First registry gets breach notice over new abuse rules
.TOP Registry allegedly ignored reports about phishing attacks and has become the first ICANN contracted party to get put on the naughty step over DNS abuse rules that came into effect a few months ago.
ICANN has issued a public breach notice claiming that the registry, which runs .top, has also been ignoring the results of Uniform Rapid Suspension cases, enabling cybersquatting to take place.
The notice says that .TOP breached new rules, which came into effect April 5, that require it to act on reports of DNS abuse (such as malware or phishing attacks) by suspending the domains or referring them to the responsible registrar.
The registry didn’t do this with respect to a report of April 18, concerning “multiple .top domain names allegedly used to conduct phishing attacks”. It didn’t even read the report until contacted by ICANN, according to the notice.
As of yesterday, only 33% of the phishing domains have been suspended by their registrars, some three months after the attacks were reported, ICANN says.
Compliance is also concerned that .TOP seems to be ignoring notices from Forum, the company that processes URS cases, requiring domains to be locked within 24 hours when they’ve been hit with a charge of cybersquatting.
The registry “blatantly and repeatedly violated” these rules, according to ICANN.
.TOP has been given until August 15 to get its act together or risk having its Registry Agreement suspended or terminated.
The registry has about three million .top domains under management, having long been one of the most successful new gTLDs of the 2012 round in volume terms. It typically sells domains very cheaply, which of course attracts bad actors.
The whole process still lacks of the definition of penalty.
The penalty is loosing the registry agreement and the TLD.
That’s very theoretical and why should they loose their TLD? Abuse Cases are used to hand over to the Registrar – case closed . We all know that Abuse mitigation is a farce on TLD site.
Referring to registrars and answering the complaint would suffice according to the agreement.
The effective date of the DNS Abuse amendments was 5 April 2024, not 2 April 2024. See https://www.icann.org/resources/pages/global-amendment-2024-en
Yup.
The CEO of .TOP Registry was at the recent ICANN Contracted Parties Summit in Paris. Btw, he does not speak English at all.
There are way too many possible moving parts in this to make any assumptions.
Plenty of people at ICANN speak Chinese last time I checked.
So all I have to say is “Me not speak Engrish” to not handle abuse reports ? Great, problem solved.