In June 2023, Squarespace acquired all domain registrations and related customer accounts from Google Domains, prompting a migration of domains. Recently, attackers exploited a vulnerability in Squarespace, hijacking domains hosted on the platform. Users who were formerly on Google Domains are advised to immediately set up two-factor authentication (2FA) for their Squarespace accounts. Additionally, it is recommended to consider moving high-value domains to more secure registrars like Cloudflare or AWS. Users should log into Squarespace and enable 2FA, and if affected, join a collaborative war room by pinging seal_911_bot on Telegram for further assistance. Some users reported issues with password resets.
Our domain has been subject to the recent attacks. Please contact us via DM on X ASAP. @squarespace @SquarespaceHelp
Post Mortem For context - Squarespace purchased all domain registrations and related customer accounts from Google Domains in June 2023, which forced the migration of domains. Recently, attackers exploited a vulnerability in Squarespace, hijacking domains hosted on their… https://t.co/0lgcvzss2r
IF YOU WERE A GOOGLE DOMAINS USER: log into squarespace and enable 2fa ASAP, then consider using a better registrar IF YOUR DOMAIN WAS AFFECTED BY SQUARESPACE: please make sure you have someone in the collaborative warroom. ping seal_911_bot on telegram to get access https://t.co/seqVCASWTJ