Enjoy unlimited access to all forum features for FREE! Optional upgrade available for extra perks.

Nominet account theft

Status
Not open for further replies.
Joined
Mar 29, 2011
Posts
6
Reaction score
0
Hello everyone,

I’ve recently had an unsettling experience with Nominet that makes me question the safety of my UK domains. I don’t want to go too deep with specifics because this investigation is still on-going. Anyway, I own about 40 UK domains, all them being 1 and 2 word domains, and a few days ago I couldn’t login to my Nominet account – after several unsuccessful login attempts I decided to change my password using the “Access Your Account” section of Nominet. After waiting 24 hours and still no reply I decided to check my account with my registrar and that’s when I noticed one of my UK domains had vanished from my account. To cut a long story short, someone had changed the email address associated with my Nominet account and reset the password to gain access. Then transferred one of my domains into a separate Nominet account, re-tagged it and then transferred it again into their own Nominet account. I could have lost all of my UK domains but I got Nominet to lock the account before anything else could be re-tagged.

What I wanted to know more than anything was “how did they manage to reset the email address associated with the Nominet account?” Nominet said it was done by my registrar!? But I thought registrars couldn’t alter the details on a Nominet account but apparently, according to Nominet, they can change anything accept the whois details (ownership info).

Anyhow, my question is this; “Can a registrar change the admin email associated with a Nominet account?” If so, how without permission from myself?

I now know the person responsible for all this and I want to prosecute. Just to clarify, they’ve fraudulently gained access to my account which has all my person details listed, then change my details to their own, transfer one domain out of the account and pay the £10 transfer charge, then leave my account in limbo. Who knows what else they would have done if I didn’t get Nominet to lock it down. I had to write a letter to Nominet explaining the situation before they released my account back to me, which they did today, but I will have to wait while Monday before I get the stolen domain back.

My main goal is to find out how this happened, how this can be prevented from happening again and to sue the hell out of the thieving git who stole my domains.

Any advice would be greatly appreciated, especially with the suing part. Do I contact the cyber division of the police!?

Thanks for reading.
 
Anyhow, my question is this; “Can a registrar change the admin email associated with a Nominet account?” If so, how without permission from myself?

Yes, they can. My guess is that someone has either contacted the registrar pretending to be you, or has gained access to the account you hold with your registrar and updated the admin email themselves.

Do I contact the cyber division of the police!?

It has never happened to me, but I would assume as it's theft and therefore a criminal offence you would be able to report it to the police. With regards to civil law, best you take legal advice to find out what exactly you would be able to seek damages for.

Most important thing is to keep full evidence and as much documentation you can get as proof for when it's needed.

If you are concerned about security you could always apply for your own registrar 'tag' which would allow you further control over your domains.
 
Yes, they can. My guess is that someone has either contacted the registrar pretending to be you, or has gained access to the account you hold with your registrar and updated the admin email themselves.

If you are concerned about security you could always apply for your own registrar 'tag' which would allow you further control over your domains.

Thanks for the quick replies.

They definitely didn’t gain access to my registrar account – I’d know if they did because it logs all IP addresses that login to the account. They could have contacted the registrar pretending to be me, that’s certainly plausible.

I was hoping there would be a division of police that specialised with online crimes – I have a feeling the regular police won’t take it seriously.

Thanks for the info on applying for my own tag, didn’t know that was possible, I’ll look into it.
 
...If you are concerned about security you could always apply for your own registrar 'tag' which would allow you further control over your domains.

Can't help highlighting that a tag shouldn't be necessary if a system is secure enough.
 
Can't help highlighting that a tag shouldn't be necessary if a system is secure enough.

Very true and I completely agree, however having a tag reduces a variable in the security of domains (i.e. external registrars).
 
Unfortunately it's not one system with just Nominet and the Registrant in the loop. There are Registrar's involved who can[/U ]change the email address associated with an account. So that's a potential weak link in the chain, if they are persuaded to make changes to a Registrant account frauduently. From reading through what the original poster has stated, what didn't happen was a change of Registrant. One very good thing about.uk is in this kind of situation, one call to Nominet and everything will be locked and can be easily undone. That's not possible in gTLDs because Registrants never deal with the Registry.


The registrant was changed on the one domain that was illegally transferred out of my Nominet account. All the other domains where locked down quickly. The only reason I was easily able to get Nominet to transfer the stolen domain was because they could see the blatantly obtuse way it was stolen.
 
how this can be prevented from happening again......

As the admin email address is the key to everything Nominet, at the very least, need to start sending a notification to the existing admin email address whenever it's modified.

Grant
 
As the admin email address is the key to everything Nominet, at the very least, need to start sending a notification to the existing admin email address whenever it's modified.

Grant

Agreed. Plus, registrars should not be allowed to change any details within Nominet. If I’d looked in my account a few days later I could have seen more than one domain disappear.
 
Status
Not open for further replies.

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Featured Services

Sedo - it.com Premiums

IT.com

Premium Members

AucDom
UKBackorder
Register for the auction
Acorn Domains Merch
MariaBuy Marketplace

Domain Forum Friends

Other domain-related communities we can recommend.

Our Mods' Businesses

Perfect
Service
Laskos
*the exceptional businesses of our esteemed moderators
Top Bottom