Tell HN: Namecheap gave my account to an unverified third party
Posted by Thrashed 1 day ago
I’ve been a NameCheap customer for 13 years. I’ve also helped out an old college club paying for a .com they use (that is registered to me under my name, address, and phone number). During a recent leadership transition, the incoming club lead wanted to make changes to the DNS and didn’t know to contact me. They figured out the domain name was parked at NameCheap, so they initiated a password reset using the domain name. I got a password reset email and immediately filed a NameCheap support ticket saying “I did not initiate this”. They called me to verify I was the one who filed the ticket, and then followed up with a canned email with tips like check your anti-virus.
The incoming club leader was persistent though, and called NameCheap support. He convinced them the domain registered in my name and address really belonged to his club, and with no verification or validation whatsoever, NameCheap changed my password, and changed the email address associated with my account. All because someone simply asked nicely on a phone call.
Meanwhile in the background, someone advised the new club leader who I was and we were able to connect and get things transferred over. Ultimately I was happy to give them access or even ownership if they wanted (student club turnover being what it is, it’s likely a domain doesn’t get renewed and gets gobbled up by a squatter, which is why I was keeping it current for them).
But NameCheap had no way of knowing any of this. As far as NameCheap was aware, this was a personal account of mine. They demonstrated they were perfectly able to pick up a phone and call me (to verify my initial support ticket) but when someone calls them and says “but I really want access to that account” they don’t bother?
I’d hesitate to even call this social engineering. It’s clearly a massive vulnerability. I’ve already moved a dozen of my most critical domains out of NameCheap after seeing just how easy it is for a third party to completely take over a NameCheap account: just ask nicely.
Comments
Comment by pilingual 1 day ago
It would be nice to have a nonprofit registrar so jumping every few years isn't necessary.
Comment by davnicwil 1 day ago
This makes total sense to me. I'm not saying it solves all problems but it eliminates so many of them, including a meta problem: the risk of new classes of problems being unexpectedly introduced (by say a private equity acquisition or similar).
If domains themselves are the profit center, you are likely in trouble if there's really any incentive for them to make incremental revenue in such a competitive market. Doing 'the right thing' just of course will not factor in if there's really no reputation at stake.
Comment by jasongill 1 day ago
Cloudflare, for example, removed the ability to change the nameservers for all domains registered with them.
Google got tired of being in the business and sold it to Squarespace.
Being a domain registrar is a total PITA and is not for the faint of heart, so it's the sort of thing that any business that takes it on as a non-core function will eventually tire of.
Comment by duskwuff 1 day ago
Cloudflare never offered that ability. From the time they started offering domain registrations, it was always with the caveat that the nameservers would be fixed to Cloudflare's.
Comment by jasongill 1 day ago
Comment by jurgenburgen 20 hours ago
Comment by ccamrobertson 1 day ago
When domains are not the profit center the company might just arbitrarily turn them off as a feature.
Comment by crossroadsguy 23 hours ago
Comment by danaris 20 hours ago
Comment by crossroadsguy 16 hours ago
Comment by apothegm 15 hours ago
Comment by ajb 1 day ago
There's a certain threshold above which you want to use the "law firm with in-house domain registry" type. I think the threshold is pretty high though, definitely "call us for a quote" territory. But you will notice that big companies like Amazon and Google that have their own registry, don't use it for their critical domains - such as Google.com or Amazon.com.
Comment by crossroadsguy 23 hours ago
Comment by AussieWog93 1 day ago
They're not necessarily better or worse than any other provider (I'm assuming support is good and local but I've never needed it), but they're based in Melbourne - so if push comes to shove I can physically go over there and speak with them directly.
Same thing with my payment provider, after a Stripe snafu.
Comment by Sabinus 1 day ago
Comment by tredre3 1 day ago
Namecheap's cavalier attitude long predate private equity, let's stop blaming the evil financiers for everything. I'm sure it's going even further downhill from here because of it, but what happened to OP happened to others before as well and is par for the course when being a namecheap customer.
Comment by happytoexplain 1 day ago
I respectfully disagree with this generalization, considering how often they deserve blame in practice.
Comment by sitzkrieg 23 hours ago
Comment by crossroadsguy 23 hours ago
Comment by crabmusket 1 day ago
Comment by terribleperson 1 day ago
Comment by deadalus 1 day ago
Comment by cube00 1 day ago
I'm not expecting something for nothing, we all need to eat. I'm happy to stay within any limits or even have no free tier at all.
I just don't want the fear of waking up to a sales email one morning demanding I suddenly fork out more then I earn in a year off the project for an enterprise plan because I've exceeded their undisclosed thresholds.
Comment by ElijahLynn 1 day ago
Comment by kevindamm 1 day ago
I'm a happy user of Cloudflare, but if you're using it for domain registration and hosting infrastructure, you need to see it as a single point of failure. Any account issues and you won't be able to point your domain to an alternate host while you work things out. Any service outage in CF systems will similarly lock you out of routing around the failure. It's better to have DNS off of cloudflare if they're handling your hosting services also. Or host elsewhere and only handle domains on cloudflare. Their domain pricing doesn't add any costs over the base registrar cost, so the latter is a reasonable option.
Comment by cube00 1 day ago
You could argue in that case it was a gambling site and it will never happen to you because you're not in a high risk category.
The scary thing for me is nowhere in their initial communications did they explain the issue they just demanded $120k upfront (refusing monthly billing).
The CEO who is usually active on HN didn't show up to give their side either, there's no way they couldn't have been aware of a 1044 upvoted post which also went viral elsewhere https://news.ycombinator.com/item?id=40481979
Comment by 0x3f 1 day ago
Comment by Imagenuity 19 hours ago
Comment by kibwen 1 day ago
Comment by dabber 10 hours ago
Comment by joshuamcginnis 1 day ago
Comment by wrs 1 day ago
Comment by joecool1029 20 hours ago
Comment by punk_ihaq 1 day ago
Comment by kilroy123 1 day ago
Comment by progbits 19 hours ago
No registrar needed, they are useless middlemen anyway.
Comment by Biganon 19 hours ago
Comment by OutOfHere 1 day ago
The latter also supports crypto domains which have no chance of a takeover except by government order, although crypto domains require the client to install a browser extension or other software to resolve. The good thing about crypto domains is that there should be no renewal fee, although there will be a fee to update the record.
Comment by iamnothere 1 day ago
Comment by deejaaymac 1 day ago
Comment by viccis 1 day ago
Comment by Adachi91 1 day ago
Comment by happytoexplain 1 day ago
Edit: Apparently they were bought by private equity just weeks before I noticed something was wrong. Not a coincidence, I'm sure. We need to legally destroy private equity takeovers. They are pure evil and nothing but a negative force, at least in the USA.
Comment by rickydroll 1 day ago
No wonder people are leaving tech to go be goat farmers.
Comment by NetOpWibby 1 day ago
Comment by js2 1 day ago
I don't have a crystal ball, but NearlyFreeSpeech was recommended to me in 2010 and I've been using it since 2012. I don't think it's changed at all in that time.
Comment by acidburnNSA 1 day ago
https://faq.nearlyfreespeech.net/q/difftos
Comment by happytoexplain 1 day ago
Comment by chrismarlow9 1 day ago
Comment by em-bee 1 day ago
Comment by happytoexplain 1 day ago
Comment by dgudkov 1 day ago
Comment by happytoexplain 14 hours ago
Comment by dgudkov 9 hours ago
Comment by fsuts 20 hours ago
Namecheap is not even cheap for names anymore, their renewal prices made me transfer elsewhere
Comment by ryandrake 1 day ago
I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely!
Comment by nkrisc 1 day ago
So, keep it hypothetical.
Comment by arendtio 19 hours ago
At least corporations seem to work like that. Not following the law seems completely okay as long as the fine is not X% of their annual turnover.
Comment by paxys 1 day ago
Comment by nkrisc 14 hours ago
Comment by jacobgkau 1 day ago
Comment by geuis 1 day ago
Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.
The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset.
This clearly isn't an answer for NC's customer support personnel and company policies.
But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence.
Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted.
Comment by Thrashed 1 day ago
I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.
Comment by geuis 1 day ago
Comment by eviks 1 day ago
Comment by blcArmadillo 1 day ago
Comment by Thrashed 1 day ago
I attempted to login after support changed the password, but prior to the club president connecting with me. So I filed a support ticket that my password stopped working, and to NameCheap's credit they locked the account shortly thereafter. I worked with support later to regain access.
I don't know for sure if the club president was able to successfully auth with the new password before NC locked the account at my request. To be completely transparent, keeping this domain on my personal account was a legacy arrangement that probably should have been handed off sooner. Student club turnover being what it is, I was just renewing it so it wouldn't get squatted. We are fully transferring ownership to them now so there's no friction.
It's fair to criticize this arrangement as messy. Regardless, NC shouldn't have simply handed over the account to an unverified phone caller.
Comment by system2 1 day ago
Comment by throwaway219450 1 day ago
Comment by paxys 1 day ago
Comment by Thrashed 1 day ago
Comment by paxys 1 day ago
Comment by Thrashed 1 day ago
Comment by vel0city 1 day ago
Comment by john_strinlai 1 day ago
Comment by 0x3f 1 day ago
Comment by john_strinlai 1 day ago
Comment by 0x3f 7 hours ago
> He convinced them the domain registered in my name and address really belonged to his club
Convinced how? Often such things are via "knowing things" about the account holder.
Comment by john_strinlai 7 hours ago
and we can be certain that domain privacy wouldn't have helped in this case (because it didn't).
https://news.ycombinator.com/item?id=49028611
>Convinced how? Often such things are via "knowing things" about the account holder.
i have some experience with social engineering attacks (former infosec turned teacher) and it was probably a combination of:
- caller confidence that they were the club owner/manager (because they were)
- offering/sending club-specific information that matched information on the site (flyers, pamphlets, etc.)
- "call the number on the website and i will answer it"
- an official college website page that had the caller listed as an owner/manager of the club
- some poor 20-something year old working in a hellish, windowless tier 1 tech support centerComment by turpentine 21 hours ago
Comment by fsuts 20 hours ago
Many/most domain registrars now give free domain privacy, so that’s not a reason to stay with namecheap.
Namecheap renewal rates are also higher than many others so surprises you have stayed and paid above market rates
Comment by palmotea 22 hours ago
That's not exactly true. IIRC, it's not allowed for .us domains.
Comment by tredre3 1 day ago
Comment by happytoexplain 1 day ago
Comment by dalmo3 1 day ago
Had an account where I managed multiple clients. One of the clients had their "IT guy" contact the registrar for a DNS change. The registrar promptly gave the guy full access to my account, changing the password and locking me out in the process.
As soon as I regained access I moved everything off there.
Comment by sixtyj 1 day ago
This is unacceptable and such companies should change their policy or be out of business.
Comment by ivanmontillam 1 day ago
Comment by rmunn 1 day ago
Comment by preg_match 21 hours ago
If the telecos can figure it out, anyone can. Yes it took them way too long, but those attack vectors are essentially dead now.
Comment by addaon 1 day ago
Comment by Retr0id 1 day ago
Comment by jolan 1 day ago
Comment by appcustodian2 1 day ago
Comment by fsuts 20 hours ago
Comment by The_Blade 1 day ago
Comment by prmph 1 day ago
My experience was kind of opposite, but still bad nonetheless. I lost domains I had with them simply because I lost the phone I used for 2FA. After several calls to them, they requested some info. I supplied all they wanted, but it took them more than a year to get back to me, by which time I had lost all interest in maintaining domains with them.
Luckily these were not critical domains; I had bought them in anticipation of building a business on them.
I am moving my domains to CloudFlare.
Comment by petecooper 1 day ago
Comment by richardchilders 1 day ago
But then when one attempts to pay for a domain, after one has already provided all of one's credit card information to Namecheap ... Namecheap up and refers its customers to something called Link, which forces Namecheap's customers to create an account and become Link's customers - providing all that confidential credit card information, all over - leaving the customer wondering why Namecheap collected it and what they are going to do with it.
Link forces you to authenticate via SMS so that they know where you are.
This all happened less than 24 hours ago and I was already getting ready to put domain service shopping on my list of things to do but I'm glad to see I'm not the only one.
I nominate Paul Vixie as a possible candidate for CTO or even CEO of a hypothetical nonprofit DNS domain service.
More info: uggcf://fnynanir-ehalba.bet/ureovr.ugzy
Comment by Walf 1 day ago
https://stripe.com/payments/link
If you've bought anything online recently, especially if it's not obvious who's collecting the payment details or it looks like first party on the checkout page, you've probably used Stripe.
Comment by ryandrake 1 day ago
Imagine going to a grocery store and when you want to buy your pack of soda and chips, they tell you: Woah there, pardner! You need an account with MyPaymentProvider before you pay for those groceries! Oh, and you'll need to set up a password and give them your mobile number...
Comment by Walf 1 day ago
Comment by Cider9986 20 hours ago
Comment by assimpleaspossi 1 day ago
Comment by paxys 1 day ago
The call center employee making third world minimum wage doesn’t give a shit who the real owner of the domain is. They want to end the call quickly and get 5 stars from the customer on the feedback form.
I have made it a point to move off services that force SMS-based 2fa for this exact reason. Recently even changed banks because of this.
Comment by preg_match 21 hours ago
For example, try to social engineer a sim swap attack or number port attack with sim lock and port lock turned on. Won’t work. These attacks were super common just 5 years ago, now they’re effectively dead in the US.
You have to technically make sure the customer service people can’t break security. If you give them the keys, you’re cooked. So put the keys in a vault and then cover the vault in spikes and a 5 day timer.
Comment by Georgelemental 1 day ago
Comment by ethin 1 day ago
Comment by mook 1 day ago
Comment by ethin 20 hours ago
Comment by thegrim33 1 day ago
Comment by n8n_and_coffee 1 day ago
Was your domain in 'locked' status, preventing transfers etc?
Comment by Thrashed 1 day ago
I also moved from Godaddy to NC. For me it was 2013 when GoDaddy supported SOPA.
Comment by system2 1 day ago
Comment by bel8 1 day ago
And recently from NameCheap to Cloudflare once I heard NameCheap changed owners.
So far, so good. If Cloudflare messes up my domains, of all things, I might as well quit tech and become a farmer.
Comment by kcartlidge 10 hours ago
Comment by dvdyzag 1 day ago
Previous discussion from 2022: https://news.ycombinator.com/item?id=32638028
Something about a bounty, the original source is down.
Comment by Georgelemental 1 day ago
Comment by velcrohn 11 hours ago
After Hamas started a war, Israel provided food, power, water, fuel, and medicine with intermittent interruptions. They had ceasefires to provide vaccines for children. Israel warned civilians of imminent attacks, and generally gave them time to move. That rarely happens in a war, never mind a genocide.
It is absolutely true that tens of thousands of civilians were killed, although it is difficult to quantify because Hamas soldiers do not wear uniforms and has 100% of its military capabilities around and below hospitals, mosques, schools, and apartments. Also, Gazan authorities have never distinguished military and civilian casualties in their reporting. And despite having the world's largest bomb shelter, i.e. 500 km of tunnels, Hamas did not allow a single civilian into them during the war.
But stipulating tens of thousands of civilian deaths during an intense urban fighting, there is a name for that. The name for that is "war". Genocide is an entirely different phenomenon. You seem to conflate the two.
Comment by Georgelemental 8 hours ago
(In the interest of keeping things on topic for HN, I won't respond to your other points)
Comment by h0mie 1 day ago
Comment by newsomix9xl 22 hours ago
It may not be some Mitnick level impersonation of a Senior VP on vacation needing an urgent change kinda trick but the point of S.E. was that it played on the human element and namely cooperation of same.
How it was obtained was not strictly defined AFAIK.
Comment by hmokiguess 1 day ago
Comment by jacobgkau 1 day ago
I kept a couple of domains on them for a while simply because their prices for some exotic TLD's were significantly lower than my previous go-to of Hover, but now Porkbun's got them beat on everything I use, anyway, so I'd transferred the last of them out over the past year or so.
Comment by slig 1 day ago
Comment by bellowsgulch 1 day ago
Comment by xyst 1 day ago
> September 2025, CVC Capital Partners acquired a majority stake in Namecheap for an undisclosed amount, valuing the company at $1.5 billion.[3][4] Kirkendall stepped down as CEO on December 16, 2025
But prior to this they have had many incidents. Switched all domains to porkbun a few years ago
Comment by superkuh 1 day ago
They locked my account so I couldn't log in. To be clear, my whois information was fullly legally compliant, and I was happy to also update my namecheap profile, but when I sent them an email they didn't get back to with an response email until there was just an hour left.
Things had been going down hill slowly and lots of my peers have already moved on to porkbun, etc, but I think now things are going downhill quite fast. I did manage to save my account (and so domains) but now I will be moving to a new registrar.
Comment by iAMkenough 1 day ago
What if their email got caught in a spam filter? What if you only check that inbox a few times a week or after business hours?
I'll be moving my personal domains after doing some research.
Comment by ramgine 1 day ago
Comment by jddj 1 day ago
I think I have one domain left with them. I haven't received anything yet, but it's a good reminder to move on.
Comment by ethin 1 day ago
And yet companies do it all the time. Which is hilarious because they also will happily tell you to beware of phishing and scams, but they do the exact same things a phisher/scammer would do
Comment by DANmode 1 day ago
Did they mention what prompted this?
Are you aware of anything?
Comment by userbinator 1 day ago
Comment by happytoexplain 1 day ago
I.e shilling skepticism is not rational in this case.
Comment by userbinator 1 day ago
Shilling has moved on from being 100% positivity, precisely because it's too obvious otherwise.
Comment by squigz 22 hours ago
I would have expected at least some responses pointing out that this sounds far too bad to be true, and asking what parts of the story are we missing, as has happened when other stories like this show up.
Comment by captn3m0 1 day ago
tl;dr: Namecheap configured Domain Privacy on my domain, which isn't allowed by my Registry (.in), and then suspended my domain coz the whois info was redacted.
I know a few other people that were impacted.
Comment by sandeepkd 1 day ago
It can be called social engineering, however one can also put it in category of account recovery by verifying content control on the domain.
The part where it gets hairy is if your credit card was associated with the account, thats probably a recipe for disaster?
Comment by maxgashkov 1 day ago
Comment by sandeepkd 1 day ago
Comment by maxgashkov 1 day ago
There are no comparable _technical_ proof-of-registration methods because all of them would require actual access to registrar control panel and be outright silly ('point the domain to a random nameserver').
So no, proper registrars never use webserver control as means to prove identity or ownership.
Comment by sandeepkd 23 hours ago
Its digression from the original topic, still, it goes way far than that, these certificates are signed by a CA that the client devices trusts by the virtue of root certificates installed on the device. If I can some how obtain the SSL/TLS certificate for google then thats a very big deal.
Comment by maxgashkov 23 hours ago
But if you somehow managed to do that, no one in the right mind would argue that you're free to undelegate the domain or point it to a NS you control.
Comment by sandeepkd 1 day ago
Comment by MetroWind 9 hours ago
Comment by system2 1 day ago
Comment by happytoexplain 1 day ago
Comment by jacobgkau 1 day ago
Comment by assimpleaspossi 1 day ago
Comment by slig 1 day ago
Comment by assimpleaspossi 1 day ago
Comment by system2 21 hours ago
Comment by OutOfHere 1 day ago
Comment by mook 1 day ago
Comment by john_strinlai 1 day ago
Comment by phendrenad2 1 day ago
Comment by slig 1 day ago
Comment by terminalbraid 1 day ago
Comment by bellowsgulch 1 day ago
Comment by bschmidt2000 1 day ago
Comment by luciana1u 1 day ago
Comment by ButlerianJihad 1 day ago
And the legitimate leadership of the college-affiliated club was able to prove to NameCheap that they had a right to the domain name, as it was (not a right to your account, but a right to their club's name on the Internet). And NameCheap cooperated in turning over control to those with legitimate rights to it, rather than whoever's credit card was on the last payment?
Am I in the ballpark here so far? Perhaps NameCheap did have ways of knowing who the rightful owner was, and who you are not--especially if it was a personal account, not a "college affiliated" or "faculty" account!
In your headline, you call the club leadership "an unverified third party" but the college, and the club, and its leadership are, in fact, a first party to this domain and its transactions, while you are the third party, and you also have no idea what verification steps were taken by NameCheap on behalf of the rightful owners, the college, the leadership, or their personal identities. You have no idea about what they did with that.
It's not your domain, and you're complaining about losing something that was never yours to begin with. So you helped pay for it. That was a mistake. The way you pay for club assets: your club has a treasurer, and your club has a "purse" or club account, and your club writes the checks. You wanna pay for something, make a donation to your club and/or college.
Thankfully, it looks like the mistakes have now been rectified.
Comment by kstrauser 22 hours ago
I could make pretty convincing letterhead "proving" that I own "Google Foods", but that doesn't mean a registrar should give me google.com. The correct process if I want to assert that is to sue for ownership and prove to a court that I'm the rightful owner, and to get an order compelling the registrar to transfer it to me. And if I can't, then Google gets to keep it. This is the only possible sane way to manage domain ownership.
Comment by ButlerianJihad 18 hours ago
Another hole in OP's story: when/how did they follow the legal dispute process, rather than just "shooting a couple emails" and creating a new HN account to complain about it?
Comment by kstrauser 9 hours ago
Comment by assimpleaspossi 1 day ago
In the meantime, been with NameCheap for I don't recall how long with no issues whatsoever.
Comment by dessimus 1 day ago
Comment by happytoexplain 1 day ago
Comment by assimpleaspossi 1 day ago
How about never heard of any issues till this unverified, anonymous thread. Shouldn't that make one suspicious of it? Does that count?
Comment by happytoexplain 1 day ago
I used Namecheap since 2011. This year, they lost me. The only difference between you and me is one bad experience.
Comment by linsomniac 1 day ago
Comment by foresto 1 day ago
Comment by sigio 1 day ago
Comment by AussieWog93 1 day ago
Everything propagates in 10 seconds rather than 10 hours.
Comment by himata4113 1 day ago
Comment by system2 1 day ago
Comment by greyface- 1 day ago