http://biblemeowimkh3utujmhm6oh2oeb3ubjw2lpgeq3lahrfr2l6ev6zgyd.onion/content/bible/darknetmarkets/how-to-verify-an-onion/how_ddf_dnl_were_hijacked/index.html
Even though the domain listed on the court order is registered through them, the web redirect is hosted with them, and the incoming email is hosted by them. So even though @Namecheap has all the evidence needed to stop not only one but two ongoing phishing attacks (the domain hijacked plus the domain used to do it) hosted by them, they refuse.