:

NAMECHEAP TRANSFERS DOMAIN TO UNVERIFIED USER

INDUSTRY DESK1 MIN READ
THU, JUL 23, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Domain registrar Namecheap handed over a customer's account to an unverified third party after a password reset request, raising security concerns for a 13-year customer.

A long-time Namecheap customer discovered the registrar transferred domain control to an unauthorized user following a password reset initiated by someone else. The customer had registered a .com domain under their own credentials for a college club they helped manage. During a leadership transition, an incoming club officer found the domain parked at Namecheap and initiated a password reset using only the domain name. Namecheap sent a reset email to the account owner, but the customer claims the registrar ultimately granted access to the unverified third party without proper verification. The incident highlights potential gaps in Namecheap's account security protocols. Password reset procedures typically require additional verification steps beyond email confirmation when sensitive assets like domain registrations are at stake. The customer filed a support ticket to address the unauthorized access. The situation underscores the importance of registrars implementing multi-factor authentication and stricter identity verification for account transfers and sensitive changes.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

At least 14 people across Serbian civil society were infected with advanced spyware in what digital rights group Share Foundation calls the country's largest documented surveillance wave. Student protesters were among those targeted, though the government of Aleksandar Vučić denies involvement.

JUST NOWSecurity Desk

An identity verification company left its systems exposed, allowing hackers real-time access to scan data for over 12 months. The breach potentially affected millions of users whose identification documents were processed through the platform.

JUST NOWSecurity Desk

France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 for failing to adequately protect the personal data of 727,000 patients and their relatives.

11H AGOSecurity Desk

The FBI is investigating a possible security breach at an ID verification company that may have exposed driver's license scans belonging to millions of Americans. The agency confirmed the investigation to Bloomberg News on Thursday.

11H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.