The author, a 13-year Namecheap customer, had their account compromised when a third party convinced Namecheap support to change the account password and email address without verification. The third party was able to do this by calling Namecheap support and claiming ownership of a domain registered to the author. The author was able to regain access to their account and has since moved many of their domains to a different registrar. The incident highlights a potential security vulnerability in Namecheap's support process.