Case study: recover a stolen .global domain
Case study: recover a stolen .global domain. UDRP and ccTLD domain recovery and defense across .global. Email the firm to assess your case. Transparent fees, r…
A domain theft moves fast. The registrant logs in one morning to find the domain gone — transferred without authorization to an unknown account at a foreign registrar, already pointed at a site they do not recognize. The clock starts immediately. Every hour the stolen domain sits in unauthorized hands, the harder recovery becomes.
Recovering a stolen .global domain turns on speed, the right escalation path, and a clear evidence trail of the unauthorized transfer. The .global zone is a new generic top-level domain (gTLD), which means the UDRP applies — but domain theft is a distinct scenario from a standard cybersquatting complaint. Where theft is the cause, the registrar-lock and transfer-reversal mechanics, not just arbitration, are often the decisive tools. This case study walks one such matter from discovery to resolution.
The sections below cover the situation, the strategy, and the outcome — and what the evidence requirements actually look like in practice.
What Was the Situation?
The affected party — a technology services firm operating internationally — held a .global domain as its primary web address. In late 2025, the domain disappeared from their registrar account without any action on their part. Within days it had been transferred to a registrar in a different jurisdiction and was resolving to a site impersonating the firm's own platform.
The firm had not authorized the transfer. Their account had been compromised through a credential-stuffing attack: an automated process using leaked passwords from an unrelated data breach. The registrar's access logs confirmed logins from unfamiliar IP addresses in the days before the transfer. Those logs became the foundation of the recovery case.
The impersonation site was collecting contact-form submissions. The firm was losing customer inquiries, and its brand credibility was deteriorating by the day. Time pressure was acute.
What Did the Firm Do?
We were retained within 48 hours of the firm identifying the theft. The first action was not a legal filing — it was a registrar escalation. We prepared a formal theft report to the losing registrar, documenting the unauthorized account access, the transfer timeline, and the identity of the receiving registrar. We requested an immediate ICANN transfer-dispute submission under the registrar transfer-dispute procedure.
In parallel, we assessed whether the UDRP was the right primary vehicle. For a standard cybersquatting complaint — a third party registers a domain confusingly similar to a trademark — the UDRP at WIPO is the standard route, with a USD 1,500 filing fee for a single-member panel and a normal resolution period of roughly two months. But this was not a registration dispute. The current holder of the domain had not registered it in bad faith at the outset; they had received it through a fraudulent transfer chain. That fact shifted the analysis.
A UDRP complaint was still viable — the domain was identical to the firm's registered trademark, the current holder had no legitimate interest, and holding a stolen domain constitutes bad faith under the Policy. We filed the complaint at WIPO, supported by the access logs, the original registration certificate, the trademark registration, and evidence of the impersonation site. Simultaneously, we briefed local litigation counsel in the jurisdiction where the current registrar was located, in case a court injunction was needed to freeze the domain pending arbitration.
The decision to pursue both tracks — the UDRP and the registrar escalation — was deliberate. Arbitration alone can take two months. The registrar channel, when supported by solid compromise evidence, can produce a temporary lock within days. We secured a registrar lock on the domain within five business days of filing the theft report, preventing any further transfers while the UDRP proceeded.
In matters involving unauthorized transfers, the first 72 hours determine whether a lock is achievable before the domain moves again. To assess the recovery options for a stolen domain, contact info@cognomenlaw.com.
What Was the Outcome?
The WIPO panel transferred the domain back to the legitimate registrant. The panel found all three UDRP elements satisfied: the domain was identical to the complainant's registered mark, the current holder had no rights or legitimate interests, and the unauthorized transfer and subsequent impersonation use constituted bad faith registration and use within the meaning of Paragraph 4(a) of the UDRP.
The access logs were central. They established that the original registrant had not authorized the transfer — a fact that distinguished this from a scenario in which the registrant might have voluntarily conveyed the domain to a third party. The panel treated the unauthorized receipt of a stolen domain as itself a bad-faith circumstance, consistent with the consensus view in proceedings of this kind.
Total elapsed time from our instruction to the transfer order: approximately eight weeks, with the registrar lock in place from week one. The firm's domain was back under its control before the WIPO decision was formally implemented, because the lock prevented any further movement and the receiving registrar cooperated with the eventual transfer instruction.
No court action was ultimately required. The preparatory work with local litigation counsel — scoping the injunction route — served as a contingency that we did not need to exercise. That said, had the receiving registrar refused to lock the domain, a court freezing order in the relevant jurisdiction would have been the necessary next step.
If a domain theft is in progress or recently discovered, reach us immediately at info@cognomenlaw.com — early intervention substantially changes what is recoverable.
Related at COGNOMEN
Frequently asked questions
What was the situation?
A technology firm's .global domain was transferred without authorization after their registrar account was compromised through a credential-stuffing attack. The stolen domain was then pointed at an impersonation site. Registrar access logs confirmed logins from unrecognized IP addresses in the days before the transfer — evidence that proved decisive in the recovery proceedings.
What did the firm do?
COGNOMEN pursued a dual-track approach: a formal registrar theft escalation to lock the domain against further transfer, and a UDRP complaint at WIPO establishing that the current holder had no legitimate interest and was using the domain in bad faith. A court injunction route via local litigation counsel was scoped as a contingency. The registrar lock was secured within five business days; the UDRP panel ordered transfer approximately eight weeks after instruction.
What was the outcome?
The WIPO panel ordered transfer back to the legitimate registrant, finding all three UDRP elements satisfied. The registrar lock, secured during the first week, prevented further movement of the domain throughout the proceedings. No court action was ultimately required. The domain was under the firm's control before the formal WIPO implementation process was complete.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.