Subdomain takeover occurs when a DNS record (typically a CNAME) points to an external cloud service (such as GitHub Pages, AWS S3, Heroku, or Zendesk) that has been deleted or deprovisioned without updating the DNS zone. An attacker can claim the abandoned resource name on the provider and take full control of your subdomain.
The high impact of a hijacked subdomain
Because the hijacked subdomain resides on your trusted company domain (e.g., `promo.yourcompany.com`), the consequences are severe:
- Authentication cookie theft: if your session cookies are scoped to `.yourcompany.com`, the attacker's server can read session tokens from visitors.
- Trusted phishing and credential harvesting: attackers can host convincing login pages on your authentic domain, bypassing email spam filters and user suspicion.
- CORS and CSP bypasses: applications that allowlist `*.yourcompany.com` in their CORS or CSP policies will blindly trust the attacker's compromised subdomain.
Continuous monitoring and remediation
Maintain tight DNS lifecycle management: whenever a cloud resource, marketing campaign, or staging environment is torn down, immediately purge its corresponding DNS record. Use BugSnaps and MyRecon to continuously monitor external DNS zones for dangling CNAME pointers.
Never decommission a third-party cloud service without first deleting its DNS record in your domain registrar.