Assess my case

Case study: recover a .eu domain used for phishing

Case study: recover a .eu domain used for phishing. UDRP and ccTLD domain recovery and defense across .eu. Email the firm to assess your case.

A phishing campaign is live. The domain — a near-identical copy of a European brand's registered name under the .eu extension — is redirecting the company's customers to a spoofed payment page. The brand owner needs it stopped, fast. The question is whether the ADR.eu procedure can move quickly enough to do real damage control.

To recover a .eu domain used for phishing, a complainant must satisfy the ADR.eu dispute procedure, which applies the three core elements drawn from the UDRP: the domain is identical or confusingly similar to a mark in which the complainant has rights; the registrant has no rights or legitimate interests; and the domain was registered or is being used in bad faith. The remedy — where the complainant also meets EU or EEA eligibility — is transfer. In clear cases of phishing, bad faith is rarely the contested element; legitimate interest is not even arguable.

This case study walks through the situation, the strategy, and the outcome — all anonymized, no case numbers, no real names.

The Situation: a .eu Look-alike Deployed for Credential Theft

In spring 2025, a mid-size European financial services company — call it the Brand — discovered a .eu domain registered two weeks earlier. It was a character-swap typosquat: one letter transposed in the Brand's exact mark. The domain resolved to a login page styled to replicate the Brand's own customer portal. Customers were receiving phishing emails directing them to it.

The Brand had held a registered EU trademark for several years. The trademark predated the disputed domain by a wide margin. That fact alone collapsed the first UDRP element into the uncontested column: a domain that differs from a registered mark by a single transposed letter is confusingly similar by any measure panels consistently apply. The real work was assembling the right package and choosing the right path.

The Brand also had an existing .eu registration for its own name, which confirmed EU eligibility for the ADR.eu procedure. That eligibility question — does the complainant meet EURid's nexus requirement to hold .eu? — is one that sometimes catches brand owners off guard, particularly those operating primarily outside the EU. Here, it was not an issue. The matter was straightforward in its elements, if not in its urgency.

The Strategy: ADR.eu, Evidence Packaging, and the Bad-Faith Record

The .eu dispute procedure is administered through the Czech Arbitration Court's ADR.eu platform. It applies the three standard elements, but the remedy available — transfer versus revocation — depends on whether the complainant can actually hold a .eu domain. Where EU eligibility is confirmed, transfer is available. Where it is not, the panel can only order cancellation. In this matter, the Brand could hold .eu, so transfer was the right claim to make.

We assessed the three UDRP elements at the outset. Confusing similarity: clear, given the single-character transposition. Legitimate interest: absent. No bona fide offering, no evidence the registrant was commonly known by the name before the dispute, no noncommercial fair use — the site was a phishing clone. Bad faith: the evidence here was the most direct we routinely encounter. A spoofed login page, customer-directed phishing emails, and a two-week-old registration all pointed one way. Under Paragraph 4(b) of the UDRP — incorporated by reference in the ADR.eu rules — registration and use to attract users by creating confusion with the complainant's mark is a paradigm bad-faith scenario.

The evidentiary package we assembled covered four categories. First, screenshots of the phishing site, date-stamped and archived through a third-party archiving service. Second, the Brand's EU trademark registration certificate with the filing and registration dates clearly visible. Third, samples of the phishing emails forwarded by affected customers, with headers intact. Fourth, a WHOIS/RDDS record showing the registration date and confirming a registrant with no apparent connection to the Brand's sector or geography.

One practical decision: whether to file the complaint immediately or to seek a registrar-level suspension first. Registrar escalation for phishing is available in some cases — a number of registrars will act on a credible abuse report — but it is not guaranteed, and it does not transfer the domain. The Brand needed the domain transferred, not merely taken offline and later re-pointed. We filed the complaint through ADR.eu without waiting.

If you are facing an active phishing campaign using a .eu domain, the evidentiary record you build in the first 48 hours is often the most durable part of the case. For an assessment of whether ADR.eu or a parallel registrar escalation is the right first move, contact info@cognomenlaw.com.

The Outcome: Transfer Ordered, Phishing Domain Taken Down

The respondent did not file a response. The 20-day response window elapsed without any submission, and the case proceeded to a single-member panelist. The decision issued within approximately two months of filing — consistent with the standard ADR.eu timeline for undefended cases. Transfer was ordered to the Brand.

That outcome is not automatic simply because the respondent defaults. A panel still reviews the complaint on its merits. What the absence of a response does is shift the overall balance: panels may draw adverse inferences from a default, and without a respondent advancing a Paragraph 4(c) safe harbor — no bona fide offering, no "commonly known by the name," no legitimate noncommercial use — the Brand's evidence stood unopposed.

The phishing site was offline before the transfer order issued, as it happened. The registrar had received an abuse report through separate channels and had suspended the domain's resolution during the proceedings. But the transfer order resolved the underlying ownership question permanently. A registrar abuse suspension alone would not have done that: the registrant could have re-pointed the domain the moment the suspension was lifted. Transfer removed that risk entirely.

What did this case demonstrate beyond the mechanics? Two things. First, that phishing-for-commercial-gain is among the clearest bad-faith scenarios in the ADR.eu and UDRP canon: the intent to profit by deceiving the complainant's own customers maps directly onto the Paragraph 4(b) factors. Second, that the contemporaneous evidence gathered in the days immediately after discovery — archived screenshots, email headers, WHOIS records — carried the complaint. Evidence assembled weeks later, from memory or reconstructed sources, is weaker and sometimes challenged.

To weigh ADR.eu against a parallel escalation strategy for a .eu phishing domain, email info@cognomenlaw.com.

Related at COGNOMEN

Frequently asked questions

What changed for .eu complainants compared with a standard UDRP?

The ADR.eu procedure applies the same three elements as the UDRP but adds an eligibility layer: the complainant must have an EU or EEA nexus to be awarded a transfer rather than mere cancellation. The "registered or used" bad-faith formulation also reflects the .eu rules' own language. Otherwise the evidence standard, the response window, and the remedy structure track closely to the UDRP.

Who is most exposed to .eu phishing domain attacks?

Financial services firms, payment processors, and e-commerce brands with a European customer base are the most common targets in our practice. Any business with a recognized name in the EU market and an existing .eu presence is a potential target. Attackers typically register the typosquat as close to a product launch or marketing campaign as possible — timing the confusion to exploit peak customer activity.

What should you do in the first 48 hours after discovering a .eu phishing domain?

Archive the phishing site immediately using a third-party web archiving service. Capture the full WHOIS/RDDS record before any privacy service updates it. Collect any customer-forwarded phishing emails with full headers intact. Notify your registrar and, if the domain is actively defrauding customers, file an abuse report with the registrar simultaneously with preparing the ADR.eu complaint. Contact counsel as early as possible — the evidence gathered in this window is the foundation of the case.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.