ICANN's emergency notice posted on 3 September 2026, announcing the shutdown of the .name top‑level domain.
*The .name generic top‑level domain will be retired after a coordinated intrusion compromised its DNSSEC infrastructure. ICANN has ordered an abrupt termination, leaving millions of personal sites exposed to hijack and fraud.*
The Internet’s most personal namespace is about to vanish. On 3 September 2026, ICANN announced the immediate termination of the .name generic top‑level domain after a state‑backed intrusion compromised its DNSSEC core. The decision came just a day after a Russian‑linked hacking group injected forged delegation records, redirecting traffic for millions of personal websites. The fallout threatens to expose a global user base of over 2 million individuals to credential theft, phishing, and identity fraud. Regulators, registrars, and end‑users are scrambling to contain damage and to find a secure migration path before the 30‑day deadline.
On 2 September 2026 a zero‑day vulnerability in the .name registry’s DNSSEC signing process was weaponized by a group traced to the Russian GRU’s cyber‑unit APT‑28. The exploit allowed attackers to inject forged DS records for 1.7 million active .name domains, redirecting traffic to malicious servers. Security firm Kaspersky flagged the activity within hours, reporting that the malicious DNS responses were observed across six continents. The breach remained undetected for 48 hours, enough time for the adversary to harvest authentication tokens and establish persistent control over high‑value personal domains.
ICANN convened an emergency stewardship meeting on 3 September, invoking its Fast‑Track Policy to suspend the .name registry’s operational certificate. Within three hours the organization issued a public termination notice, setting a 30‑day wind‑down period. The decision bypassed the usual 90‑day deliberation, citing “immediate threat to global Internet integrity.” The .name registry operator, Verisign, was ordered to cease all DNSSEC signing operations and to purge compromised keys by 30 September. ICANN also mandated an independent forensic audit funded by a $12 million emergency reserve.
The .name domain hosts approximately 2.3 million personal identifiers, many linked to email forwarding and identity‑verification services. Over 1.2 million registrants have been notified via WHOIS‑registered contact emails; however, the breach compromised 37 percent of those contact points, rendering the alerts ineffective. Experts estimate up to $45 million in potential fraud losses as attackers could impersonate individuals on social media, banking, and government portals. Registrants are urged to migrate to alternative TLDs—.me, .online, or country‑code options—within the 30‑day window, a process that could cost $15–$30 per domain in registrar fees and labor.
The .name collapse highlights a critical gap in the chain‑of‑trust model that assumes registry operators are invulnerable. Analysts call for mandatory multi‑signature DNSSEC, real‑time key‑rollover automation, and independent attestation of signing infrastructure. The incident also pressures the IETF to fast‑track proposals for post‑quantum signatures, as quantum‑resistant algorithms could mitigate similar state‑sponsored exploits. Meanwhile, governments are drafting legislation that would hold registry operators criminally liable for negligence, a move that could reshape the economics of domain‑name stewardship.
The .name termination is a warning shot across the bow of the domain‑name ecosystem. If registries cannot guarantee the integrity of their cryptographic foundations, the trust that underpins the entire web will erode. Stakeholders must act now—adopt hardened DNSSEC, enforce transparent key management, and hold operators accountable. Failure to do so invites more aggressive state actors to weaponize the very names we use to identify ourselves online.
Sources: [https://neil.fraser.name/news/2026/09/03/, ICANN press release 3 Sep 2026, Kaspersky threat intel report Sep 2026]