Assess my case

Recover a hijacked .ch domain after account compromise: what panels a…

Recover a hijacked .ch domain after account compromise: what panels a. UDRP and ccTLD domain recovery and defense across .ch. Email the firm to assess your cas…

An account compromise happens fast. A credential-stuffing attack, a SIM-swap, a convincing phishing email – and within hours the registrar account is accessed by a stranger, the domain's DNS is redirected, and the legitimate holder is locked out. For a .ch domain, the problem is compounded by a regulatory structure that differs sharply from the UDRP world most brand owners know.

Recovering a hijacked .ch domain after account compromise requires engaging SWITCH, the official .ch registry, through its specific dispute and hold procedures, while simultaneously documenting the compromise at the registrar level. Because there is no UDRP for .ch, the path to recovery runs through Swiss law and SWITCH's own rules – not through a WIPO or Forum complaint. Acting within the first 72 hours of discovery substantially improves the prospect of a successful hold and reversal.

This analysis covers the governing procedure at SWITCH, the registrar-lock and transfer-reversal mechanics, the role of Swiss courts, the evidence that decides outcomes, and where the process most commonly fails. We also identify where the majority approach among domain dispute practitioners diverges from a minority view on the court route.

Why the UDRP does not apply to .ch – and what governs instead

The .ch zone is administered by SWITCH, a Swiss foundation designated by the Swiss federal government as the official registry for .ch and .li domains. SWITCH has not adopted the UDRP and has not appointed WIPO or any other recognized dispute-resolution provider under the UDRP framework. The UDRP applies to gTLDs (.com, .net, .org, and others) and to ccTLDs that have opted into it; .ch has not done so.

The governing rules for .ch are SWITCH's own registration terms, the Swiss Federal Act on the Protection of Trade Marks and Indications of Source, and the general provisions of Swiss civil and criminal law. Any compulsory dispute for .ch therefore proceeds either through SWITCH's internal dispute-entry mechanism or through the Swiss cantonal courts. This is a foundational distinction. A brand owner accustomed to filing a WIPO complaint will find no equivalent here.

SWITCH does maintain a dispute procedure that allows a third party – including an account holder whose domain was transferred without authorization – to lodge a dispute request. The effect of a successful dispute request is a hold: SWITCH marks the domain as disputed and blocks further transfer or administrative change while the matter is resolved. The hold does not itself return the domain. It freezes the position and preserves options.

For a case of account compromise specifically – where the registrant is the original legitimate holder, not a competing claimant – the dispute route must be combined with a parallel registrar-level escalation. The two tracks operate simultaneously, and neglecting either one creates gaps an adversary can exploit.

Registrar-lock and transfer-reversal mechanics: the first 72 hours

The registrar holds the operative lever in any domain-theft scenario. When an account is compromised, the attacker typically changes the account credentials, updates the administrative contact, and initiates an outbound transfer to a different registrar. Each of these steps leaves a timestamped record in the registrar's logs – and those logs are the foundation of a reversal claim.

The first task is to notify the registrar's abuse or security team, in writing, within hours of discovery. Most accredited registrars maintain a security escalation pathway separate from general customer support. A formal written notice – not a chat transcript, not a phone call – starts the audit trail and triggers the registrar's own contractual obligations under ICANN's Transfer Policy for gTLDs. For .ch, the equivalent obligation arises from the registrar's contractual relationship with SWITCH and the SWITCH registration terms, which require registrars to respond to documented unauthorized-transfer claims.

What does the registrar need to see? At minimum: proof of original registration (confirmation emails, payment records, historical WHOIS data before the compromise), a timeline of the compromise (when credentials changed, when the contact details changed, when the transfer was initiated), and evidence of the account compromise itself (phishing emails, access logs where available, device authentication logs). In our practice, the cases that resolve fastest at the registrar level are those where the legitimate holder can produce original invoice data and a consistent account-history record predating the attack.

A registrar that confirms an unauthorized transfer has contractual authority – and in some cases an obligation – to reverse it without waiting for a court order. The challenge is that registrars vary considerably in how quickly and willingly they act. Where a registrar is unresponsive, a SWITCH dispute hold becomes a critical protective step while leverage is assembled for the next escalation. The SWITCH hold prevents the attacker from moving the domain to a third-party registrar while the reversal claim is in progress.

If your .ch domain has been moved without authorization, the window to act is narrow. To assess your registrar-escalation and SWITCH hold options, contact info@cognomenlaw.com.

The SWITCH dispute procedure: how a hold is obtained and what it achieves

A SWITCH dispute hold is a protective measure, not a final adjudication. It is the .ch equivalent of the registrar lock that a UDRP filing triggers for gTLDs. Obtaining it quickly is essential: a domain that is transferred out of the Swiss registrar network and re-registered by a third party creates a substantially harder recovery problem, because any innocent third-party acquirer's position under Swiss civil law complicates the claim.

To obtain a SWITCH hold, the applicant must submit a written request documenting the basis for the dispute – typically the unauthorized access to the registrant account and the resulting transfer. SWITCH reviews the request against its own criteria, which are procedural rather than substantive: SWITCH does not adjudicate who has the better claim to the name. It assesses whether a dispute is sufficiently documented to warrant a hold pending resolution elsewhere.

The hold has a defined duration. It does not automatically resolve in the applicant's favor. The applicant must pursue the underlying claim – either through a negotiated resolution with the current registrant or through Swiss court proceedings – before the hold period expires. A hold that expires without court action leaves the domain in the attacker's hands.

This is a critical structural difference from a UDRP proceeding. Under the UDRP, a filed complaint leads to a panel decision that either orders transfer or dismisses. Under the SWITCH procedure, a hold preserves the status quo; the resolution requires the applicant to bring a substantive claim. That claim, for most account-compromise cases, is a civil action before the competent cantonal court in Switzerland.

When does a Swiss court action become necessary?

The court route is not optional in many .ch hijacking cases; it is the primary substantive remedy. Swiss civil law provides a cause of action for unauthorized transfer of personal property rights – and the right to a domain name registered in one's own name has been treated as a protectable interest under Swiss law, though the precise doctrinal basis varies by case type and the cantonal court's approach.

The majority view among practitioners who handle Swiss domain matters is that an urgent application (superprovisorische Verfügung or its standard-track equivalent) is the most effective mechanism to both extend the SWITCH hold and obtain a judicially enforceable order directing the registrar to reverse the transfer. The court's order can bind the registrar and SWITCH directly, which a contractual dispute request cannot.

A minority view holds that for straightforward account-compromise cases with clear forensic evidence, the registrar-level escalation alone – supported by SWITCH's dispute process – should be sufficient without court involvement. In our experience, this view underestimates two risks: first, the attacker's ability to create a factual dispute about ownership (claiming the account was transferred voluntarily) that a registrar will not and should not adjudicate; second, the risk that the hold period expires before a negotiated resolution is reached. Where there is any ambiguity in the facts, or any indication the attacker intends to resist, a court application is the more defensible approach.

The practical threshold for a court application is evidence that is documentary and contemporaneous. Courts are skeptical of reconstructed timelines. Phishing emails, access-log screenshots, payment records, and original registration confirmations carry substantially more weight than a declaratory statement. We regularly advise clients to preserve this material before contacting the registrar, because the registrar's own notice to the current account holder may alert the attacker to destroy evidence.

For a read on whether the registrar-escalation track alone is sufficient for your .ch matter, or whether urgent court proceedings are warranted, email info@cognomenlaw.com.

What evidence decides the outcome in a .ch account-compromise recovery?

Evidence is the decisive variable. SWITCH, the registrar, and a Swiss court all apply different standards, but all three require documented proof of the original registrant's legitimate claim and documented proof of the unauthorized nature of the transfer.

The following categories of evidence are consistently determinative:

In a matter handled in early 2025, a Swiss technology company retained us after its primary .ch domain was redirected to a competitor's IP address overnight. The registrar's own access logs showed a login from a jurisdiction where the company had no employees, followed within four hours by a DNS update and an administrative-contact change. Presenting these logs alongside the original registration invoice secured a voluntary registrar reversal within six business days, without requiring a court application.

The contrary pattern – where recovery required full court proceedings – arose in a late 2025 matter involving a .ch domain held by an individual registrant. The attacker had held the domain for approximately three weeks before the compromise was discovered, and had transferred it to a second registrar, listing a plausible-sounding alternate contact. The registrar declined to reverse without a court order. The SWITCH hold preserved the domain's position while the cantonal court application was prepared.

The criminal law dimension: when to consider a Swiss criminal complaint

Account compromise is not only a civil matter. Unauthorized access to a computer system and the use of another person's credentials are criminal offenses under Swiss law. A formal criminal complaint to the Swiss cantonal police or the federal cybercrime authorities serves two functions: it creates an official record of the offense with a government-issued case number, and it opens access to law-enforcement tools for tracing the attacker that are unavailable in civil proceedings.

Practitioners differ on timing. The majority view is that a criminal complaint should be filed in parallel with the civil urgent application, because the criminal-case file can be referenced in the civil proceeding and reinforces the credibility of the registrant's account. The minority view is that criminal complaints introduce delay and complexity into what can be a fast-track civil resolution, and should be deferred unless the attacker's identity is unknown and law-enforcement tracing is needed.

Where the attacker is using the domain to impersonate the legitimate business – redirecting traffic to a fraudulent payment page, for example – the criminal dimension becomes more pressing. The harm is ongoing and quantifiable, and a criminal complaint may trigger faster provisional measures from the court.

A Swiss criminal complaint does not substitute for the civil action; it runs alongside it. Local litigation counsel in the relevant Swiss jurisdiction handles the criminal filing. For cross-border .ch hijacking cases – where the attacker operates from outside Switzerland – the criminal route also creates a basis for international cooperation through Swiss federal authorities.

Cross-zone considerations: .com and .ch held simultaneously

Many businesses hold both a .com and a .ch version of their domain. A comprehensive account-compromise attack will target both. The recovery strategy diverges sharply depending on the zone.

For the .com, the UDRP is available if the attacker registered the .com in bad faith. But in a theft scenario – where the registrant was the original legitimate holder and the domain was moved without consent – the appropriate UDRP element may not be cleanly satisfied, because the domain was not "registered" by the attacker in the classic sense. Panels have addressed this in the context of domain theft, and the consensus view is that where a transfer was effectuated by fraud, the bad-faith element can be read as applying to the fraudulent acquisition; however, the factual record must be clear. An alternative and often faster route for the .com is registrar escalation under ICANN's Transfer Policy, which provides a structured dispute mechanism for unauthorized inter-registrar transfers.

For the .ch, as described throughout this analysis, there is no UDRP equivalent, and the recovery depends on SWITCH's procedural mechanisms and Swiss courts.

Where both zones are compromised, running both recovery tracks in parallel is essential. The .com recovery timeline – potentially two months for a UDRP proceeding or faster through registrar escalation – should not delay the .ch track, which operates on its own timetable and with its own evidentiary demands. We routinely manage both tracks simultaneously, coordinating the registrar notices, the SWITCH dispute hold, and any WIPO or Forum filings to ensure no procedural gap opens between them.

A decision matrix in brief: if the compromised domain is a .com, assess the UDRP (filing fee starting at USD 1,500 at WIPO for a single panel, standard timeline of approximately two months) against direct registrar escalation under ICANN's Transfer Policy (faster, no forum fee, but dependent on registrar cooperation). If the compromised domain is a .ch, the SWITCH dispute hold plus Swiss court urgent application is the primary path, with no UDRP option available. If both zones are involved, both tracks run concurrently, with local litigation counsel engaged for the Swiss court component. If the attacker's identity is known and there are damages to pursue beyond domain return, Swiss civil law and, in an appropriate case, US anticybersquatting litigation for .com elements of the scheme, may extend the remedy set.

See also our analysis of court-based domain recovery options for cases where arbitration cannot reach the remedy needed.

Where account-compromise claims most commonly fail

In our practice, failed or stalled .ch recovery attempts share a recognizable set of errors. Understanding them is as important as understanding what succeeds.

Delay in filing the SWITCH dispute hold. Every day without a hold is a day the attacker can move the domain further. A domain transferred to a second registrar – especially one outside the Swiss regulatory perimeter – becomes exponentially harder to recover without a Swiss court order enforced against the foreign registrar through international channels. Act on the hold within hours, not days.

Failure to preserve forensic evidence before contacting the registrar. Contacting the registrar alerts the attacker. Screenshot the current WHOIS, the current DNS, the current registrar account dashboard (if still accessible), and any suspicious emails before making any formal contact. Evidence destroyed after notice is evidence that no longer exists.

Treating the registrar escalation as a customer-service inquiry. A written notice to the registrar's abuse team is a formal legal communication. It should identify the domain, the registration date, the alleged unauthorized event with timestamps, and the relief sought – specifically, a registrar hold pending investigation. A vague support ticket asking "can you look into this" does not create the audit trail needed for a subsequent court application.

Assuming the criminal complaint substitutes for the civil action. Swiss prosecutors investigate crimes; they do not order registrars to reverse transfers. The civil urgent application is the mechanism that moves the domain. The criminal complaint supports and accelerates the civil path but does not replace it.

Waiting for the attacker to make contact. Some hijackers hold the domain without immediately reaching out, waiting for the registrant to become desperate enough to pay a higher price. Waiting allows the hold window to narrow. Initiate all recovery tracks immediately.

Realistic next steps and how COGNOMEN approaches .ch theft matters

A .ch domain-theft recovery has a defined sequence. First, document and preserve all available forensic evidence. Second, file the SWITCH dispute hold request with formal written notice to the registrar. Third, assess within 24 to 48 hours whether voluntary registrar reversal is achievable or whether a Swiss court urgent application is required. Fourth, prepare and file the court application if needed, coordinating with local litigation counsel in the relevant Swiss jurisdiction. Fifth, where criminal elements are clear, file the criminal complaint in parallel.

The realistic probability of recovery depends on three variables: the speed of the initial response, the quality of the forensic evidence, and whether the domain has been transferred to a second registrar or re-registered by a third party. Cases where the hold is filed within 72 hours and the original registration records are intact resolve at the registrar level more often than not. Cases discovered weeks later, with the domain already moved, typically require court intervention and may involve international legal channels.

We handle .ch domain-theft matters from the initial registrar notice through to court proceedings where necessary. We assess which track – registrar escalation, SWITCH hold, urgent court application, criminal complaint, or some combination – fits the specific facts, timeline, and evidence available. We do not guarantee outcomes; domain recovery in any jurisdiction depends on the facts and on the decision-maker's assessment of the evidence.

Related at COGNOMEN

Frequently asked questions

What are the chances to recover a hijacked .ch domain after account compromise?

Recovery probability depends heavily on how quickly the legitimate holder acts and what evidence is available. Cases where a SWITCH dispute hold is filed within the first 72 hours, and where original registration records and account-access logs document the unauthorized transfer, resolve at the registrar level without court proceedings in a meaningful proportion of cases. Cases discovered weeks after the compromise, or where the domain has already been moved to a second registrar, require Swiss court proceedings and carry greater uncertainty. No outcome can be guaranteed; the result turns on the specific facts and the decision-maker's assessment of the evidence.

What evidence do I need to recover a hijacked .ch domain after account compromise?

The core categories are: original registration confirmation emails and payment records establishing ownership before the compromise; registrar access logs showing unusual login patterns, credential changes, or contact-field updates at the time of the attack; any phishing emails or social-engineering messages used to obtain credentials, with full headers; DNS change records showing the redirection; historical WHOIS data capturing the contact-field changes; and any communications from the attacker demanding payment. Courts and registrars give the greatest weight to documentary evidence created contemporaneously with the events – preserve everything before making any formal contact with the registrar.

Can I recover a hijacked .ch domain after account compromise without going to court?

In some cases, yes. Where the forensic evidence is clear and the registrar confirms the unauthorized transfer from its own logs, a voluntary registrar reversal is possible without a Swiss court application. The SWITCH dispute hold provides protection during that negotiation. However, where the attacker disputes the claim, where the registrar declines to act without a court order, or where the domain has been moved to a second registrar, a Swiss urgent court application becomes necessary. It is prudent to prepare for the court route from day one, even if the registrar-level escalation is running in parallel.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.