Customers question TrustName’s response to alleged unauthorized transfers.

Several customers of TrustName, a domain registrar that received a de-accreditation notice last week, claim that their domains have been stolen from the registrar.
ICANN informed Fewmoretaps OU, d/b/a TrustName.com, last week that it would be de-accredited for its handling of abuse complaints.
The company pitched itself as a “bulletproof” registrar that would stand up for registrants who were likely to “face false or bad-faith abuse reports.”
Now, some customers are reporting that their domains have been stolen from the registrar in the wake of the de-accreditation announcement.
Ijon Tichy told Domain Name Wire that the day after the breach notice, some domains were pushed out of customer accounts to a single receiving account at the same registrar, then transferred to other registrars.
He said his domain was pushed to another TrustName account on August 28. He reached out to the registrar several times over the next few days, asking the registrar to add a transfer lock on the domain, but the registrar did not. The domain was transferred to Dynadot on August 30.
Tichy said he had two-factor authentication on his account. He can no longer log in; his password is accepted, but the two-factor code does not work.
Other customers are reporting the same issue.
They claim that two-factor authentication was on their accounts, and the receiving account for the domains was modastores@proton .me.
Tichy said that TrustName told him there were logins from Dushanbe, Tashkent, and Karachi, and relied on that apparent geographic spread (specifically that the receiving party accepted the push “from a different IP address and location”) to say that it could not conclude the transfers were unauthorized. He wrote:
I checked all four addresses against public registry data:
187.40.39.41 AS212238 (Datacamp) “Packethub Tajikistan” → Kelsterbach, Germany
187.15.124.30 AS212238 (Datacamp) “Packethub Uzbekistan” → Kelsterbach, Germany
187.40.236.9 AS212238 (Datacamp) “Packethub Pakistan” → Singapore
187.40.236.43 AS212238 (Datacamp) “Packethub Pakistan” → SingaporeOne autonomous system, four commercial VPN exit nodes, two data centres. The country names are VPN pool labels, not locations. The session that logged into my account and the session in which the “buyer” accepted the transfer both resolve to the same facility in Germany, minutes apart. The geographic separation the registrar relied on doesn’t exist.
Dynadot told Tichy to file a Transfer Dispute Resolution Policy claim with TrustName.
But with TrustName’s de-accreditation becoming official on September 11, Tichy wonders what happens to disputed domains during the de-accreditation window, when domains are transferred to another registrar through ICANN’s De-Accredited Registrar Transition Procedure.





Brilliant.
Definitely an inside job. 12 of my domains stolen in 3 minutes. Transfer not prevented by Trustname and all of them appear to be at dynadot.
The owner of Modafinilxl.com has paid trustname to steal all the domains. Since they lost ICANN accreditation so they sold it. All the domains are being redirected to either modafinilxl or their new sites. The NS are same, so you can check by yourself. Vitali from trustname did not help. We tried to reach him + 375292964411 as that is where we spoke very often before onboarding with them but they are not responding. They have stolen all domains as mentioned by other reviewers. Keep reporting your sites to ICANN so they will not be able to keep it in the same place and eventually you may gain control. Also report Modafinilxl.com and afinil.com as they owns them.
Inside job. We lost 25 domains in 140 seconds. All had 2FA. We filed in federal court this morning but it moves slow. We need ICANN and Verisign to act like this is an emergency and fix it fast. We have traffic and emails being intercepted.
Further context, Trustname gave us the exact same response as Tichy. They knew exactly what was actually going on. We had 2FA and had never accessed the account from anywhere but Arizona. Andrew, can you give this more noise?
Never trust someone who says “Trust me…” all the time.
The trust was in ICANN accreditation and Verisign. Amazing to me that they aren’t treating this like an emergency. The 60 day registrar transfer lock was somehow bypassed on one domain and the 60 day registrant contact update lock was bypassed on the rest. This should be throwing GIANT red flags at both ICANN and Verisign.
They were a domain registrar purely for criminals, this is absolutely hilarious!!!!!! Keep crying.. it’s no wonder they lost their ICANN accreditation, they didn’t give a sh.t about abuse reports.
Good riddance
Hahahahahha trustname was used by criminals for scam and phishing domains, no sympathy here.
Only crying cyber criminals lol!!!!!!!!
Warning for anyone whose domains landed at Dynadot.
Mine moved again: pushed inside TrustName 28 Aug, transferred to Dynadot 30 Aug, transferred to NiceNIC (Hong Kong, IANA 3765) on 2 Sep. Expiry extended twice in five days, 2031 → 2032 → 2033.
I asked Dynadot four times to hold it against further transfer. No hold was applied. Three days after it arrived, it was gone.
Check the registry record for each of your domains today, and ask Dynadot in writing to preserve the outbound transfer records — dates, the account they left from, and the IPs on the transfer requests. If they move on, those logs may be the only trace of where they went.
Unfortunately, DynaDot doesn’t cooperate at all, they say to take it up with the losing registrar (Trustname). Trustname just sent a blanket response: “Trustname has not identified sufficient evidence to conclude that the transfers between accounts and/or subsequent inter-registrar transfers were unauthorized or were processed contrary to the applicable ICANN Transfer Policy.”, to all customers that have a case open with them regarding this. I’m in contact with multiple affected users, all the same reaction.
Only route is to open an ICANN complaint for an Unauthorized Transfer but nothing is moving there besides the case being registered.
Same template response here, near enough word for word.
You mention you’re in contact with multiple affected users — I’d like to join that if it’s open. I’ve been doing this one to one and it’s slow. Is there an email or somewhere better than a comment thread?
For anyone weighing legal action: Fewmoretaps OÜ carries a court ruling on the Estonian register — Ä 50187242 / M3, warning for compulsory dissolution for insufficient net assets, in force since 08.06.2026, additional term to 08.12.2026. 2025 accounts show €418,369 revenue and a €78,116 loss, with losses every year since incorporation. Registry code 16354846, ariregister.rik.ee.
If interested here is the brief dossier: https://justpaste.it/h8a4v
Previous message was a Dossier for all this Trustname Business parties and associates
Everything was found open on Net, read and find out the answer – why that happened.
And it should be to happen in did.
Here is some info for oathresearch owners whose domain was also stolen
https://justpaste.it/dgy2s
Associated company in above dossier makes a Trademark for oathresearch in UK on Sept 1st instead of yours US one
Now you know who did that all – MODA…..XL
The owner of Modafinilxl.com has paid trustname to steal all the domains. Since they lost ICANN accreditation so they sold it. All the domains are being redirected to either modafinilxl or their new sites. The NS are same, so you can check by yourself. Vitali from trustname did not help. We tried to reach him + 375292964411 as that is where we spoke very often before onboarding with them but they are not responding. They have stolen all domains as mentioned by other reviewers. Keep reporting your sites to ICANN so they will not be able to keep it in the same place and eventually you may gain control. Also report Modafinilxl.com and afinil.com as they owns them.