:

NAMECHEAP TRANSFERS DOMAIN TO UNVERIFIED USER

INDUSTRY DESK1 MIN READ
THU, JUL 23, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Domain registrar Namecheap handed over a customer's account to an unverified third party after a password reset request, raising security concerns for a 13-year customer.

A long-time Namecheap customer discovered the registrar transferred domain control to an unauthorized user following a password reset initiated by someone else. The customer had registered a .com domain under their own credentials for a college club they helped manage. During a leadership transition, an incoming club officer found the domain parked at Namecheap and initiated a password reset using only the domain name. Namecheap sent a reset email to the account owner, but the customer claims the registrar ultimately granted access to the unverified third party without proper verification. The incident highlights potential gaps in Namecheap's account security protocols. Password reset procedures typically require additional verification steps beyond email confirmation when sensitive assets like domain registrations are at stake. The customer filed a support ticket to address the unauthorized access. The situation underscores the importance of registrars implementing multi-factor authentication and stricter identity verification for account transfers and sensitive changes.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Two major US law firms have fallen victim to cyber extortion attacks, with threat actors obtaining and publishing private client documents. The incidents highlight ongoing security vulnerabilities in the legal sector.

4H AGOSecurity Desk

U.S. cybersecurity and intelligence agencies have identified six Chinese AI companies conducting large-scale distillation attacks on American frontier AI models since late 2024, extracting billions of tokens in the process.

4H AGOAI Desk

Healthcare technology company Veradigm disclosed a data breach after a ransomware attack on a third-party vendor exposed patient personal information. A cybersecurity incident at the vendor compromised data stored on Veradigm's systems.

5H AGOAI Desk

While multi-factor authentication strengthens account security, attackers are increasingly exploiting password recovery and authentication reset processes. Stronger identity verification at service desks is now critical to block social engineering attacks.

6H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.