The Lenovo.com DNS Hijack: When Lizard Squad Took a Hardware Giant's Front Door
On February 25, 2015, attackers changed Lenovo.com's nameserver and mail routing, sending visitors to a webcam slideshow and exposing some email traffic. Researchers attributed the incident to a Webnic compromise, but Webnic did not publicly confirm their reported exploit chain.
- domains
- security
- dns
- domain-security
On February 25, 2015, the website of the world's largest PC maker pointed at a slideshow of bored teenagers staring into their webcams, scored to a song from High School Musical. Lenovo said traffic to its website had been redirected. Public reporting pointed to changes at its registrar rather than a compromise of Lenovo's web servers.
The attackers changed the domain's nameserver and mail-routing configuration through its registrar. That was enough to redirect Lenovo's front door and expose some mail during the incident window.
This is Domain Mayday EP17: the Lenovo.com DNS hijack. It is a compact demonstration of a lesson many companies miss: registrar and DNS-provider access belong inside the organization's security program. The public record does not establish that Lenovo's production systems or customer database were breached in this incident.
A hardware giant whose domain is its face
By 2015, Lenovo was the world's largest PC manufacturer, shipping more laptops and desktops than anyone on earth. For a company that size, lenovo.com is not a marketing asset. It is the load-bearing center of the entire operation: where customers buy, where support tickets land, where warranty registrations flow, and — crucially — the domain behind every @lenovo.com email address in the company.
When a brand reaches that scale, the domain stops being a website address and becomes infrastructure. Every press release, every retail box, every employee signature, every order confirmation routes through it. Which means whoever controls the domain's DNS controls not just the website, but the truth about where lenovo.com points — for browsers and mail servers alike.
That is the prize Lizard Squad went after. Not the website. The pointer to it.
February 25, 2015: the bizarre redirect

Starting that afternoon, visitors who typed lenovo.com did not reach Lenovo. The site had been replaced with a slideshow of webcam pics of kids sitting at their computer, looking blank and faintly embarrassed, all set to the sounds of "Breaking Free" from High School Musical. The Register described the same scene as a slideshow of webcam photos of a bored-looking youth instead of the company's normal wares.
It was deliberately absurd, and the absurdity was the point. This was not a quiet data theft meant to stay hidden. It was a public humiliation, staged on the most visible URL the company owned.
The attribution was hiding in plain sight. The replacement page's HTML credited its "new and improved rebranded" build to Ryan King and Rory Andrew Godfrey — two names internet sleuths quickly tied to Lizard Squad, the same crew that had spent the prior holiday season knocking the PlayStation Network and Xbox Live offline. The group took credit on Twitter, quoting the High School Musical lyrics back at Lenovo for good measure.
And then it got worse than embarrassing. Because the attackers controlled lenovo.com's DNS, they did not just own the website — they owned the mail. As one outlet put it, the hijack meant it was able to intercept Lenovo email as well, until the redirect was shut off. Lizard Squad later published two messages sent to employees at Lenovo during the window it held control. One of them, with grim comedic timing, referred to a Lenovo Yoga laptop that was "bricked" when a customer tried to run Lenovo's own tool to remove a piece of software called Superfish.
That attacker-posted email fed speculation about motive, but it does not independently establish that the removal tool caused the reported device failure or why Lenovo was targeted.
The Superfish backdrop
To understand why Lenovo specifically, you have to rewind five days.
Superfish was adware that Lenovo had been bundling with some of its computers since September 2014. On its face it was just an ad-injector — software that slipped extra shopping ads into your browser. But the way it worked was catastrophic. To inject ads into encrypted pages, Superfish installed its own root certificate so it could introduce ads even on encrypted pages — in other words, it broke the padlock that protects HTTPS.
Worse, the certificate used the same private key on every machine, and that key was crackable. Any attacker who extracted it could impersonate any HTTPS website to any Lenovo laptop running Superfish. This was not a theoretical flaw. On February 20, 2015, the United States Department of Homeland Security advised uninstalling it and its root certificate.
Lenovo had shipped some consumer notebooks with software that introduced a man-in-the-middle vulnerability. The hijack followed days of public backlash over Superfish, so contemporary reports discussed retaliation as a possible motive. The attackers did not publish evidence that conclusively established their motive, and Lenovo's official statement focused on restoring service and investigating the redirect.
How it happened: reported compromise at the registrar

Lenovo's public statement confirmed the traffic redirect but did not publish the underlying exploit chain. Independent researchers pointed instead to the registrar layer.
Security researchers attributed the hijack to a compromise of Web Commerce Communications — better known as Webnic.cc, a Malaysia-based registrar. As Help Net Security reported, the researchers' account was that the attackers compromised Webnic rather than Lenovo's servers. Webnic told KrebsOnSecurity that it was still investigating and did not publicly confirm the detailed mechanism.
Just two days earlier, Google's Vietnamese domain had been redirected in a similar way. SecurityWeek reported that both incidents followed a Webnic breach. Brian Krebs was more explicit about the attribution: his mechanism came from statements by researchers Ryan King and Rory Godfrey, who said attackers had seized control over Webnic.cc. That account is credible reporting, but it should not be read as a Webnic-confirmed forensic finding.
The mechanics below are the researchers' account as reported by Krebs, not a mechanism confirmed by Webnic or Lenovo:
- The reported way in. The researchers said Lizard Squad used a command-injection vulnerability in Webnic.cc to upload a rootkit, which would have enabled hidden access to registrar systems.
- The reported auth-code exposure. They also said the attackers gained access to Webnic's store of "auth codes", the EPP secrets used to authorize inter-registrar transfers. The Lenovo incident itself was a routing change, not a disclosed domain transfer.
- The redirect. With registrar-level control, they changed lenovo.com's nameserver records. The Register noted the domain's nameserver settings were suspiciously updated today to point at DNS servers belonging to web hosting biz CloudFlare — using Cloudflare to mask the true destination server.
- The mail grab. Crucially, they didn't stop at the website. They changed mail server records allowing them to intercept messages sent to Lenovo addresses. DNS controls more than the
Arecord; it controls theMXrecord too. Owning the domain meant owning the mail.
That last point is the one people forget. A defacement is loud and obvious. Silent email interception is the dangerous half of a DNS hijack — and it falls out of the same single act of changing a record at the registrar.
Response and aftermath
Lenovo moved fast, because there was little else it could do — the fix lived at the registrar, not on its own servers. The company confirmed it had been the victim of a cyber attack whose effect was to redirect traffic from the Lenovo website, and it appeared to have restored complete access to its public website by the evening of Feb. 25. Cloudflare, finding its name used in the redirect chain, cut off the malicious nameservers, which also ended the email interception.
The bigger investigation belonged to Webnic. Researchers attributed two high-profile redirects — Lenovo and Google Vietnam — to its systems within a 48-hour span. Because Webnic did not publicly confirm the reported command-injection and rootkit chain, the incident is best treated as a strong third-party attribution rather than a completed public forensic report.
For Lenovo, the lasting damage was reputational. Coming days after Superfish, the hijack turned a serious security failure into a two-act story: first the company broke trust for its own customers, then it visibly lost control of its own name. The webcam slideshow is what people remembered, but the registrar compromise is what actually mattered.
What this teaches: your registrar is your real perimeter
The uncomfortable lesson of EP17 is that Lenovo did most things right on the parts it controlled, and still got hijacked through the part it didn't.
A few takeaways that generalize far beyond 2015:
- The registrar is in your trust boundary whether you treat it that way or not. You can harden every server you own and still lose the domain at a third party you've probably never security-reviewed. The attacker takes the path of least resistance — and the registrar is often softer than you are.
- DNS control is mail control. A hijack isn't just a defaced homepage. The same record change quietly reroutes email, enabling interception, password resets against your domain, and impersonation. Treat the
MXrecord as a security-critical asset, not plumbing. - Use the right lock for the change you want to stop.
clientTransferProhibitedblocks inter-registrar transfer; it does not block nameserver updates. For high-value domains, ask whether the registrar and registry support update-prohibiting controls such asclientUpdateProhibited,serverUpdateProhibited, or a registry-lock service, and define an authenticated emergency-unlock process. Restrict EPP/auth-code access separately. - Understand the DNSSEC boundary. DNSSEC lets validating resolvers detect answers that do not match the signed delegation. It does not prevent an authorized registrar or registry path from changing delegation data, and a bad change may turn a hijack into a validation failure and outage rather than preserve availability. Monitor DNS and DNSSEC state together.
- Monitor your own DNS for drift. Lenovo's nameservers changing to an unexpected provider was the tell. Continuous monitoring of NS and MX records turns "we found out when customers saw a slideshow" into "we got paged when the record changed."
The shared theme: domain control is a security domain of its own, and most companies have outsourced it to a vendor that never appears in their threat model.
The Namefi angle

The Lenovo hijack was a DNS-administration incident: someone changed nameserver and mail-routing state through the registrar path. That state is separate from domain ownership. An ownership record — conventional or tokenized — does not by itself stop a compromised registrar or registry from changing NS, MX, DS, or other delegation data.
Namefi provides an on-chain ownership and transfer layer for tokenized domains. It can make that ownership state independently auditable, but it does not make registrar or DNS-provider changes automatically appear on-chain, and it would not by itself have prevented the Lenovo redirect. The relevant defenses remain hardened registrar access, update-prohibiting registry controls where available, DNS/DNSSEC monitoring, and an incident-recovery process that spans every provider in the resolution path.
Sources and further reading
- Lenovo — Statement on Cyber Attack
- Krebs on Security — Webnic Registrar Blamed for Hijack of Lenovo, Google Domains
- The Register — Oh No, Lenovo! Lizard Squad on the attack, flashes swiped emails
- Engadget — Lenovo's website hijacked, apparently by Lizard Squad
- SecurityWeek — Lizard Squad Hijacks Lenovo Website, Emails
- Help Net Security — Lenovo.com hijacking made possible by compromise of Webnic registrar
- BankInfoSecurity — Lenovo Website Hijacked
- IT Security Guru — Lizard Squad domain hijack gives control of Google Vietnam and Lenovo website
- CNBC — Lenovo website breached, hacker group Lizard Squad claims responsibility
- We Live Security (ESET) — Lenovo website hacked, Lizard Squad claims responsibility
- Computing — Lenovo website hijacked by Lizard Squad after Superfish debacle
- Wikipedia — Superfish
- CISA — Lenovo Superfish Adware Vulnerable to HTTPS Spoofing
Contributors
Aileen Wright is a student in her twenties living in New York City, where the distance between a museum wall and a library reading room is a short walk and a long afternoon. She came to name writing through art and history — the way a single portrait, coin, or manuscript margin can carry a name across centuries and change its meaning on the way.
Most weeks you can find her in Central Park with a paperback, or in the quiet of a public reading room chasing down where a name actually comes from rather than what a name-list says it means. She is also teaching herself to code, which has made her oddly precise about spelling, sorting, and the small details that decide whether a name ages well.
For Namefi she writes about the history and culture behind domain names, the stories brands carry as they rename, and the difference between a good story and a verified source.
Victor Zhou is a technology founder and standards editor focused on digital identity and trust. He founded Namefi, edits Ethereum Improvement Proposals, and previously led smart-contract architecture work at Google Labs.
His work sits at the intersection of naming, ownership, and the systems people use to establish identity online. That perspective makes him especially interested in the way names move between personal meaning, public recognition, and digital infrastructure.
For Namefi, Victor edits and writes about domains as durable digital identity: how names become ownable onchain assets, how tokenization changes custody and trust, and what naming can learn from the systems people use to establish identity online.
Related guides
- The $12 Minute: When Google Domains Accepted a Google.com OrderIn September 2015, Google Domains accepted a $12 order for google.com from former employee Sanmay Ved, then canceled it about a minute later. What the incident proves, what remains uncertain, and why the $6,006.13 bounty still matters for domain security.
- Domain Mayday EP03: The 2020 Twitter Bitcoin Account TakeoverOn July 15, 2020, attackers phoned their way into Twitter, hijacked the verified accounts of Obama, Biden, Musk, Gates, Apple and Uber, and ran a Bitcoin doubling scam — netting about $118,000. A deep-dive on how control of an online identity was stolen, and what it teaches about owning a name.
- Domain Mayday EP05: The 2024 Squarespace DeFi Domain Mass-HijackIn July 2024, a registrar migration from Google Domains to Squarespace turned weak default authentication into a mass attack surface. Attackers hijacked the domains of crypto and DeFi projects — Compound Finance, Celer Network, Pendle, Unstoppable Domains — and pointed them at wallet-drainer phishing sites. Here is how a "seamless" migration created hundreds of unlocked front doors, and what it teaches about registrar security and MFA.
- The BadgerDAO Front-End Attack: $120M Drained Through One Injected ScriptIn December 2021, attackers compromised BadgerDAO's Cloudflare account and injected one malicious script into its website front-end. The audited smart contracts were never touched — yet ~$120M walked out the door through wallet approvals users signed without knowing. A deep-dive on why the website is part of your security surface.