Assess my case

Update: changes affecting how to recover a stolen .cloud domain

Update: changes affecting how to recover a stolen .cloud domain. UDRP and ccTLD domain recovery and defense across .cloud. Email the firm to assess your case.

A domain disappears from your account overnight. The registrar's WHOIS shows a new registrant. The recovery window is closing. For .cloud domains specifically, the procedural picture has clarified in ways that directly affect how quickly – and through which route – you can act.

To recover a stolen .cloud domain, a registrant typically has two parallel paths: registrar-escalation for account-compromise cases, and a UDRP proceeding before WIPO (which accepts .cloud disputes) for contested transfer or bad-faith registration claims. The 20-day response window under the UDRP makes early action essential. Where arbitration cannot reach the bad actor – or where damages are needed – court action with local litigation counsel remains an option.

This alert covers what changed, who is affected, and the concrete next steps.

What changed for .cloud domain recovery?

.cloud is a new generic top-level domain whose registry accepts UDRP proceedings administered by WIPO, the Forum, CAC, and ADNDRC. That access to arbitration is unchanged. What practitioners are seeing in early 2026 is a tightening of registrar-level transfer-dispute handling: several accredited registrars have updated their account-compromise escalation policies following revised ICANN Transfer Policy guidance, shortening the internal investigation window and adjusting how they treat contested bulk transfers. For registrants who discover a theft late – weeks rather than days after the unauthorized transfer – that shorter window is consequential. The practical result is that the gap between discovering a compromise and having a usable registrar remedy is narrower than it was a year ago.

At the same time, WIPO's 2025 caseload reached a record, with growing volumes of domain theft and hijacking matters alongside conventional cybersquatting complaints. Panels handling theft cases have refined their analysis of evidence: log-file records, RDDS change timestamps, and registrar authentication records now carry greater weight. Unverified claims of compromise, submitted without technical corroboration, are less likely to succeed without supplementary evidence.

Who is affected?

Any registrant holding a .cloud domain registered through an ICANN-accredited registrar is affected if that domain is transferred without authorization. So is any brand owner whose trademark matches a .cloud domain that has been registered or re-registered by a third party following a theft. The update matters most for three groups.

In our practice, we regularly advise registrants in exactly these situations – where the theft was clean enough to survive a first-level registrar inquiry, and where a formal proceeding becomes necessary.

What should you do now?

The route to recovery depends on when the theft is discovered and what evidence exists. Three situations call for different approaches.

Immediate discovery (within days). Contact the losing registrar at once, assert the unauthorized transfer, and request a registrar lock pending investigation. Document every step: the account-access logs, the email trail, and the RDDS change timestamps. Registrars are obligated under ICANN's Transfer Policy to investigate and can reverse a transfer within a prescribed period if compromise is established. Speed is the asset here.

Delayed discovery (weeks or more). The registrar route may be closed. If the domain now sits with a different registrar and the new registration shows a third party, a UDRP complaint at WIPO is the most direct formal remedy. The filing fee at WIPO for a single-member panel is USD 1,500 for a single domain. A standard case runs approximately two months. The complainant must establish the three elements of Paragraph 4(a) – confusing similarity to a mark, no legitimate interest in the registrant, and registration and use in bad faith. Theft and account compromise, corroborated technically, can ground the bad-faith and legitimate-interest elements.

Where arbitration is insufficient. If the bad actor is identifiable, damages are needed, or the stolen domain is being used for active fraud, court action may be the right supplementary step. We coordinate with local litigation counsel in the relevant jurisdiction for cross-border enforcement where a UDRP transfer order alone does not end the harm.

For a read on whether the three UDRP elements are met in your situation, or to assess the registrar-escalation route for a compromised .cloud domain, reach us at info@cognomenlaw.com.

Related at COGNOMEN

Frequently asked questions

Does the UDRP apply to .cloud domains?

Yes. .cloud is an ICANN-accredited new gTLD whose registry has adopted the UDRP. Proceedings may be filed before WIPO, the Forum, CAC, or ADNDRC. The standard three-element test under Paragraph 4(a) applies. The only remedies available are transfer or cancellation of the domain – no monetary damages are available through arbitration.

What evidence is needed to show a .cloud domain was stolen?

Panels and registrars look for technical corroboration of the compromise: account-access logs showing unauthorized login, RDDS change timestamps, authentication records from the registrar, and email evidence of the breach. Claims of theft unsupported by technical records are vulnerable. Gathering and preserving this evidence promptly is the single most important early step.

When does a court route make more sense than a UDRP for a stolen .cloud domain?

Court action becomes relevant when the bad actor is identifiable and damages are sought, when the domain is being actively used for fraud requiring injunctive relief, or when the UDRP's transfer-only remedy is insufficient to address the full harm. Court proceedings are slower and more costly than arbitration; they are coordinated with local litigation counsel in the relevant jurisdiction.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.