Assess my case

Case study: recover a stolen .sg domain under the applicable domain ru

Case study: recover a stolen .sg domain under the applicable domain ru. UDRP and ccTLD domain recovery and defense across .sg. Email the firm to assess your ca…

The email arrived on a Tuesday morning. A Singapore-based business owner logged into the registrar portal and found the domain gone – transferred overnight to an account the owner had never created. The attacker had used a credential-stuffing method to access the registrar account, changed the WHOIS contact email, and initiated a transfer out before any alert fired. The domain had been in continuous use for more than six years and carried the company's primary brand.

Recovering a stolen .sg domain requires acting on two parallel tracks: immediate registrar escalation to freeze the gaining registrar's account, and a formal filing under the Singapore Domain Name Dispute Resolution Policy (SDRP) – or, where arbitration cannot reach the wrongdoer, court action coordinated with the Singapore registry. The window to act is narrow. The longer the domain sits in the attacker's hands, the harder the evidence of compromise becomes to preserve.

This case study walks through how COGNOMEN approached that situation, the mechanics that worked, and what the outcome required.

The Situation: What the Registrant Faced

The registrant – a Singapore-registered trading company – held a single .sg domain that had served as its main web presence for six-plus years. Over a long weekend, the attacker gained access to the registrar account through a reused password exposed in an unrelated data breach. The account recovery email was changed. The domain was placed in a new account at a different registrar, and the DNS was pointed at a phishing page designed to harvest the company's customer credentials.

By the time the company's IT team identified the misdirection, roughly 72 hours had passed. The losing registrar had no automated hold in place. The gaining registrar – based outside Singapore – initially declined to act, citing the transfer's apparent regularity under its own internal records. The client came to us four days after the initial compromise was discovered.

Three facts defined the risk. First, the company's customers were actively reaching a fraudulent site. Second, the domain had independent commercial value, meaning a demand for ransom was plausible. Third, the .sg registry – administered by the Singapore Network Information Centre (SGNIC) – has its own dispute framework that does not map cleanly onto the UDRP.

The Strategy: Registrar Lock, SDRP, and the Court Route

On day one we sent simultaneous notices to both registrars and to SGNIC. The notice to the losing registrar invoked its abuse-reporting process and asked for account-level evidence: login timestamps, IP addresses, and the sequence of credential changes. That evidence was essential – not just for any filing, but to demonstrate to SGNIC that the transfer was unauthorized.

SGNIC's published framework for .sg domains includes the SDRP, which covers abusive registrations. But domain theft – as distinct from cybersquatting – falls partially outside the SDRP's designed purpose. The SDRP focuses on rights-versus-registration conflicts; it does not straightforwardly address an unauthorized transfer of a legitimately held domain. That distinction matters for route selection.

Where arbitration under the SDRP cannot reach the wrongdoer or cannot deliver a transfer reversal on a theft theory, the alternative is court action in Singapore. A court application can compel the registry to freeze and restore a domain pending full proceedings, and can reach a foreign gaining registrar through jurisdictional hooks if the domain itself is treated as property within SGNIC's zone. We assessed that the court route, combined with a registrar-level escalation, was the more direct path in this instance.

In parallel, we documented the phishing activity through archived screenshots, DNS change logs from a third-party DNS monitor, and the client's own server logs showing a drop in legitimate inbound traffic. That evidence package served two purposes: it supported an emergency application for an interim freeze on the domain, and it rebutted any claim by the attacker that the transfer was consensual.

For an assessment of whether court action or SDRP is the right route for your .sg domain, contact info@cognomenlaw.com.

The Outcome: What Decided the Case

In a matter concluded in early 2026 involving a stolen .sg domain, we secured an interim freeze on the domain within approximately ten days of filing. The gaining registrar, faced with a formal court document and coordinated pressure from SGNIC, placed the domain in a registrar lock pending resolution. The phishing site went dark. The domain was ultimately returned to the legitimate registrant after the attacker failed to appear and contest the application.

Three elements decided the outcome. First, speed: the interim freeze application was filed before the attacker could re-transfer the domain to a further registrar, which would have complicated enforcement substantially. Second, evidence quality: the account-compromise logs obtained from the losing registrar provided a clean chain of unauthorized access – timestamped, with IP geolocation inconsistent with the registrant's documented location. Third, the registry relationship: coordinating with SGNIC directly, rather than relying solely on the gaining registrar's abuse team, accelerated the lock by several days.

What did not help was the 72-hour delay before the client contacted outside counsel. In domain theft cases, that window is when the attacker re-transfers, changes DNS records, and creates the evidentiary smoke that slows a court application. Had the client escalated on day one rather than day four, the interim application would have been faster and the phishing exposure shorter.

The realistic next step for any registrant facing a similar situation is the same: escalate to the registrar and the registry simultaneously on the day of discovery, preserve all login and DNS evidence before anything is overwritten, and get a legal assessment of whether the SDRP or a court application is the right vehicle before time is lost.

To plan recovery of a stolen or hijacked .sg domain, contact info@cognomenlaw.com.

Related at COGNOMEN

Frequently asked questions

Does the SDRP cover domain theft, or is court action always required for .sg?

The Singapore Domain Name Dispute Resolution Policy is designed primarily for cybersquatting – cases where a party registers a domain to take unfair advantage of another's rights. Domain theft, meaning an unauthorized transfer of a legitimately held domain, often falls outside that designed scope. Where the SDRP cannot deliver a transfer reversal on a theft theory, a court application in Singapore is the more direct route, and can be combined with a registry-level freeze request to SGNIC while the matter proceeds.

How quickly does a registrar lock need to be in place to make recovery realistic?

The critical window is the first 48 to 72 hours after a theft is identified. If the attacker re-transfers the domain to a second or third registrar within that window, enforcement becomes substantially more complex. A simultaneous notice to both the losing and gaining registrars, alongside a direct contact with SGNIC's abuse team, gives the fastest route to a lock. Any delay before escalation reduces the chance of an interim freeze before the domain moves again.

What evidence is most important in a stolen .sg domain case?

The three most valuable evidence types are registrar login logs showing the unauthorized access (timestamps and IP addresses inconsistent with the legitimate registrant's documented location), DNS change records demonstrating the redirection from the legitimate site, and archived screenshots of any fraudulent or phishing content placed on the domain after the theft. This evidence package supports both the interim freeze application and the underlying claim that the transfer was not consensual.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.