Warning to all Namecheap Users !!!!

From HN:

Code:
[HR][/HR]
NamecheapCEO 3 hours ago | next [–]

To be clear, the issue was with a 3rd party provider that we use to send our newsletter. None of our own systems or customer accounts where breached. I sent a follow up email to all users that were affected. The domains linked in the original phishing emails were also disabled. I apologize for this issue and to anyone it may have affected. We have also taken immediate steps to insure it will not happen again.
 
Check the email headers. And pretty sure it’s not just the $7 as the email claims but once you click the link or open attachment, you might end up having your payment account compromised or device infected with malware or both which results in far more damage. Social engineering at its best.
But the who did this also had control of the namecheap domain at the time to do the fake redirect in the email to the phishing website.
 
But like it shows as from Namecheap .

how would you detect this without googling the ip ?
If I was in a hurry and didn’t verify with dhl, I would pay it probably. It’s not a normal phishing email , it’s a hack

All that skills and they did it for a 7$ scam lol .
Spray and pray technique. Not much thought placed into it. :D

But still they were able to send emails with namecheap's domain is crazy.
 
Thank God I don't use DHL for a currier, as it was sent with Namecheap name. It looked genuine.
 
Spray and pray technique. Not much thought placed into it. :D

But still they were able to send emails with namecheap's domain is crazy.
It is but still with a good idea I’m sure it can do a lot more damage , lucky they were lazy and stupid .

true yeah could have done something like “free year of domain service with purchase “ and made a lot more though ..

guess If they were that good though that wouldn’t be hacking for nothing though .

prob made like 60-500k max and now they are watched by the feds so they can’t really cash most of it .

Never understood why non these people use their hacking skills to go legal . Actually pretty amazing they hacked Namecheap .
 
What the heck peoples expect namecheap to send them through DHL ? SSL certificates ? lol

The scammers could've emulate a true email from namecheap, and end up with dozens of accounts at their hands, so it seem that the scammers were stupid as well.
 
But the who did this also had control of the namecheap domain at the time to do the fake redirect in the email to the phishing website.

Not likely. Phishing url contained in the emails were of a different domain. See the VT scan of one such URL below. Namecheap uses sendgrid for email delivery and since they are authorized to send emails on behalf of Namecheap, whoever has control of sendgrid can send out such emails.

https://www.virustotal.com/gui/url/...d8cb39b5e7671272c65f3f02268372cfe9d59/details
 
I mean the email was sent from a legit corporation, so that way it would seem more legit for people who are not that "tech-savvy".

It just so happens that im expecting a package from DHL any day now. And when i saw the email was legit, i had to think for a second.

I never clicked of course, but i did pause for a second.
 
Back
Top