In the case of website like bitcoin.org some people noticed suspicious things on website and reported. Later Andrew Chow did some analysis and it seems DNS records were changed for the domain: https://github.com/bitcoin-dot-org/Bitcoin.org/issues/3743#issuecomment-926189200
How would users know if one of the domains used by DNS seeds in Bitcoin Core will be hacked and resolve to malicious nodes? What will be the impact of this until owner of domain knows about it if lasts for few hours?
peers.dat
). A node checks 3 seeds at a time, so it would require coordination. For new nodes it takes a few hours just to sync the blockchain.