This is not a complaint to ICANN. ICANN is a technical body — it standardises DNS resolution and allocates IP space.
It was not designed to stop wire fraud. The RAA §3.18 acknowledgement requirement exists on paper.
In practice, enforcement is a multi-year process of letters and reviews,
measured in months while victims are measured in dollars lost per hour.
That is the wrong regulator for this problem.
This is about money flows.
Every domain in this dataset generated a registration fee. Every renewal generated another.
Every day an abuse report sat unanswered, the registrar collected revenue from an active fraud operation.
That is not a compliance gap — that is a business model.
Registrars are not passive infrastructure. They are the
first and only chokepoint
that can kill a fraud domain in 24 hours — no court order required.
Their choice not to act is a decision with a revenue motive attached.
The "not our jurisdiction" defence does not survive
contact with one question: then why are you cashing the check?
The Deliberate Choice
Exclude the newcomers — the inexperienced operator who found a registrar via a Google ad or picked the cheapest option.
Organised scam teams don't pick registrars by price.
They pick by track record: which registrar ignores abuse reports, which privacy shield survives a takedown attempt,
which reseller delivers domains fast with no questions asked.
In CIS-language fraud forums and Telegram channels, registrar recommendations circulate as operational intelligence.
There are black-market resellers — "bulletproof domain" brokers —
who specifically source from NICENIC, NameSilo, and similar registrars and sell to scam teams pre-configured.
These resellers exist because these registrars reliably do not act on abuse reports.
That is the product being sold.
When the same operator fingerprints — email clusters, favicon hashes, server stacks — appear across hundreds of domains
registered at the same registrar over months: that is not coincidence.
That registrar's non-enforcement is documented institutional knowledge in the criminal ecosystem.
The question is not why scammers keep buying from NICENIC or NameSilo.
The question is why NICENIC and NameSilo keep selling to them.
"We Never Received Any Reports"
PhishDestroy is not the only source. Every major registrar receives abuse reports from
APWG, PhishTank, national CERTs, ISACs, brand protection teams, and individual researchers — continuously, in volume.
There is no global centralised body that audits whether those reports are actually processed,
no mandatory disclosure requirement, no independent verification.
A registrar can claim to have received nothing, and there is currently no mechanism to prove otherwise at speed.
NameSilo received documented abuse reports from PhishDestroy alone — more than 20, with full evidence packages,
timestamped, on record. Their public position was that they had received nothing.
That is not a miscommunication. That is a lie.
The same pattern is predictable across Russian-connected registrars: when confronted,
the default response will be "we never received any reports." It is the only legally useful position —
because receiving a report and ignoring it is not the same as never receiving one.
Receiving an abuse report and ignoring it is not negligence.
Negligence is an accident. Receiving documented evidence of an active fraud domain,
taking no action, and collecting the renewal fee is a choice.
That choice has a name: complicity.
When NameSilo responded to documented abuse of xmrwallet[.]com —
a Monero drainer with $10–20M in confirmed victim losses —
by offering to clear its VirusTotal detections
rather than suspending the domain: that was not a mistake. That was a choice.
Real audience for this data
FBI IC3
FinCEN
Europol EC3
CISA / NCSC
Interpol IGCI
Journalists
Legislators
Threat Intel Teams
One Domain Suspended Is Not Enforcement
There is a measurable difference between registrars that treat abuse as a
compliance checkbox and those that treat it as a
business policy.
Responsible registrars — the ones that do not want fraud operators as clients —
respond to a confirmed abuse report by suspending the entire account:
every domain registered by that operator, in one action.
They have seen the account. They know what it is.
The registrars documented in this investigation respond differently.
A complaint arrives. One domain — the reported one — may eventually be suspended.
The other 200, 500, or 1,000 domains on the same account
continue operating.
The operator registers new ones the same day.
The registrar has seen the pattern. They have chosen to look away.
KYC and reseller vetting requirements exist on paper.
In practice they are either absent or trivially bypassed —
a formality that provides legal cover without creating any actual barrier
to a fraud operator opening an account and registering domains at scale.
Our non-public investigation into registrar intake processes, conducted prior to this report,
found no meaningful friction at the account-creation stage for the registrars examined here.
Responsible registrar
- Abuse report received
- Account reviewed — pattern identified
- Entire account suspended
- All domains on account killed
- Operator loses infrastructure
Complicit registrar
- Abuse report received (maybe)
- Account reviewed — pattern ignored
- One domain suspended
- 499 domains continue operating
- Operator registers replacements
Every domain in this dataset is a receipt.
The receipt exists whether the registrar acknowledges the transaction or not.