I've been a long, long term customer of Namecheap as well.
Domain privacy protection is a feature that Namecheap provides for all valid domains. Its included by default at no extra cost.
The poster didn't indicate if they had this feature enabled or not for the domain. It would have prevented the college club person from even seeing their email address to initiate a password reset.
This clearly isn't an answer for NC's customer support personnel and company policies.
But I've been a happy customer for many years and I discourage others from immediately reading other comments and rushing to jump to other registrars without doing your due dilligence.
Remember that in any situation, the people most likely to leave negative comments and reviews are the people that have had genuine bad experiences or feel like they've been slighted, even if unwarranted.
I did have domain privacy enabled. NC allows people to initiate a password reset via username, email address, or domain name.
I was a happy customer right up until this incident. And I certainly agree that due diligence is a must for something as critical as a registrar.
Agreed - I switched away from Namecheap, but do research. Don't just switch because a couple people on HN did.
Namecheap's privacy WHOIS still shows a unique email address so that the owner is reachable. Sending mails to it would have been forwarded to OP.
How is domain privacy relevant here? That only hides your email from public records. What if the attacker already knows it (as they did in this case)? Email address is quite literally something you are meant to share publicly. It is not a password.