Credential Theft and Domain Name Hijacking through Phishing Sites
ID: 554853bc-3371-5277-ba96-d2086a442f9b
STIX ID: report--554853bc-3371-5277-ba96-d2086a442f9b
Feed Name: JPCERT Blog
In July 2023 JPCERT/CC reported a domain hijacking case where attackers tricked a domain administrator into entering registrar credentials on a phishing site, then used those credentials to change contact information, disable transfer locks, and transfer the domain to another registrar; the report explains the attack flow and recommends mitigations such as accessing registrars via trusted bookmarks or official apps, enabling two-factor authentication, avoiding password reuse, and contacting registrars or ICANN dispute processes if a transfer is unauthorized.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
