Case study: recover a stolen .it domain under the applicable domain ru
Case study: recover a stolen .it domain under the applicable domain ru. UDRP and ccTLD domain recovery and defense across .it. Email the firm to assess your ca…
A domain disappears overnight. The WHOIS record flips to a stranger. Emails bounce. The company's Italian e-commerce site – years of brand equity, a live customer base – goes dark. The registrar says the transfer was authorized. The registrant of record says nothing at all.
Recovering a stolen .it domain requires moving on two tracks simultaneously: a registrar-level lock to freeze the domain while the account compromise is documented, and a legal route to compel transfer back to the legitimate holder. For .it, Italy's national registry (Registro.it, operated by CNR-IIT) does not operate a UDRP-style arbitral procedure for theft disputes; when a fraudulent outbound transfer has already occurred, the governing national procedure – and, where necessary, Italian court action – is the primary route. Speed and evidence quality decide everything.
This case study walks through the situation, the strategy we built, and the outcome achieved for a European software company whose .it domain was taken without authorization in early 2025.
Situation: an unauthorized transfer, a locked-out registrant
The client – a software development firm with an established Italian market – discovered in winter 2025 that its primary .it domain had transferred to a registrar it had never contracted with. The losing registrar confirmed a transfer request had been submitted through the account portal, but the client's IT team had not authorized it. A credential-compromise event, consistent with a phishing attack on an administrative email account, was the likely entry point.
By the time the client contacted us, the domain was live and pointing to a parked page with pay-per-click advertising. The new registrar of record was based outside the European Economic Area. No contact with the new registrant of record produced any response. The client had roughly three years left on the .it registration and a significant volume of transactional email and application traffic routed through the domain.
The business harm was immediate. Customer-facing services were degraded. Inbound mail to the domain was undeliverable. A five-figure monthly revenue exposure compounded each week the situation remained unresolved.
Strategy: registrar lock first, evidence chain second, legal route third
We moved in three layers from the first day.
Layer one: freeze the domain in place. We submitted a formal dispute-entry request through the losing registrar and escalated to Registro.it for a registry-level hold. The goal was to prevent any further transfer or deletion while the legal basis for reassignment was established. Domain theft recovery depends on a clean chain of title – one additional transfer makes reversal exponentially harder.
Layer two: build the evidence file. We compiled the full account-access log from the client's registrar account, the phishing email header analysis from the client's IT team, a screen-capture record of the domain's live use (pay-per-click parking), and the original registration history showing continuous ownership since the domain's registration date. The client held Italian and EU trademark registrations for the brand name matching the domain. That registeredtrademark record was central – it established both the client's prior rights and the absence of any legitimate basis for the receiving registrant to hold the domain.
We also documented the timeline gap: the outbound transfer was processed within a window of approximately forty minutes after a credential reset that the client did not initiate. That compression pointed unambiguously to a scripted, automated attack rather than an arms-length commercial transaction.
Layer three: select and pursue the legal route. For .it, the UDRP does not apply – Registro.it has not adopted the UDRP and operates under Italian law and its own registration regulations. Where a domain has already been fraudulently transferred, the applicable route for compelled reassignment runs through the Italian courts, supported by an application to the registry for provisional measures pending a substantive decision. We engaged local litigation counsel in Italy to file for an interim injunction freezing the domain and compelling the receiving registrar to cooperate with a transfer-back order. The legal theory rested on the documented account compromise, the client's established prior rights, and the bad faith of the receiving registrant – demonstrated by the pay-per-click use and the failure to respond to any contact.
If your domain has been transferred without your authorization, the first hours matter more than anything that follows. To plan recovery of a stolen or hijacked domain, contact info@cognomenlaw.com.
Outcome: domain returned, registry record restored
The Italian court granted interim relief within approximately three weeks of filing. The receiving registrar, faced with the court order and the registry's cooperation, facilitated a transfer back to the client's chosen registrar within ten days of the interim order. The full legal process, from our instruction to registry-record restoration, took approximately two months – a fast resolution by the standards of cross-border court proceedings, attributable to the strength of the evidence file assembled at the outset.
The client's Italian services were restored in full. The pay-per-click parking content was taken down as a condition of the interim order. The client subsequently moved to two-factor authentication on all registry accounts and engaged COGNOMEN for ongoing portfolio monitoring.
What decided the outcome was not the legal theory alone – Italian law provides a clear path for unauthorized-transfer reversal. What decided it was the quality of evidence: the access-log trail, the phishing-event timeline, the trademark record, and the contemporaneous capture of the bad-faith use. A thinner file would have meant a longer proceeding and a harder hearing.
In domain theft recovery, the difference between a two-month resolution and a two-year dispute is almost always the evidence assembled in the first 72 hours.
This case also illustrated when a court route beats an arbitral one. Had the domain been a .com under UDRP, a complaint would have been an option – but the UDRP's remedies are limited to transfer or cancellation, its timeline runs to roughly two months in any event, and a theft case involving account compromise (rather than a bad-faith registration by a stranger) sits awkwardly in the UDRP framework, which was designed for cybersquatting rather than fraud. The court route, here, allowed for interim injunctive relief against a specific registrar and a provisional hold – tools the UDRP cannot provide.
Related at COGNOMEN
Case summary: your questions answered
What was the situation?
A European software firm lost its primary .it domain to an unauthorized transfer following a credential-compromise event. The domain moved to an unfamiliar registrar and was pointed to a pay-per-click parking page, causing immediate disruption to Italian e-commerce operations and transactional email. The client had no contact with the new registrant of record and had not authorized any transfer.
What did the firm do?
COGNOMEN secured a registry-level hold to freeze the domain, built an evidence file from account-access logs, phishing-event forensics, and the client's Italian and EU trademark records, then engaged local litigation counsel in Italy to seek interim court relief. The combination of a strong evidence file and coordinated registrar escalation allowed the court application to proceed quickly.
What was the outcome?
Italian courts granted interim relief approximately three weeks after filing. The domain transferred back to the client within ten days of that order. Full service restoration took approximately two months from initial instruction. The case demonstrated that for .it theft disputes, a court-backed interim injunction – rather than arbitration – is the most effective tool available.
COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. Our domain theft recovery practice covers registrar escalation, account-compromise documentation, and transfer-reversal proceedings across jurisdictions, coordinated with local litigation counsel where foreign court action is required. To discuss a domain, contact info@cognomenlaw.com.
Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.