Summary

  • ARIN’s 2026 meeting recap says its Registry Integrity and Oversight team received 223 policy-noncompliance reports in 2025: 195 were out of scope and 28 were deemed legitimate.
  • The quarterly findings reconcile to those totals, but the 28 remaining reports have mixed outcomes. Some prompted corrections or restrictions, some concerned routes or ROAs already withdrawn, some could not be confirmed, and others remained open.
  • Out of scope describes the boundary of ARIN’s process, not whether a complaint is true or important. Conversely, entry into the process does not establish fraud.
  • A public cohort-and-disposition ledger should keep intake, scope, evidence, investigation and remedy separate while protecting reporters and confidential customer material.

The most dangerous word in ARIN’s fraud statistics is not fraud. It is legitimate.

At its April 2026 meeting, ARIN summarised the previous year’s policy-noncompliance traffic in one clean split. Its Registry Integrity and Oversight team had received 223 reports. Of those, 195 were out of scope and 28 were deemed legitimate. The two parts add up. A reader could naturally assume that the second number means ARIN found 28 genuine cases of fraud.

That is not what the detailed record establishes.

ARIN’s quarterly findings describe 28 reports that survived the out-of-scope classification. They do not all end in the same place. Several produced a change to a registry record or account. Seven concerned routes that were withdrawn, with no additional action described. Two reports about unauthorised ROAs ended with the ROAs removed. Other allegations could not be confirmed. Some drew a warning and a flag for attention if the organisation returned for more resources. Nine matters were still marked as ongoing in the published year-end record.

Those are materially different dispositions. Folding them into one word makes the system look more certain than its own evidence.

The totals reconcile; the state does not

The ARIN 57 Day 3 recap gives the annual total. ARIN’s archived 2025 findings let the reader rebuild it.

ARIN recorded 81 reports in the first quarter, 43 in the second, 49 in the third and 50 in the fourth. That is 223. It placed 79, 40, 37 and 39 respectively outside the scope of its fraud-reporting process. That is 195. The quarterly remainder is therefore two, three, twelve and eleven: 28 in all.

This arithmetic is useful because it closes one question. It does not create an evidentiary verdict. The quarterly rows reveal at least five kinds of ending.

First, ARIN sometimes changed something it controlled. It made abandoned registrations inactive, removed stale reassignment information, locked an account until functional contact details were supplied and removed an unauthorised reallocation. Two reports say unauthorised ROAs were removed. Each action matters, but the public row does not always say whether ARIN or another authorised actor performed every removal.

Second, seven unauthorised-routing reports ended after the routes were withdrawn and ARIN said no additional action was needed. A withdrawal is observable closure for the reported route state. It is not, by itself, a finding about intent, identity or the truth of every allegation in the submission.

Third, two reports led to warnings and later follow-up flags even though ARIN could not confirm the alleged unauthorised use. That is a risk-control response under uncertainty. It is neither exoneration nor substantiation.

Fourth, four reports are described as unconfirmed or not verified without the warning-and-follow-up outcome. Their public evidence state is unresolved in the negative sense: ARIN did not establish the allegation from the material available.

Fifth, nine investigations remained open. An open case is a promise of later work, not a result. The public archive must be revisited before anyone assigns those matters a final disposition.

This grouping is an editorial reconstruction of ARIN’s published rows, not an official ARIN taxonomy. Its purpose is to show why one aggregate label cannot carry the evidentiary weight a casual reader may put on it.

Scope is a jurisdictional decision

ARIN’s fraud-reporting process defines a narrow institutional job. It accepts allegations involving false information used to obtain number resources, abuse of policies including reserved pools, fraudulent transfer approval, unauthorised Whois changes and hijacking of resources in ARIN’s registry.

It expressly excludes phishing, spam, identity theft, hacking, scams and other harmful Internet activity unrelated to ARIN’s mission. Those exclusions do not declare the conduct harmless. They say ARIN is not the institution that can investigate it through this process. A report about resources managed by another RIR may be referred to that registry. Other matters may belong with a network operator, a platform, a police service, a court or another regulator.

Out of scope is therefore closer to a routing decision than a truth decision. A well-designed intake system sends the issue toward a competent forum and records that handoff. Treating 195 out-of-scope submissions as 195 bad complaints would punish reporters for choosing a door whose label they misunderstood.

The reverse error is equally serious. Once a complaint falls within ARIN’s remit, it still needs investigation. ARIN may review documents previously supplied for an allocation or transfer, conduct external research and ask relevant parties for more material. The duration varies. The result may be confirmed, unconfirmed, corrected, referred, overtaken by a third-party action or left open.

The scope decision answers: may ARIN examine this here? Substantiation answers: what did the evidence establish? Remedy answers: what changed, by whom, and with what remaining uncertainty? They are three separate joins.

The public process already promises more structure

ARIN says a reporter must confirm an email before the submission enters the process and then receives a report ID. That creates a useful intake boundary. It also says public reporting will exclude submitter information, a necessary protection where accusations may be sensitive or wrong.

The findings index says quarterly publication will include the report date, resource type, investigation result and any ARIN action. The process page describes date and ticket number, report type and a general summary. Together these commitments point toward a stateful public record rather than a one-time annual ratio.

The 2025 archive is already valuable. It gives quarter totals, ticket identifiers for in-scope rows, broad allegation classes and short outcomes. The weakness is not absence. It is that annual language can compress those rows into a category that sounds like a verdict.

A durable public account would give each protected case a sequence. It would record the intake quarter and confirmation, the scope decision and reason, any referral class, the allegation and resource types, the current evidence state, the investigation state, the actor responsible for an action, the action date, residual uncertainty, a later update and correction lineage.

Public aggregates could then use verbs that do not steal certainty from the next stage: submitted, confirmed for intake, outside scope, referred, under investigation, substantiated, not substantiated on available evidence, resolved by another actor, remediated by ARIN and closed. One report may pass through several of these states. A cohort table can preserve that movement without exposing a reporter or a customer file.

A transcript error shows why lineage matters

The ARIN 57 transcript records the speaker as saying 233 reports, followed immediately by 28 legitimate and 195 out of scope. Those components total 223. ARIN warns that the transcript may contain transcription or formatting errors and is not an authoritative record. The meeting recap says 223, and the four quarterly totals independently reconstruct 223.

The defensible conclusion is a bounded one: the public transcript contains a ten-report discrepancy that the recap and detailed ledger resolve in favour of 223. It is not evidence of ten hidden cases, deleted reports or a suppressed category.

That small mismatch is also a model for the larger problem. A number is trustworthy when its lineage lets a reader return to the components, identify the controlling source and correct the public interpretation. The quarterly ledger makes the annual total auditable. A disposition vocabulary would make the annual meaning auditable too.

The outcome ARIN can safely claim

ARIN is right to protect the integrity of its number-resource registry. False documents, unauthorised changes, improper reallocation and hijacking can corrupt the public evidence operators use to establish authority and coordinate repairs. A functioning reporting channel is part of registry operations, not an optional public-relations exercise.

Its credibility does not require every complaint to end in confirmed fraud. Quite the opposite. A mature institution should be able to say that most submissions belonged elsewhere, some allegations could not be proved, some risks justified a warning, some states were corrected, some disappeared before further action and some work remained open.

The 28 are evidence that ARIN processed 28 matters within or adjacent to its defined control surface. They are not a conviction count. The stronger annual sentence would preserve that distinction instead of asking one adjective to do the work of an investigation ledger.

Sources