Namecheap Reportedly Handed Customer Account to Stranger
24 Jul 2026
What happened
A Hacker News post titled "Tell HN: Namecheap gave my account to an unverified third party" describes an alleged account takeover at the domain registrar Namecheap. According to the customer — who says they had been with Namecheap for 13 years — an account registered under their own name, address, and phone number was accessed by someone identified only as an "incoming club leader."
The customer alleges that Namecheap changed both the account password and the associated email address after this third party called in and simply claimed the domain belonged to their club — without any verification of that claim.
What makes the incident notable is the apparent inconsistency in Namecheap's process: the customer says the company was able to call them directly to verify a separate support ticket, but did not apply that same verification standard when a stranger requested access to take over the account.
In the aftermath, the customer reports moving a dozen of their most critical domains away from Namecheap.
The core allegation
- An unverified caller claimed ownership of a domain on behalf of a "club."
- Namecheap allegedly changed the password and email on file without confirming the caller's identity or authority.
- The original account holder — verified elsewhere by Namecheap via phone — was not consulted before the change.
Sourcing caveat
This account currently comes from a single source (the Hacker News post itself), and there is no independent corroboration yet from Namecheap or other affected customers. Readers should treat the specifics as one customer's allegation pending further verification.
Why founders should care
For founders, this story is a reminder that domain registrars sit at a critical point of failure for online businesses — control of a domain can mean control of email, DNS, and ultimately customer trust. If the allegations are accurate, they suggest that identity verification processes at even established registrars may not be uniformly applied, which could plausibly increase the risk of unauthorized account changes for any business relying on a single registrar for critical infrastructure.
Founders who depend heavily on one registrar for mission-critical domains may want to consider what verification safeguards (such as two-factor authentication, registrar lock, or multi-party approval for changes) are actually enforced — not just advertised — before an incident like this affects their own accounts. Until corroborated, this remains an unverified single-source report, but the underlying risk it describes (weak identity verification enabling account takeover) is one many early-stage teams may find worth testing against their own providers regardless of this specific case's outcome.