Namecheap Domain Hijacking: Account Transferred Without MFA
Popular domain registrar Namecheap is facing severe criticism after customer support staff transferred control of a developer's account to an unverified third party. The incident occurred when support agents accepted a forged identity document to bypass the account's active multi-factor authentication (MFA) protections. This security failure allowed the attacker to hijack high-traffic domain names.
Once in control, the hijacker modified the DNS records to redirect traffic to malicious phishing clones and spam portals, disrupting services for thousands of end users. The original owner discovered the breach when alert systems flagged unauthorized nameserver updates, but support took several hours to lock the account and revert the changes. This lag exposed Namecheap's slow incident response workflows.
Subscribe to Tech Bytes
Get deeper technical analysis and daily pulse reports directly in your inbox.
In response to the incident, security researchers are advising developers to use registrars that offer advanced enterprise security locks. Namecheap has apologized for the breach and stated it is implementing stricter support verification policies. This incident highlights the risk that human customer support loops pose to automated cryptographic security protocols.
AI Video Generator
Transform scripts into highly engaging faceless YouTube and TikTok videos in seconds.
Advertisement