logo

Researchers: Weak Security Defaults Enabled Squarespace Domains Hijacks

ID: 9cd63d82-3524-58f0-b205-7f495dc44020

STIX ID: report--9cd63d82-3524-58f0-b205-7f495dc44020

Feed Name: Krebs on Security

Threat Score
65/100

Date Published: 2024-07-15

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

- Between July 9 and July 12, attackers exploited account-creation and migration weaknesses during Squarespace’s takeover of Google Domains to claim uninitialized domain-associated email accounts, hijack at least a dozen domains (notably crypto businesses), and in some cases redirect them to phishing sites; researchers point to missing email verification and disabled MFA during migration as root causes while Squarespace later reported an OAuth-related issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.