Domain registrar Namecheap handed over a customer's account to an unverified third party after a password reset request, raising security concerns for a 13-year customer.
A long-time Namecheap customer discovered the registrar transferred domain control to an unauthorized user following a password reset initiated by someone else.
The customer had registered a .com domain under their own credentials for a college club they helped manage. During a leadership transition, an incoming club officer found the domain parked at Namecheap and initiated a password reset using only the domain name.
Namecheap sent a reset email to the account owner, but the customer claims the registrar ultimately granted access to the unverified third party without proper verification.
The incident highlights potential gaps in Namecheap's account security protocols. Password reset procedures typically require additional verification steps beyond email confirmation when sensitive assets like domain registrations are at stake.
The customer filed a support ticket to address the unauthorized access. The situation underscores the importance of registrars implementing multi-factor authentication and stricter identity verification for account transfers and sensitive changes.
At least 14 people across Serbian civil society were infected with advanced spyware in what digital rights group Share Foundation calls the country's largest documented surveillance wave. Student protesters were among those targeted, though the government of Aleksandar Vučić denies involvement.
An identity verification company left its systems exposed, allowing hackers real-time access to scan data for over 12 months. The breach potentially affected millions of users whose identification documents were processed through the platform.
France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 for failing to adequately protect the personal data of 727,000 patients and their relatives.
The FBI is investigating a possible security breach at an ID verification company that may have exposed driver's license scans belonging to millions of Americans. The agency confirmed the investigation to Bloomberg News on Thursday.