Data Theft Without a Breach. The Price of a Forgotten Domain.
An expired domain is a massive cybersecurity risk. See how attackers buy abandoned domains to intercept emails and reset passwords without hacking.
Two firms merge.
The old name appears on the letterhead one last time, then disappears.
A year later someone registers the abandoned domain for the price of a coffee.
The firm’s mail starts arriving in a stranger’s inbox.
No one hacked anything.
Whoever owns the domain owns the mail.
A domain is the thing email runs on.
Its MX record tells every mail server on the internet where to deliver messages addressed to that domain.
Register the lapsed name, point the MX record at your own server, switch on a catch-all, and every message sent to anyone at the old address lands in your inbox. No password is involved.
You own the namespace, so you own everything addressed to it.
Then it gets worse.
The people who worked at the old firm used those addresses to sign up for things — Microsoft 365, Google Workspace, LinkedIn, the court filing portal, the practice-management software.
The accounts are still live.
Many of those people have since moved to new firms. And every one of those services has a button that says “forgot password.”
The reset link goes to whoever owns the domain.
An attacker does not even have to go looking.
Many TLD registries publish expiring names in daily drop lists. Cross-reference them against any week’s merger announcements, and the work is done for you.
This is most dangerous at the precise moment a domain gets dropped: a merger, an acquisition, a rebrand, a wind-up.
That is when the old name becomes nobody’s job to renew. In 2017 there were 102 mergers among top-tier US law firms alone; at the small-practice level the number runs into the thousands.
The exposure outlives the business.
The mail keeps arriving — from clients, banks, opposing counsel — to a firm that no longer exists. The outside world keeps trying to reach the former staff through the address they left behind.
Gabor Szathmari, an Australia-based security researcher, proved it.
Over three months in 2018, he re-registered six abandoned domains, several of them formerly belonging to Australian law firms, and pointed their mail at himself.
Without hacking anything, he received confidential client documents, bank correspondence, and invoices from other firms.
He showed he could reset the passwords on the firms’ Microsoft 365 and Google accounts and on former staff’s LinkedIn and Facebook profiles — then deliberately stopped short of logging in or taking any account over. (On one Microsoft 365 account, two-factor authentication blocked the reset.)
From past public data breaches, he recovered the real passwords of roughly thirty legal professionals.
The systems a company uses every day get a security budget — the firewall, the multi-factor prompts, the staff training.
The domain it stopped using gets a renewal notice nobody opens.
That unpaid fifteen dollars is the key to everything the other line items were bought to protect.
Magyar változat: [zona.hu/adatlopas-egyszeru-ujraregisztracioval-egy-elfelejtett-domain-ara/]


