Case study: recover a hijacked .sg domain after account compromise
Case study: recover a hijacked .sg domain after account compromise. UDRP and ccTLD domain recovery and defense across .sg. Email the firm to assess your case.
A Singapore-registered .sg domain – the company's primary web address, tied to its email, payment gateway, and customer portal – disappeared overnight. The registrant account had been compromised, the domain's WHOIS record updated to a stranger's details, and a transfer pushed through to a different registrar before anyone noticed. The company had roughly 72 hours before the new registrar's transfer-lock window closed.
Recovering a hijacked .sg domain after account compromise requires moving simultaneously on two tracks: a registrar-level emergency lock to stop further transfers, and a formal dispute submission under Singapore's Singapore Domain Dispute Resolution Policy (SDRP) or, where the speed and evidence profile demands it, a direct court route. The governing procedure for .sg is the SDRP, administered under Singapore law; unlike the UDRP's cumulative "registered and used in bad faith" test, a theft-recovery case rests primarily on demonstrating the unauthorized nature of the transfer itself. The realistic window for registrar escalation is short – often days, not weeks.
This case study walks through the situation, the strategy we deployed, and the outcome. Names, registration details, and all identifying information have been changed.
The Situation: What the Client Faced
The client was a mid-sized Singaporean professional-services firm. Its .sg domain had been registered for more than a decade. Overnight in late 2025, a credential-stuffing attack compromised the registrant's email account – the same address tied to the domain's registrar portal. The attacker used password-reset flows to take over the registrar account, updated the WHOIS contact records, initiated an inter-registrar transfer, and cleared the authorization code from the registrant's inbox before the client noticed anything was wrong.
The first sign of trouble was a cascade of delivery failures. The firm's internal email routed through the domain. When the DNS was silently redirected, inbound client correspondence began bouncing. The finance team flagged it at 9 a.m. By afternoon, the registrar's records showed a completed transfer to a registrar outside Singapore. The attacker had also placed the domain behind a privacy proxy, making WHOIS confirmation slow.
The client had no UDRP rights in this situation – there was no trademark dispute. The domain was legitimately theirs, taken by fraud. That distinction matters enormously for route selection. A UDRP complaint requires the complainant to hold trademark rights; a theft recovery case does not fit that mold. The right path here was registrar escalation first, and the SDRP or court action as a backstop if the registrar process stalled.
The Strategy: Registrar Lock, Evidence Assembly, and Forum Choice
We were instructed within 24 hours of the client discovering the loss. The first action was not a legal filing – it was a formal abuse notification to the gaining registrar, citing ICANN's Inter-Registrar Transfer Policy (IRTP) provisions that require a gaining registrar to investigate fraud claims and, where substantiated, cooperate in reversal. That notification was accompanied by a structured evidence packet.
What did the evidence packet contain? It included the original registrar account creation records showing the client's historical ownership; server-side email logs demonstrating the domain's uninterrupted operational use over more than ten years; forensic screenshots of the credential-stuffing access event from the client's email provider; timestamped WHOIS change records; and a statutory declaration from the firm's managing director attesting to the unauthorized nature of every step.
The gaining registrar acknowledged receipt but did not move quickly. On day three, we filed a SDRP complaint in parallel. The SDRP, Singapore's ccTLD dispute procedure, is distinct from the UDRP. For a theft case, the grounds are framed around the registrant's lack of any legitimate basis to hold the domain – the "abusive registration" framing is adapted to cover unauthorized transfers. Critically, the SDRP allows a complainant to seek an immediate suspension of the domain pending the outcome, which functions as a practical lock against further transfer.
At the same time, we assessed whether a Singapore court application – an ex-parte injunction – was warranted alongside the SDRP route. The calculus here is specific. Court action is slower to initiate and substantially more expensive than an administrative procedure, but it carries coercive power the SDRP cannot: a court order can compel a registrar, a privacy proxy service, and even an upstream DNS provider to freeze and disclose. In this matter, the registrar's initial inaction made the court route a credible second weapon. We prepared the injunction application in draft, ready to file within 48 hours if the SDRP suspension was not actioned.
If your domain has been transferred without your authorization, time is the critical variable. To assess your recovery options under the SDRP or through the Singapore courts, contact info@cognomenlaw.com now.
The Outcome: Transfer Reversed and Domain Secured
The SDRP suspension request was granted within approximately one week of filing, placing the domain in a locked state at the gaining registrar while the complaint proceeded. That event triggered the gaining registrar to cooperate. Faced with a formal suspension order and the prospect of the draft injunction, the registrar moved within five business days to place the domain on hold and begin the reversal process.
The full SDRP proceeding was not ultimately needed to its conclusion. The gaining registrar, having reviewed the fraud evidence we submitted directly – and aware of the pending court application in draft – agreed to a consensual transfer reversal under the ICANN IRTP framework. The domain returned to the client's original registrar. New authentication credentials were established. DNS was restored. Email flow resumed within hours of the registrar update propagating.
The total elapsed time from our instruction to domain restoration was just under four weeks. No UDRP was filed; no trademark rights were asserted. The recovery rested entirely on documenting the account compromise, moving fast on the administrative track, and maintaining a credible court-route backstop. The client then engaged us for a follow-on review of its domain portfolio's registrar-security posture – a step we recommend in every theft-recovery matter.
What does this case illustrate for brand owners and registrants holding .sg domains? Two things stand out. First, the SDRP suspension mechanism is a genuine lever – faster than full court proceedings, and sufficient to stop a clean-hands registrar from processing a further transfer. Second, the court route is not just a last resort; it is a negotiating instrument. A credibly drafted injunction application, held in reserve and communicated clearly, changes registrar calculus. We regularly use both tracks together in theft-recovery matters.
For a read on whether registrar escalation, the SDRP, or a court application is the right first step for your hijacked domain, email info@cognomenlaw.com.
Related at COGNOMEN
Frequently asked questions
What was the situation?
A Singapore professional-services firm lost its primary .sg domain to a credential-stuffing attack in late 2025. The attacker compromised the registrant's email account, reset the registrar-portal password, updated WHOIS records, and completed an inter-registrar transfer before the client noticed. The domain underpinned the firm's email, payment gateway, and client portal – making fast recovery operationally critical.
What did the firm do?
COGNOMEN was instructed within 24 hours of discovery. We filed an immediate fraud-based abuse notification to the gaining registrar under ICANN's Inter-Registrar Transfer Policy, assembled a structured evidence packet including account-creation records, email logs, and a statutory declaration, filed a parallel SDRP complaint seeking suspension, and prepared a Singapore court injunction application as a backstop in case the administrative track stalled.
What was the outcome?
The SDRP suspension was granted within approximately one week, which prompted the gaining registrar to cooperate. The domain was returned by consensual reversal under the ICANN transfer framework in just under four weeks from our instruction. No UDRP was filed and no trademark rights were involved. The recovery rested on fraud documentation, fast administrative action, and a credible court-route backstop held in reserve.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.