12 ms·
NameCheap's email hacked to send Metamask, DHL phishing emails
- pictur 4y ago[flagged]
- KronisLV 4y ago> Please stop using this company. Out of curiosity, what are these better alternatives? I think many viewed NameCheap as the better alternative to GoDaddy in the first place. Apparently some were successful with Porkbun for their domains, but I don't think they offer e-mail, hosting as well as a bunch of other stuff NameCheap has. There's also Google Domains I guess, but some are cautious about using too many of Google's services, given automated bans. I'm sure that good alternatives exist out there, but that might mean using a bunch of separate services instead of one (which can be okay), for example: Porkbun for domains, Fastmail for e-mails, Hetzner for servers and so on... Edit: I was wrong about Porkbun, apparently they also provide e-mail and hosting now. Though their front page also has a warning about phishing e-mails.
- sundarurfriend 4y agoI saw a lot of people recommending Gandi.net as a Namecheap alternative the last time there was a controversy, and I've recently switched my domains over to them myself. Gandi seems to be a solid provider that's maintained its good reputation for a long while.
- neoromantique 4y ago>Gandi seems to be a solid provider that's maintained its good reputation for a long while. Apart from that time when they lost users data AND backups. https://news.ycombinator.com/item?id=22001822 https://news.ycombinator.com/item?id=22001822 (Though I am still using gandi, can't fault them otherwise).
- srmarm 4y agoWhy do you say that? I've got a lot of names with them so would be keen to know if there are any issues. Personally I've used them for years and they are by far the best of the many registrars I've used over the past 25+ years.
- pictur 4y agowhen you have a problem and it is not resolved, you better understand what i mean. good luck with this risk.
- walrus01 4y agosome more details here: https://mailman.nanog.org/pipermail/nanog/2023-February/221616.html https://mailman.nanog.org/pipermail/nanog/2023-February/2216...
- OJFord 4y agoThat's just a couple of guys (I don't recognise the names, don't mean any offence if they are well known, still) guessing, no insider information.
- pier25 4y agohttps://www.namecheap.com/status-updates/archives/74848 https://www.namecheap.com/status-updates/archives/74848
- deleted 4y ago[deleted]
- splittydev 4y agoSeems like the hackers also had access to at least some customer data. Several people I know who were also Namecheap clients, including me, received those emails. Whether that data was also stored with the upstream provider remains to be seen. Might be an even bigger deal.
- NamecheapCEO 4y agoA third part email provider we use for our newsletter was impacted. Our own systems and customer accounts were not breached.
- ginja 4y agoWhat customer information did you store with that provider? Just names and emails, or was there anything else that attackers may have been able to access?
- notahacker 4y agoI don't know what they had stored, but the mailshots were addressed "Dear User" which suggests it was probably just emails My email was also my domain name contact email, so I originally thought they'd obtained it by DNS lookup...
- thenickdude 4y agoMine was addressed with my full name in the "To:" field, so they do have our full names (but just didn't mail-merge those into the body of the message).
- worksonmine 4y agoYou and who else? If it's one of your employees credentials getting compromised this excuse isn't going to age well and will do more harm than good. I assume you're using a big provider and there would be news of others being affected.
- Something1234 4y agoJust received a bunch of cryptocurrency phising spam from their domain. Definitely pretty interesting, and they were actually fairly well done with a proper link text, but an incorrect link.
- SOLAR_FIELDS 4y agoHuh, I wonder what the logic was. I own several domains through Namecheap over several years and I haven’t received any spam
- CyanBird 4y agoI can corroborate the same, no spam As of now I haven't yet received spam/phishing from this breach either
- emeril 4y agome too - I haven't received anything from namecheap despite being a customer for 10 years or so
- version_five 4y agoFWIW, I also have some namecheap domains and I didn't get anything
- 2000UltraDeluxe 4y agoThe Metamask spamming campaign primarily use their own list -- compromised credentials are mainly used to get SMTP access and then spam away until they get caught.
- codazoda 4y agoI wonder who the upstream is? I’m guessing a large email provider. Maybe owned by a company with a history of recent breaches.
- LAC-Tech 4y agoGod damn it, my main business email account is namecheap. I am so sick of them, they let so much spam in to my inboxes as well. If I have a domain from namecheap, and an email address with that domain, can I transfer it to something solid like outlook or gmail? My idea of how email works is really fuzzy.
- deleted 4y ago[deleted]
- vxNsr 4y agoyes that is entirely possible, don't know if it will actually prevent this though, as the issue is that they have the domain.
- nicoburns 4y ago> If I have a domain from namecheap, and an email address with that domain, can I transfer it to something solid like outlook or gmail? My idea of how email works is really fuzzy. Yes you can. You'll need to: - Setup the account with the new provider (note: that most providers including I believe outlook and gmail will charge a monthly fee for using a custom domain). I recommend Fastmail. - "Add the domain" with the provider (which will mean they're expecting mail from it on their end - Update a bunch of DNS records to point to your new provider. This will include MX records as well as things like DKIM and SPF. The provider will likely tell you what you need to set in as part of the previous step.
- jsonne 4y agoIt's a guided process for Google apps for business and very simple.
- keeperofdakeys 4y agoUltimately a DNS record tells other email servers how to send email to your domain. So you just need to get an email service at another provide, and update your DNS records. Most providers have instructions on how to do this. I'd recommend having a look at Fastmail as well.
- walrus01 4y ago
- toomuchtodo 4y agohttps://news.ycombinator.com/item?id=34768590 https://news.ycombinator.com/item?id=34768590
- dang 4y agoWe've merged that thread hither.
- NamecheapCEO 4y agoTo be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a follow up email to all users that were affected. The domains linked in the original phishing emails were also disabled. I apologize for this issue and to anyone it may have affected. We have also taken immediate steps to insure it will not happen again.
- joshka 4y agoI never received an email, but just today received spam on an email address only used with namecheap. You might want to check your logic for what was impacted.
- walrus01 4y agoCan you please clarify how exactly the decision making process occurred to give a 3rd party email provider a copy of your private DKIM signing key for the domain "namecheap.com" ? The emails could not have gone out with DKIM-signature and successfully validated by openDKIM at my receiving MX/SMTPD against the public half of the key in your DNS TXT record for your DKIM key, unless you had given them access to the private key. Did the persons who are responsible for creating and maintaining your DKIM public/private key pair and its selectors directly give the key to some third party (sendgrid, mailchimp, whatever) type email newsletter services, or were they ordered to do so by somebody else in Namecheap management? Or, did the persons responsible for your authoritative DNS zone for namecheap.com insert an additional DNS TXT record for the DKIM key used by a 3rd party service?
- oneplane 4y agoWhile I don't know the details of the third party at name cheap, it's pretty common to have a bunch of third parties with their own DKIM keys and just trusting and including their public keys on your DNS zone. Nobody sends all their own mail, your service desk, support software, ticketing system, alerting system, collaboration provider all have DKIM keys and SPF records you're adding to your zone and they just control the keys for their own input. This means that if they get pwned, it's their ability to send mail on your behalf that gets abused, not some key stealing and DKIM impersonation (and why would they bother if a perfectly fine emailing system is already open and ready to spam the crap out of everyone).
- dvngnt_ 4y agoyeah I got the same email sent to two different accounts. it was pretty obvious though lol
- FpUser 4y agoGot one today. Funny I was actually expecting a package. Of course the email is for suckers as it has more than enough clues about being scam but I guess some poor souls might actually fall for it.
- ColonelBlimp 4y ago>Of course the email is for suckers as it has more than enough clues about being scam but I guess some poor souls might actually fall for it. I wonder whether that type of comment is in line with Hacker News Guidelines. In any case, blaming or demeaning scam victims (what you call "suckers" and "poor souls") only adds to the psychological damage that those people experience. There are plenty of studies, recommendations and campaigns on this issue. For example, the UK's Financial Conduct Authority has a whole section in their website https://www.fca.org.uk/scamsmart https://www.fca.org.uk/scamsmart and have been running TV ads to help protect pensioners. The clues in the Metamask and DHL phising emails may have been obvious to you and many other Hacker News readers. I received them and quickly noticed they were phising messags. However, having the skills to spot (and stop) this type of messages doesn't mean we are always able to do it. A recent blog post by Kev Quirk, an infosec expert, is a case in point https://kevquirk.com/i-was-nearly-phished/ https://kevquirk.com/i-was-nearly-phished/
- FpUser 4y ago>"In any case, blaming or demeaning scam victims..." The demeaning in this particular case goes for the authors of the scam. The clues are in plain sight. They did not bother to hide it at all. I am not blaming victims.
- Scoundreller 4y agoChecked my emails, didn't find anything, but looking through gmail spam box, I got a DHL one: Subject: Your parcel was not able to be delivered Sender: contact <hello@namecheap.com> > Dear Client, > We regret to inform you that your parcel was not able to be delivered on the specified date, xx/02/2023. The parcel is currently located in the DHL warehouse near your town. > The reason for the delay was that the sender did not pay the necessary fees for the delivery. To avoid the parcel being returned, we ask that you pay the fee of 6.xx USD. You can track your parcel and pay the fee by clicking the tracking button. > Track and Pay >> > DETAILS > Order number: xxxxxxxxxxxx > Total: (x.xx USD) > Delivery is planned between: xx.02.2023 - xx.02.2023 > Once the fee is paid, we will be able to deliver the parcel . We apologize for any inconvenience caused and thank you for your understanding. Sincerely, > The DHL Team Link URL is: https://links.namecheap.com/u/click?_t=[long https://links.namecheap.com/u/click?_t=[long tracking info redacted] Tried following the link in TOR and on a virtual machine, both get just a 2 word "Unauthorized Access", but it redirects to: hxxps://accomplish-delivery . mysafebridge . info/WorldwideDelivery0/auth/dhl/index.php?utm_source=Iterable_Marketing&utm_medium=email&utm_campaign=MKTG_CRM_Welcome_Hosting_D5_WF_20221118 Slightly modified it to make it non-clickable
- Dead_Lemon 4y agoI found the Metamask email in my spam, with the subject: "MetaMask : Your wallet is about to be suspended", with the headline of the mail "Your wallet is about to be suspended Apply for KYC Verification" Hopefully no one falls for these, sneaky to hind the redirect behind the links.namecheap
- mmphishfight 4y agoWould you be able to share the (scrubbed from your own personal info) headers on a gist or pastebin or similar?
- notahacker 4y agoI think the redirect being behind links.namecheap was an artefact of the compromised mailing service rather than intended behaviour: the body text of the Metamask email displayed a fake metamask URL https://verification.metamask.io/KYC?[snipped https://verification.metamask.io/KYC?[snipped ID] that the link.namecheap.com link was wrapped around Did make it clear that something belonging to Namecheap had been compromised though...
- ianbutler 4y agoI got one of these earlier. I found it highly suspicious that the sender was "Namecheap". I'll admit my first thought was a cheeky way to validate my ICANN info but I quickly waved that away and figured it was phishing.
- 878654Tom 4y agoJup, got one as well. That the fee was in USD immediately triggered my mental spam alert (living in Europe). But when checking the headers I could not find any indication this was a spoofed message. That the link was also first a valid link to namecheap made it also harder. I was still very paranoid so I opened it in a non-Javascript, private browser but it seems that my DNS with anti-spam filters already picked it up as the destination was not being resolved.
- cortic 4y agoNameCheap have been training their customers to be vulnerable to this for years. When your account gets suspended (in my case for using VPN to login) they send you an email telling you to go to a privately registered domain (not referenced on their site) and do a cam show with your credit card.. Support is so slow they have already shut down your account before you get a response. I lost a domain and only got a partial refund.. dreadful service, and expensive compared to alternatives.
- galleywest200 4y agoI am fairly certain I have used a VPN to connect to namecheap.com and I have never had this issue. This sounds as if you got scammed by another actor or made this up.
- cortic 4y agovalidation.com was the site (still anonymously registered domain) they were sending me to, and they confirmed from a support ticket that the email request was sent by them, you can see on the site an example of the credit card cam show they require. The support ticket took 5 days and they shut down my account later that day, actually while i was trying to get a buggy old webcam to work. They actually mention validation.com now; https://www.namecheap.com/id-validation/ https://www.namecheap.com/id-validation/ though i couldn't find any reference to it at the time.
- morganbird 4y agolol what?
- ChrisMarshallNY 4y agoI’m pretty sure that either NameCheap or Rackspace was hacked fairly badly, sometime in the not-so-distant past. How do I know this? Attempted fraud on a business card that is only used for those two places.
- dan1234 4y agoSomeone once managed to spend on a card I've never used! Presumably they got lucky with a Luhn generator and ecommerce that was especially lax in their checks, but it was still pretty concerning!
- nibbleshifter 4y agoA lot of smaller charities donation pages are readily abusable to "validate" card numbers, bruteforce CVV number, expiry, etc. A few local charities that all had their sites running the same shit ended up getting absolutely hammered with charge back fees a while back, someone had been abusing their pages to check and crack card numbers to use. Donation pages seem to be the easiest to abuse based on the data I've seen.
- pera 4y agoThat was Rackspace: https://techcrunch.com/2023/01/06/rackspace-ransomware-data-exchange https://techcrunch.com/2023/01/06/rackspace-ransomware-data-...
- ChrisMarshallNY 4y agoI never got an email from them, so I guess I wasn’t in “The 27 Club.”
- foverzar 4y agoFuck NameCheap. I have no sympathy towards them after they decided to kill the service for my account, just because I happened to be born in Russia, without even refunding. Ironically, after all that high morals grandstanding, they are still sending me notification emails "reminding to prolong a yearly subscription". Like, WTF.
- neoromantique 4y agoConsidering your comment history -- good job NameCheap.
- anaganisk 4y agoThey are one angry person, from quantum mechanics to politics, not one comment that barely even tries to be friendly. Just bashing.
- neoromantique 4y agoThat and the obvious narrative pushing of whataboutism and Russian apologism.
- foverzar 4y agoUgh, this is boring. Not everything is a narrative and not every omitted fact or forgotten nuance visible from a perspective of a local is "apologism". Back again, kinda hard to act friendly when people are so systemically discriminating against anything that doesn't correlate with their impressions. What is so wrong with my comment history that you are now accusing me of a thoughcrime? It's just that your comment history is also full of, let us call it "opinionated", arguments, but I'm not acting that you are a worse person than me. Why are you acting like you are a better person than me I wonder?
- neoromantique 4y agoI am saying that being mad or surprised over a company with significant employee base in Kharkiv not wishing to conduct any business with Russian (Located in Russia, not tested by DNA, mind you) customers whilst their city was literally being bombed by Russia is very tone deaf. And /on top of that/, the fact that almost a whole year of war later you spread Russian propaganda about "we don't know the whole truth, think about what US did in 'nam!", is just cherry on the cake.
- antifa 4y agoIt wasn't the first crypto/NFT email I've gotten from namecheap, I just assumed it was real and they were getting shadier.