Quite simple really. Imagine you buy a domain (e.g. foo.com) and park it on some popular registrar. Many of those create a few "CNAME" DNS records like ftp.foo.com, mail.foo.com, etc. by default. Then you decide to use Shopify with this domain you bought, so you modify its "A" DNS record to point to Shopify's IP address. Boom, you're now susceptible to this "attack" -- >anyone< can go ahead and register a Shopify account and attach one of your dangling subdomains to it!