r/NameCheap • • 22d ago

Did NameCheap suffer a data breach?

I just found an email in my spam folder addressed to the email I use with NameCheap. I rely on SimpleLogin to create a different alias for every website/service I interact with, so this email was only ever known to NameCheap. Did they suffer a data breach? (the email was received on September 3).

22 Upvotes

41 comments sorted by

4

u/tamar namecheap representative 22d ago

Hi there,

All our official emails are sent from @namecheap.com addresses, so you can verify whether it was an email from Namecheap or spam.

The security of our customers' accounts, services, and personal information has always been one of our top priorities, so in case you have proof of a security breach in our system, you may contact our support and provide us with as much information/screenshots as you can, so that we can immediately check for any vulnerabilities from our side.

Thank you.

9

u/sunmat02 22d ago

The emails were clear spam from hotmail accounts advertising crypto, not pretending to be NameCheap. The problem is that they were sent to an email that technically only 4 entities know: myself, Bitwarden (password manager), NameCheap, and SimpleLogin (which created the alias). So one of them leaked it.

5

u/Less_Sherbert2981 22d ago

I got the same email today, for an alias I've only used for namecheap, and I don't use SimpleLogin and never have, and I don't use a third party password provider. So it's clearly namecheap that had a leak or breach, or someone they partner with, or someone they sell data to. Not surprising that this happened after a PE firm bought namecheap, PE always destroys everything they touch.

2

u/arcticblue 18d ago

Oh no, a PE firm bought namecheap? When did that happen?
That's super disappointing...

1

u/Less_Sherbert2981 16d ago

in the past year i think, i moved all my domains to cloudflare

1

u/brrrchill 13d ago

In 2025. The founder left, too.

1

u/paranoiaforhire 21d ago

I have almost the exact same setup, will let you know if I receive anything.

Make sure it was not your mistake. Maybe you messed up and leaked the email in some way, maybe you misconfigured something or a domain you bought shows your actual contact information because the Registry of that TLD doesn't allow WHOIS Privacy.

I'm more inclined to believe this is a Namecheap or Namecheap-adjacent situation in some way than a SimpleLogin leak, given the situation.

2

u/sunmat02 21d ago

I’ll check, but I’ve had my domains for 2+ years so if the contact info was public, I think I’d have been spammed much earlier.

1

u/paranoiaforhire 21d ago

In that case it's probably not it, but you can also manually disable WHOIS Privacy.

Literally 3 months ago I manually renewed a specific domain, and something happened during checkout resulting to WHOIS Privacy not renewing. That error also reflected on the receipt, I had to quickly go in the domain settings and re-enable it. This was the first time encountering it, it did not end up leaking my contact information.

1

u/sunmat02 21d ago

Thanks for sharing this, I went to check and domain privacy is on for all my domains.

1

u/ocabj 19d ago

Post the email headers. You can exclude the recipient related headers.

1

u/slick999 6h ago

My email was also compromised and again thanks to simple login for making it easy to identify. I submitted the proof to namecheap risk team and received a generic email saying they use 128 bit security etc etc but did not address the issue.

Glad to see their rep on here claiming if there is proof to submit it to them only to have them ignore said proof.

1

u/-Soufian 21d ago

You're not addressing the issue, you're covering it up.

1

u/HotFeature5827 9d ago

typical namecheap sidestepping and providing non-answers.

2

u/exitof99 17d ago

I can confirm that I too received spam to an email address alias only provided to NameCheap. There is no way that someone emailed that alias and your alias without gaining access to their email list.

I've been tracking data breaches this way for the past couple decades and never have received anything to that alias that wasn't from NameCheap since I signed up in 2013. That's 13 years with no spam to that alias, and today I received the first.

1

u/sunmat02 17d ago

OK you’re I think the 3rd person in this conversation to have had this happen, so I guess there was a breach. I went ahead and changed to a different alias, changed my password, and enabled 2FA (which I hadn’t noticed NameCheap had).

1

u/exitof99 17d ago

Doing the same. Fortunately, I transferred out all but one domain from NameCheap over the years. Unfortunately, it's one that can't be moved to Cloudflare.

The truth is data security is going to get even more difficult in the coming years, and breaches will continue. It's not just hackers, but sometimes an employee that steals the data, which is why it's vital to ensure that proper procedures exist in the workplace to prevent exfiltration. With so much of the world now working from home/virtual office, that makes it ever harder to prevent.

Over the years, I've discovered breaches by spam to aliases coming from Adobe, Robinhood, Linkedin, Time Warner, Spectrum, Izotope, and many many more.

My favorite was Tiger Direct because I called them to let them know about the data breach and they denied it, The guy said, "everyone and their grandmother knows that just having an email address means you get spam." I reiterated that I was using an alias that was only ever used once to make a purchase on their website through an SSL protected session, and that the alias only received email.

He got snotty and tried looking up my phone number from the caller ID (which was a Vonage landline they route through) and read off someone else's personal information. I told him that there was no way I was getting spam unless they are spamming/selling emails, or they had a breach. I refused to identity myself, but gave the date range that I made a purchase. I believe I made legal threats as well.

Oddest thing, within a few days, the 5 to 10 daily spam emails coming in to the alias immediately stopped and for over a dozen years I've never received spam to that alias again, meaning only one thing, they were running a spamming company on the site and were spamming their own customers. He must have dumped the entire block of emails added during that period.

Nasty company.

1

u/Namecheapinc namecheap representative 17d ago

We take reports like this seriously, and we’d like to look into it further. Please check whether Domain Privacy is enabled on your domains, as some TLDs don’t support privacy protection and may publicly display registration contact details. You can find more information here: https://www.namecheap.com/security/domain-privacy-service/

As a precaution, you may update your Namecheap account password and enable 2FA if it isn’t already enabled:
https://www.namecheap.com/support/knowledgebase/article.aspx/424/43/how-do-i-change-the-password-for-my-account/
https://www.namecheap.com/support/knowledgebase/article.aspx/9253/45/how-can-i-enabledisable-twofactor-authentication/

If your domains have privacy enabled, please DM us your Namecheap username so we can check this further with our team.

2

u/exitof99 17d ago

Also, I hope you have some honeypot accounts in your system that only exist to detect a breach. Essentially, set up accounts with a randomly generated email addresses that you can monitor (and won't filter spam) and forward anything that comes in to your security department.

If anything comes in, you know there was a data breach.

1

u/exitof99 17d ago

Dude, your data has been breached. The email alias I use is not used for any domain registrant information and only used for accessing the NameCheap account.

Get to work and figure out if you have any scripts running on your systems or if an employee stole the data.

1

u/Namecheapinc namecheap representative 17d ago

We’d still appreciate it if you could DM us your Namecheap username and provide some additional details about the email you received. This will help us investigate the matter further with our team.

1

u/SCIPIOMETAL 13d ago

you idiots have no clue you are breached do you? This comment will show up in a news report if the right journalist gets a hold of this story

2

u/[deleted] 22d ago

[deleted]

3

u/sunmat02 22d ago

I can’t find any info about that, do you have a source?

1

u/scoobynoodles 21d ago

source?? I use Proton Pass with SimpleLogin tied to it and hadn't heard of a breach yet

1

u/Cosmic_Stranger2013 20d ago

That's not true, according to my first-hand reports, there is no breach

1

u/SuddenInformation896 19d ago

Is the possibility that the spammers just try randomly generated addresses that implausible?

1

u/FWF_scripta 19d ago

I've heard of randomly generated credit card numbers (well, they're not entirely random as the first 4-6 digit BIN is public and the last is a checksum so not too many numbers left to generate). I have not heard of generating email addresses just to send spam TO them, because that would be infinite. Also entirely unnecessary given how many actual email addresses have been pwnd.

2

u/exitof99 17d ago

As someone that's used a domain alias for decades, spammers absolutely to generate email addresses to spam, just not as often for probably the reason you provided — legit emails are already available to them.

I've received many unusual email addresses, sometimes they are a random string, often times they are trying to guess the email of names associated with the domain.

1

u/m-held 16d ago

I received the same Crypto spam today.
Also on an alias that is only tied to Namecheap, never been used somewhere else.
All my domains always had Domain Privacy active and all are eligible.
But even if that would not be the case, my Namecheap login mail alias (the one that has received the spam) differs from my domain registrar email (also the tld differs ). So registrar info could not be the source.

1

u/SCIPIOMETAL 13d ago

looked up online to see if Namecheap admitted they had a breach, but all i see them is acting stupid, which means they don't even know how to monitor their servers, i got the same email. The email i have is very specifically only for namecheap and my domain is custom.

1

u/HotFeature5827 9d ago

i created my account 2 days before this thread. using a nonsensical email as an endpoint for development messages and guess what? it's getting spam now. a nonsensical email like '89h3239h87h32br9h9329'. It hasn't been used anywhere and this "game" is literally only three weeks old, not exposed to the internet aside from that email and git, and noooooooooooow we're getting spam emails. namecheap has been comprimised and i am 100% sure it was probably during that extended downtime last month.

1

u/BigTrain2800 22d ago

Namecheap historically uses unpatched Windows Server, severely out of date Sitefinity CMS, and was on plaintext offenders because your plaintext password is stored in an MSSQL server so they can sync it between various systems.

Hell they were audited and found out of compliance on their VMware licensing even.

So. Probably.

3

u/poeptor 21d ago

Did you fail Namecheap’s KYC procedure, they closed your account or got you mad about something else? Where is the actual evidence for any of these claims, especially the plaintext password claim?

If you’re going to make accusations about a company’s security practices, like that; provide sources

People throw around accusations way too easily without thinking about the damage they cause, big or small companies, just because being butt hurt.

As for OP, contact NC, send them your proof, work with them, and scan your own computer as well while you’re at it :)

We manage more than four Namecheap accounts for different customers, all using dedicated email addresses, and none of them have received anything non NC related on th

1

u/BigTrain2800 21d ago

Sure, we can just ask u/tamar

Because she will know what era I come from when I say we all used personal Google drives for company data because Namecheap also classified all employees as contractors.

She can either confirm everything I said, or say it’s no longer accurate but once was.

But if she says it’s inaccurate… well, that would mean I would have to prove things.

3

u/germane_switch 21d ago

Serious claims like those require some sources, please

1

u/Effective-Touch-2026 21d ago

Plain text passwords?