logo

Credential Theft and Domain Name Hijacking through Phishing Sites

ID: 554853bc-3371-5277-ba96-d2086a442f9b

STIX ID: report--554853bc-3371-5277-ba96-d2086a442f9b

Feed Name: JPCERT Blog

Threat Score
50/100

Date Published: 2023-11-07

Date Updated: 2026-04-19

Author: 水野 哲也 (Tetsuya Mizuno)

...
...

In July 2023 JPCERT/CC reported a domain hijacking case where attackers tricked a domain administrator into entering registrar credentials on a phishing site, then used those credentials to change contact information, disable transfer locks, and transfer the domain to another registrar; the report explains the attack flow and recommends mitigations such as accessing registrars via trusted bookmarks or official apps, enabling two-factor authentication, avoiding password reuse, and contacting registrars or ICANN dispute processes if a transfer is unauthorized.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.