Namecheap: a user tells how their account was transferred to an unverified third party upon simple request

Cybersecurity 2 h agoAdd to bookmarks

Namecheap: a user tells how their account was transferred to an unverified third party upon simple request
Illustration : Momiji Shirogane

A user claims on Hacker News that the registrar Namecheap transferred his account to someone pretending to be him, without serious verification procedures. If the facts are confirmed, the case raises the question of the weak link in the DNS model: the registrar's customer support.

A post published on the front page of Hacker News on July 23, 2026, recounts a concerning experience with Namecheap, one of the most widely used public registrars in the world. According to the author, Namecheap's support would have given access to their account to a third party without robust identity verification, simply at the request of the latter.

What is claimed

The author of the post recounts that an individual impersonated them to Namecheap support, requested control of the account, and allegedly obtained it after what he describes as a very weak verification procedure. The consequences can be severe for the victim: access to the domain names in the account (and thus to the DNS, emails, and related hosting), billing history, and potentially stored payment methods.

Facts:

  • Source: original post on the front page of Hacker News, 2026-07-23, item id 49028037 (URL below).
  • Official Namecheap response: as of the publication date of this article, we have no official public communication from the registrar either confirming or refuting the account.
  • Independent verification: the account comes from a single party and is not yet corroborated by published logs or a registrar statement.

It is important to emphasize this point: at this stage, we are reporting the user's claims. They are serious, they deserve to be known and discussed, but they do not constitute confirmation of a documented procedural flaw at Namecheap.

Analysis: the true weak link in DNS

The account resonates because it touches on a known structural weakness of the entire registrar ecosystem: account recovery procedures ultimately rely on support staff who must balance ease for legitimate users who lose their credentials (a common case) and security against attackers who engage in social engineering (a rare but devastating case).

There is a precedent that we have been following for a long time: the theft of cryptocurrency accounts via SIM swap exploits exactly the same primitive on the telecom operator side. And there have been, historically, several public incidents at registrars (including, in 2020, a compromise of accounts at GoDaddy via social engineering of their support). The support-registrar threat is a classic, and it is difficult to cover in pure automation.

For the attacker, the target is lucrative: taking control of a domain means being able to modify MX records (email interception), redirect the site (A / AAAA), or even pivot towards a complete takeover of SaaS services linked to that domain (Google Workspace, Microsoft 365, everything that uses you@yourdomain.com as an identifier).

What to do now

Regardless of your registrar, if you manage important domains:

  • Enable registrar lock (clientTransferProhibited) on all your domains: this blocks outgoing transfers, including those initiated from your account as long as the lock is not explicitly lifted.
  • Enable enhanced 2FA - application TOTP (Authy, Aegis, Bitwarden) and not SMS. SMS is breakable by SIM swap.
  • Consider a "corporate" registrar for your critical domains: MarkMonitor, CSC Global, Gandi Corporate offer documented account recovery procedures with strong identity verification (ID documents, passcodes, predefined contacts) - at the cost of assumed friction and a higher price.
  • Monitor your WHOIS and DNS with an alert service (DNSTwist, GoDaddy Domain Monitoring, or simple cron on dig): an unauthorized modification should reach you within the hour.
  • Separate critical production domains from the rest. The domain on which your business relies should not be in the same account as the personal domain you took for a side project in 2018.

We will monitor any potential response from Namecheap and update this article. We also encourage the registrar to publish its version of the facts - that's how we progress collectively.

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

19 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information