---
id: "sitting-ducks"
kind: "glossary-term"
title: "Sitting Ducks attack"
language: "en"
category: "Security and abuse"
updated: "2026-10-04T14:01:23Z"
canonical: "https://tldlog.com/glossary/sitting-ducks/"
translations:
  es: "https://tldlog.com/es/glosario/ataque-sitting-ducks/"
  de: "https://tldlog.com/de/glossar/sitting-ducks-angriff/"
  fr: "https://tldlog.com/fr/glossaire/attaque-sitting-ducks/"
  it: "https://tldlog.com/it/glossario/attacco-sitting-ducks/"
  pt-BR: "https://tldlog.com/pt/glossario/ataque-sitting-ducks/"
  ru: "https://tldlog.com/ru/glossariy/ataka-sitting-ducks/"
  zh-Hans: "https://tldlog.com/zh/cihui/sitting-ducks-gongji/"
---

# Sitting Ducks attack

A way to hijack a domain without touching the owner's registrar account. It works when a domain is delegated to a DNS provider where it is not properly set up, known as a lame delegation, and that provider lets someone else claim the name. Researchers at Infoblox and Eclypsium named it in 2024.

## related terms

- [DNS hijacking](https://tldlog.com/glossary/dns-hijacking/)
- [domain hijacking](https://tldlog.com/glossary/domain-hijacking/)
- [name server](https://tldlog.com/glossary/name-server/)
- [delegation (TLD)](https://tldlog.com/glossary/delegation/)
- [subdomain takeover](https://tldlog.com/glossary/subdomain-takeover/)
