Cyber Incident Victim: eNom
Date:
Apr 2015
Location:
United States of America
Summary
A domain registrar experienced a DNS hijacking attack where attackers altered DNS settings for four domains, redirecting traffic to malicious locations for a brief period. The sophisticated attack did not compromise sensitive information, customer accounts, or result in stolen domains. The incident was quickly mitigated, with federal law enforcement notified promptly. The registrar's transparency efforts included informing customers, though affected domains were not disclosed. The attack shares similarities with a separate incident involving a financial institution's DNS vendor breach, which also involved unauthorized DNS modifications leading to fraudulent site redirection, suggesting potential connections between the events.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On May 21, 2015, domain registrar eNom notified customers of a DNS hijacking attack targeting four domains under its management. Attackers altered DNS settings to redirect web traffic from legitimate domains to unauthorized destinations, potentially exposing visitors to malicious content or credential harvesting. CEO Taryn Naidu characterized the incident as a sophisticated attack but emphasized no evidence indicated compromise of customer accounts, stolen domains, or access to sensitive information. The DNS configuration changes affected name server IP address mappings, which translate domain names to their corresponding web server locations. eNom detected the hijacking quickly, mitigating the situation within a short timeframe to limit unauthorized traffic redirection. Federal law enforcement agencies were engaged within hours of discovery, though specific dates of the attack and affected domains were not publicly disclosed. The company's notification letter emphasized transparency regarding the breach while asserting that operational impacts were contained to temporary DNS manipulation.

Investigations confirmed the attackers exclusively manipulated DNS records without penetrating eNom’s account systems or exfiltrating customer data. The St. Louis Federal Reserve had separately reported a DNS hijacking incident on April 25, 2015, involving unauthorized name server modifications through an unnamed DNS vendor later identified as eNom. This temporal proximity and registrar relationship suggested a potential connection between the events, though eNom’s breach notification did not explicitly confirm this linkage. No additional domains beyond the initial four were confirmed as compromised, and normal DNS resolution services were restored following mitigation. The incident highlighted risks associated with DNS infrastructure vulnerabilities but resulted in no verified data loss or persistent system compromise for eNom or its clients.
