5 ms·
Correct. I'm surprised no one else has mentioned no 2FA for the email. The email being compromised opened the door to this happening.
by matthewdrussell 10y ago
Correct.
I'm surprised no one else has mentioned no 2FA for the email. The email being compromised opened the door to this happening.
- mbrameld 10y agoThe email being compromised opened the door to his email being compromised. The door to his Namecheap account being compromised was apparently already wide open.
- levemi 10y agoNo, OP didn't have 2FA enabled on their namecheap account. It was namecheap's fault for improper handling of the social engineering attack but OP could have protected themselves by having 2FA
- cname 10y agoThe article pretty clearly states 2FA was enabled for the Namecheap account in question. In fact, that is sort of the whole point of the article.
- levemi 10y agoOh this comment by CIO led me to think 2FA wasn't... https://news.ycombinator.com/item?id=11480221 https://news.ycombinator.com/item?id=11480221 You should not be able to overcome 2FA with social engineering wtf!