I've been a long, long term customer of Namecheap as well. Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost. The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset. This clearly isn't an answer for NC…
I did have domain privacy enabled. NC allows people to initiate a password reset via username, email address, or domain name. I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.
Tell HN: Namecheap gave my account to an unverified third party
31–40 of 190 posts
Re: Tell HN: Namecheap gave my account to an unverified third party
#32Just a few weeks ago I moved from Namecheap to Porkbun. That's not an advertisement - I simply Googled popular registrars. But it is an indictment of Namecheap. They are going the way of GoDaddy. Please move away from them immediately. They are shifting to short-term strategies (high prices, immoral data practices, etc). Edit: Apparently they were bought by private equity just weeks before I noticed something was wro…
Is it time to change registrars already? I fled Gandi a while ago because of private equity fuckery. And now I need to go somewhere else. Who won't adopt enshitification-as-a-business-plan for a few years? No wonder people are leaving tech to go be goat farmers.
Re: Tell HN: Namecheap gave my account to an unverified third party
#33In the meantime, been with NameCheap for I don't recall how long with no issues whatsoever.
Re: Tell HN: Namecheap gave my account to an unverified third party
#34> September 2025, CVC Capital Partners acquired a majority stake in Namecheap for an undisclosed amount, valuing the company at $1.5 billion.[3][4] Kirkendall stepped down as CEO on December 16, 2025
But prior to this they have had many incidents. Switched all domains to porkbun a few years ago
Re: Tell HN: Namecheap gave my account to an unverified third party
#35Re: Tell HN: Namecheap gave my account to an unverified third party
#36I can't even log in to most web sites anymore without doing a side-trip to my E-mail inbox, "for enhanced security," but these clowns let you just take a domain by asking nicely!
Re: Tell HN: Namecheap gave my account to an unverified third party
#37But then when one attempts to pay for a domain, after one has already provided all of one's credit card information to Namecheap ... Namecheap up and refers its customers to something called Link, which forces Namecheap's customers to create an account and become Link's customers - providing all that confidential credit card information, all over - leaving the customer wondering why Namecheap collected it and what they are going to do with it.
Link forces you to authenticate via SMS so that they know where you are.
This all happened less than 24 hours ago and I was already getting ready to put domain service shopping on my list of things to do but I'm glad to see I'm not the only one.
I nominate Paul Vixie as a possible candidate for CTO or even CEO of a hypothetical nonprofit DNS domain service.
More info: uggcf://fnynanir-ehalba.bet/ureovr.ugzy
Re: Tell HN: Namecheap gave my account to an unverified third party
#38People are (rightfully) concerned about superintelligent AI but social engineering continues to be by far the biggest attack vector for digital infrastructure. And it’s being made worse by companies continuously cutting costs in areas like support. The call center employee making third world minimum wage doesn’t give a shit who the real owner of the domain is. They want to end the call quickly and get 5 stars from th…
Re: Tell HN: Namecheap gave my account to an unverified third party
#39Re: Tell HN: Namecheap gave my account to an unverified third party
#40It can be called social engineering, however one can also put it in category of account recovery by verifying content control on the domain.
The part where it gets hairy is if your credit card was associated with the account, thats probably a recipe for disaster?