• Subscribe
  • Log In
  • Sign up for email updates
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

The Texas Lawbook

Free Speech, Due Process and Trial by Jury

  • Appellate
  • Bankruptcy
  • Commercial Litigation
  • Corporate Deal Tracker
  • GCs/Corp. Legal Depts.
  • Firm Management
  • White-Collar/Regulatory
  • Pro Bono/Public Service/D&I

Domain Name Hijacking: What It Is and How to Avoid It

© 2017 The Texas Lawbook.

spnsredx1l

By Craig Carpenter and Fred Fulton of Thompson & Knight

(July 6) – One hacking trend that is often under the radar, but which can be devastating on businesses, is domain name hijacking. In today’s online world, a company’s domain name can be one of its most valuable assets. Catchy domain names are often valued in the millions of dollars, and e-commerce websites can be a company’s primary or sole revenue generator. And when a company loses control of that asset, recovering it can be very expensive and difficult (if not impossible).

Craig Carpenter
When a hacker takes control of a domain name, the hacker can use the stolen domain name to wreak havoc on the company by:

• Vandalizing the website with disparaging content or materials;
• Using the website for other hacking activity, such as phishing or distributing malware or spam;
• Diverting income from the website to the hacker; or
• Shutting down the company’s e-commerce operations.

Domain name hijacking occurs when an unscrupulous person exploits a vulnerability to steal a company’s domain name. The unauthorized access can relate to a vulnerability in the domain name registrar’s system, a password hack of the administrative email associated with the account, social engineering, keyloggers or a disgruntled employee with access to the administrative email. Once the hacker has access to the administrative email account or the registrar account through one of these means, the hacker can take control of the domain name and lock out the true owner.

Once a domain name has been hijacked, it can be difficult for the true owner to recover access to it. With enough documentation, the owner may be able to recover access from the registrar, but this may be ineffective if the domain name has been transferred to another registrar or another country (frequently China), or if the registrar just declines to help. If the registrar cannot or will not help, companies may try to recover stolen domain names through legal action, either in the form of a Uniform Domain Name Dispute Resolution Policy through the Internet Corporation for Assigned Names and Numbers (or ICANN), or a lawsuit based on theft. These actions have a better chance of succeeding when the stolen domain name includes the owner’s registered trademark or service mark.

Fred Fulton
Fortunately, there are steps companies can take on the front end to help prevent this type of cybercrime. No single step is likely to be 100 percent effective at preventing domain name hijacking, but in combination they can improve a company’s security posture and greatly reduce the effort and expense needed to recover the name. The steps include:

1. Careful registration

In the domain name world, the “WHOIS” field in the domain name registrar’s database is analogous to the title to the domain name, so it’s critical that the correct information be entered there. When registering your domain name with a registrar, be sure to follow these tips:

• Enter correct and valid information in the WHOIS (registrant), administrative, technical and billing contact fields.

• The entity listed as the registrant in the WHOIS field is the entity that will have the legal right to transfer the domain name, acting through any individual who has been designated as an administrative contact with respect to it. So make sure all of those individuals are trustworthy employees.

• After the initial registration has been completed, continue to update all of the administrative, technical and billing contact information in your domain name customer account.

2. Limit access to the administrative contact email address

Each employee who has access to, and thus the ability to send email to the domain name registrar from, the administrative contact email address associated with your domain name will have the ability to effect the transfer of the domain name to another registrar or owner, or to make other changes to the domain name customer account.

Accordingly, it is extremely important to limit access to the administrative contact email address to trustworthy employees. Do not give your domain name customer account login, password, username, user ID, credit card number or shopper PIN information to anyone, including your webmaster.

Do not allow the administrative contact email address to expire, as this could make it possible for an unauthorized third party to sign up for that email address. That would provide access to your domain name customer account and the ability to transfer the domain name or make other changes to the domain name customer account.

3. Agreements with employees

The entity in whose name your domain name is registered, and so owns it, should enter into written agreements with all employees who have access to the administrative contact email address wherein they acknowledge and agree that the domain name is

a. Owned exclusively by their employer, and
b. Cannot be transferred, nor can any change be made in the related domain name customer account, without prior authorization from specified senior officers of their employer.

4. Monitoring and documentation

Regularly log in to your domain name customer account to confirm that the registrant and the related administrative, technical and billing contacts are listed correctly, reflecting all changes that have been made with proper authorization and no others.

Keep records of your account information to help show that you have a prior claim to the rights to the domain name. Records could include registration records, billing records, web logs, correspondence from the registrar and third-party directory information.

5. Lock your domain name

Lock your domain name from within your domain name customer account. Your registrar may provide an option to purchase additional features to help prevent your domain name from being transferred, or changes being made to your domain name customer account, without proper authorization.

6. Use secure email

Keeping secure the email through which you administer the registration of your domain name is important to preventing unauthorized changes to the registration. Consider the following precautions:

• Use a secure email address. Free email accounts can be easy targets for those seeking unauthorized access to your domain name customer account.

• Create passwords to limit access to the administrative contact email address associated with your domain name, using a complex series of letters, numbers and symbols.

• Use two-factor authentication when it’s available.

7. Antivirus and antispyware

To prevent keylogging software from capturing your account logins, usernames, user IDs and passwords, and forwarding the information to unauthorized persons, install antivirus and antispyware software and update it periodically.

8. Register your domain name as a trademark

If, despite your best efforts, your domain name is stolen, you may have to seek legal recourse to recover it if other means fail. However, if the stolen domain name comprises a trademark or service mark that is registered in the name of your company, you will likely have more options for recovering it and preventing further unauthorized use of it, which can make the process easier, faster and less expensive.

To learn more about Data Privacy and CyberSecurity, visit the T&K CyberSecurity Blog.

© 2017 The Texas Lawbook. Content of The Texas Lawbook is controlled and protected by specific licensing agreements with our subscribers and under federal copyright laws. Any distribution of this content without the consent of The Texas Lawbook is prohibited.

If you see any inaccuracy in any article in The Texas Lawbook, please contact us. Our goal is content that is 100% true and accurate. Thank you.

Primary Sidebar

Features

  • My Five Favorite Books: Leigha Simonton (Member at Dykema and Former U.S. Attorney for the Northern District of Texas) - I have a secret hobby that only my close friends know: I advise high-school seniors (and younger students) about college admissions, including helping them create a list of schools that would be good fits for their interests and aspirations as well as their family’s pocketbooks. This unpaid side-gig started years ago, when my oldest daughter began high school and I decided to try to “hack” the college admissions game. I don’t mean that I plotted to get her into a U.S. News top 10 school — no, I defined “winning” as finding a school that would allow her to flourish in college, set her up for success after college (success as defined by her, not me), and be somewhere our family could afford on what was then two government salaries. Here are my Five Favorite Books: College Application Edition. October 15, 2025Leigha Simonton
  • P.S. — HBA’s Days of Service Mobilizes Houston Legal Community to Support 14,000 Residents, Early Giving Underway in El Paso, and More - In this week’s edition of P.S., the Legal Aid of NorthWest Texas is reviving its in-person Builders of Justice Progressive Dinner and Awards Program in McKinney, honoring local advocates for expanding access to justice. In Houston, the Bar Association’s Days of Service engaged about 300 lawyers and benefitted more than 14,000 people through community service projects. Meanwhile, Texas RioGrande Legal Aid is encouraging early donations for El Paso Giving Day to support its wide-ranging civil legal work across 68 counties, and the Association of Corporate Counsel San Antonio makes a donation to the San Antonio Legal Services Association. Rounding out this issue, Bracewell hosted 25 Aldine ISD students for a law career panel in partnership with Momentum Education.  October 10, 2025Krista Torralva

GCs, Lawyers & Firms

  • Midwest Law Firm with Texas Offices Merges with Northeast Firm - Cincinnati-based Frost Brown Todd, which has operations in Dallas and Houston, announced Wednesday that it is merging with the Newark-headquartered law firm Gibbons. The merged firm will be called FBT Gibbons and will have about 800 lawyers in 25 offices across the country.
  • White & Case Adds Energy M&A Dealmaker in Houston
  • Norton Rose Hires Veteran Finance Partner from Winston & Strawn
  • Invitation Homes Selects Former SEC Associate Director as VP of Litigation and Investigations
  • Houston Trial Firm Boosts Associate Salaries
  • SALSA Names New Executive Director
  • New GE Vernova GC of Wind Energy Dionne Hamilton: ‘We’re Working to Make the World a Better Place’
  • Ross & Smith Announces Partnership with Full-Service Maryland Firm
  • Martin Sosland, Candice Carson Join Vartabedian Hester
  • Banks Brings Decades of Experience to Husch Blackwell’s New Biz Dev Leadership Role
More GCs, Lawyers & Firms

Lawyers in the News

Hover right to see full list

Chip Babcock
Chris Bankler
Jamie B. Beaber
David J. Beck
Bill Benitez
Jessica Berkowitz
Brent Bernell
Tyler Bexley
Shawn Blackburn
Michael Blankenship
Jeffrey Brill
Anita Brown
Ian Brown
Stuart Campbell
Jack Chadderdon
Paul Clement
Erin Nealy Cox
Scott Craig
Kevin Crews
Shamus Crosby
Hannah M. Crowe
Geoffrey Culbertson
Sean Cunningham
John Daywalt
Rajiv Dharnidharka
James Ducayet
Brian K. Erickson
Scott Everett
Weiru Fang
Elizabeth Freeman
Tad Freese
Melanie Fry
Geoff Gannaway
Paul Genender
John J. Gilluly III
Rodney Gilstrap
Andrew Gorham
John Greer
Joseph Grinstein
Matthew Haddad
Colleen Haile
Breen Haire
Shahmeer Halepota
Dionne Hamilton
Troy Harder
Rusty Hardin
Michael Hawes
Nathan Hecht
Stephen Hessler
Hillary Holmes
Marc Jaffe
Lauren Jenkins
David Jones
Atma Kabad
Susan Kennedy
David Kinder
Justin King
Allan Kirk
Melanie Koltermann
Doug Kubehl
Joe Laurel
Sang Lee
Steven Lockhart
Arthur Lotz
Barbara Lynn
Mike Lynn
Nora McGuffey
Stephanie McPhail
Mark Melton
Jeri Leigh Miller
Kimberly A. Moore
Mark Moore
Shelby Morgan
Alia Moses
Davis Mosmeyer III
Darren Nicholson
Eamon Nolan
Ivy Nowinski
Holland O’Neil
George Padis
Ian Peck
Jonathan Platt
Chase Proctor
Doug Rayburn
Joel Reese
Kevin Richardson
Andrew Rodheim
Seth Rubinson
Mazin Sbaiti
Ana Sanchez
Vincenzo Santini
Jeffrey Scharfstein
Robert Schroeder III
Scott Seidel
Steven Sexton
Ahmed Sidik
Robert Slovak
Emily Smith
Melissa R. Smith
Jonathon Soler
Robert Soza
Lande Spottswood
Craig Stanfield
Justin Stolte
Josh Teahen
Kelly Tidwell
Linda Tieh
Rafael B. de Toledo
Monica Uddin
Rhett Van Syoc
Rahul Vashi
Gabe Vazquez
Patrick Venter
Sarah Walden
Kandace Walter
Kyle Watson
Mikell Alan West
Noël Wise
Meng Xi

Firms in the News

Hover right to show full list

AZA
Baker Botts
The Bandas Law Firm
Beck Redden
Boies Schiller Flexner
Bracewell
Bradley Arant
Burns Charest
Clement & Murphy
Condon & Forsyth
DLA Piper
Dykema
Foley & Lardner
Gibson Dunn
Gillam & Smith
Haynes Boone
Holland & Knight
Jackson Walker
King & Spalding
Kirkland & Ellis
Latham & Watkins
Lynn Pinker
Mayer Brown
MoloLamken
Pamela Welch PLLC
Patton Tidwell Culbertson
Paul Hastings
Porter Hedges
The Probus Law Firm
Reese Marketos
Rusty Hardin & Associates
Sbaiti & Company
Sidley Austin
Simpson Thacher
Skadden
Squire Patton Boggs
Sullivan & Cromwell
Susman Godfrey
Troutman Pepper Locke
Vinson & Elkins
Weil
Willkie
Winston & Strawn

Footer

Who We Are

  • About Us
  • Our Team
  • Contact Us
  • Submit a News Tip

Stay Connected

  • Sign up for email updates
  • Article Submission Guidelines
  • Premium Subscriber Editorial Calendar

Our Partners

  • The Dallas Morning News
The Texas Lawbook logo

1409 Botham Jean Blvd.
Unit 811
Dallas, TX 75215

214.232.6783

© Copyright 2025 The Texas Lawbook
The content on this website is protected under federal Copyright laws. Any use without the consent of The Texas Lawbook is prohibited.