← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Namecheap Account Compromised After Unverified Third Party Gains Access

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Namecheap account password and email were changed by an unverified third party.
  • The third party convinced Namecheap support the domain belonged to their club.
  • The account owner had previously reported an unauthorized password reset attempt.
  • Namecheap's verification process is criticized for lacking proper validation.

Unauthorized Account Access Reported

A long-term Namecheap customer experienced unauthorized access to their account. A new leader of a college club, for which the customer maintained a domain, contacted Namecheap support. This individual successfully convinced Namecheap to change the account's password and associated email address, despite the domain being registered under the customer's personal details.

Prior Warning Ignored

The customer had previously received a password reset email initiated by the new club leader and immediately filed a support ticket with Namecheap, stating they did not initiate the request. Namecheap contacted the customer to verify the support ticket but subsequently allowed the third party to gain control of the account without further verification.

Security Vulnerability Identified

The incident points to a significant vulnerability in Namecheap's account security protocols. The customer noted that Namecheap was able to contact them for verification regarding their support ticket, but failed to apply similar rigorous verification when a third party requested account changes. This suggests that a simple phone call was sufficient to bypass security measures and gain control over an account.

Customer Response and Impact

Following the incident, the customer has begun transferring critical domains away from Namecheap due to concerns over the ease with which a third party could compromise an account. While the underlying issue of domain ownership was resolved between the customer and the club leader, the security lapse by Namecheap remains a concern for the customer.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~39 min · 35 stories · Jul 22

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Primary sources

GitHub HackerNews/API

Reporting from

A Namecheap customer reported that an unverified third party gained access to their account and changed the password and associated email address. This occurred after the third party, a new club leader, convinced Namecheap support that a domain registered to the customer actually belonged to their club, despite the customer having previously alerted Namecheap to an unauthorized password reset attempt. This incident highlights a significant vulnerability in Namecheap's account verification processes, allowing unauthorized access based on a phone call without proper validation.