Skip to content

Major brand lost domain to phishing—are we all vulnerable?

Domain Names by minh1987 1 replies 170 views
11 #1

Read the news this morning. Attacker called registrar, impersonated CFO, got auth code emailed to compromised inbox. Transfer completed in 48 hours. Brand paid $2M recovery fee in my country that would fund a small ISP.

Attack vector was not technical. No DNS hijack, no BGP leak. Pure social engineering against tier-1 support.

Questions for the thread:
- Who here has phone verification enabled with their registrar?
- Has anyone tested their own support's resistance to social engineering?
- Registry lock: worth the cost and hassle?

In my country, registrar support is outsourced and turnover is high. Training varies by shift.

phở at 3AM, deploy at 4
#2

The compromised inbox likely contained personal data of registrants, which triggers notification obligations under Article 33. The registrar's data processing agreement should cover this, but most registrants never read it. Registry lock adds a contractual layer that may qualify as a technical and organisational measure under Article 32. The $300/year is steep for individuals, but for any processing of personal data at scale, it is proportionate.

Neuland. Aber schnell.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft