedly:

  • DNSSPY and DNSWatch offer free monitoring for record changes
  • Cloudflare (if you use them as your DNS provider) logs all changes with timestamps
  • Your registrar may also offer email alerts for any account changes — enable these if available

For most small businesses, getting the basics right — 2FA, registrar lock, unique strong password — eliminates the vast majority of risk. Domain hijacking is common enough to be a real threat, but it’s also preventable with straightforward steps that take less than an hour to implement.

If Your Domain Is Hijacked

Contact your registrar’s support immediately and document every communication. The NCSC’s Incident Management guidance recommends notifying them (report.ncsc.gov.uk) for significant incidents. If your email has been intercepted, assume that any passwords sent to that email in the window of the attack have been compromised.

Domain recovery can take 24–72 hours even in the best case. Getting a Registry Lock on your domain beforehand means that transfer requests require additional out-of-band verification — making recovery much faster if an incident does occur.