Live data from Hacker News

NameCheap's email hacked to send Metamask, DHL phishing emails

bleepingcomputer.com

71–80 of 114 posts

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#71

Checked my emails, didn't find anything, but looking through gmail spam box, I got a DHL one: Subject: Your parcel was not able to be delivered Sender: contact > Dear Client, > We regret to inform you that your parcel was not able to be delivered on the specified date, xx/02/2023. The parcel is currently located in the DHL warehouse near your town. > The reason for the delay was that the sender did not pay the necess…

I found the Metamask email in my spam, with the subject: "MetaMask : Your wallet is about to be suspended", with the headline of the mail "Your wallet is about to be suspended Apply for KYC Verification" Hopefully no one falls for these, sneaky to hind the redirect behind the links.namecheap

Would you be able to share the (scrubbed from your own personal info) headers on a gist or pastebin or similar?

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#73

To be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a follow up email to all users that were affected. The domains linked in the original phishing emails were also disabled. I apologize for this issue and to anyone it may have affected. We have also taken immediate steps to insure it will not happen again.

I had clicked on the DHL one link. It took me to a site which looked like DHL, and in the next step, chrome refused to load the website. Is there any impact on folks on clicked on the links? I never entered any info as such, so not sure, but looking for more information on whether I should be concerned.

I assume it was a phishing site where the threat came if you actually provided them with details

(I didn't receive the DHL one, but did test the Metamask link in a safe browser environment. It was just a phishing site to try to get people's crypto credentials)

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#74

Checked my emails, didn't find anything, but looking through gmail spam box, I got a DHL one: Subject: Your parcel was not able to be delivered Sender: contact > Dear Client, > We regret to inform you that your parcel was not able to be delivered on the specified date, xx/02/2023. The parcel is currently located in the DHL warehouse near your town. > The reason for the delay was that the sender did not pay the necess…

I found the Metamask email in my spam, with the subject: "MetaMask : Your wallet is about to be suspended", with the headline of the mail "Your wallet is about to be suspended Apply for KYC Verification" Hopefully no one falls for these, sneaky to hind the redirect behind the links.namecheap

I think the redirect being behind links.namecheap was an artefact of the compromised mailing service rather than intended behaviour: the body text of the Metamask email displayed a fake metamask URL https://verification.metamask.io/KYC?[snipped ID] that the link.namecheap.com link was wrapped around

Did make it clear that something belonging to Namecheap had been compromised though...

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#75
post #21

Earlier quoted context omitted.

A third part email provider we use for our newsletter was impacted. Our own systems and customer accounts were not breached.

What customer information did you store with that provider? Just names and emails, or was there anything else that attackers may have been able to access?

I don't know what they had stored, but the mailshots were addressed "Dear User" which suggests it was probably just emails

My email was also my domain name contact email, so I originally thought they'd obtained it by DNS lookup...

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#76
post #29
post #27

Earlier quoted context omitted.

I just wanted to add another note in favor of Fastmail. I switched from Gmail this year as part of an early new year's resolution and have been far happier with their service thus far. Especially with how aliases are handled.

If only their app and spam filtering weren’t garbage. I made the move from gmail a while ago but it’s been kinda meh tbh.

I've never understood this criticism.

You can use any email client you like.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#77

I’m pretty sure that either NameCheap or Rackspace was hacked fairly badly, sometime in the not-so-distant past. How do I know this? Attempted fraud on a business card that is only used for those two places.

Someone once managed to spend on a card I've never used!

Presumably they got lucky with a Luhn generator and ecommerce that was especially lax in their checks, but it was still pretty concerning!

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#78

To be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a follow up email to all users that were affected. The domains linked in the original phishing emails were also disabled. I apologize for this issue and to anyone it may have affected. We have also taken immediate steps to insure it will not happen again.

This ridiculous registrar threatened to lock our domain and destroy our business within 24 hours for a defective DMCA notice that addressed one if our 40 million user profile subdomains. Our legal counsel advised to temporarily comply instead of arguing (although he did send them a nasty letter) to move over to a normal registrar from this cheap one, that i got when i was bootstrapping with no money because it was several dollars cheaper. It's not a business of a domain registrar (unlike a web host) to enforce DMCA notices.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#79
post #78

To be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a follow up email to all users that were affected. The domains linked in the original phishing emails were also disabled. I apologize for this issue and to anyone it may have affected. We have also taken immediate steps to insure it will not happen again.

This ridiculous registrar threatened to lock our domain and destroy our business within 24 hours for a defective DMCA notice that addressed one if our 40 million user profile subdomains. Our legal counsel advised to temporarily comply instead of arguing (although he did send them a nasty letter) to move over to a normal registrar from this cheap one, that i got when i was bootstrapping with no money because it was se…

So you found out how DMCA works and how much it sucks the hard way, eh?

You’re right it shouldn’t be the business of a domain registrar. But every provider in the chain that the copyright holders can reach to will end up responsible. You, the registrar, web host, ISP, everything.

Send your complaints to the US government and the copyright lobby. It’s a bullshit law. Namecheap complies with it because if they don’t, THEY get cut off by their own providers, and so on up the chain until the fines roll in.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#80

I’m pretty sure that either NameCheap or Rackspace was hacked fairly badly, sometime in the not-so-distant past. How do I know this? Attempted fraud on a business card that is only used for those two places.

That was Rackspace: https://techcrunch.com/2023/01/06/rackspace-ransomware-data-...
Post reply on HN