3,593
Total Detected
400
Last 30 Days
9,737
Zone Scan Total
35.3%
Phishing Rate
35.3%
of all Trustname domains are confirmed phishing
— the highest contamination rate of any ICANN-accredited registrar in our dataset
— the highest contamination rate of any ICANN-accredited registrar in our dataset
Corporate Profile — Fewmoretaps OÜ (Estonia)
Registered inEstonia (OÜ)
FoundersBelarusian nationals
Declared annual revenueEUR 120
Employees1
EquityNegative
IANA accreditation#4318
Key Findings
Live report available: Full zone scan breakdown, registration burst timeline, and raw domain lists are published on GitHub Pages.
View Live Report- 35.3% phishing contamination — one in three domains is a phishing site. Across 9,737 total domains in Trustname's zone, 3,433 are confirmed phishing pages. This is not a registrar that has a phishing problem. This is a registrar whose primary operational purpose appears to be providing phishing infrastructure. No legitimate registrar operating in good faith reaches a contamination rate in this range.
- The corporate structure is a shell designed for regulatory evasion. Fewmoretaps OÜ is incorporated in Estonia, a jurisdiction that offers straightforward company formation to non-residents. The declared annual revenue of EUR 120 and single employee are inconsistent with any legitimate domain registrar business model. Registrar fees alone on 9,737 domains at cost would exceed this figure by orders of magnitude. The financial profile suggests revenue is routed elsewhere and the Estonian entity serves as a regulatory shield.
- Registration bursts confirm coordinated actor control. On 2026-06-15, 232 phishing domains were registered in a single day — 11.1 times the daily average for the platform. Burst activity of this scale within a registrar of 9,737 total domains indicates that a small number of actors, likely with privileged or automated access to Trustname's provisioning system, are directly driving registration. This is not customer abuse; this is operator-level activity.
- Negative equity and declared losses indicate the business has no viable licit revenue. Estonian commercial registry filings show Fewmoretaps OÜ carrying negative equity. A registrar collecting ICANN fees, domain registration revenue, and renewal income should not be running at a loss unless that revenue is not being reported. The financial structure is consistent with a front company maintaining legal ICANN accreditation while actual revenue flows through undisclosed channels.
- Abuse reports produce no action. Trustname has no functional abuse desk. Reports submitted by PhishDestroy and partner organizations receive no responses, and domains confirmed as phishing infrastructure remain active indefinitely. The absence of any takedown mechanism is not operational neglect — it is the product's feature, not its bug.
- ICANN accreditation gives this entity a veneer of legitimacy it has not earned. Trustname obtained ICANN accreditation (#4318) and uses it to operate as a Reseller-of-Record for phishing actors who need domain registrations to appear legitimate in WHOIS data. The ICANN accreditation process and ongoing compliance reviews have not detected or acted on the contamination rate documented here. The full dataset is structured for ICANN compliance intake.
Live Detection Feed
Most recent Trustname phishing domains detected by PhishDestroy. Updated continuously.
| Domain | Detected | Type / Brand |
|---|---|---|
| loading-domain-example.com | 2026-06-20 | phishing |
| another-fake-domain.net | 2026-06-20 | phishing |
| third-placeholder-domain.org | 2026-06-19 | phishing |
| fourth-placeholder-domain.com | 2026-06-19 | phishing |
| fifth-placeholder-domain.xyz | 2026-06-18 | phishing |
Evidence & Related Investigation
Related Articles