Companies That Forgot to Renew: Real Incidents, and the Myths

9 min readExamfy Software

There's a genre of blog post listing famous domain expirations. Most of them cite each other rather than any original source, and a good share of the best-known stories turn out to be misremembered, miscategorised, or simply wrong.

So this is that article with the sourcing done. Every incident below traces to a primary document — a regulator's consent decree, a company postmortem, a congressional report — or to contemporaneous reporting from a named outlet. At the end there's a section on the stories that don't survive checking, because several of the most-repeated ones don't.

The pattern that emerges is worth the read on its own: these failures almost never happen to careless organisations. They happen to competent ones, through ordinary process gaps.

Part 1: Domains that lapsed

Sorenson Communications, June 2016 — the one with real consequences

The most serious documented case, and the one with a regulator's own account of it.

Sorenson provides Video Relay Service for deaf and hard-of-hearing users. On 6 June 2016 the registration for sorenson.com expired and was deactivated. As ISPs updated their caches to reflect the expired domain, affected users couldn't make or receive calls routed through it — including 911 calls. The disruption continued for some callers into the morning of 8 June.

The FCC consent decree describes it as "a preventable, internal operational failure." Sorenson agreed to reimburse $2.7 million to the TRS Fund and pay $252,000 to the US Treasury, plus a compliance plan requiring an annual certification reviewing every domain used for VRS.

Note the correction: this is frequently reported as "a $3 million fine." It was a consent decree totalling $2.952 million, not a fine.

Marketo, July 2017 — auto-renew failed

On 25 July 2017, marketo.com expired. The marketing-automation platform's login page became unreachable, and — because Marketo hosted forms embedded on customers' websites — those forms stopped capturing data. Email tracking pixels and links stopped resolving, so opens and clicks went unrecorded across its customer base.

CEO Steve Lucas's statement is the useful part: "We renew thousands of domain name properties we own every year with precision, yet the auto renew process for registering our main domain, Marketo.com, failed." He cited "process errors with auto renewals as well as human errors."

A company that successfully renews thousands of domains still lost its primary one. That's the failure mode why auto-renew fails is about — auto-renew is an instruction to attempt a charge, not a guarantee.

Foursquare, March 2010

foursquare.com lapsed on 25 March 2010, and the site was replaced by the registrar's parking page the following day. Foursquare admitted the mistake publicly rather than blaming anyone — and it happened while the company was closing a $10 million funding round.

Dallas Cowboys, November 2010

Low stakes, excellent timing. The team had held dallascowboys.com since 1995. It lapsed, and on the morning of Monday 8 November 2010 — the day they announced they were firing their head coach — fans arrived at a registrar's "for sale" page.

Microsoft's passport.com, Christmas 1999

Microsoft didn't pay a $35 renewal invoice. On 24 December 1999, the nameservers for passport.com were pulled. Because Hotmail sign-in depended on Passport, users couldn't log in — the services were running, just unreachable by name.

A Linux consultant, Michael Chaney, paid Microsoft's outstanding $35 bill on Christmas Day. Service was restored on 26 December.

Two caveats, since this story gets embroidered: Chaney has been explicit that he never owned or controlled the domain — he paid someone else's invoice. And the contemporaneous record here is a Slashdot post with the receipt plus Chaney's own account, rather than mainstream press.

Part 2: Certificates that expired

Ericsson → O2 and SoftBank, December 2018 — the largest blast radius

An expired software certificate inside two specific versions of Ericsson's SGSN–MME core network software caused affected nodes to shut down. Roughly 32 million O2 UK customers lost mobile data for most of a working day, taking down the MVNOs riding on O2 — Tesco Mobile, giffgaff, Sky Mobile, Lycamobile — with it. SoftBank in Japan was hit the same day.

CEO Börje Ekholm: "The faulty software that has caused these issues is being decommissioned and we apologize not only to our customers but also to their customers."

(The widely-quoted "£100 million compensation" figure was press speculation about what O2 might claim. No settlement amount was ever confirmed.)

Microsoft Azure Storage, February 2013 — the best postmortem in the genre

Three wildcard certificates expired within four minutes of each other, globally:

CertificateExpired
*.blob.core.windows.net22 Feb 2013, 12:29:53 PST
*.queue.core.windows.net22 Feb 2013, 12:31:22 PST
*.table.core.windows.net22 Feb 2013, 12:32:52 PST

All HTTPS access to Blobs, Tables and Queues failed worldwide. Availability was restored by 00:09 PST the next day.

Microsoft's postmortem is unusually candid about the cause, and it's the most instructive passage in this entire article:

"While the expiration of the certificates caused the direct impact to customers, a breakdown in our procedures for maintaining and monitoring these certificates was the root cause… the team failed to flag the storage service release as a release that included certificate updates. Subsequently, the release … was delayed behind updates flagged as higher priority… Additionally, because the certificate had already been updated in the Secret Store, no additional alerts were presented to the team, which was a gap in our alerting system."

The certificates had been renewed a month and a half earlier. The renewal simply never shipped, and the system that should have warned them had been silenced by the very act of preparing the fix.

Firefox, May 2019 — "Armagadd-on 2.0"

The intermediate certificate used to sign every Firefox add-on expired at midnight UTC on 4 May 2019. Firefox checked the signature, found it invalid, and disabled every installed extension worldwide, simultaneously. Mozilla estimates 40–50% of users have add-ons.

Their technical report contains an unusually honest root cause: teams "knew that dates were not checked for end-entity certificates … but might not have realized that dates for intermediate certificates were still checked," and "these various teams did not cross-check their underlying assumptions."

The shorter ones

  • Oculus Rift, March 2018 — a code-signing certificate expired, Windows refused to run the runtime service, and every Rift headset worldwide stopped working until patched.
  • Microsoft Teams, February 2020 — an unrenewed authentication certificate locked users out globally for several hours.
  • Google Voice, February 2021 — a certificate expired at 23:51 on 15 February; inbound and outbound VoIP calls failed for 4 hours 22 minutes.
  • Spotify's Megaphone, May 2022 — roughly nine hours down; publishers locked out of the CMS and listeners unable to download episodes. NPR, itself an affected publisher, reported it.
  • US federal shutdown, January 2019 — certificate renewal wasn't an essential function. Netcraft found 80+ expired TLS certificates on .gov domains. Because some are on the HSTS preload list, browsers blocked access outright rather than showing a bypassable warning. NIST's Computer Security Resource Center was among the casualties.

Part 3: Equifax — when an expired certificate isn't an outage

The most consequential case in this article produced no downtime at all.

From the House Oversight Committee's report on the 2017 breach:

"Equifax did not see the data exfiltration because the device used to monitor ACIS network traffic had been inactive for 19 months due to an expired security certificate."

On 29 July 2017, Equifax updated the expired certificate and immediately noticed suspicious traffic — which is how the intrusion was discovered, 76 days after it began. Roughly 148 million people were affected.

The report also found Equifax had allowed over 300 security certificates to expire, including 79 covering business-critical domains.

This is the case that reframes the whole subject. An expired certificate on a monitoring appliance doesn't break a website — it silently disables a security control, and nothing tells you. There's no error page, no support ticket, no alert. Just a blind spot that persists until someone happens to renew.

Part 4: The stories that aren't true

These circulate constantly. They don't survive checking.

"Google forgot to renew google.com and someone bought it for $12." Real event, wrong category. In 2015 Google Domains erroneously listed google.com as available; Sanmay Ved bought it and held it about a minute before the order was cancelled. Google paid him a bounty, doubled when he donated it. The domain never expired — it was a listing error.

"Google forgot to renew google.de." Not an expiry. The 2007 incident was an unauthorised transfer: a request was processed automatically without verification, and the losing provider didn't object within the customary window, which DENIC's system treats as consent. That's a hijack story, not a renewal story — and arguably a more alarming one.

"Hotmail went down across the UK when hotmail.co.uk expired." The lapse is real and well sourced — a member of the public picked it up in 2003 and spent nearly two weeks trying to give it back while Microsoft ignored him. But no source documents any service disruption. It was a redirect domain. Good governance story; not an outage.

"Regions Bank was offline for a week across 16 states." Every source traces to domain-industry blogs reading WHOIS. Contemporaneous posts suggest one to two days, and the story is frequently conflated with a separate online-banking outage days earlier attributed to a cyberattack.

"Alaska Airlines' outage was caused by an expired certificate." This appears in certificate-management vendor blogs. Alaska's own stated causes were an unspecified technology problem in 2024 and, for the 2025 ground stop, failure of a third-party hardware component. No source supports a certificate.

What the real cases have in common

Four things, across every verified incident above:

  1. Competence didn't help. Marketo renewed thousands of domains successfully. Microsoft had already prepared the Azure certificates. Equifax had a monitoring programme. The failure was never ignorance of the task.
  2. The warning went somewhere nobody was. An unpaid $35 invoice, a release deprioritised behind higher-priority work, an alert suppressed because the certificate had been updated in one system.
  3. The blast radius was wider than the asset. Marketo's expiry broke forms on its customers' websites. Ericsson's broke four other networks. One certificate, four minutes apart, took down three Azure services globally.
  4. Nothing looked wrong beforehand. In every case the systems were healthy right up to the deadline. There's no degradation to notice — the transition from fine to broken is instantaneous.

That last point is the whole argument for monitoring these dates independently of whatever system is supposed to handle them. A renewal process you can't see failing is indistinguishable from one that's working.

You can check any domain's registration and certificate expiry free, with no signup, using our domain and SSL expiry checker — or read how to never let a domain expire for the systematic version.

Track every domain and SSL certificate you own

Store your domains in a chest, so you never forget one again.

Start free — 3 domains