Cybersecurity 2 h agoAdd to bookmarks

A user claims on Hacker News that the registrar Namecheap transferred his account to someone pretending to be him, without serious verification procedures. If the facts are confirmed, the case raises the question of the weak link in the DNS model: the registrar's customer support.
A post published on the front page of Hacker News on July 23, 2026, recounts a concerning experience with Namecheap, one of the most widely used public registrars in the world. According to the author, Namecheap's support would have given access to their account to a third party without robust identity verification, simply at the request of the latter.
The author of the post recounts that an individual impersonated them to Namecheap support, requested control of the account, and allegedly obtained it after what he describes as a very weak verification procedure. The consequences can be severe for the victim: access to the domain names in the account (and thus to the DNS, emails, and related hosting), billing history, and potentially stored payment methods.
Facts:
It is important to emphasize this point: at this stage, we are reporting the user's claims. They are serious, they deserve to be known and discussed, but they do not constitute confirmation of a documented procedural flaw at Namecheap.
The account resonates because it touches on a known structural weakness of the entire registrar ecosystem: account recovery procedures ultimately rely on support staff who must balance ease for legitimate users who lose their credentials (a common case) and security against attackers who engage in social engineering (a rare but devastating case).
There is a precedent that we have been following for a long time: the theft of cryptocurrency accounts via SIM swap exploits exactly the same primitive on the telecom operator side. And there have been, historically, several public incidents at registrars (including, in 2020, a compromise of accounts at GoDaddy via social engineering of their support). The support-registrar threat is a classic, and it is difficult to cover in pure automation.
For the attacker, the target is lucrative: taking control of a domain means being able to modify MX records (email interception), redirect the site (A / AAAA), or even pivot towards a complete takeover of SaaS services linked to that domain (Google Workspace, Microsoft 365, everything that uses you@yourdomain.com as an identifier).
Regardless of your registrar, if you manage important domains:
clientTransferProhibited) on all your domains: this blocks outgoing transfers, including those initiated from your account as long as the lock is not explicitly lifted.dig): an unauthorized modification should reach you within the hour.We will monitor any potential response from Namecheap and update this article. We also encourage the registrar to publish its version of the facts - that's how we progress collectively.
Article produced by artificial intelligence, reviewed under human editorial control.