Stopping Domain Name Theft featured image

Stopping Domain Name Theft

by Eric Misterovich

Partner

Internet Lawyer

Not many people question the value of domain names. Multi-million dollar domain names are nothing new. But as we grow more comfortable understanding the true value of domain names, the steps users take to secure those domain names is severally lacking.

This can lead to the stunning realization that a domain name has been transferred out of your possession. You didn’t feel it, you didn’t see it, and there is next to no evidence readily available to figure what happened. You are a victim of domain name theft. To read an example of this, check our the HuffPo article on the theft of MLA.com

15721594607_005d7966c2_z Over the past year, we have noticed a considerable rise in instances of domain theft, often emanating from overseas hackers. Owners of valuable domain portfolios need to pay attention to this trend and take the steps necessary to reduce the risk of losing valuable property. It’s time to treat your domains like the valuables in your home.

 

Only Use Registrars That Offer Two-Factor Authentication

The best advice to preventing domain theft is using a registrar that requires two-factor authentication (2FA). As we previously discussed, registrars that do not use 2FA could be opening themselves up to liability. However, you should avoid the problem all together by ensuring your registrar requires two forms of authentication to alter a domain’s settings. This is especially important given the phishing scams arising from ICANN’s relatively new WHOIS accuracy program, explained below.

Beware of Phishing Attacks

Phishing is generally referred to the attempt to acquire information by masquerading as a trustworthy source.

ICANN’s “WHOIS Accuracy Data Specification” requirement, while well intended, has opened the door for these types of attacks. This requirement states that within 15 days after changes to a WHOIS record, the registrar must verify the changes. The registrar will attempt to verify this change by sending a confirmation email.

This gives enterprising hackers a wonderful option. If a hacker can determine that a site was recently updated, it can send a fake-verification email that could lead to any number of bad results.

If you have recently transferred a domain or changed a WHOIS record, take great care in responding to the registrar verification emails.

Use Private WHOIS Listings

Many times hackers gain access to a domain owner’s email account and use that to access the domain owner’s registrar account. Once inside the registrar account, the hacker can easily transfer out the domains to another registrar.

A simple way to prevent this is to prevent the public from seeing the email addresses associated with your domains by using a private WHOIS listing. Many domain privacy services exist and for a small fee, you can keep your information from prying eyes.

Revision Legal’s Internet attorneys help people recover stolen domains. If you find yourself in this position, contact us today.

 

Extra, Extra!
Recent Posts

Does the AI-Copyright Legal Fight Represent a National Security Threat?

Does the AI-Copyright Legal Fight Represent a National Security Threat?

Copyright

The holders of copyrights for newspapers, magazines, books, and other publications are involved in numerous legal battles with owners of AI modules over alleged copyright infringement. The plaintiff copyright owners claim that the AI large language modules have been trained on huge quantities of copyrighted materials without permission and — most importantly — without payment. […]

Read more about Does the AI-Copyright Legal Fight Represent a National Security Threat?

How Does Buy-Sell Insurance Work For An Owners’ Agreement?

How Does Buy-Sell Insurance Work For An Owners’ Agreement?

Corporate

The owners of most small, closely-held businesses negotiate and sign some form of an “Owner’s Agreement.” An important part of such Agreements is the “Buy-Sell” provisions. These are often some of the most difficult to negotiate. The gist of the buy-sell part of the Owners’ Agreement is to establish the rules for what happens if […]

Read more about How Does Buy-Sell Insurance Work For An Owners’ Agreement?

Status on Social Media Moderation Statutes and Cases

Status on Social Media Moderation Statutes and Cases

Internet Law

Social media content moderation by technology platforms was one of the “hot” legal topics in 2023-2024. Three States — California, Texas, and Florida — passed different statutes to either require more content moderation (California) or to limit such moderation (Texas and Florida). All the statutes, in one way or another, demanded more transparency and information […]

Read more about Status on Social Media Moderation Statutes and Cases

Put Revision Legal on your side