Assess my case

Recover a hijacked .global domain after account compromise: what pane…

Recover a hijacked .global domain after account compromise: what pane. UDRP and ccTLD domain recovery and defense across .global. Email the firm to assess your…

A senior brand manager opens her inbox on a Monday morning to find a transfer confirmation she never requested. The company's .global domain – the anchor of a global product launch campaign – has moved to an unknown registrar in a foreign jurisdiction overnight. The registrar's abuse team sends a form response. The thief is already pointing the name at a phishing page. What happens next, and what actually works?

Recovering a hijacked .global domain after account compromise requires moving simultaneously on two tracks: an emergency registrar escalation to freeze any further transfers, and a formal recovery route – either a UDRP complaint before WIPO or a court action in the relevant jurisdiction – to compel the return of the name. The .global registry operates under standard gTLD accreditation, which means ICANN's transfer dispute resolution and the UDRP both apply. Speed and evidence quality decide whether you win.

This analysis covers the applicable rules for .global, the registrar-lock and transfer-reversal mechanics, the choice between arbitration and court action, and the evidence that panels and courts require to order a return of the name.

Why .global Domain Hijacking Is a Distinct Problem

.global is an accredited new-gTLD operating under ICANN's standard registry and registrar agreements, which means the full suite of ICANN transfer protections – including the 60-day inter-registrar transfer lock and the Transfer Dispute Resolution Policy – applies. That is the foundation for any recovery effort.

Domain hijacking in this zone typically follows one of three patterns. First, credential theft: an attacker obtains the registrant's registrar login via phishing, credential-stuffing, or a data breach, then initiates an outbound transfer before the account owner notices. Second, social engineering: the attacker contacts the registrar's support team, impersonates the registrant, and convinces support to unlock the domain and override authentication. Third, registrar-side vulnerability: a flaw in the registrar's account-recovery or WHOIS-update system allows unauthorized changes without correct credentials.

Each pattern leaves a different evidence trail, and that trail is the core of the recovery case. In our practice, the most common pattern we see is credential theft combined with a rapid WHOIS update to substitute the registrant's details before a transfer is initiated. The attacker's goal is to place the domain behind a new registrant identity before the original holder can raise an alarm.

What distinguishes .global from a national ccTLD dispute is that there is no separate national body with jurisdiction over the zone. The applicable procedure is ICANN's, and the dispute forum – for a UDRP-based recovery route – is WIPO, the Forum, CAC, or ADNDRC. That matters because these fora apply a set of rules designed for cybersquatting, not theft. We return to that tension below.

What Rules Apply to .global and Why UDRP Fits Imperfectly

The UDRP governs .global exactly as it governs .com: a complainant must satisfy all three elements of Paragraph 4(a) – confusing similarity to a mark, no legitimate interest in the registrant, and registration and use in bad faith. That third element is the structural problem in a hijacking case.

When a domain is hijacked, the current "registrant" (the thief) did not register the domain in the ordinary sense. The domain was originally registered by the legitimate brand owner. The attacker acquired it through unauthorized transfer, not through a new registration event. Panels have approached this asymmetry in two main ways, and the resulting split in reasoning is the most important doctrinal tension in this area.

The consensus view – followed by the majority of panels – holds that the relevant bad-faith registration for UDRP purposes is the current registrant's acquisition of the domain, not the original registration date. Under this reading, an unauthorized transfer constitutes a de facto re-registration, and the thief's conduct satisfies the bad-faith requirement because no legitimate purpose explains acquiring a domain that already carries a known brand owner's identity. That reading permits a UDRP complaint to succeed even where the original owner was the first registrant.

The contrary view, adopted by a minority of panels, applies the bad-faith test more literally: if the domain was originally registered by the complainant itself, the "registration" element is satisfied by the complainant's own act, not by the thief's acquisition. Under that reasoning, the UDRP is not the right vehicle for hijacking recovery at all, and the preferred path is a court action for conversion or a direct registrar escalation under ICANN's transfer dispute mechanism.

Practically, this split means that a UDRP complaint filed in a hijacking case carries a panel-selection risk. Filing before WIPO – which has the deepest pool of experienced panelists and accounts for the large majority of gTLD UDRP caseload – reduces, but does not eliminate, the risk of drawing a panel that applies the minority view. We advise clients in hijacking matters to prepare parallel evidence sets: one calibrated for a UDRP panel adopting the majority position, and one suitable for a court filing if the UDRP route fails or is unavailable.

For an assessment of which recovery route fits your .global hijacking situation, contact info@cognomenlaw.com.

The Registrar Escalation Track: Freeze Before Filing

Before any formal proceeding, the registrar escalation track must begin immediately. The 60-day inter-registrar transfer lock under ICANN's transfer policy means that a domain cannot be transferred again for 60 days after a completed registrar-to-registrar transfer. If the hijack has only just occurred, that lock is your most powerful immediate tool: it prevents the attacker from moving the name to a second registrar, which would reset the chain of evidence and complicate recovery further.

The first step is to file an abuse report with both the losing registrar (where your account was held) and the gaining registrar (where the domain now sits). The abuse report should document the unauthorized transfer, include timestamped screenshots of account access logs, and attach any phishing or social-engineering correspondence that triggered the compromise. ICANN's Registrar Accreditation Agreement obliges accredited registrars to maintain an abuse contact and to respond to documented abuse reports within a reasonable timeframe.

The second step – often missed – is to request a formal Transfer Dispute Resolution Policy (TDRP) complaint through ICANN's processes. The TDRP is specifically designed for unauthorized inter-registrar transfers and is separate from the UDRP. It does not require proof of a trademark right; it requires proof that the transfer was unauthorized. If the losing registrar failed to verify authorization before releasing the domain – which is the most common registrar-side failure mode – the TDRP process can order the name back to the original registrar without the need to prove bad faith as a separate element.

In our experience, the TDRP route is underused. Brand teams discover the hijack, call their trademark lawyers, and immediately reach for the UDRP. The TDRP is faster when it fits, because it bypasses the three-element UDRP test entirely. Its limitation is that it addresses only the transfer mechanics, not the underlying entitlement to the name. If the attacker contests ownership on substantive grounds, the UDRP or a court will still need to address the merits.

The third immediate step is to contact the .global registry operator directly. Registry operators maintain the authoritative zone file and, in documented emergency situations involving fraud, some operators will place a registry-level hold on a domain pending investigation. This is not guaranteed and is discretionary, but it can buy critical time while formal proceedings are prepared.

What Evidence of Compromise Decides the Outcome

Evidence quality is the single greatest variable in .global hijacking recovery. Panels applying the majority UDRP view and courts in anticybersquatting proceedings both assess the same core body of evidence; they weight it differently, but the underlying documentary record is the same.

The essential evidence set consists of the following categories. First, proof of original registration: the original registration confirmation, billing records, historical WHOIS data, and any prior correspondence with the registry or registrar showing that the complainant held the domain before the disputed transfer. Second, proof of the compromise event: server logs, email headers from phishing messages, account-access logs from the registrar showing the IP address and geolocation of the unauthorized login, and any customer support transcripts from social-engineering attempts. Third, proof of the trademark right: registration certificates, first-use evidence, and any prior trademark opinion that predates the dispute – because a complainant filing a UDRP complaint in a hijacking matter still needs a qualifying trademark right. Fourth, proof of bad faith by the current holder: conduct evidence showing the domain is being used for phishing, redirected to a competing site, or offered for sale to the legitimate owner at an inflated price.

That last category – evidence of what the thief is actually doing with the domain – is frequently the deciding factor. Panels applying the majority view are considerably more comfortable ordering transfer when the domain is actively misused in a way that causes consumer harm. Passive holding after hijacking, by contrast, creates a factual question: panels have found passive holding by a domain thief to constitute bad faith in appropriate circumstances, but the analysis is more demanding, and some panels have declined to extend the passive-holding doctrine into a hijacking fact pattern without additional evidence of intent.

In a recent matter (a .global hijacking, spring 2025), we assembled a registrar-login audit trail showing that the unauthorized access originated from an IP address in a jurisdiction with no prior account history, within minutes of a spear-phishing message that impersonated the registrar's billing team. That evidence, combined with proof that the domain was subsequently redirected to a credential-harvesting page, produced a rapid transfer order through the emergency registrar escalation track before a formal UDRP filing was necessary. The name was returned within three weeks of the initial compromise being discovered.

When a Court Route Beats Arbitration for .global Recovery

The UDRP is the default route for .global hijacking recovery, but it is not always the right one. Four situations favor a court action over arbitration.

First, when the minority panel view is likely to block a UDRP complaint. If the specific facts of the case involve an original registration by the complainant followed by an unauthorized outbound transfer – and counsel assesses a meaningful risk of a panel applying the narrow "registration" requirement – a court action in the relevant jurisdiction avoids that doctrinal trap entirely. Courts handling conversion, fraud, or computer-access claims do not apply the three-element UDRP framework; they apply general property and tort principles that are more naturally suited to a theft scenario.

Second, when monetary relief is needed. The UDRP's remedies are limited to transfer or cancellation. No damages, no costs, no injunction beyond the domain itself. If the hijacking caused significant business harm – lost revenue during a product launch, customer-data exposure from a phishing page, or brand damage from a diversion campaign – only a court can award compensation.

Third, when the attacker's identity is known or discoverable. Anonymous registrants make UDRP proceedings efficient because the panel does not need to serve or locate a specific individual. When the attacker can be identified – through the registrar-access logs, a ransom demand, or disclosed WHOIS data – a court action can proceed against a named defendant, with the possibility of asset recovery and an injunction that extends beyond the domain.

Fourth, when urgent interim relief is needed immediately. Courts can grant a temporary restraining order or an equivalent interlocutory injunction within days, freezing the domain and any associated accounts while the substantive case proceeds. The UDRP has no equivalent: the fastest timeline for a WIPO case is approximately one month under its expedited option, and standard cases run closer to two months. An attacker can do significant damage in that window.

The decision matrix in practice looks like this. If the .global domain has been cleanly hijacked, the attacker is anonymous, no damages are sought, and the panel-selection risk is acceptable: file a UDRP complaint at WIPO and run the registrar escalation in parallel. If the attacker is identified, damages matter, or urgency is extreme: engage local litigation counsel in the relevant jurisdiction and pursue a court action. If the transfer mechanics are the primary issue: file a TDRP complaint before reaching for either of the above. In complex cases, all three tracks may run simultaneously, with the TDRP and registrar escalation providing immediate containment while the UDRP or court action resolves the merits.

To weigh UDRP against a court action for your .global hijacking case, email info@cognomenlaw.com.

Addressing the Objection: Can the UDRP Really Handle a Theft Case?

A persistent myth in this area is that the UDRP is categorically the wrong tool for domain hijacking because it was designed for cybersquatting, not theft. That view is partly right and partly overstated.

It is right in this sense: the UDRP was not written with hijacking in mind. Its three-element test maps naturally onto the cybersquatter who registers a brand-identical domain to sell it back, park it, or redirect traffic. It maps less naturally onto the attacker who acquires an existing registration by fraud. The minority panel view reflects that design tension accurately.

It is overstated in this sense: the majority of panels have concluded that the policy's remedial purpose – protecting mark owners from abusive domain registrations – extends to unauthorized acquisitions, because the alternative would leave hijacking victims with no UDRP remedy at all. The WIPO jurisprudential overview and consistent panel reasoning both support the view that a fraudulent transfer constitutes a registration for UDRP purposes. That consensus has held across thousands of disputes over more than two decades.

What this means for a .global hijacking victim is that the UDRP is a viable route, not a guaranteed one. The outcome turns on which panel is appointed, how the evidence of compromise is presented, and whether the current holder's conduct clearly evidences bad faith. A case that leads with the account compromise evidence, pairs it with a clear trademark right, and demonstrates ongoing misuse of the domain is well-positioned under the majority view. A case that relies on the UDRP without that evidence package is not.

We regularly advise registrants and brand owners who have attempted a self-filed UDRP in a hijacking matter and received a denial. In those situations, a focused re-read of the panel decision usually identifies the element that was insufficiently supported – most often, the bad-faith use evidence was absent or the trademark right was not clearly established for the .global zone specifically.

Cross-Zone Considerations: What If the Hijack Spans Multiple Domains?

Hijacking campaigns are rarely limited to a single domain. An attacker who compromises a registrar account typically sweeps every valuable domain in the portfolio, not just the .global name. That creates a cross-zone dimension that shapes the recovery strategy.

A UDRP complaint may cover multiple domains if they share the same registrant. If the attacker has consolidated the hijacked domains under a single WHOIS identity – a common move to simplify resale – a single UDRP complaint covering all the gTLD names may be possible. That reduces both the forum filing fee and the time to resolution. At WIPO, filing fees for one to five domains on a single-member panel currently stand at USD 1,500; covering six to ten domains costs USD 2,000 at the single-member rate.

Where the hijacked portfolio includes ccTLDs, separate national procedures apply. A .de name in the same portfolio requires a German court action and a DENIC DISPUTE entry; a .uk name goes to Nominet's DRS. Those proceedings run in parallel to, not inside, a UDRP complaint. We coordinate that parallel filing structure routinely for clients who discover a multi-zone sweep.

One practical point on cross-zone evidence: the account compromise documentation – the phishing emails, the registrar-access logs, the unauthorized WHOIS updates – typically applies across all the hijacked domains simultaneously. Assembling that master evidence file once and adapting it for each proceeding is more efficient than treating each domain as a separate investigation. Courts and panels both benefit from a clean, chronological account of the compromise event, and a unified evidence record supports that presentation across jurisdictions.

In a separate matter (a multi-zone hijacking spanning a .global and two regional ccTLDs, autumn 2024), we coordinated simultaneous registrar escalations across three registrars while filing a UDRP complaint at WIPO covering the gTLD names. The ccTLD matters were referred to local litigation counsel in the relevant jurisdictions. All affected domains were returned within approximately two months of the initial escalation, with the UDRP decision arriving before the court actions were required to proceed to a full hearing.

Realistic Next Steps After a .global Hijacking

The timeline after a hijacking discovery is compressed. Every hour the domain sits under a fraudulent registrant's control, the attacker can deepen the damage: changing nameservers, establishing hosting accounts, sending phishing emails from the domain, or initiating a second transfer to an even more opaque registrar chain.

The first 24 hours should focus entirely on containment: report to the losing registrar's abuse team, obtain confirmation that the 60-day transfer lock is in place, contact the gaining registrar's abuse team, and document everything with timestamps. Do not attempt to log into the compromised account if the credentials have been changed; further login attempts may complicate the account-recovery process.

The first week should focus on evidence assembly: obtain the registrar's access logs under applicable data-protection rules, preserve the phishing or social-engineering correspondence, secure the trademark registration certificates, and obtain current WHOIS and DNS snapshots of what the attacker has done with the domain.

By the end of the first week, the recovery route selection – TDRP, UDRP at WIPO, court action, or a combination – should be finalized. That decision drives the remaining timeline: a UDRP complaint at WIPO, once prepared, is typically filed within a further two to four weeks, with a decision arriving approximately two months after commencement. A court action in many jurisdictions can produce interim relief faster, at higher cost. The TDRP, where it fits, is the fastest formal mechanism of the three.

One element that often delays recovery unnecessarily is the instinct to negotiate with the attacker. Paying a ransom to a domain thief does not resolve the legal claim, does not guarantee actual return of the domain, and creates a payment record that complicates any subsequent fraud or criminal referral. In our practice, we advise clients to avoid any direct payment to an identified attacker and to proceed directly to the formal recovery routes described above.

Related at COGNOMEN

Frequently asked questions

How long does it take to recover a hijacked .global domain after account compromise?

Timeline depends heavily on the route chosen. A registrar escalation combined with a successful TDRP complaint can return the domain in days to weeks if the unauthorized transfer is clearly documented. A UDRP complaint at WIPO typically produces a decision within approximately two months of filing, with the 20-day response window for the current holder built into that timeline. A court action can produce interim relief faster in some jurisdictions, though the final merits hearing takes longer. There is no single fixed timeline: evidence quality and forum selection are the controlling variables.

What does it cost to recover a hijacked .global domain after account compromise at WIPO?

The WIPO filing fee for a single .global domain on a single-member panel is USD 1,500, rising to USD 4,000 for a three-member panel. Legal preparation fees for a hijacking case – which requires more complex evidence assembly than a standard cybersquatting complaint – typically run in the USD 3,000–7,000 range for a single-domain matter, though fact complexity, the volume of evidence, and any parallel court work will affect that figure. Registrar escalation and TDRP filings carry lower formal fees; the cost is primarily in legal time.

Do I need a lawyer to recover a hijacked .global domain after account compromise?

Self-representation is technically permitted in UDRP proceedings. In a straightforward cybersquatting matter with clear evidence, some experienced registrants manage without counsel. In a hijacking case, the doctrinal complexity – the split between the majority and minority panel views on whether unauthorized transfer satisfies the bad-faith registration element – and the need to coordinate registrar escalation, TDRP, UDRP, and potentially court action simultaneously make legal guidance materially valuable. A poorly assembled complaint in a hijacking matter risks denial on a panel that applies the minority view, closing the UDRP path for a refiling.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.