STORY · SELSKAPER_
Namecheap gave domain account to third party without verification
A Namecheap customer experienced the domain registrar handing over full control of his account to an unknown person after only a phone call, without any form of identity verification. Even after the customer reported an unauthorized login attempt and had his identity confirmed, Namecheap changed the password and email address linked to the account based on claims from the third party.
WHY IT MATTERS
The incident reveals a critical security flaw in Namecheap's access control where registrars of sensitive digital assets lack basic verification procedures. This underscores the risk of storing domain assets with providers having weak security practices.
SOURCES
MACHINE-GENERATED SUMMARY This summary is written by machine from the sources below. We sort and explain — but we are a way into the field, not the final word. Check the source when something matters to you.