Home / Blog / Namecheap Domain Hijacking: Account Transferred Wi...
Security

Namecheap Domain Hijacking: Account Transferred Without MFA

By Dillip Chowdary โ€ข July 24, 2026
Namecheap Domain Hijacking: Account Transferred Without MFA

Popular domain registrar Namecheap is facing severe criticism after customer support staff transferred control of a developer's account to an unverified third party. The incident occurred when support agents accepted a forged identity document to bypass the account's active multi-factor authentication (MFA) protections. This security failure allowed the attacker to hijack high-traffic domain names.

Once in control, the hijacker modified the DNS records to redirect traffic to malicious phishing clones and spam portals, disrupting services for thousands of end users. The original owner discovered the breach when alert systems flagged unauthorized nameserver updates, but support took several hours to lock the account and revert the changes. This lag exposed Namecheap's slow incident response workflows.

Subscribe to Tech Bytes

Get deeper technical analysis and daily pulse reports directly in your inbox.

In response to the incident, security researchers are advising developers to use registrars that offer advanced enterprise security locks. Namecheap has apologized for the breach and stated it is implementing stricter support verification policies. This incident highlights the risk that human customer support loops pose to automated cryptographic security protocols.

Spotlight Tool

AI Video Generator

Transform scripts into highly engaging faceless YouTube and TikTok videos in seconds.

Try Tool Free

Advertisement

๐Ÿ”Ž More interesting analysis