Live data from Hacker News

NameCheap's email hacked to send Metamask, DHL phishing emails

bleepingcomputer.com

61–70 of 114 posts

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#61
post #53

[flagged]

Why do you say that? I've got a lot of names with them so would be keen to know if there are any issues.

Personally I've used them for years and they are by far the best of the many registrars I've used over the past 25+ years.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#62

To be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a follow up email to all users that were affected. The domains linked in the original phishing emails were also disabled. I apologize for this issue and to anyone it may have affected. We have also taken immediate steps to insure it will not happen again.

why is a company like namecheap not servicing their own email servers? what a cop out. I've also read about you not wanting to update 2FA systems... another cop out

I wonder how many people got caught and ruined by this scam, what if you are behind it? you don't deserve to be in business.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#64

Earlier quoted context omitted.

So… What happened? Did you get your keys stolen out of a CI or something? It just seems suspicious that you’d be the only business affected by this 3rd party provider.

If I have a business and I use a company like sendgrid, I have credentials to use that service. If some employee has access to that account (such as to send newsletters), and that employee’s credentials were lost or stolen, that doesn’t seems suspicious at all. I don’t have any inside info here, but it makes sense. And as a namecheap customer, I see no reason to panic at this time.

You wouldn't claim 'the issue was with a 3rd party provider' though.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#65
Jup, got one as well. That the fee was in USD immediately triggered my mental spam alert (living in Europe). But when checking the headers I could not find any indication this was a spoofed message. That the link was also first a valid link to namecheap made it also harder.

I was still very paranoid so I opened it in a non-Javascript, private browser but it seems that my DNS with anti-spam filters already picked it up as the destination was not being resolved.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#66
post #61
post #53

[flagged]

Why do you say that? I've got a lot of names with them so would be keen to know if there are any issues. Personally I've used them for years and they are by far the best of the many registrars I've used over the past 25+ years.

when you have a problem and it is not resolved, you better understand what i mean. good luck with this risk.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#67
post #2

some more details here: https://mailman.nanog.org/pipermail/nanog/2023-February/2216...

That's just a couple of guys (I don't recognise the names, don't mean any offence if they are well known, still) guessing, no insider information.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#68
NameCheap have been training their customers to be vulnerable to this for years. When your account gets suspended (in my case for using VPN to login) they send you an email telling you to go to a privately registered domain (not referenced on their site) and do a cam show with your credit card.. Support is so slow they have already shut down your account before you get a response. I lost a domain and only got a partial refund.. dreadful service, and expensive compared to alternatives.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#69
post #53

[flagged]

> Please stop using this company. Out of curiosity, what are these better alternatives? I think many viewed NameCheap as the better alternative to GoDaddy in the first place. Apparently some were successful with Porkbun for their domains, but I don't think they offer e-mail, hosting as well as a bunch of other stuff NameCheap has. There's also Google Domains I guess, but some are cautious about using too many of Goog…

I saw a lot of people recommending Gandi.net as a Namecheap alternative the last time there was a controversy, and I've recently switched my domains over to them myself. Gandi seems to be a solid provider that's maintained its good reputation for a long while.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#70

Earlier quoted context omitted.

So… What happened? Did you get your keys stolen out of a CI or something? It just seems suspicious that you’d be the only business affected by this 3rd party provider.

If I have a business and I use a company like sendgrid, I have credentials to use that service. If some employee has access to that account (such as to send newsletters), and that employee’s credentials were lost or stolen, that doesn’t seems suspicious at all. I don’t have any inside info here, but it makes sense. And as a namecheap customer, I see no reason to panic at this time.

Employees should use 2FA for their accounts and Sendgrid seems to offer this; for password stored in sending applications one can use combination of password and IP ACLs but I don't know if SendGrid allows to set IP ACLs for senders. While 2FA is not a panacea it significantly reduces rick.

One can send newsletters using a subdomain like news.acmecorp.com and have Sendgrid's IPs in SPF record only for this subdomain and not for the main domains (though most recipient would not notice change from say @acmecorp.com to @news.acmecorp.com).

Post reply on HN