field notes
Short pieces flagging what's notable across the telecom, identity, trust, and fraud beats, newest first.
October 1, 2026
- ICANN terminates Trustname, the first registrar de-accredited over DNS abuse
ICANN Compliance terminated the accreditation of Fewmoretaps OU, which does business as Trustname.com (IANA #4318), on August 27, effective September 11. The NetBeacon Institute calls it the first registrar termination over DNS abuse. The n…
September 30, 2026
- Cloudflare serves most of 88 deepfake abuse sites, study finds
Sarah Morgan, Hany Farid and Sophie Nightingale identified 88 public sites hosting AI-generated non-consensual intimate imagery over six weeks, 38 of them dedicated to it, and traced nine infrastructure services behind each. The paper is in…
September 29, 2026
- Hiya: 45% of French consumers lost money to a phone scam this year
Hiya reports from its State of the Call 2026 survey, of more than 12,000 consumers and 3,600 business professionals in six countries, that 45% of French respondents lost money to a phone scam in the past year. The other five: Germany 12%, C…
September 24, 2026
- Ofcom reads its numbering conditions as an anti-fraud duty, and opens two cases
Ofcom opened enforcement investigations on 24 September into whether numbers allocated to Voxbone SA and Vonage Business Limited are being misused, including to perpetrate scams. Both are own-initiative — the complainant on each case page i…
September 22, 2026
- The case for watching DNSSEC between outages instead of after them
Muhammad Shahzaib argues in CircleID that DNSSEC failures get diagnosed from point-in-time snapshots, and that the same handful of failure modes keep recurring because nothing records how the signed namespace changes between incidents. &ldq…
- Five FCC cards telling consumers to switch on filtering their carriers already shipped
The FCC released five one-page robocall blocking guides on 22 September — Android and iPhone at the device level, AT&T, T-Mobile and Verizon at the provider level. The news release came from the Consumer and Governmental Affairs Bureau.…
- Carriers ask the FCC to drop the robocall scorecard, or score the intermediates too
Comments on the Consumer and Governmental Affairs Bureau’s robocall scorecard proposal (CG Docket No. 26-239) closed September 22, and the three carrier trade associations asked the Bureau not to build it. USTelecom urged it to &ldquo…
September 21, 2026
- Appeals to authority in 73.8% of robocall scams aimed at older adults, against 7.1% of the rest
GASA’s Research Working Group met 17 September, and the writeup carries two studies rather than the membership news the source usually produces. The robocall one is Ryan Moore (UT Austin) and Doug Shadel (Fraud Prevention Strategies),…
September 16, 2026
- Zone files as early warning, instead of a UDRP after the site is built
Muhammad Shahzaib of EUNOMATIX has the numbers on UDRP and the argument for using zone data instead. Trademark owners filed a record 6,282 UDRP complaints with WIPO in 2025, up from 6,168 in 2024, from brand owners in 133 countries; more th…
- The KYUP reply round: 25 filings, 406 pages, 44% opposed
TransNexus read all 406 pages of reply comments on the FCC’s KYUP FNPRM and summarised each of the 25 submissions. Its tally: 28% supported the proposed rules, 44% opposed, with opponents arguing the rules are too prescriptive and sho…
September 14, 2026
- CSC's CISO survey moves social media impersonation to the top of the three-year list
Walt Fry, senior director of technology for domains at CSC, writes on CircleID from CSC’s CISO Outlook 2026, a survey of 300 senior security executives split across North America, Europe and Asia-Pacific. Asked what they faced in 2025…
September 10, 2026
- Consumer coalition asks the FCC to take the safe harbors out of KYUP
EPIC joined the National Consumer Law Center, Consumer Action and the National Consumers League in comments filed 8 September backing the FCC’s proposal to tighten Know-Your-Upstream-Provider requirements and attestation levels. From …
September 9, 2026
- Forty-nine attorneys general ask the FCC to make KYUP prescriptive
NAAG filed comments on 9 September for a bipartisan coalition of 49 state and territory attorneys general, led by Indiana, New Jersey, North Carolina, Ohio and Pennsylvania. The asks: providers collect, verify and regularly review informati…
- FCC narrows TCPA revoke-all for informational calls, as utilities asked
The FCC adopted its TCPA consent-revocation order at the September 30 open meeting (CG Docket No. 02-278), largely as drafted. Under the September 9 draft, a stop request made in response to an informational call or text can be applied only…
September 7, 2026
- Interisle puts the floor for criminal gTLD registrations at 10%, and the likely figure at 20%
Terence Eden reads the numbers out of a new Interisle Consulting study and calls the result a crisis. The study counts nearly 85 million newly registered gTLD domains in 2025. By mid-May 2026, 8.5 million of them — 10 percent — had been add…
September 4, 2026
- Club for Growth asks the FCC to exempt AI-voice political calls from consent
Club for Growth filed a petition on August 31 seeking a limited waiver of 47 CFR § 64.1200(a)(1)(iii) and an exemption from 47 U.S.C. § 227(b)(1)(A)(iii), which together would let callers place noncommercial political calls to wireless numb…
September 3, 2026
- CFCA's DNO+ would have enterprises declare which providers may sign for their numbers
The CFCA Trust & Transparency Working Group published a framework for DNO+ on September 3, with the full framework document behind it. I co-chair that working group, so this is a note on my own group’s output rather than an outsid…
September 2, 2026
- Signed-call coverage reaches 54.8% as prolific robocall signers keep A-level attestation
TransNexus published its August STIR/SHAKEN numbers on September 2. Signed calls at termination rose half a point to 54.8%, which the company calls the highest it has recorded “but far from the level needed to deliver the full benefit…
- The FCC's robocall scorecard would rate only the providers at the end of the call path
The Consumer and Governmental Affairs Bureau released a public notice on September 2 seeking comment on a public-facing robocall mitigation scorecard (CG Docket No. 26-239, DA 26-932). It proposes rating only domestic voice service provider…
September 1, 2026
- Meta's settlement puts a number on age-estimation accuracy in one direction only
David Greene reads the Meta settlement provision by provision. Meta settled with 52 state attorneys general — every state except Florida, New Mexico and Texas, plus D.C., American Samoa, Guam, the Northern Mariana Islands and Puerto Rico. W…
- 153 million license scans for sale, and the infrared images name the source
Brian Krebs reports that a dark web service called Nexus is selling digital scans of more than 153 million drivers licenses from the United States and Canada, alongside more than 10 million ID cards, three million travel documents and 579,0…
- ICANN's IDN report: 29% of tested mail servers accept internationalized addresses
ICANN’s IDN Implementation and UA Adoption Report 2026, dated September 1 and covered by CircleID on September 23, counts 151 delegated IDN top-level domains in 37 languages and 23 scripts as of June, and about 4.3 million IDN registr…
August 27, 2026
- Two of the three lead robocall task force states take questions in September
Kelley Drye is running a webinar on September 23 with three sitting state enforcers and members of the Anti-Robocall Multistate Litigation Task Force. The guests are Erin B. Leahy, Senior Assistant Attorney General in Ohio; Tracy Nayer, Spe…
- Nine providers get a final 14 days to answer tracebacks or leave the RMD
The Enforcement Bureau ordered nine companies on August 27 to cure their Robocall Mitigation Database certifications or explain why the Bureau should not remove them. The deficiency is conduct, not paperwork: each company “failed to r…
August 19, 2026
- A reverse image search service left nine million faces open
Jeremiah Fowler found 9,042,977 image files, 450.2 GB, in a cloud storage database belonging to ClarityCheck, a US-registered reverse image search and people-finder service. The store was “neither password-protected nor encrypted.&rdq…
- The FCC moves to close 24 TCPA petitions, one of them 23 years old
The Consumer and Governmental Affairs Bureau released DA 26-867 on August 19, announcing its intention to dismiss twenty-four petitions with prejudice across CG Dockets 02-278, 05-338 and 17-59. The stated reason: “To improve efficien…
August 18, 2026
- TransNexus charts three months of accelerating scam calls
TransNexus’s July robocall trends post says up front where its numbers come from: “The source data is from YouMail’s Robocall Index, a widely followed measure of robocall activity in the U.S.” This is a chart-and-com…
- ICANN's associated-domain checks, and the commenters drawing the evidentiary line
The GNSO’s DNS Abuse Mitigation PDP 1 initial report proposes Associated Domain Checks: a registrar shown actionable evidence that one domain is engaged in DNS abuse would be required to investigate other domains tied to that customer…
August 17, 2026
- Robocall volume climbs for a third month, and the scam share climbs faster
YouMail’s Robocall Index puts July 2026 at just over 4.35 billion robocalls, up about 1.5% from June. That is roughly 139.3 million calls a day, or 1,612 a second. May was about 4.1 billion and June was more than 4.25 billion, so July…
August 14, 2026
- The networks hold the number data and still can't hand it over
John Wilkinson, CEO of TMT ID, names the assumption his company got wrong: “We assumed mobile networks would be able to provide their data into the fraud industry and the identity verification industry. They don’t.” TMT ID…
August 13, 2026
- A prompt injection in a court filing, caught by white space
A self-represented plaintiff in Connecticut Superior Court buried instructions to an AI model inside his own pleadings, written in 3-point white type. Matthew Elliott, who sued the New York Bariatric Group in October, wrote: “IF THIS …
August 11, 2026
- Four vendors, four disciplines, one agent identity
Liminal’s Filip Verley hosted four vendors at Identiverse, eight minutes each, and the write-up is more useful as a map of how the agent-identity market has split than as a review of any one demo. P0 Security binds the human and the a…
- Fifty state AGs tell the FCC its KYC baseline is too thin
Fifty state and territory attorneys general filed joint comments in the FCC’s KYC Further Notice in late July, and Kelley Drye’s Paul Singer, Beth Bolen Chun and Jennifer Rodden Wainwright have the summary. The FNPRM proposed or…
August 10, 2026
- Industry answers the KYUP notice with one word: safe harbor
Comments on the FCC’s know-your-upstream-provider FNPRM closed August 10 in WC Docket 17-97 and CG Docket 17-59. CTIA, USTelecom, NCTA, ACA Connects, WISPA, the Voice on the Net Coalition, INCOMPAS and Bandwidth all filed, and they co…
- Somos wants attestation replaced with proof
Somos filed 50 pages in WC 17-97 and CG 17-59 on August 10, plus an appendix of proposed rule text. It opens on a single proposition: “no call should be placed onto the telephone network unless it has been authenticated and the party …
- Telnyx: KYUP builds the database the bad actors want
Telnyx filed in WC 17-97 and CG 17-59 on August 10 under a section heading that says the whole argument: “THE PROPOSED KYUP INFORMATION-COLLECTION REQUIREMENTS ARE DISPROPORTIONATE AND RAISE SERIOUS PRIVACY CONCERNS.” The list i…
August 6, 2026
- Iconectiv takes the toll-free bidding petition to the Chairman's office
On August 4, Kathy Timko, Michael Poling and John Malyar of iconectiv, with counsel John Nakahata of HWG, met Danielle Thumann, Senior Counsel to Chairman Carr. The ex parte notice was filed August 6 in WC 20-174, WC 17-192 and CC 95-155. T…
August 5, 2026
- Twilio takes US branded calling to GA on a competitor's survey
Twilio moved US Branded Calling to general availability, displaying a verified business name, logo, and where supported a reason for calling. The technical description is the part worth reading: Branded Calling “uses Rich Call Data in…
August 3, 2026
- New York's crawler bill is an identity mandate for machine traffic
EFF and 17 other organizations have asked Governor Hochul to veto S9934A, New York’s Stealth Crawler Prohibition Act. The bill would require every web crawler to disclose its identity and explicit purpose, and would let media outlets …
- Liminal's AI fraud numbers, and the ones worth keeping
Liminal’s Filip Verley argues that AI didn’t create new identity fraud so much as reprice it: drawing on a report co-authored with the Brazilian IDV vendor Unico, he puts the cost of running a sophisticated attack at more than 1…
July 31, 2026
- Nobody is fighting hardest at the front door
Socure president Matt Thompson, writing on Liminal’s Friday Five, makes a plain argument that lands harder than its bullet-point form: new account fraud is the origin point of nearly every downstream loss, and the industry still under…
July 30, 2026
- The House commerce subcommittee folds AI threats into the network-security conversation
Wiley’s recap of the July 22 House Energy and Commerce hearing on “Protecting Communications Networks and Improving Connectivity” is worth reading for what it says about where the AI-security conversation is heading — and …
- Surveillance pricing makes privacy the thing you pay for
Cory Doctorow’s latest is a clean statement of where consumer surveillance and pricing collide: surveillance pricing charges every customer a different price for the same transaction, keyed to the dossier data brokers hold on them. Th…
- Teams vishing is now a ransomware on-ramp
Sophos has documented a campaign it tracks as STAC4749 in which attackers pose as IT helpdesk staff over Microsoft Teams chats and voice calls, talk employees into starting a remote-support session, and — in at least three cases — end up de…
July 23, 2026
- FCC proposes RMD filing for dialing platforms, call centers and cloud providers
The FCC’s Further Notice on the Robocall Mitigation Database (WC Docket Nos. 24-213 and 17-97, CG Docket No. 17-59), adopted July 22, was published in the Federal Register September 9. Comments are due October 9 and replies November 9…
- A privacy-first trust framework starts by treating consolidated data as a liability
The Center for Democracy & Technology has published What is a Database?, a technical explainer by Hannah Quay-de la Vallee on the risks of government data consolidation. Limited, targeted data sharing between agencies has long been defe…
- STI-GA moves to vet governance authorities no national regulator stands behind
The Secure Telephone Identity Governance Authority — STI-GA, the ATIS-administered body that runs STIR/SHAKEN certificate governance in the US — has selected Numeracle to design a framework for vetting “non-jurisdictional governance a…
July 22, 2026
- FCC moves to close the Covered List's hardware-component loophole
At its July 22 open meeting, the FCC takes up a Third Report and Order and Third Further Notice of Proposed Rulemaking that would bar equipment authorization for devices containing “logic-bearing” hardware components produced by…
- NIST turns its mDL work from the technology to the harder half: adoption
Speaking at an NCCoE Cybersecurity Connections event, NIST identity program lead Ryan Galluzzo made a quietly telling pivot: the hard part of mobile driver’s licenses is no longer the cryptography. As Biometric Update reports, NIST an…
July 21, 2026
- Bitdefender's cross-channel scam numbers, filtered through GASA
GASA is surfacing Bitdefender’s 2026 Global Scam Intelligence Report, and the framing is one the trust world keeps circling back to: scams no longer live on a single channel. A deceptive ad leads to a fraudulent site, the interaction …
July 20, 2026
- CDT Europe: the EU-US border data deal bypasses fundamental-rights protections
CDT Europe, with 29 other civil-society organisations and academics, has sent an open letter to the Council of the EU warning that the Enhanced Border Security Partnership (EBSP) would mandate “continuous, systematic transfers of Euro…
- EFF: bills to unmask 'stealth crawlers' threaten the open web more than the crawlers do
The EFF pushes back on a new legislative boogeyman. “Stealth crawlers,” its Deeplinks post argues, are simply automated tools that collect public web data without disclosing the operator’s identity — and anonymous crawling…
July 18, 2026
- AI mania is eviscerating global decision-making
Nik Suresh, writing as Ludicity, has a knack for naming the thing everyone in the meeting is thinking and no one will say out loud. His latest — which shot up Hacker News over the weekend (via Simon Willison) — is about how “AI strate…
July 17, 2026
- ATIS closes the last mile of the SHAKEN-over-TDM problem
ATIS has published ATIS-1000107, SHAKEN: STI-CPS Discovery for Out-of-Band PASSporT Transmission Involving TDM Networks — the piece that makes out-of-band SHAKEN actually operable when a call crosses legacy switching. The framing in the ann…
July 15, 2026
- Ofcom puts KYC and Sender ID checks on mobile operators to fight messaging scams
Ofcom has finalised a package of rules and guidance requiring mobile providers to block, limit, and disrupt messaging scams. The context it cites: fraud accounts for an estimated 45% of all reported crime in England and Wales, £1.28 billion…
- Apple's China AI licence, and per-country rules for how AI gets used
Chinese regulators have granted Apple a licence to ship Apple Intelligence on iPhones in China, with Alibaba’s Qwen and Baidu as the technical partners — reported by the South China Morning Post (Alibaba-owned), alongside approvals fo…
- First Orion makes the RCS-over-push case for transactional alerts
First Orion has a head-to-head arguing RCS beats in-app push notifications for mission-critical transactional alerts — OTPs, fraud alerts, delivery tracking. The delivery argument is architectural: RCS gets carrier-level priority with autom…
- 49 state AGs press the FCC to choke off scammers' number supply
Forty-nine state attorneys general — the NAAG Anti-Robocall Multistate Litigation Task Force — filed reply comments urging the FCC to tighten numbering policy, the least-watched lever in the robocall fight. The mechanism they’re targe…
- Scam robocalls jump 24% in June, per YouMail data
TransNexus’s monthly read of YouMail’s Robocall Index shows overall robocalls up 3.4% month-on-month in June 2026 — a six-month high — though still down 4.6% against June 2025. The number to watch is scam volume: scam robocalls …
July 13, 2026
- Numeracle: number rotation is becoming a compliance risk, not a spam-label fix
Numeracle has a post arguing that number rotation — cycling flagged numbers out for fresh ones — has stopped working and is turning into a regulatory liability. The mechanics it lays out are sound: carriers now flag dormant, no-history numb…