Assess my case

Case study: recover a .pl domain used for phishing

Case study: recover a .pl domain used for phishing. UDRP and ccTLD domain recovery and defense across .pl. Email the firm to assess your case.

A financial services brand discovered a .pl domain identical to its registered trademark — pointing at a cloned version of its website, harvesting customer credentials. The registrant was anonymous. The damage was immediate and ongoing. The question was which legal route could remove the domain fastest and most reliably.

Recovering a .pl domain used for active phishing requires understanding that Poland has no UDRP procedure: the governing national route runs through the Polish courts, supported by an administrative dispute mechanism operated under NASK (the Polish registry), and in parallel by any available UDRP filing if a corresponding gTLD domain is also involved. In a matter handled in early 2026, COGNOMEN coordinated a two-track strategy — an urgent administrative escalation with the .pl registry plus referral to local litigation counsel in Poland — that resulted in the domain being locked, then transferred, within a matter of weeks. Evidence of active phishing was the decisive factor.

This case study sets out the situation, the strategy, and the result, and explains what it means for brand owners facing similar abuse in the .pl zone.

Situation: a cloned site, an anonymous registrant, and a live phishing operation

The client was a mid-sized financial services provider registered in Poland, holding a national trademark for its brand name. In winter 2026, its compliance team flagged a .pl domain incorporating the brand name in full, preceded by a single descriptive word. The domain was live. It served a near-pixel-perfect copy of the client's login portal, capturing usernames and passwords.

WHOIS data showed a privacy-proxy registration. The registrant's identity was masked. No contact was made through official channels before COGNOMEN was instructed. The client's customers had already received phishing emails directing them to the domain. The risk was not theoretical — it was active and measurable.

Three problems made this harder than a standard recovery. First, .pl is not a UDRP zone: there is no three-element panel procedure before WIPO or the Forum. The governing national procedure applies, and any dispute over a .pl domain runs through NASK's administrative process or the Polish courts. Second, the registrant's concealment behind a privacy proxy required a disclosure step before any substantive filing. Third, the client needed removal in days, not months.

Strategy: administrative escalation, litigation coordination, and parallel gTLD action

The strategy combined three tracks, sequenced to move as fast as Polish procedure allowed.

Track 1 — registry escalation. Under NASK's abuse-reporting rules, a verified rights holder can request an expedited lock of a .pl domain where active fraud is documented. We prepared a formal abuse complaint to NASK, attaching screenshots of the cloned site, server-log excerpts showing active credential harvesting, and a certified copy of the client's Polish trademark registration. NASK placed a registrar lock on the domain within 48 hours of submission. The phishing site went dark.

Track 2 — national court proceedings. A lock is not a transfer. To compel reassignment, the applicable national procedure in Poland requires a court order or a settlement brokered through NASK's mediation channel. We referred the matter to local litigation counsel in Poland, who filed an urgent application for an interim injunction and domain transfer in the relevant Polish court. The evidence package we had already assembled for the NASK complaint formed the core of that application.

Track 3 — parallel UDRP on the matching .com. The same registrant, identifiable once the privacy proxy was lifted by NASK's disclosure request, also held the corresponding .com domain. That domain was parked, not actively phishing, but its existence created a second threat vector. Because the .com is a gTLD, all three UDRP elements of Paragraph 4(a) applied: confusing similarity to the client's mark, no legitimate interest in the registrant, and registration and use in bad faith. We filed a UDRP complaint at WIPO. The registrant had 20 days to respond after commencement. No response was filed. A single panelist issued a transfer order in the expected timeframe — roughly two months from filing to decision. The only remedies available under the UDRP were transfer or cancellation; we sought and obtained transfer.

If you are facing active abuse of a domain in any zone — including active phishing, credential harvesting, or a cloned site — the fastest first step is an accurate diagnosis of which procedure governs. To weigh UDRP against a court action for your case, email info@cognomenlaw.com.

Outcome: domain locked, site taken down, and transfer ordered

The .pl domain was locked by NASK within two days of the abuse filing. The phishing site ceased operating immediately. The Polish court issued an interim injunction within a matter of weeks, and the subsequent transfer order followed after the merits hearing. The client regained control of the .pl domain before the phishing campaign could resume under a new host.

The .com domain was transferred by the registrar following the WIPO panel's decision, approximately two months after the UDRP complaint was filed. The client now holds both zones.

What decided the outcome? In both tracks, the quality of the evidence package was the turning point. Screenshots alone rarely suffice. What made the difference here was contemporaneous server-log data, a confirmed phishing email chain from customers, a certified trademark registration predating the domain, and a clear chronology showing the registrant had no plausible good-faith purpose. Panels and courts read the same record. Build it carefully.

One common misconception is worth addressing directly. Brand owners sometimes assume that because .pl is outside the UDRP, recovery is slower or less certain than for a .com. That is not always true. Where active fraud is documented, NASK's abuse channel can move a .pl lock faster than a UDRP panel issues a decision. The two procedures are different instruments. The right one depends on the zone, the remedy needed, and how strong the abuse evidence is.

For a read on whether the three UDRP elements are met — or whether the national .pl procedure is the better path — reach us at info@cognomenlaw.com.

Related at COGNOMEN

Frequently asked questions

What was the situation?

A financial services brand found an identical .pl domain operated as a live phishing site, serving a cloned version of its login portal and harvesting customer credentials. The registrant was concealed behind a privacy proxy. Active fraud was confirmed before COGNOMEN was instructed. The client held a Polish trademark registration predating the domain.

What did the firm do?

COGNOMEN filed an urgent abuse complaint with NASK to lock the .pl domain, assembled a full evidence package — screenshots, server logs, phishing emails, certified trademark record — and coordinated with local litigation counsel in Poland to pursue transfer through the court process. In parallel, COGNOMEN filed a UDRP complaint at WIPO against the registrant's matching .com domain, where the standard three-element Policy applied.

What was the outcome?

The .pl domain was locked within approximately 48 hours and later transferred following a Polish court order. The .com domain was transferred under the WIPO panel's decision, issued roughly two months after the UDRP complaint was filed. The client recovered both zones. No damages were available under the UDRP; the court track addressed the .pl transfer directly.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.