Assess my case

Recover a hijacked .info domain after account compromise: what panels…

Recover a hijacked .info domain after account compromise: what panels. UDRP and ccTLD domain recovery and defense across .info. Email the firm to assess your c…

A registrant's control panel is breached overnight. By morning, the .info domain they built a business on has been transferred to a stranger's account at a different registrar, the DNS points elsewhere, and the original owner's credentials no longer work. The question is not merely whether the transfer was unauthorized — it clearly was. The question is which legal route reaches a reversal fastest, what evidence panels and registrars actually require, and where the UDRP's limits force the dispute into a courtroom instead.

To recover a hijacked .info domain after account compromise, a legitimate owner must typically pursue one or more of three routes: a registrar escalation under ICANN's transfer dispute resolution procedures, a UDRP complaint before WIPO or another approved provider, or — where arbitration cannot reach — court action. The 20-day response window under the UDRP, the WIPO filing fee of USD 1,500 for a single-member panel, and the critical distinction between a theft scenario and a cybersquatting scenario all shape the strategy. No single path guarantees recovery; the specific facts of the account compromise, the conduct of the new registrant, and the speed of the response decide which route to take first.

This analysis covers the governing rules for .info, the registrar-lock and transfer-reversal mechanics, the evidentiary record that panels demand, the points of doctrinal disagreement among panels, and when a court action overtakes arbitration as the only realistic option.

Why .info sits firmly within the UDRP — and what that means for hijack cases

.info is an ICANN-accredited gTLD governed by the standard UDRP, meaning every .info registrant and every .info complaint falls under the same Policy that applies to .com, .net, and .org. That starting point matters enormously in a hijack case, because the UDRP was designed for cybersquatting — not theft. The Policy's three elements (Paragraph 4(a)(i)–(iii)) ask whether the domain is confusingly similar to a mark you hold, whether the current registrant lacks legitimate interest, and whether the domain was registered and is being used in bad faith. That third element is cumulative and conjunctive.

A thief, by definition, is not the original registrant. The domain was not registered in bad faith by the original owner — it was stolen from them. Panels have grappled with exactly this tension. The consensus view that has developed is that a UDRP complaint filed by the original owner against the receiving party (the entity that accepted the fraudulent transfer) can succeed if: the complainant demonstrates it held rights in the name, the receiving party cannot show any legitimate interest, and the receipt of a known-stolen domain itself constitutes bad-faith use even where the initial registration was not made by that party. Several panels have treated the receipt of a fraudulent transfer as the functional equivalent of a bad-faith registration for purposes of Paragraph 4(a)(iii), particularly where the receiving party then used the domain to redirect traffic, hold it for ransom, or simply park it.

The contrary view — a genuine minority position but one that shapes litigation risk — holds that the UDRP cannot be used to recover a stolen domain because the complainant, as the original registrant, no longer "has rights" in a domain they no longer control under the strict reading of the Policy. That minority view has not prevailed in most panels, but it is enough to create uncertainty. Where that risk is live, the registrar route or a court action may be more reliable.

Registrar escalation and the transfer-reversal mechanics: the fastest path in practice

Before a complaint is filed anywhere, the fastest practical step after a hijacking is a registrar escalation. ICANN's transfer policy — the Inter-Registrar Transfer Policy — imposes specific obligations on registrars when a transfer is alleged to be unauthorized. An owner who discovers a hijack should immediately contact both the losing registrar (where the domain was held before the compromise) and the gaining registrar (where it now sits), submitting a formal unauthorized-transfer claim with supporting documentation.

What that documentation must include is not merely an assertion. Panels and registrars consistently require: (a) a timestamped record showing the complainant was the registrant of record immediately before the transfer; (b) evidence of the account compromise — login attempt logs, phishing emails received, password-reset notifications triggered without the owner's action, or a police or cybercrime report; (c) proof of the trademark or business rights that make recovery more than a private account dispute; and (d) communications or lack thereof from the gaining registrar, which is relevant to any later showing of registrar neglect.

The ICANN transfer policy gives the losing registrar tools to initiate a reversal, and the gaining registrar an obligation to cooperate with legitimate reversal requests. In practice, cooperation is uneven. Some registrars act swiftly on credible documentation; others require escalation to ICANN's Contractual Compliance function before they move. In a recent matter — a .info hijacking that came to our attention in spring 2025, involving a multi-year business domain transferred without consent — we initiated the registrar escalation within 48 hours of discovery, secured a registrar lock on the domain within one week, and prevented further DNS manipulation while the broader dispute proceeded. The registrar lock does not itself return the domain, but it stops the clock on further harm.

For an assessment of your domain dispute and the fastest path to a registrar lock, contact info@cognomenlaw.com.

How panels evaluate account-compromise evidence: the consensus and the contested ground

The evidentiary record in a .info hijack UDRP is different from a standard cybersquatting case, and panels have developed a body of reasoning — largely consistent but with notable divergences — about what that record must show.

On the consensus side, panels have consistently held that a complainant in a hijack scenario can establish "rights" under Paragraph 4(a)(i) by demonstrating prior registration history and any trademark, trade name, or documented business use of the domain — even without a registered trademark. The confusing similarity element in these cases is almost always met: the domain the complainant seeks to recover is the domain they previously held, so identity is literal. What varies is the treatment of the second and third elements.

For the second element — no legitimate interests in the registrant — panels have generally been willing to infer the absence of legitimate interest from the receiving party's silence. Default rates in hijack cases are higher than in ordinary cybersquatting disputes, because the fraudulent acquiring party often disappears once the WHOIS or RDDS record has been manipulated. A panel that receives no response has consistently held that the failure to come forward with any legitimate-interest evidence, combined with the complainant's prima facie showing of prior rights, satisfies element two.

The third element is where doctrinal disagreement is sharpest. The majority approach treats the unauthorized receipt of a domain, followed by any use — parking, redirection, ransom demands — as satisfying the bad-faith registration-and-use requirement, applying the Policy's Paragraph 4(b) factors by analogy. The minority view demands that the panel find the receiving party was itself the architect of the compromise, not merely a downstream recipient. That second strand of reasoning has been used in a handful of cases to deny relief, leaving the original owner without a remedy at WIPO and requiring a pivot to court.

What does that disagreement mean in practice? It means the strength of your account-compromise evidence matters not just for the registrar escalation, but as the linchpin of a UDRP complaint. A police report, a cybercrime referral, phishing email headers, two-factor authentication logs, or server access records that show an intrusion — any of these substantially narrows the risk that a panel treats the receiving party as merely an innocent transferee. We regularly advise registrants who contact us after a hijacking to gather this evidence before filing, because a thin factual record invites the minority position.

When a UDRP complaint is the right vehicle — and when it is not

The UDRP is almost always the right starting point for a .info hijack where the complainant holds a trademark or can demonstrate well-established secondary meaning in the name. A standard case at WIPO runs approximately two months to a decision. The filing fee is USD 1,500 for a single-member panel on one to five domains. The only remedies are transfer or cancellation — the Policy offers no damages, no costs award, and no injunction. For a hijack victim who simply wants the domain returned, that limitation is acceptable. The speed and the cost are real advantages over litigation.

Three scenarios push the analysis away from a UDRP filing and toward a court action.

First: where the complainant cannot satisfy Paragraph 4(a)(i) because the .info domain is a personal name, a generic descriptor, or a name over which they hold no recognized rights. The UDRP requires rights in a mark. A non-trademark domain — a purely descriptive .info used for a personal project, for example — may not qualify. In that scenario, court provides the only route to a theft-based recovery theory.

Second: where the hijack involved identity fraud that extends beyond the domain — email accounts, financial accounts, or other digital assets affected in the same breach. The UDRP cannot address those collateral harms. A coordinated fraud may require law enforcement action and civil litigation in parallel, not just a domain proceeding.

Third: where damages are essential. The UDRP orders transfer; it never awards money. If the hijacking caused measurable revenue loss, customer diversion, or reputational harm, and the perpetrator is identifiable and within a jurisdiction that supports civil recovery, US anticybersquatting litigation or the equivalent national cause of action may be the only path to compensation. We work in those matters with local litigation counsel in the relevant jurisdiction.

A practical decision matrix: if you hold a trademark, the domain is a .info gTLD, and you want it back quickly, file a UDRP at WIPO — but pursue the registrar escalation in parallel, because the lock provides interim protection the UDRP cannot. If no trademark exists but the account compromise is documented and provable, lead with the registrar route and assess whether the governing national procedure supports a theft-based civil claim. If you need damages or the perpetrator must be identified through discovery, court is the primary vehicle from the outset.

To weigh UDRP against a court action for your case, email info@cognomenlaw.com.

RDNH risk in reverse: why complainants in hijack cases rarely face it

Reverse Domain Name Hijacking (RDNH) — a panel finding that a complaint was filed in bad faith to deprive a legitimate registrant of their domain — is a genuine risk in standard cybersquatting cases, particularly where a complainant over-reaches against a domain investor with a plausible legitimate interest. In a documented hijack case, the RDNH risk to the complainant is substantially lower, for an obvious reason: a complainant who was the registrant of record before the unauthorized transfer, and who can document the compromise, is not a bad-faith filer. They are the theft victim.

The scenario where RDNH does become relevant in hijack cases arises when the "hijack" claim is contested — where the receiving party asserts they acquired the domain through a legitimate secondary-market sale, the original owner disputes this, and the panel cannot resolve the factual conflict from the documentary record alone. In those cases, a panel may decline to transfer the domain and, in rare instances, may question whether the complaint was filed without adequate pre-filing due diligence. We have defended registrants facing exactly this kind of contested-acquisition claim, where the complaint was framed as a hijack but the documented chain of title pointed to a valid marketplace transaction.

The lesson is that the framing of a hijack UDRP matters as much as the underlying facts. A complaint that overstates the compromise evidence, or that conflates a disputed secondary-market sale with a fraudulent transfer, risks a finding that damages credibility — even if RDNH is not formally declared.

Multi-zone and cross-border dimensions: when the hijack spans more than one domain

Hijackers rarely stop at one domain. In our practice, account compromises that target a .info domain frequently also capture the corresponding .com, .net, or ccTLD registrations held in the same registrar account. That creates a multi-zone dispute with different governing rules for each zone.

A single UDRP complaint may cover multiple domains only if the registrant is the same holder — which in a hijack scenario may be true at the moment of the transfer but may change rapidly as domains are parceled to different shell accounts. A complainant who files too late may face separate proceedings for each zone. For the .info domain, the UDRP applies directly. For a simultaneously hijacked .de domain, there is no UDRP equivalent — the dispute belongs in the German courts, and a DENIC DISPUTE entry can block further transfer while the claim is pursued. For a hijacked .uk domain, the Nominet DRS applies, with its own test of "abusive registration" and a free mediation stage before any expert decision.

In a recent matter involving a coordinated account compromise affecting a .info and two ccTLDs (autumn 2024), we assessed the multi-zone exposure immediately, secured a registrar lock across all three domains within days, and then pursued the .info through a UDRP filing while coordinating with local litigation counsel for the national procedures. The parallel track was essential — a sequential approach would have left the ccTLD domains unprotected during the UDRP pendency.

The cross-border dimension also affects the evidence strategy. WIPO panels deciding a .info complaint can consider the full factual record, including evidence of the coordinated nature of the breach across zones, as context for bad faith. Presenting that coordinated evidence — rather than treating each domain in isolation — tends to strengthen the inference that the receiving parties were not innocent transferees.

The respondent-side perspective: defending against a mischaracterized hijack claim

Not every "hijack" claim is accurate. A domain owner who acquires a .info through a broker, an auction, or a direct secondary-market sale occasionally finds themselves named as a respondent in a UDRP complaint filed by a prior owner who asserts the transfer was unauthorized. That scenario is more common than the industry acknowledges, partly because lapsed registrations are sometimes recaptured by third parties and the original holder mistakenly attributes the loss to fraud rather than non-renewal.

A respondent defending against a mischaracterized hijack claim has 20 days to file a response after commencement. The core defense is documentation of the acquisition chain: broker communications, marketplace transaction records, escrow records, registrar confirmation of the transfer type (push, pull, or auction), and any WHOIS or RDDS history showing the domain dropped from the previous holder before the acquisition. Where that chain is clean, the legitimate-interest defense under Paragraph 4(c) is strong, and an RDNH finding against the complainant is a realistic outcome.

We have defended registrants in exactly this position — domain investors who acquired .info domains through documented marketplace transactions and then faced complaints framed as theft. The factual record, assembled promptly and presented coherently, has been decisive. A panel that receives a full acquisition-chain record alongside a credible business rationale for holding the domain will rarely transfer it, regardless of the complainant's characterization of events.

The respondent angle also highlights a procedural asymmetry worth noting: a UDRP complainant who files a mischaracterized hijack claim is unlikely to face monetary sanction — the UDRP awards no costs. The only consequence is an RDNH finding, which is reputational. That asymmetry means some complainants over-reach. A respondent who understands this and builds a thorough defense is in a stronger position than the Policy's apparent imbalance might suggest.

Related at COGNOMEN

Frequently asked questions

Is it worth it to recover a hijacked .info domain after account compromise?

In most cases, yes — particularly where the .info domain carries an established business identity, trademark rights, or significant inbound traffic. The cost of a UDRP complaint at WIPO, with a filing fee of USD 1,500 for a single-member panel and typical legal fees in the market range for a documented hijack case, is generally far lower than the commercial cost of losing the domain permanently. The calculus shifts where the domain is low-value, where no trademark rights exist, or where the account compromise was so complex that only expensive court action can resolve it. A pre-filing assessment of the evidence and the applicable route is the right starting point before committing to any proceeding.

What are the most common mistakes when you recover a hijacked .info domain after account compromise?

The three most consistent errors we observe are: delay in securing a registrar lock (which allows further DNS manipulation while the dispute is being organized); filing a UDRP complaint without first assembling the account-compromise evidence (a thin record invites the minority panel view that the receiving party was an innocent transferee); and treating the .info dispute in isolation when the same compromise affected multiple zones, each requiring a different procedure. A fourth error is failing to notify ICANN's Contractual Compliance function when a registrar is unresponsive to an unauthorized-transfer claim — that escalation path is underused and can move faster than either arbitration or litigation in some situations.

Can a three-member panel change the outcome?

In a hijack case, a three-member panel can matter — but not always in the direction a complainant expects. A three-member panel at WIPO costs USD 4,000 versus USD 1,500 for a single panelist, and if the complainant requested a single panelist but the respondent requests three members, the parties generally split the higher fee. Where the doctrinal question — particularly the contested "registered and used in bad faith" element in a theft scenario — is genuinely uncertain, a three-member panel provides more deliberative depth and a majority opinion that carries more persuasive weight in future proceedings. For a straightforward default case with strong compromise evidence, a single-member panel is usually sufficient and faster.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.