Live data from Hacker News

NameCheap's email hacked to send Metamask, DHL phishing emails

bleepingcomputer.com

51–60 of 114 posts

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#51

To be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a follow up email to all users that were affected. The domains linked in the original phishing emails were also disabled. I apologize for this issue and to anyone it may have affected. We have also taken immediate steps to insure it will not happen again.

What about the open redirect?

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#52

To be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a follow up email to all users that were affected. The domains linked in the original phishing emails were also disabled. I apologize for this issue and to anyone it may have affected. We have also taken immediate steps to insure it will not happen again.

[flagged]

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#54
post #8

I wonder who the upstream is? I’m guessing a large email provider. Maybe owned by a company with a history of recent breaches.

Sendgrid

Sendgrid says they weren't hacked. It sounds like there was some sort of intermediary party sitting between NameCheap and Sendgrid that got hacked. Maybe.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#55
post #52

To be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a follow up email to all users that were affected. The domains linked in the original phishing emails were also disabled. I apologize for this issue and to anyone it may have affected. We have also taken immediate steps to insure it will not happen again.

[flagged]

[flagged]

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#56

Checked my emails, didn't find anything, but looking through gmail spam box, I got a DHL one: Subject: Your parcel was not able to be delivered Sender: contact > Dear Client, > We regret to inform you that your parcel was not able to be delivered on the specified date, xx/02/2023. The parcel is currently located in the DHL warehouse near your town. > The reason for the delay was that the sender did not pay the necess…

I found the Metamask email in my spam, with the subject: "MetaMask : Your wallet is about to be suspended", with the headline of the mail "Your wallet is about to be suspended Apply for KYC Verification"

Hopefully no one falls for these, sneaky to hind the redirect behind the links.namecheap

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#57
post #52

Earlier quoted context omitted.

[flagged]

[flagged]

Mindless comments like these are not useful to the discussion. You are speculating on something that didn’t even happen, if indeed it’s just a newsletter provider that got beached.

Namecheap is still responsible for the third parties they work with. But nobody “gave your password”.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#58
post #53

[flagged]

> Please stop using this company.

Out of curiosity, what are these better alternatives?

I think many viewed NameCheap as the better alternative to GoDaddy in the first place.

Apparently some were successful with Porkbun for their domains, but I don't think they offer e-mail, hosting as well as a bunch of other stuff NameCheap has.

There's also Google Domains I guess, but some are cautious about using too many of Google's services, given automated bans.

I'm sure that good alternatives exist out there, but that might mean using a bunch of separate services instead of one (which can be okay), for example: Porkbun for domains, Fastmail for e-mails, Hetzner for servers and so on...

Edit: I was wrong about Porkbun, apparently they also provide e-mail and hosting now. Though their front page also has a warning about phishing e-mails.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#59

To be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a follow up email to all users that were affected. The domains linked in the original phishing emails were also disabled. I apologize for this issue and to anyone it may have affected. We have also taken immediate steps to insure it will not happen again.

I had clicked on the DHL one link. It took me to a site which looked like DHL, and in the next step, chrome refused to load the website. Is there any impact on folks on clicked on the links? I never entered any info as such, so not sure, but looking for more information on whether I should be concerned.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#60
post #36

Earlier quoted context omitted.

[flagged]

Yeah! Like why is Microsoft lying by no longer being “micro.” They’re way too big for that name.

Tried buying any fruit from Apple? Can't do it! They only sell computers and phones and stuff!
Post reply on HN