Security Glossary

What is DNS Hijacking?

DNS hijacking redirects users who type your real domain to attacker infrastructure by altering DNS records or registrar control. Victims see the correct hostname in the browser while landing on a fake site — a powerful path for mass credential theft.

How a DNS Hijacking Attack Works

1

Target registrar or DNS admin access

Phished registrar credentials or weak DNS host security are common entry points.

2

Change critical records

MX, A, or NS records are pointed at attacker infrastructure.

3

Intercept traffic or mail

Users and partners continue using the real domain name unknowingly.

4

Harvest or manipulate

Credentials, mail, and resets flow through attacker systems.

Real-World Example

A retailer's DNS host account was phished via a lookalike admin portal. Attackers briefly pointed the checkout hostname to a skimming site during a holiday weekend.

How AiVERSARY Detects DNS Hijacking Risk

AiVersary reconnaissance includes domain and infrastructure context that often reveals how visible and attractive your DNS estate is to attackers casing registrar takeover paths.

Is your organization exposed to dns hijacking?

AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.

Get Your Threat Report

Related Terms

Lookalike Domains

Lookalike domains are registered names that visually or typographically resemble a trusted brand — rn instead of m, extra letters, or alternate TLDs. They power phishing sites, fraudulent invoices, and executive impersonation that bypass casual visual checks.

Tenant Compromise

Tenant compromise is when an attacker gains administrative control over your organization's cloud environment — your Microsoft 365 tenant, Google Workspace, or AWS account. Unlike stealing a single employee's password, this gives the attacker the keys to everything: every email, every file, every application, and every user account in your cloud infrastructure. It is the most devastating outcome of a successful credential attack.

Spear Phishing

Spear phishing is a targeted email attack where criminals research a specific person and craft a message designed just for them. Unlike mass spam, these emails reference real details about your job, your colleagues, or recent company events to appear legitimate. They are the number one way attackers breach organizations today.

OSINT Reconnaissance

OSINT reconnaissance — Open Source Intelligence gathering — is the first phase of nearly every targeted cyberattack. It's the process of collecting publicly available information about an organization and its people to plan an attack. Everything from your company website and LinkedIn profiles to job postings, DNS records, and conference presentations becomes intelligence. This is exactly the same process AiVersary uses, but we do it first so you can fix what's exposed.