warning Concerning e-mail from NameCheap

SpaceshipSpaceship
Watch

pb

Top Member
Impact
7,046
I've just received a weird e-mail from NameCheap (attached below). It was sent from [email protected] (IP 149.72.141.59 - passed SPF, DKIM, DMARC) to the mail address I'm using with NameCheap, using my name&surname, and the links in the mail are under links.namecheap.com. If it's not a breach I don't know what it is...

1676236912872.png
 
Last edited:
25
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
2
•••

That's a pretty damning headline -

NameCheap's email hacked to send Metamask, DHL phishing emails​


This is not something that can just be dismissed as no big deal.

People can actually lose assets because of this.

Sure, you should not be clicking on random links in email for things like MetaMask, but at the same time when the emails are actually coming from NameCheap...that is a big deal.

Brad
 
Last edited:
3
•••
2
•••
Last edited:
4
•••
Thanks to @pb for starting this thread on NamePros.
 
12
•••
Got them here in PH . They did look suspicious from the start . They just got deleted .
 
0
•••
Yes, thanks for the alert by starting this thread, @pb I did not personally get either email, so they must not have gone to all NC customers.

Namecheap now have an update that service has been restored (they had stopped any emails including auth codes).

I hope we will learn more from Namecheap after investigation is complete.

-Bob
 
4
•••
These third parties can be a nasty attack vector with major consequences for domain owners. For example, last year I explicitly requested a registrar to a) no longer include all individual authorization codes for all domains when requesting the domain portfolio (this could not be turned off, the auth codes were always included), b) arrange downloading of the portfolio through the trusted, TLS secured website of the registrar instead of emailing unsecured CSVs with all auth codes through the external third party mail service, and c) more often use direct URL links to the registrar's website in email communications, for example when it comes to opt-ins for Afternic .
 
Last edited:
7
•••
Last edited:
2
•••
Last edited:
6
•••
Got the same email.
 
1
•••
8
•••
2
•••
Last edited:
3
•••
"unsolicited emails to our clients" - either it's bad wording, or they admit that the mailing database was also accessed/used.
Hopefully, Namecheap customers will be informed soon about what is going on.

Fortunately, I didn't receive any such spam or phishing emails.

Note though that I had had ongoing concerns about the security of their privacy services. As a result, upon request last month, Namecheap had completely removed from my account any connection whatsoever to their "Withheld For Privacy" subscriptions. There had been unusual issues showing up on my account, such as unexplained FT listings and wrong Whois information.

The privacy company used by NC had an outdated copyright of 2021 listed. This did not inspire confidence. If a company responsible for significant privacy and security can't even get the year right on their main web page, can they be trusted for the bigger stuff? I'm not sure, but I didn't want to find out.

Hopefully, that privacy company is not where the current breach happened, but admittedly I wouldn't be surprised if it was. And the company may be unrelated to the other ongoing security concerns in my account, but removing it seemed like a good start for now.
 
Last edited:
2
•••
4
•••
OK, I'm feeling dumb... what's FT? (fast transfer?)
That's not a dumb question. We sometimes use these abbreviations on the forum, and take it for granted others understand them. Thanks for pointing that it.

Yes, FT is Fast Transfer. I kept getting Afternic's "Fast Transfer" showing up on my Namecheap registrar portfolio, even well after the domains were completely removed from Afternic. Also, I was seeing various Whois services citing that my domains were under their privacy service, when no such service was ever activated whatsoever (in other words not even having privacy off--not even having a subscription with them to begin with).

So, that's part of the reason taking the radical move of removing any and all connection to their privacy service contractor. It may not be the reason that I never received the scam/spam emails cited by others, but it does reconfirm my preference to not use that service.

Unfortunately, removing myself completely from their service has not eliminated the recurrent Fast Transfer designation showing up on Namecheap. NC tech support is apparently working on trying to fix this AGAIN, and hopefully provide an answer this time as to why it keeps happening.
 
Last edited:
1
•••
2
•••
Last edited:
0
•••
0
•••
Appraise.net

We're social

Spaceship
Domain Recover
CatchDoms
DomainEasy — Payment Flexibility
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back