IT.COM

Domains got stolen from my Namesilo [Recovered]

Spaceship Spaceship
Watch

TSB

Upgraded Member
Impact
313
Yesterday, I was checking domain list in my namesilo account. Found that my 4L.com's were missing. Immediately I've sent mail to namesilo and got a reply like the domains got transferred to another account.

And when I checked IP login info in the domain transaction history, for these 3 alone the access is from the UK. I shared this info with the namesilo customer support and waiting for their reply. I'm sure the domains were stolen from my account, but not sure how did it happen.

Screen Shot 2018-08-29 at 3.23.02 PM.png


First time facing this problem. I hope a lot of people gone through this situation. But what is the success rate in getting back the stolen domains?
 
10
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
@namesilo will no doubts respond with a comment here.
Suggestion for namesilo: implementation of a configurable system of emailed login notifications, such as for example if a login from noticeably different location occured (such as on the screenshot). Up to sending email about each successful (or unsuccessful) login attempt. And/or denying obviously suspicious login attempts like this one (185.220.101.44 is a tor exit node).
@TSB - do you have 2FA enabled with namesilo?

Edited: I just found that emailed notifications are already available at namesilo. Right into "proactive notifications" config. It might still make sense to implement a default (non-configurable) email notification of unusual correct logins, and of all incorrect logins though.
 
Last edited:
3
•••
@tonyk2000, actually I didn't enable it, but I enabled right after finding this.
 
0
•••
I've enabled all of my other registrars except this. my bad.
 
1
•••
0
•••
It’s under domain history on the right side bar
 
0
•••
I get an email every time I push or receive a domain. Any movement. Thought that was automatic.
 
1
•••
I get an email every time I push or receive a domain. Any movement. Thought that was automatic.
Yes, indeed. It is likely an icann requirement... @TSB did you receive any domainpush notification on 19/7 ? Or, any sort of email notifications like a change of account email etc... ?
 
2
•••
0
•••
0
•••
no IP nor location shown in domain history.

Click the View Details under Details in DOmain Activity History, it will open popup with info.
 
1
•••
Nope, I haven't received any.
So it may well be that your email account was also accessed by the person who stole the domains :(
They might delete it from the inbox before you checked email.
 
0
•••
It should be able to be traced
 
0
•••
Click the View Details under Details in DOmain Activity History, it will open popup with info.

I did, I still get nothing like what I see in your screenshot.
Anyway, let's not change the subject of the thread :)

I wish you all the luck getting your domains back. Thanks for letting us know.
 
1
•••
Since it was accessed from TOR, the real location of a hacker cannot be traced based on IP. What can be found out is what happened with the domain pushed, they are likely not with namesilo already. Might be sold or resold 1 or more times... including to other domain investors. In any case, a separate warning post on this forum with the list of domains (stolen - do not buy) will not harm I think.
 
0
•••
they are likely not with namesilo already. Might be sold or resold 1 or more times

When I checked the Whois lookup they are still with name silo
 
1
•••
When I checked the Whois lookup they are still with name silo
Then NS should help you get them back. Hopefully the domains are locked in the hackers account.
 
0
•••
Please share the domain names , so that we can skip buying those domains if someone offered us the same...
 
0
•••
0
•••
Hi guys,

The domains are still with us so we have blocked the ability to transfer out while we investigate.
TSB - lets take this convo back to support chat.
 
27
•••
4
•••
Yesterday, I was checking domain list in my namesilo account. Found that my 4L.com's were missing. Immediately I've sent mail to namesilo and got a reply like the domains got transferred to another account.

And when I checked IP login info in the domain transaction history, for these 3 alone the access is from the UK. I shared this info with the namesilo customer support and waiting for their reply. I'm sure the domains were stolen from my account, but not sure how did it happen.

Show attachment 96383

First time facing this problem. I hope a lot of people gone through this situation. But what is the success rate in getting back the stolen domains?
Your vigilance has saved you. Just folloup and get back your domains. Cheers
 
0
•••
Hope you get your names back - Please keep us updated
 
2
•••
This is undoubtedly something you have checked, but they were not in any chance for sale on Afternic premium network with fast transfer enabled, and they have actually sold, but for some reason you did not get (maybe spam filter?) the Afternic notification of the sales? There was a post a while back that a NP member thought his domain was stolen and that turned out to be the answer.

Anyway, I hope that it does get resolved.

ps I presume you have checked to see what you can find out about the IP address where right now.
 
3
•••
So it may well be that your email account was also accessed by the person who stole the domains :(
They might delete it from the inbox before you checked email.
Maybe there is a filter that deletes all mail from namesilo.com. I hope the OP was not using the same password for E-mail and all online services...
 
4
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back