I’ve been a NameCheap customer for 13 years. I’ve also helped out an old college club paying for a .com they use (that is registered to me under my name, address, and phone number)…

The incoming club leader was persistent though, and called NameCheap support. He convinced them the domain registered in my name and address really belonged to his club, and with no verification or validation whatsoever, NameCheap changed my password, and changed the email address associated with my account. All because someone simply asked nicely on a phone call. Meanwhile in the background, someone advised the new club leader who I was and we were able to connect and get things transferred over. Ultimately I was happy to give them access or even ownership if they wanted (student club turnover being what it is, it’s likely a domain doesn’t get renewed and gets gobbled up by a squatter, which is why I was keeping it current for them). But NameCheap had no way of knowing any of this. As far as NameCheap was aware, this was a personal account of mine. They demonstrated they were perfectly able to pick up a phone and call me (to verify my initial support ticket) but when someone calls them and says “but I really want access to that account” they don’t bother? I’d hesitate to even call this social engineering. It’s clearly a massive vulnerability. I’ve already moved a dozen of my most critical domains out of NameCheap after seeing just how easy it is for a third party to completely take over a NameCheap account: just ask nicely. It would be nice to have a nonprofit registrar so jumping every few years isn't necessary. There's a certain threshold above which you want to use the "law firm with in-house domain registry" type. I think the threshold is pretty high though, definitely "call us for a quote" territory. But you will notice that big companies like Amazon and Google that have their own registry, don't use it for their critical domains - such as Google.com or Amazon.com. This makes total sense to me. I'm not saying it solves all problems but it eliminates so many of them, including a meta problem: the risk of new classes of problems being unexpectedly introduced (by say a private equity acquisition or similar). If domains themselves are the profit center, you are likely in trouble if there's really any incentive for them to make incremental revenue in such a competitive market. Doing 'the right thing' just of course will not factor in if there's really no reputation at stake.