IT.COM

warning Concerning e-mail from NameCheap

NameSilo
Watch
Impact
4,246
I've just received a weird e-mail from NameCheap (attached below). It was sent from [email protected] (IP 149.72.141.59 - passed SPF, DKIM, DMARC) to the mail address I'm using with NameCheap, using my name&surname, and the links in the mail are under links.namecheap.com. If it's not a breach I don't know what it is...

1676236912872.png
 
Last edited:
25
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
1
•••
8
•••
2
•••
Last edited:
3
•••
"unsolicited emails to our clients" - either it's bad wording, or they admit that the mailing database was also accessed/used.
Hopefully, Namecheap customers will be informed soon about what is going on.

Fortunately, I didn't receive any such spam or phishing emails.

Note though that I had had ongoing concerns about the security of their privacy services. As a result, upon request last month, Namecheap had completely removed from my account any connection whatsoever to their "Withheld For Privacy" subscriptions. There had been unusual issues showing up on my account, such as unexplained FT listings and wrong Whois information.

The privacy company used by NC had an outdated copyright of 2021 listed. This did not inspire confidence. If a company responsible for significant privacy and security can't even get the year right on their main web page, can they be trusted for the bigger stuff? I'm not sure, but I didn't want to find out.

Hopefully, that privacy company is not where the current breach happened, but admittedly I wouldn't be surprised if it was. And the company may be unrelated to the other ongoing security concerns in my account, but removing it seemed like a good start for now.
 
Last edited:
2
•••
4
•••
OK, I'm feeling dumb... what's FT? (fast transfer?)
That's not a dumb question. We sometimes use these abbreviations on the forum, and take it for granted others understand them. Thanks for pointing that it.

Yes, FT is Fast Transfer. I kept getting Afternic's "Fast Transfer" showing up on my Namecheap registrar portfolio, even well after the domains were completely removed from Afternic. Also, I was seeing various Whois services citing that my domains were under their privacy service, when no such service was ever activated whatsoever (in other words not even having privacy off--not even having a subscription with them to begin with).

So, that's part of the reason taking the radical move of removing any and all connection to their privacy service contractor. It may not be the reason that I never received the scam/spam emails cited by others, but it does reconfirm my preference to not use that service.

Unfortunately, removing myself completely from their service has not eliminated the recurrent Fast Transfer designation showing up on Namecheap. NC tech support is apparently working on trying to fix this AGAIN, and hopefully provide an answer this time as to why it keeps happening.
 
Last edited:
1
•••
2
•••
0
•••
0
•••

Namecheap notify by the following email:


Important: Update on recent unsolicited phishing emails from Namecheap

Update on recent unsolicited phishing emails​

Dear Igor,

We are writing to inform you of a recent issue with our email system.

Our investigation has revealed that an upstream (third party) system that we use to send emails has been impacted. This caused unauthorized emails being sent on our behalf. We have immediately suspended the sending of emails until the issue is resolved.

We would like to assure you that Namecheap’s own systems were not breached and your products, accounts and personal information remain secure.

We kindly request that you ignore these emails and do not click on any links contained within them. Our team is currently working closely with the upstream provider to investigate the root cause.

We sincerely apologize for any inconvenience or confusion this may have caused and thank you for your understanding and patience as we work to resolve the issue. We will update this post as soon as we have further information.

Sincerely,
Richard Kirkendall
CEO
 
1
•••
Any updates from NameCheap on the investigation?
 
Last edited:
1
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back