DNS Hijacking
An attack where DNS queries are redirected to malicious servers, sending users to fake websites that harvest credentials even when they type the correct URL.
DNS hijacking (also called DNS redirection) occurs when an attacker modifies DNS settings (either on a router, at the ISP level, or through malware) to redirect users to fraudulent websites. The user types the correct URL, but the DNS response points to an attacker-controlled server hosting a convincing replica.
This is particularly dangerous because the URL in the address bar appears correct, making it harder for users to detect the fraud. The fake site captures credentials, which the attacker can then use to access the real service.
Defenses include DNSSEC (DNS Security Extensions), monitoring DNS configurations, using DNS-over-HTTPS (DoH), and relying on password managers that match credentials to exact domains rather than visual appearance of URLs.
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide