Domain Registrar Namecheap Sent Phishing Emails to Its Customers

Namecheap sent out phishing emails

Domain registrar Namecheap’s email was hacked last weekend and the company sent a flurry of phishing emails (allegedly from MetaMask and DHL) to users. In this way, hackers tried to steal recipients’ personal information and cryptocurrency from their wallets.

Let me remind you that we also wrote about IceBreaker Backdoor Emerged, Exploiting New Phishing Way, and also, you might be interested to know Why Phishing is Still the Most Common Cyber Attack?

The media also indicated that Meta sues operators of 39,000 phishing sites.

The phishing emails originated from SendGrid, an email platform historically used by Namecheap to send notifications and marketing emails.

After recipients of strange emails started complaining about the incident on Twitter, Namecheap CEO Richard Kirkendall confirmed that the company’s account had been compromised, and now an option of sending mail via SendGrid was urgently disabled while the investigation was underway. However, this tweet was later deleted.

Kirkendall also wrote that, according to Namecheap experts, this attack could be related to a recent CloudSek report, where researchers warned about exposing Mailgun, MailChimp and SendGrid API keys in mobile applications.

Phishing emails sent by hackers as part of this campaign were disguised as notifications from DHL or MetaMask. For example, emails from fake DHL allegedly contained shipping invoices that had to be paid to complete the delivery of the package. In fact, the links embedded in these messages led to a phishing page where they tried to steal data from the victims.

In turn, the fake letter from MetaMask imitated a request for a KYC (Know Your Customer) check, otherwise the wallet would allegedly be suspended.

These emails contained a Namecheap (https://links.namecheap.com/) marketing link that redirected victims to a phishing page posing as the MetaMask website. On this page, the user was prompted to enter their seed phrase or private key.

Namecheap sent out phishing emails

Later, Namecheap representatives released an official statement, according to which the company’s systems were not hacked, and the problem was related to an unnamed third-party system that the registrar used to work with mail.

We have evidence that a third party upstream system we use to send emails has been involved in sending unsolicited emails to our customers. As a result, you may have received a number of unauthorized emails. We would like to assure you that Namecheap’s own systems have not been hacked and your products, accounts and personal information remain safe.the registrar said.

Although Namecheap did not say which upstream system they were talking about, the company’s CEO himself confirmed on Twitter that the company uses SendGrid to work with mail (this was also confirmed by the headers of the phishing emails).

Interestingly, at the same time, the developers of Twilio SendGrid assured Bleeping Computer journalists that this incident had nothing to do with hacking or compromising their systems.

We are aware of the situation regarding the use of our phishing email platform and our anti-fraud, compliance and cybersecurity teams are already looking into it. This situation is not the result of a breach or compromise of the Twilio network. <…> We are still investigating the incident and cannot provide any additional information at this time.Twilio SendGrid representatives said.

By Vladimir Krasnogolovy

Vladimir is a technical specialist who loves giving qualified advices and tips on GridinSoft's products. He's available 24/7 to assist you in any question regarding internet security.

Leave a comment

Your email address will not be published. Required fields are marked *