ICANN sent a notice of breach on September 25 to Netpia.com, Inc., the South Korean registrar that holds IANA ID 130. The letter, signed by Jamie Hedlund, ICANN’s senior vice president for global government engagement and contractual compliance, says Netpia is “in fundamental and material breach” of its Registrar Accreditation Agreement for one reason, unpaid accreditation fees, and “noncompliant” for two more: an RDAP directory service that ICANN’s monitoring finds “not functioning,” and no link on its homepage explaining how to request non-public registration data.
Netpia has until October 16, 21 days from the letter, to cure all of it, or “ICANN may commence the RAA termination process.”
The chronology attached to the letter brings together two sets of issues of very different age. The fee case opened on 7 January 2021 and has produced three compliance notices, five telephone calls and seven escalated notices since. The RDAP finding, the missing disclosure link and all seven of ICANN’s additional concerns come from a single line dated 23 September 2026: “ICANN conducted compliance check to identify other areas of noncompliance.” That was two days before the letter went out.
Key facts
- The age: only 39 currently accredited registrars carry a lower IANA ID than Netpia’s 130, which puts it 40th by that measure.
- The money: ICANN says Netpia “has made partial payments” but its account “has remained delinquent for a prolonged period,” despite agreed extensions.
- The website: the homepage does carry an abuse address, but it is labeled for misuse of personal data and the link behind it is malformed.
- The size: 5,931 .com domains in ICANN’s May report, rank 301 of the 2,948 registrars in that file, with 533 renewals and 14 transfers out.
| Registrar | Netpia.com, Inc., Republic of Korea, trading as ibi.net |
|---|---|
| Accreditation | IANA ID 130, status accredited, under a 2013-form RAA dated 18 January 2025 |
| Breach | Unpaid accreditation fees, Section 3.9 of the RAA |
| Noncompliance | RDAP directory service, Section 3.3.1 and the RDDS Specification. Disclosure-request link, Section 10.1 of the Registration Data Policy |
| Further concerns | Seven, under Sections 3.7.5.5, 3.17 and 3.18 of the RAA, the Registrar Information Specification and the Expired Registration Recovery Policy |
| Cure deadline | 16 October 2026, 21 days from the notice |
Five Years on the Fees, Two Days on Everything Else
Case 00999026 opened with three compliance notices in January 2021, on the 7th, the 18th and the 29th. Each records the same outcome: “No response was received from the Registrar.” Two telephone calls in February and April 2021 did reach a secondary contact, who was given the case details. Then the file stops for more than four years.
It resumes on 16 June 2025. A call in July 2025 reached the registrar’s main contact number, and emails that month were judged “insufficient to demonstrate compliance,” the phrase ICANN then repeats against every reply Netpia sends. From February 2026 the notices become escalated ones, seven in all. The first went out by email and fax on 4 February, then one in May, two in June, two in July and one on 13 August. The last of those drew no response at all.
Netpia’s public-facing business is still active. Its trading site at ibi.net sells .com, .net, .kr and other domains, hosting, SSL certificates, website building, online advertising and trademark registration, all in Korean, and carried a Chuseok holiday support notice dated 16 September 2026 when we looked. The company built its name in the early 2000s on a service that let users reach sites by typing Korean words into the browser address bar, which Telecompaper reported in November 2003.
The .com report shows the profile of a small, low-activity book. Which is the point of this letter. It is not about what Netpia’s customers do with their domains. It is about what the registrar pays, publishes and operates.
The Abuse Address Is on the Homepage, and the Link Is Broken
ICANN’s concerns about the website are specific, and the homepage repays a close look. Section 3.18.1 of the RAA requires an email address or webform on the home page to receive reports of DNS abuse and illegal activity. The footer of ibi.net does show an address, [email protected], but it is labeled in Korean as a channel for reporting misuse of personal information, which is a different thing from what the RAA asks for.
The link behind it does not work either. Its target is written as mailto:reportabuse@[email protected], with the domain duplicated, so a reader who clicks the only abuse address on the page gets an invalid recipient. The displayed text is correct and the link is not.
On the RDAP finding our own checks are worth stating carefully, because they do not show what ICANN’s monitoring shows. ICANN’s Service Level Agreement Monitoring system reports the service “not functioning,” detected “intermittently, with consistent ‘down’ results,” and says that while it is down “all sponsored domain name queries fail.” When we queried the registered base URL on September 29 and again on September 30, the root of rdap.ibi.net returned a two-line placeholder rather than an RDAP response, but a proper domain query to the same endpoint returned valid RDAP data on both days.
A base URL is not obliged to answer at its root, so the placeholder proves nothing on its own. The intermittency is ICANN’s finding, measured over time by a monitoring system we cannot reproduce from outside. What ICANN wants by October 16 is a service that answers for every sponsored name, the February-2024 version of the RDAP profile implemented, and one live domain uploaded to the registrar’s Naming Services portal so the monitoring has something to test.
What a Bulk Transfer Actually Does to a Registrant
October 16 is a cure deadline, not an automatic termination or transfer date. A breach notice is a demand with a deadline. Termination is a separate letter with its own effective period, as a recent case shows: ICANN terminated Fewmoretaps OU, trading as Trustname.com, on 27 August, and that letter set the termination to “become effective 11 September 2026, 15 calendar days from the date of this notice,” after what its own chronology calls “the fourth Notice of Breach over the course of 78 days.”
The two registrars are opposite profiles. Trustname was terminated under Sections 5.5.4 and 5.5.6, after four breach notices over its handling of abuse reports under Section 3.18, with the share of its domains reported for phishing rising from about 0.7 percent in January to about 10 percent by August. Netpia is a quiet legacy registrar at the first notice, and the breach ICANN names is unpaid fees under Section 3.9. Both moved through the same public compliance process under the same 2013 RAA, for very different failures.
If an accreditation does end, ICANN applies its De-Accredited Registrar Transition Procedure, under which the gTLD names move to a gaining registrar by bulk transfer. The losing registrar may propose that recipient, and ICANN weighs whether the two are related in a way that “could allow abuse or gaming” of the transfer, and whether the proposed recipient is in good standing with its own ICANN obligations. If no voluntary transfer is approved, ICANN picks the gaining registrar itself, choosing at staff discretion between a competitive application process and “a fast-track process in which ICANN selects a registrar from a pre-qualified registrar pool.”
For the registrant, ICANN’s own guidance on bulk transfers is more concrete than the procedure. There is no cost. But “unlike a normal inter-registrar transfer, the registration terms will not be extended by a year,” and the gaining registrar “may deny transfers for the first 60 days following the bulk transfer, at its discretion,” a lock ICANN describes as permissible under the transfer policy and intended to protect registrants.
That reverses the usual advice, and it is a reason for inventory rather than alarm. A hosting provider reselling through Netpia, or holding a Korean customer whose .com sits there, can confirm which registrar sponsors each domain, check that the registrant contact details are current, and make sure transfer authorization can be obtained if it is ever needed. Nothing here requires moving a domain before October 16. It is the 60-day restriction after a bulk transfer, not the cure deadline, that is worth knowing about in advance.
ICANN’s findings and the chronology are quoted from its notice of 25 September. The homepage and RDAP observations are ours, made on 29 and 30 September 2026, and may change. The .com figures are from ICANN’s May 2026 registrar transactions report, the latest posted, and the rank is our count of the registrars in that file. The count of older accreditations is our count of entries in the IANA registrar registry whose status is accredited. Netpia was not contacted for this article.
Sources
- Notice of Breach of Registrar Accreditation Agreement, Netpia.com, Inc. (IANA#130), 25 September 2026 - ICANN
- Notices of Breach, Suspension, Termination and Non-Renewal - ICANN
- Registrar IDs - IANA
- .com Monthly Registry Reports, per-registrar transactions for May 2026 - ICANN
- The 130th oldest domain registrar just got a breach notice - Domain Name Wire
- IBI.net - Netpia.com, Inc.
- rdap.ibi.net - Netpia.com, Inc.
- Netpia non-English search tool takes off - Telecompaper
- Notice of Termination of Registrar Accreditation Agreement, Fewmoretaps OU d/b/a Trustname.com (IANA#4318), 27 August 2026 - ICANN
- De-Accredited Registrar Transition Procedure - ICANN
- Bulk Transfers - ICANN