Tell HN: Namecheap gave my account to an unverified third party
I’ve been a NameCheap customer for 13 years. I’ve also helped out an old college club paying for a .com they use (that is registered to me under my name, address, and phone number). During a recent leadership transition, the incoming club lead wanted to make changes to the DNS and didn’t know to contact me. They figured out the domain name was parked at NameCheap, so they initiated a password reset using the domain name. I got a password reset email and immediately filed a NameCheap support ticket saying “I did not initiate this”. They called me to verify I was the one who filed the ticket, and then followed up with a canned email with tips like check your anti-virus. The incoming club leader was persistent though, and called NameCheap support. He convinced them the domain registered in my name and address really belonged to his club, and with no verification or validation whatsoever, NameCheap changed my password, and changed the email address associated with my account. All because someone simply asked nicely on a phone call. Meanwhile in the background, someone advised the new club leader who I was and we were able to connect and get things transferred over. Ultimately I was happy to give them access or even ownership if they wanted (student club turnover being what it is, it’s likely a domain doesn’t get renewed and gets gobbled up by a squatter, which is why I was keeping it current for them). But NameCheap had no way of knowing any of this. As far as NameCheap was aware, this was a personal account of mine. They demonstrated they were perfectly able to pick up a phone and call me (to verify my initial support ticket) but when someone calls them and says “but I really want access to that account” they don’t bother? I’d hesitate to even call this social engineering. It’s clearly a massive vulnerability. I’ve already moved a dozen of my most critical domains out of NameCheap after seeing just how easy it is for a third party to completely take over a NameCheap account: just ask nicely.
Discussion Highlights (20 comments)
superkuh
Yep. I've been with Namecheap for a similar length of time. This week they sent me an email saying I had to update my namecheap profile information or they would close my account in 24 hours. They locked my account so I couldn't log in. To be clear, my whois information was fullly legally compliant, and I was happy to also update my namecheap profile, but when I sent them an email they didn't get back to with an response email until there was just an hour left. Things had been going down hill slowly and lots of my peers have already moved on to porkbun, etc, but I think now things are going downhill quite fast. I did manage to save my account (and so domains) but now I will be moving to a new registrar.
happytoexplain
Just a few weeks ago I moved from Namecheap to Porkbun. That's not an advertisement - I simply Googled popular registrars. But it is an indictment of Namecheap. They are going the way of GoDaddy. Please move away from them immediately. They are shifting to short-term strategies (high prices, immoral data practices, etc). Edit: Apparently they were bought by private equity just weeks before I noticed something was wrong. Not a coincidence, I'm sure. We need to legally destroy private equity takeovers. They are pure evil and nothing but a negative force, at least in the USA.
addaon
Well, they didn't call it NameCompetent, did they?
dalmo3
I've had the exact same issue with a small local registrar. Had an account where I managed multiple clients. One of the clients had their "IT guy" contact the registrar for a DNS change. The registrar promptly gave the guy full access to my account, changing the password and locking me out in the process. As soon as I regained access I moved everything off there.
geuis
I've been a long, long term customer of Namecheap as well. Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost. The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset. This clearly isn't an answer for NC's customer support personnel and company policies. But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence. Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted.
phendrenad2
Ah namecheap. Stories about them make it to HN quite regularly: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
pilingual
Namecheap has been owned by a private equity firm for several months now. It would be nice to have a nonprofit registrar so jumping every few years isn't necessary.
linsomniac
CloudFlare has their plusses and minuses, but they do offer domain registration at cost, for example $10.46/year for .com (every year, not one of those deals for the first year then more expensive down the line).
paxys
People are (rightfully) concerned about superintelligent AI but social engineering continues to be by far the biggest attack vector for digital infrastructure. And it’s being made worse by companies continuously cutting costs in areas like support. The call center employee making third world minimum wage doesn’t give a shit who the real owner of the domain is. They want to end the call quickly and get 5 stars from the customer on the feedback form. I have made it a point to move off services that force SMS-based 2fa for this exact reason. Recently even changed banks because of this.
hmokiguess
Humans are the weakest link, wouldn't be shocked if it's some underpaid off shore call centre or whatever. That's not a vulnerability though, that is social engineering, the attack vector was a human and the exploit was a form of identity theft.
assimpleaspossi
Scrolling through the current comments. In the meantime, been with NameCheap for I don't recall how long with no issues whatsoever.
xyst
Notably, they have been bought out by private equity. > September 2025, CVC Capital Partners acquired a majority stake in Namecheap for an undisclosed amount, valuing the company at $1.5 billion.[3][4] Kirkendall stepped down as CEO on December 16, 2025 But prior to this they have had many incidents. Switched all domains to porkbun a few years ago
ryandrake
This kind of story makes me wonder what's the most popular/valuable domain I can take control of simply by being convincing over the phone. Sounds tempting! I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely!
richardchilders
Namecheap forces users to log in to identify themselves. So far, OK. But then when one attempts to pay for a domain, after one has already provided all of one's credit card information to Namecheap ... Namecheap up and refers its customers to something called Link, which forces Namecheap's customers to create an account and become Link's customers - providing all that confidential credit card information, all over - leaving the customer wondering why Namecheap collected it and what they are going to do with it. Link forces you to authenticate via SMS so that they know where you are. This all happened less than 24 hours ago and I was already getting ready to put domain service shopping on my list of things to do but I'm glad to see I'm not the only one. I nominate Paul Vixie as a possible candidate for CTO or even CEO of a hypothetical nonprofit DNS domain service. More info: uggcf://fnynanir-ehalba.bet/ureovr.ugzy
sandeepkd
In the absence of actual details its hard to say what was considered for making this decision. If I have to take a wild guess then being able to demonstrate the control on the webserver hosting the content could have been one way to prove ownership over the domain. It can be called social engineering, however one can also put it in category of account recovery by verifying content control on the domain. The part where it gets hairy is if your credit card was associated with the account, thats probably a recipe for disaster?
OutOfHere
It was not declared whether 2FA was enabled on the account or not. I will assume that it wasn't enabled.
Georgelemental
I left Namecheap when they took away Databases for Palestine's domains for daring to publish evidence of the Gaza genocide. They do not deserve your business https://www.thecanary.co/skwawkbox/2026/01/03/namecheap-gaza...
n8n_and_coffee
This is disheartening to hear. This year I began slowly switching my domains to NameCheap from Godaddy before renewal because of the huge difference in price plus the added NameCheap free stuff Godaddy charges extra for. I guess there's a reason NameCheap is cheap :( Was your domain in 'locked' status, preventing transfers etc?
Adachi91
I moved from Namecheap 2 years ago when I had auto renew on but it did not auto-renew, which their system automatically turns your domain into an advertisement hell page. Transfer system was locked and I contacted them and told them to transfer it to my other registrar or I would file an ICANN complaint. I moved it to my main registrar (Hover) which while more expensive I haven't a problem with them in the decades I've been with them. My original registrar shutdown sometime in the mid 2000s and Hover picked up my domains, so I'm all in over there now.
terminalbraid
porkbun is really good