Live data from Hacker News

NameCheap's email hacked to send Metamask, DHL phishing emails

bleepingcomputer.com

81–90 of 114 posts

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#81
post #78

Earlier quoted context omitted.

This ridiculous registrar threatened to lock our domain and destroy our business within 24 hours for a defective DMCA notice that addressed one if our 40 million user profile subdomains. Our legal counsel advised to temporarily comply instead of arguing (although he did send them a nasty letter) to move over to a normal registrar from this cheap one, that i got when i was bootstrapping with no money because it was se…

So you found out how DMCA works and how much it sucks the hard way, eh? You’re right it shouldn’t be the business of a domain registrar. But every provider in the chain that the copyright holders can reach to will end up responsible. You, the registrar, web host, ISP, everything. Send your complaints to the US government and the copyright lobby. It’s a bullshit law. Namecheap complies with it because if they don’t, T…

My experience with namecheap is similar very bad too. They also sent me an email saying if you don't respond in a short time(24 hours) your domain will be revoked. Related experience: https://news.ycombinator.com/item?id=14139288 I moved my domains from namecheap to gandi.net and so far no problems. I would avoid namecheap like the plague for any large site. Of note, I had millions of unique vistors per month on that domain for a normal legal site.

ycombinator uses gandi.net too.

and even if they obey us and internation laws, threating to revoke a domain within 24 hours if no reply regarding an external complaint, with just an email warning is ridiculous and not how other reputable domain registrars work.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#82

Earlier quoted context omitted.

So you found out how DMCA works and how much it sucks the hard way, eh? You’re right it shouldn’t be the business of a domain registrar. But every provider in the chain that the copyright holders can reach to will end up responsible. You, the registrar, web host, ISP, everything. Send your complaints to the US government and the copyright lobby. It’s a bullshit law. Namecheap complies with it because if they don’t, T…

My experience with namecheap is similar very bad too. They also sent me an email saying if you don't respond in a short time(24 hours) your domain will be revoked. Related experience: https://news.ycombinator.com/item?id=14139288 I moved my domains from namecheap to gandi.net and so far no problems. I would avoid namecheap like the plague for any large site. Of note, I had millions of unique vistors per month on that…

Why should it matter how many visitors you have? People with 3 visitors pay the same and can be also badly affected if the domain is yanked at a wrong time. Especially nasty if you run email on the yanked domain.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#83
post #77

I’m pretty sure that either NameCheap or Rackspace was hacked fairly badly, sometime in the not-so-distant past. How do I know this? Attempted fraud on a business card that is only used for those two places.

Someone once managed to spend on a card I've never used! Presumably they got lucky with a Luhn generator and ecommerce that was especially lax in their checks, but it was still pretty concerning!

A lot of smaller charities donation pages are readily abusable to "validate" card numbers, bruteforce CVV number, expiry, etc.

A few local charities that all had their sites running the same shit ended up getting absolutely hammered with charge back fees a while back, someone had been abusing their pages to check and crack card numbers to use.

Donation pages seem to be the easiest to abuse based on the data I've seen.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#84
post #78

To be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a follow up email to all users that were affected. The domains linked in the original phishing emails were also disabled. I apologize for this issue and to anyone it may have affected. We have also taken immediate steps to insure it will not happen again.

This ridiculous registrar threatened to lock our domain and destroy our business within 24 hours for a defective DMCA notice that addressed one if our 40 million user profile subdomains. Our legal counsel advised to temporarily comply instead of arguing (although he did send them a nasty letter) to move over to a normal registrar from this cheap one, that i got when i was bootstrapping with no money because it was se…

Abusive DMCA takedowns are unfortunately extremely easy, very time consuming to report, and seemingly very rarely have any action taken against the person who falsely claimed. Not excusing Namecheap here, what they did was totally shit.

Heroku did the same thing to me for same reason - completely shut down my entire account with several revenue generating websites with zero notice.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#85
Fuck NameCheap. I have no sympathy towards them after they decided to kill the service for my account, just because I happened to be born in Russia, without even refunding.

Ironically, after all that high morals grandstanding, they are still sending me notification emails "reminding to prolong a yearly subscription". Like, WTF.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#86
post #82

Earlier quoted context omitted.

My experience with namecheap is similar very bad too. They also sent me an email saying if you don't respond in a short time(24 hours) your domain will be revoked. Related experience: https://news.ycombinator.com/item?id=14139288 I moved my domains from namecheap to gandi.net and so far no problems. I would avoid namecheap like the plague for any large site. Of note, I had millions of unique vistors per month on that…

Why should it matter how many visitors you have? People with 3 visitors pay the same and can be also badly affected if the domain is yanked at a wrong time. Especially nasty if you run email on the yanked domain.

I agree with that. I was just emphasizing the livelihood of multiple people and a whole business depended on answering a email from namecheap within 24 hours due to an complaint they received.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#87
post #80

I’m pretty sure that either NameCheap or Rackspace was hacked fairly badly, sometime in the not-so-distant past. How do I know this? Attempted fraud on a business card that is only used for those two places.

That was Rackspace: https://techcrunch.com/2023/01/06/rackspace-ransomware-data-...

I never got an email from them, so I guess I wasn’t in “The 27 Club.”

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#88

Fuck NameCheap. I have no sympathy towards them after they decided to kill the service for my account, just because I happened to be born in Russia, without even refunding. Ironically, after all that high morals grandstanding, they are still sending me notification emails "reminding to prolong a yearly subscription". Like, WTF.

Considering your comment history -- good job NameCheap.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#89

Just received a bunch of cryptocurrency phising spam from their domain. Definitely pretty interesting, and they were actually fairly well done with a proper link text, but an incorrect link.

Huh, I wonder what the logic was. I own several domains through Namecheap over several years and I haven’t received any spam

The Metamask spamming campaign primarily use their own list -- compromised credentials are mainly used to get SMTP access and then spam away until they get caught.

Re: NameCheap's email hacked to send Metamask, DHL phishing emails

#90

Fuck NameCheap. I have no sympathy towards them after they decided to kill the service for my account, just because I happened to be born in Russia, without even refunding. Ironically, after all that high morals grandstanding, they are still sending me notification emails "reminding to prolong a yearly subscription". Like, WTF.

Considering your comment history -- good job NameCheap.

They are one angry person, from quantum mechanics to politics, not one comment that barely even tries to be friendly. Just bashing.
Post reply on HN