britechguy
Well-Known Member
- Reaction score
- 4,788
- Location
- Staunton, VA
Last night I decided I'd hop on to my Namecheap account to take a look at what's there for email records, even though I do not have any email routed through my domain. I had logged in probably 2 weeks ago.
Imagine my surprise when, after entering my userid and password, I was being prompted for an OTP. I've put MFA on quite a few of my accounts, but not this one, at least not yet. That's when the cycle of identity verification and ownership began.
I've submitted my payments via my credit card directly as well as via PayPal - not good enough/"doesn't match what we have." I've now been forced to submit my driver's license through a service called veriff.
My website's still up and there's definitely no ultra-sensitive information in that account that's not a matter of public record. The fact that my existing username and password still work, but I'm being hounded for an OTP is even stranger. I've only ever used Google Authenticator and 2FAS, with the latter being my current "go to" and neither has anything for Namecheap. Someone, somewhere obviously does.
Since I renewed for 5 years in 2022, we'll see how this all plays out. I've even checked my email archive as I keep notifications regarding MFA being enabled, and I've got nothing.
Strange.
The fact that I have 2 separate ID theft monitoring services from my involvement in the Anthem and Equifax breaches some years back gives me a bit of comfort as far as anyone attempting ID theft. Nothing's shown up as notifications from either regarding suspicious activity.
Imagine my surprise when, after entering my userid and password, I was being prompted for an OTP. I've put MFA on quite a few of my accounts, but not this one, at least not yet. That's when the cycle of identity verification and ownership began.
I've submitted my payments via my credit card directly as well as via PayPal - not good enough/"doesn't match what we have." I've now been forced to submit my driver's license through a service called veriff.
My website's still up and there's definitely no ultra-sensitive information in that account that's not a matter of public record. The fact that my existing username and password still work, but I'm being hounded for an OTP is even stranger. I've only ever used Google Authenticator and 2FAS, with the latter being my current "go to" and neither has anything for Namecheap. Someone, somewhere obviously does.
Since I renewed for 5 years in 2022, we'll see how this all plays out. I've even checked my email archive as I keep notifications regarding MFA being enabled, and I've got nothing.
Strange.
The fact that I have 2 separate ID theft monitoring services from my involvement in the Anthem and Equifax breaches some years back gives me a bit of comfort as far as anyone attempting ID theft. Nothing's shown up as notifications from either regarding suspicious activity.