Assess my case

Case study: bring a court action when UDRP cannot reach a .global dom…

Case study: bring a court action when UDRP cannot reach a .global dom. UDRP and ccTLD domain recovery and defense across .global. Email the firm to assess your…

A global software brand discovered, in early 2026, that its flagship .global domain had been silently transferred out of its registrar account. The new registrant was unknown. The domain was resolving to a lookalike site harvesting customer credentials. The brand's legal team asked a single question: can the UDRP fix this?

When a .global domain is hijacked through account compromise rather than bad-faith registration at the outset, the UDRP is often the wrong tool. All three UDRP elements require proof that the domain was registered in bad faith — a standard that a post-registration theft rarely satisfies on its face. A court action, supported by an emergency registrar lock, is frequently the only route that can compel return of the domain and restrain ongoing harm.

This case study walks through the situation, the strategic choices made, and the result — with all identifying details anonymized.

What was the situation?

The brand — a mid-sized enterprise software company operating under a registered mark in multiple jurisdictions — had held its .global domain for several years. In winter 2026, an account-compromise event at the registrar level allowed an unauthorized party to change the administrative contact and initiate an outbound transfer. The transfer completed before the brand's IT team detected the change through routine RDDS monitoring.

By the time the company contacted us, the domain was pointing to a cloned version of their product login page. Credential-harvesting scripts were active. Every day the domain remained out of the company's control compounded the reputational and legal exposure.

The brand's in-house team had already considered a UDRP complaint. The obstacle was real. The registrant at the time of the original registration was the brand itself — the theft occurred post-registration, through account takeover, not through a bad-faith registration by a stranger. Panels have consistently held that a complainant cannot use the UDRP where the core issue is who transferred the domain, not whether it was registered in bad faith. The UDRP's Paragraph 4(a) demands all three elements, and element three — registered and used in bad faith — does not bend to accommodate a theft scenario where the domain was legitimately registered in the first place.

What did the firm do?

We moved on two tracks simultaneously. Speed was the operative constraint.

On the registrar track, we escalated immediately to the registrar's abuse and legal departments, presenting documented evidence of the account compromise: access logs, change-of-registrant timestamps, authentication anomalies, and an affidavit from the brand's IT security officer. We requested an emergency registrar lock — a hold that prevents any further transfer or change of nameservers while the dispute is resolved. The registrar granted the lock within approximately 48 hours of our escalation. That stopped the bleeding. The domain remained pointed at the lookalike site, but it could not be moved again or transferred onward to a second registrant, which would have created a much more complex chain of title.

On the litigation track, we coordinated with local litigation counsel in the relevant jurisdiction to pursue a court action grounded in anticybersquatting principles and the brand's registered trademark rights. The evidentiary record we assembled included the original registration history confirming the brand as the legitimate prior registrant, the registrar-level access logs showing unauthorized credential use, RDDS snapshots before and after the transfer, and forensic analysis of the lookalike site confirming the credential-harvesting function. That combination — a clear chain of prior title plus documented unauthorized transfer plus active consumer harm — formed a strong basis for interim injunctive relief.

A key strategic decision: we did not attempt to route this through a UDRP complaint in parallel. Doing so would have risked a procedural finding that the matter was sub judice in litigation, and a UDRP panel would almost certainly have declined jurisdiction or denied the complaint on the bad-faith registration element. Splitting resources between two forums where only one had jurisdiction was not advisable.

If your domain has been transferred out of your account without authorization, the registrar-lock step and the litigation track must move together. To assess the right route for your situation, contact info@cognomenlaw.com.

What was the outcome?

Interim relief was granted by the court within approximately two weeks of filing. The order required the registrar to re-delegate nameserver control to the brand pending final determination. The lookalike site went dark. Within roughly six weeks of our initial instruction, the domain's registrant of record had been restored to the brand through the court's transfer order, confirmed by the registrar's implementation of that order.

The case illustrates a point we return to in our practice regularly: the UDRP and the court route are not interchangeable. The UDRP is a contractual arbitration procedure built to address bad-faith registration. When a domain is legitimately registered by the brand and then stolen, the legal question shifts entirely — to unauthorized transfer, to chain of title, and to the registrar's obligations under its own terms of service. Courts can reach all of those questions. Panels operating under the UDRP generally cannot.

For brand owners holding .global domains — and for that matter any gTLD or ccTLD domain — the lesson from this matter is that the registrar-lock escalation path and the court litigation path must be understood before a compromise occurs. Reactive planning under time pressure, with a live credential-harvesting site running, is the most expensive way to handle it.

For a read on whether a court action is the right route for your domain dispute, reach us at info@cognomenlaw.com.

Related at COGNOMEN

Frequently asked questions

What was the situation?

A software brand's .global domain was transferred out of its registrar account through an unauthorized credential compromise. The domain began resolving to a lookalike site harvesting customer credentials. A UDRP complaint was not viable because the domain had been legitimately registered by the brand originally — the issue was theft, not bad-faith registration, and panels require proof of bad-faith registration under Paragraph 4(a) of the UDRP.

What did the firm do?

We pursued two simultaneous tracks: an emergency registrar-lock escalation backed by documented evidence of account compromise, and coordination with local litigation counsel to pursue a court action for unauthorized transfer and trademark-based relief. We deliberately did not file a parallel UDRP complaint, which would have lacked jurisdiction over the registration-bad-faith element and risked procedural complications with the litigation.

What was the outcome?

The court granted interim relief within approximately two weeks of filing, ordering nameserver re-delegation to the brand. The lookalike site went offline. Within roughly six weeks of instruction, the domain's registered ownership was formally restored to the brand through the court's transfer order. The registrar implemented the order without further dispute.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.