By 16:30 UTC on September 6, Autistici/Inventati's shutdown notice had collected 521 points and 289 comments on Hacker News. The larger operational number sits on the Italian collective's own history page: nearly 12,000 mailboxes, more than 1,000 websites, over 3,000 blogs, and around 3,000 mailing lists. A/I now says it will discontinue every service soon. Thousands of accounts are therefore on a migration clock, even though the group has not announced the final cutoff date.
The service failure started before the shutdown notice. A/I's September 2 technical FAQ says the autistici.org domain had become unreachable worldwide. External mail to and from @autistici.org addresses stopped working, while mailboxes remained accessible through a different host. That distinction is the core of this story for developers: an operator can retain its machines and data while a registry-level action breaks the names and identity endpoints that make them usable.
A shutdown after 25 years
The collective began in Italy in March 2001, bringing together people working on technology, privacy, digital rights, and political activism. Its account of its history describes a volunteer-run alternative to commercial communications platforms. The service catalog grew far beyond email. It included web hosting, mailing lists, the NoBlogs publishing platform, video conferencing, and streaming. The shutdown therefore affects personal communication as well as sites and group infrastructure that may have accumulated archives and links over years.
A/I has always described itself as a political provider. Its service page says accounts were free, funded by donations, and limited to noncommercial use. Volunteers manually reviewed requests for compatibility with the collective's principles. This matters when reading the dispute now: the U.S. government treats A/I's selective provision of infrastructure as support for violent groups, while A/I says it supplied privacy and communication tools to activists. The service model is agreed; the legal meaning and alleged uses of that service are contested.
In its September 6 notice, the collective tied the closure directly to the risk created by its sanctions designation. It said continued operation could expose users, collaborators, and their relatives to legal or financial consequences. The announcement promises instructions for backing up blogs, mailboxes, and websites, but gives no schedule for those instructions or for individual services to stop. It also warns that more failures may arrive without notice, as happened with autistici.org.
What the U.S. designation does
On August 26, the U.S. Treasury's Office of Foreign Assets Control added Autistici Inventati to the Specially Designated Nationals list under Executive Order 13224. The OFAC entry labels the entity an SDGT, or Specially Designated Global Terrorist, records it as an Italy-based data-processing and hosting organization established in 2001, and flags secondary-sanctions risk. SDGT is a sanctions designation. It should not be confused with the separate U.S. Foreign Terrorist Organization list.
Treasury alleges that A/I supplied hosting, encrypted email, chat, video conferencing, and NoBlogs infrastructure to violent left-wing groups, including the Kurdistan Workers' Party, which the United States designates as a terrorist organization. Treasury designated A/I for allegedly providing material or technological support for terrorism under the executive order. A/I rejects that account. In its response and case summary, the collective says its role was to provide general communications infrastructure and digital self-defense, and that it has not been convicted of a crime.
For U.S. persons, the designation blocks covered property and generally prohibits transactions involving the listed entity unless OFAC authorizes or exempts them. OFAC also says entities owned 50 percent or more by blocked persons are blocked. Its one-page General License 36 allows transactions ordinarily needed to wind down dealings with A/I until 12:01 a.m. Eastern Daylight Time on September 25, 2026. Payments to A/I during that process must go into a blocked account. The license is a closing window, not permission for normal service to continue indefinitely.
The immediate effects have crossed borders. According to A/I's published timeline, PayPal suspended its account on August 27 and Italy's Banca Etica suspended the association's bank account on September 1 while seeking legal guidance. These are the collective's claims, and the public record cited by A/I does not show that the U.S. government directly ordered either company to act. The distinction matters because sanctions can change a provider's risk calculation without a separate order naming each domain, bank account, or payment service.
The domain failed before the servers
A/I says autistici.org was placed in serverHold after the designation. ICANN's status-code guide defines serverHold as a status set by a domain's registry operator; a domain in that state is not activated in DNS. This explains how email can fail even when stored messages and backend systems survive. Sending servers cannot find the domain's mail records, browsers cannot follow the usual name to an address, and authentication tied to the old hostname can break.
The status code establishes the technical mechanism, not the full decision chain. A/I identifies Public Interest Registry, the .org registry operator, as the point that applied the hold. Its case summary also says no public PIR statement confirms that OFAC directly ordered the action, and it says there is no evidence that ICANN ordered or authorized it. Reporting the gap is important: the domain stopped resolving, while the authority, request path, and policy used to set the hold remain publicly unexplained.
Users have already had to work around the damage. The A/I FAQ directs users to webmail at inventati.org and new POP or IMAP connection settings. Mailing lists formerly addressed at @autistici.org were moved to @inventati.org. Hardware security tokens registered against accounts.autistici.org no longer authenticate because the relying domain changed; users need another second factor or the account-recovery flow before registering a new token. A/I says existing mailbox contents remain available.
A separate NoBlogs security incident adds urgency without proving who was behind it. The same technical FAQ says an attacker gained privileged access to the WordPress platform on August 28 through a software vulnerability. A/I found no proof of data exfiltration, but could not exclude access to a user database containing email addresses and hashed passwords. It advised NoBlogs users to change passwords and enable two-factor authentication. The collective has not attributed that intrusion to OFAC, PIR, or the U.S. designation.
The lesson for independent infrastructure
A/I's week exposes four separate failure domains in a service that users experience as one thing. The OFAC license controls transactions. The serverHold documented in A/I's case summary controls whether the original domain appears in DNS. The FAQ shows that a hostname change can invalidate registered security tokens even when account data survives. A software flaw created another path into NoBlogs. Owning or administering servers did not remove any of those dependencies.
Migration advice must stay narrower than a normal provider exit because A/I has yet to publish its promised export procedure. Users can verify access through the replacement inventati.org endpoints and follow the current recovery guidance, but the collective has not said which export formats will be available or how long retrieval will remain possible. Site owners also need the forthcoming instructions before assuming a copy includes databases, uploads, DNS records, or mailing-list archives. A rushed generic command would offer false certainty where the operator has supplied none.
What to watch next
The shutdown notice leaves its service-by-service timetable open, and Public Interest Registry has not published the decision path behind the reported hold. The next concrete signal will be A/I's promised backup instructions, especially the deadline and scope for mailbox, website, NoBlogs, and list exports. OFAC's fixed date is 12:01 a.m. EDT on September 25, when General License 36 stops authorizing ordinary wind-down transactions. Until those details arrive, the safest conclusion is limited but serious: the original domain is already broken, replacement endpoints are temporary operational guidance, and the provider says the rest of its infrastructure will follow.