Case study: reverse an unauthorized transfer of a .biz domain
Case study: reverse an unauthorized transfer of a .biz domain. UDRP and ccTLD domain recovery and defense across .biz. Email the firm to assess your case.
A business domain disappears overnight. The registrant wakes up to find the .biz name that anchored its email, its invoices, and its customer portal is now registered to a stranger in a different country. The account was not sold. No authorization was given. The domain was stolen.
Reversing an unauthorized transfer of a .biz domain requires moving fast on two simultaneous tracks: a registrar-escalation and lock request to freeze any onward transfer, and a parallel legal action – either a UDRP complaint before WIPO (available for .biz, which operates under the UDRP) or direct court proceedings where arbitration cannot reach the remedy needed. The outcome turns on how quickly the evidence of account compromise is assembled and how clearly ownership can be documented to the gaining registrar and, if necessary, a panel or court.
This case study walks through one such matter – anonymized, with no real names or case numbers – and identifies the decisions that determined the result.
The Situation: What Happened and Why It Was Urgent
In early 2025 a mid-sized professional-services firm contacted COGNOMEN after discovering that its primary .biz domain had been transferred out of its registrar account to an account at a different registrar, controlled by a third party with no connection to the business.
The transfer had taken place roughly 72 hours before the firm noticed. The firm's IT team confirmed that the registrar account credentials had been compromised through a phishing attack targeting the firm's administrative email address. Once inside the account, the attacker had disabled the transfer lock, changed the WHOIS contact email to an address they controlled, and initiated an outbound transfer request. The gaining registrar processed the request without further verification – relying on the confirmation sent to the now-hijacked admin email.
The domain had been registered by the firm for over a decade. It carried active MX records, pointed to the firm's hosted application, and was the anchor identifier in several commercial contracts. Every hour of displacement created compounding operational harm.
The Strategy: Registrar Escalation First, Legal Action in Reserve
The first decision was practical: go to the registrar before going to a panel. WIPO's UDRP procedure – which governs .biz disputes – is designed for cybersquatting, not account hijacking. A UDRP complaint requires proof that the registrant had no legitimate interest and registered in bad faith. Here, the domain had not been registered in bad faith by anyone; it had been stolen from a registrant with years of documented ownership. That distinction matters.
We escalated simultaneously to both the losing registrar (where the firm's account had been compromised) and the gaining registrar (which now held the transferred domain). The escalation package included: the original registration records showing continuous ownership from the registration date; technical logs from the firm's email provider documenting the phishing compromise and unauthorized access; a notarized statement from the firm's authorized officer confirming that no transfer authorization had been given; and a formal abuse complaint citing the gaining registrar's own transfer-policy obligations under ICANN's Transfer Policy.
The gaining registrar placed a registrar lock on the domain within 48 hours of receiving the escalation package. That lock prevented any onward transfer to a third party while the dispute was reviewed – the critical intervention that buys time for a legal action if needed.
At this stage, we also prepared a UDRP complaint on a contingency basis. .biz is a sponsored generic TLD that operates fully under the UDRP, and WIPO is the principal forum for those disputes. Had the registrar escalation stalled or the gaining registrar refused to cooperate, a UDRP filing would have forced the matter before a panel, with transfer as the available remedy. In parallel, we documented the facts necessary for a court action – specifically, the unauthorized-access elements that would support an anticybersquatting or computer-fraud theory in the applicable jurisdiction – because court proceedings can reach damages and can compel registrar cooperation in ways that UDRP cannot.
If your domain has moved without your authorization, the window to act is narrow. To assess your options for reversing an unauthorized transfer, contact info@cognomenlaw.com.
The Outcome: Transfer Reversed, Domain Restored
The gaining registrar completed its internal investigation within approximately three weeks of the initial escalation. On review of the compromise documentation, it concluded that the transfer had been processed on the basis of a hijacked authorization. The domain was transferred back to the firm's account at its original registrar.
No UDRP complaint was filed. The court action was not commenced. The registrar route, driven by a complete and immediate evidence package, resolved the matter before arbitration became necessary.
Two factors were decisive. First, speed: the escalation reached the gaining registrar before any onward transfer occurred, which meant there was only one party holding the domain when the lock was applied. Second, documentation: the firm's IT logs provided an unambiguous chain connecting the phishing attack to the unauthorized transfer request. Absent that technical record, the gaining registrar would have had no basis to override a transfer it had already processed in apparent compliance with its own procedures.
What did not work, and what practitioners regularly see fail in these matters, is a complaint that leads only with trademark rights. Trademark ownership, on its own, does not explain a stolen domain to a registrar's abuse team. The operative evidence is account compromise: access logs, phishing headers, IP address anomalies, and the timeline of credential changes preceding the transfer request.
If a prior escalation stalled or a registrar failed to act, a focused review of the original evidence package can identify what was missing. Email info@cognomenlaw.com to discuss next steps.
Related at COGNOMEN
Frequently asked questions
Can WIPO handle a stolen .biz domain, or does court action apply?
WIPO administers UDRP proceedings for .biz, and a UDRP complaint is available as a route. However, the UDRP is designed for cybersquatting – bad-faith registration targeting a trademark owner. Where the domain was stolen rather than registered in bad faith, a registrar escalation under ICANN's Transfer Policy is typically faster and more directly responsive to the facts. Court proceedings remain available where arbitration cannot supply the remedy needed.
How quickly must you act after discovering an unauthorized transfer?
Immediately. Each day after the transfer increases the risk of an onward transfer to a third party, which adds a new registrant and complicates any reversal. The first priority is a registrar lock request to the gaining registrar, supported by evidence of account compromise. Delays in assembling that evidence are the most common reason escalations fail or take significantly longer to resolve.
What evidence is essential to reverse an unauthorized domain transfer?
The core package is: original registration records showing continuous ownership; technical logs documenting the account compromise (phishing headers, unauthorized login records, IP anomalies); a statement from an authorized officer confirming no transfer was authorized; and a formal abuse complaint citing the applicable transfer policy. Trademark certificates help establish identity but do not substitute for compromise evidence in a theft scenario.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.