Security · 2h ago
Namecheap Gave Account Access to Unverified Caller
A 13-year Namecheap customer reports that a third party gained full account access by simply calling support and claiming ownership of a domain. Namecheap changed the password and email without verifying identity, despite having previously called the account owner. The incident highlights a severe security flaw in Namecheap's account recovery process.
Meridian48 take
Namecheap's lax verification undermines trust, but the real story is how easily social engineering bypasses even basic security protocols at a major domain registrar.
Read the full reporting
Namecheap Gave My Account to an Unverified Third Party Just Because They Asked →
Hacker News
namecheapaccount-security