24 ms·
To be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a f
by NamecheapCEO 4y ago
To be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a follow up email to all users that were affected. The domains linked in the original phishing emails were also disabled. I apologize for this issue and to anyone it may have affected. We have also taken immediate steps to insure it will not happen again.
- joshka 4y agoI never received an email, but just today received spam on an email address only used with namecheap. You might want to check your logic for what was impacted.
- walrus01 4y agoCan you please clarify how exactly the decision making process occurred to give a 3rd party email provider a copy of your private DKIM signing key for the domain "namecheap.com" ? The emails could not have gone out with DKIM-signature and successfully validated by openDKIM at my receiving MX/SMTPD against the public half of the key in your DNS TXT record for your DKIM key, unless you had given them access to the private key. Did the persons who are responsible for creating and maintaining your DKIM public/private key pair and its selectors directly give the key to some third party (sendgrid, mailchimp, whatever) type email newsletter services, or were they ordered to do so by somebody else in Namecheap management? Or, did the persons responsible for your authoritative DNS zone for namecheap.com insert an additional DNS TXT record for the DKIM key used by a 3rd party service?
- oneplane 4y agoWhile I don't know the details of the third party at name cheap, it's pretty common to have a bunch of third parties with their own DKIM keys and just trusting and including their public keys on your DNS zone. Nobody sends all their own mail, your service desk, support software, ticketing system, alerting system, collaboration provider all have DKIM keys and SPF records you're adding to your zone and they just control the keys for their own input. This means that if they get pwned, it's their ability to send mail on your behalf that gets abused, not some key stealing and DKIM impersonation (and why would they bother if a perfectly fine emailing system is already open and ready to spam the crap out of everyone).
- 28mm 4y agoI received one of the phishing messages as well as the follow up / apology. An interesting wrinkle is that both were handled by sendgrid and used the same dkim selector. I would guess that a set of sendgrid api credentials shared with some 3rd party service was compromised.
- oneplane 4y agoI've seen it even worse: - One of our domains had a DKIM trust with Mailgun (3rd party) - Mailgun was integrated with a planning service (4th party?) - Planning service was integrated with a CRM (5th party?) - CRM was integrated with a website (6th party?) Website got pwned, spam ensues using the entire chain all the way back to our domain. This was a while ago but I think the website was pwned, leaked API credentials for the CRM, those were locked to only read the address book for sources (not even destinations! but '*' was allowed...) but because the software was crap the planning/calendaring service was registered as a 'source', which included API creds. The planning service itself was pretty good, no further grab-keys-via-API, but using what was already allowed you could send raw MIME messages and it would just use the Mailgun API it had access to. Luckily for me, I was on a prometheus spree and had an exporter grab the Mailgun metrics every few minutes (Ironically to support the CRM team because they didn't have any good metrics of their own and did like to blame everyone else), so while it was configured to look for dips, it also triggered on spikes because those tend to end with dips too. I think in the end nobody learned from it because every team/vendor covered their ass with "well we only run it in datacenters with firewalls so this is the cloud at fault" and I don't think anyone got flak for it (but some definitely deserved a fair bit).
- clarifyitto 4y agoSo… What happened? Did you get your keys stolen out of a CI or something? It just seems suspicious that you’d be the only business affected by this 3rd party provider.
- jcrawfordor 4y agoI don't think this is unique to NameCheap, I've gotten both metamask and DHL emails from other lists I'm on, I assume from the same threat actor. I would assume that they're opportunistically using whatever mailing list they can gain access to.
- morganbird 4y agoThey're actually pretty common, just like there are tons of metamask phishers on twitter. Those are just popular vectors because they're fairly broadly effective. Preventing spam and phishing like this is unfortunately a pretty big part of the job for anyone in the business of sending email. (source: engineering manager at a marketing platform)
- btgeekboy 4y agoIf I have a business and I use a company like sendgrid, I have credentials to use that service. If some employee has access to that account (such as to send newsletters), and that employee’s credentials were lost or stolen, that doesn’t seems suspicious at all. I don’t have any inside info here, but it makes sense. And as a namecheap customer, I see no reason to panic at this time.
- OJFord 4y agoYou wouldn't claim 'the issue was with a 3rd party provider' though.
- citrin_ru 4y agoEmployees should use 2FA for their accounts and Sendgrid seems to offer this; for password stored in sending applications one can use combination of password and IP ACLs but I don't know if SendGrid allows to set IP ACLs for senders. While 2FA is not a panacea it significantly reduces rick. One can send newsletters using a subdomain like news.acmecorp.com and have Sendgrid's IPs in SPF record only for this subdomain and not for the main domains (though most recipient would not notice change from say @acmecorp.com to @news.acmecorp.com).
- satoshiiii 4y ago[flagged]
- ezekg 4y agoYeah! Like why is Microsoft lying by no longer being “micro.” They’re way too big for that name.
- SturgeonsLaw 4y agoTried buying any fruit from Apple? Can't do it! They only sell computers and phones and stuff!
- cebert 4y agoNamecheap is still reasonably cost competitive. I use them for a few domains I own and haven’t had any major issues and found the price closer to other well known competitors.
- homero 4y agoPorkbun is cheaper
- dicknuckle 4y agoCloudflare is cheaper.
- orangepurple 4y agoUntil you try to put a single NS record on your domain. Then you have to cough up the dough for a business plan. Utterly laughable and why I moved off Cloudflare for my domains. NS records are free on Namecheap and Porkbun.
- davchana 4y agoI alway compare prices at domcomp.com Over the time, most of my 15 domains (mixed tlds, .com .net .us .xyz .in etc) got moved over to cloudflare & dynadot, with them both having cheaper renewals.
- Krisjohn 4y agoWhat about the open redirect?
- xena 4y ago[flagged]
- chronogram 4y ago[flagged]
- scrollaway 4y agoMindless comments like these are not useful to the discussion. You are speculating on something that didn’t even happen, if indeed it’s just a newsletter provider that got beached. Namecheap is still responsible for the third parties they work with. But nobody “gave your password”.
- junon 4y agoShots at someone's language to make yourself feel superior makes you look like a jerk, too. You knew what they meant.
- ankit219 4y agoI had clicked on the DHL one link. It took me to a site which looked like DHL, and in the next step, chrome refused to load the website. Is there any impact on folks on clicked on the links? I never entered any info as such, so not sure, but looking for more information on whether I should be concerned.
- notahacker 4y agoI assume it was a phishing site where the threat came if you actually provided them with details (I didn't receive the DHL one, but did test the Metamask link in a safe browser environment. It was just a phishing site to try to get people's crypto credentials)
- morganbird 4y agoIt's just phishing. You're not at risk if you didn't give them your credit card info or anything like that.
- zeitgeist1 4y agowhy is a company like namecheap not servicing their own email servers? what a cop out. I've also read about you not wanting to update 2FA systems... another cop out I wonder how many people got caught and ruined by this scam, what if you are behind it? you don't deserve to be in business.
- cft 4y agoThis ridiculous registrar threatened to lock our domain and destroy our business within 24 hours for a defective DMCA notice that addressed one if our 40 million user profile subdomains. Our legal counsel advised to temporarily comply instead of arguing (although he did send them a nasty letter) to move over to a normal registrar from this cheap one, that i got when i was bootstrapping with no money because it was several dollars cheaper. It's not a business of a domain registrar (unlike a web host) to enforce DMCA notices.
- scrollaway 4y agoSo you found out how DMCA works and how much it sucks the hard way, eh? You’re right it shouldn’t be the business of a domain registrar. But every provider in the chain that the copyright holders can reach to will end up responsible. You, the registrar, web host, ISP, everything. Send your complaints to the US government and the copyright lobby. It’s a bullshit law. Namecheap complies with it because if they don’t, THEY get cut off by their own providers, and so on up the chain until the fines roll in.
- highclass 4y agoMy experience with namecheap is similar very bad too. They also sent me an email saying if you don't respond in a short time(24 hours) your domain will be revoked. Related experience: https://news.ycombinator.com/item?id=14139288 https://news.ycombinator.com/item?id=14139288 I moved my domains from namecheap to gandi.net and so far no problems. I would avoid namecheap like the plague for any large site. Of note, I had millions of unique vistors per month on that domain for a normal legal site. ycombinator uses gandi.net too. and even if they obey us and internation laws, threating to revoke a domain within 24 hours if no reply regarding an external complaint, with just an email warning is ridiculous and not how other reputable domain registrars work.
- megous 4y agoWhy should it matter how many visitors you have? People with 3 visitors pay the same and can be also badly affected if the domain is yanked at a wrong time. Especially nasty if you run email on the yanked domain.