TrustName Customers Report Domains Stolen After ICANN Warning

Customers question TrustName’s response to alleged unauthorized transfers.

Picture of shaded man in hoodie with the words

Several customers of TrustName, a domain registrar that recently received a de‑accreditation notice, say their domains have been taken from the registrar amid the de‑accreditation process. The notice, issued by ICANN last week, cited concerns about how the registrar handled abuse complaints. Since then, a number of registrants report apparent unauthorized pushes and transfers of domains that they believe occurred while the registrar’s account controls were compromised or mishandled.

TrustName marketed itself as a “bulletproof” registrar intended to protect registrants facing contentious or bad‑faith abuse reports. That positioning attracted customers who wanted strong resistance to takedown requests. But the recent de‑accreditation notice has prompted public scrutiny and renewed customer concerns about account security and transfer procedures.

One registrant, Ijon Tichy, told domain industry reporters that the day after the de‑accreditation notice, several domains were pushed out of customer accounts into a single receiving account at the same registrar, and then those domains were moved to other registrars. According to Tichy’s report, his own domain was pushed into another TrustName account on August 28. He immediately contacted the registrar multiple times over the following days asking that a transfer lock be placed on the domain, but the lock was not added. The domain was then transferred to another registrar on August 30.

Tichy also reported that he had two‑factor authentication (2FA) enabled on his TrustName account. After the incident he can no longer access his account: his password still registers as correct, but the two‑factor authentication code no longer works. Other customers have publicly described the same pattern—2FA enabled yet unable to prevent account takeover or a push to a receiving account—suggesting the issue may have affected multiple accounts.

Several of those affected say the receiving account for the pushed domains used an email address hosted at a privacy‑focused provider. Common details reported by multiple complainants point to a single receiving address appearing in several incidents, which customers say indicates coordination and a pattern rather than isolated errors.

In communications with Tichy, TrustName reportedly cited login activity from multiple geographic locations and different IP addresses, saying the apparent geographic spread made it difficult to conclude transfers were unauthorized. TrustName characterized the events as logins and transfer acceptance from varied locations and therefore not incontrovertible proof of fraud.

Tichy disputed that explanation. He investigated the logged IP addresses and found they all resolved to the same autonomous system and a small set of commercial VPN exit nodes and data centers. In his assessment, the geographic labels associated with those IPs were merely VPN pool names and not the true physical locations of the sessions. He noted that the session that logged into his account and the session that accepted the push both resolved to the same facility in Germany and occurred minutes apart, undermining the registrar’s geographic argument.

After the domain moved to the other registrar, that registrar advised Tichy to file a transfer dispute under the receiving registrar’s transfer dispute processes. At the same time, TrustName’s de‑accreditation became official on September 11, activating ICANN’s De‑Accredited Registrar Transition Procedure. That procedure moves management of impacted domains to another registrar during the de‑accreditation window and includes steps for notifying registrants and transferring records.

Customers like Tichy now face uncertainty over how disputed domains will be handled during the de‑accreditation transition. When a registrar is de‑accredited, ICANN’s process aims to ensure continuity of domain management and protect registrants, but registrants still must navigate transfer dispute procedures, potential delays, and coordination between multiple registrars. For domains already pushed or transferred during the de‑accreditation notice period, affected registrants may need to pursue transfer dispute filings, contact the gaining registrar, and document their account security settings such as 2FA and account change requests.

Industry observers note that registrants should always maintain current ownership contact details, use registrar locks where available, enable strong two‑factor authentication, and monitor account activity closely. When unexpected account changes occur, promptly documenting communications with the registrar, gathering IP and session data when possible, and initiating formal dispute processes are critical steps. As this situation evolves, affected customers and the wider registrant community will be watching how the de‑accreditation transition addresses alleged unauthorized transfers and whether additional safeguards or remediation measures are implemented.