Domain registrar Name.com attacked, customer passwords reset
Internet registrar Name.com on Wednesday revealed it was hit by a security breach. The company sent an email to its customers informing them that their usernames, email addresses, passwords, and credit card account information “may have been accessed by unauthorized individuals.”
The good news is that the last two were encrypted, according to Name.com’s email. Details on what encryption was used, however, was not revealed (Update: 4096-bit RSA encryption), but the company did say:
Name.com stores your credit card information using strong encryption and the private keys required to access that information are stored physically in a separate remote location that was not compromised. Therefore, we don’t believe that your credit card information was accessed in a usable format. Additionally, your EPP codes (required for domain transfers) were unaffected as they are also stored separately. We have no evidence to suggest that your data has been used for fraudulent activities.