Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Squarespace Domain Hijacks Enabled by Email Address Exploit ...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
1,017
Company Posts That Month
16
Language
English
Hacker News Points
-
Post removed?
No
Summary

In July 2023, after Google sold its Google Domains accounts to Squarespace for an estimated $180 million, over a dozen domains were hijacked due to security vulnerabilities associated with the migration process. The transfer resulted in weak security defaults, as Squarespace did not migrate Multi-Factor Authentication (MFA) details, allowing threat actors to gain access through email addresses tied to existing domains without email verification for new accounts. This issue affected not only the domains but also compromised associated Google Workspace accounts, leading to unauthorized actions such as domain transfers, DNS changes, and email spoofing. Despite Squarespace implementing patches to address these vulnerabilities, security researchers criticized the acquisition's oversight, urging users to consider alternative registrars and reinforcing the importance of robust security measures like enabling 2FA and using unique passwords to safeguard against unauthorized access.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.