Case study: reverse an unauthorized transfer of a .global domain
Case study: reverse an unauthorized transfer of a .global domain. UDRP and ccTLD domain recovery and defense across .global. Email the firm to assess your case.
A domain disappears overnight. The registrant wakes to find the .global name that anchors their brand has moved to a new registrar, under a new registrant record, with no authorization given. The lock that should have held it was silently removed. The attacker is already pointing the domain at a credential-harvesting page.
Reversing an unauthorized transfer of a .global domain requires moving on two tracks at once: a registrar-level escalation to freeze the domain in place, and – where the receiving registrar will not act voluntarily – a court order or WIPO complaint to compel reversal. The .global registry operates under UDRP rules administered by WIPO, which means both the arbitration route and the registrar-lock mechanics available for standard gTLDs apply here. Speed is the controlling variable; every day the attacker holds the name the evidentiary trail grows colder.
This case study walks the situation, the strategy, and the result.
What Was the Situation?
In late autumn 2025, we were contacted by the operator of a professional-services group whose flagship .global domain had been transferred without authorization earlier that week. The registrant's account at their accredited registrar had been accessed through a credential-stuffing attack. The attacker changed the registrant email, disabled two-factor authentication on the account, removed the registrar lock, and initiated a transfer to a second registrar in a different jurisdiction – all within a four-hour window.
By the time our client realized what had happened, the transfer had completed. The domain was resolving to a phishing page that mimicked the client's login portal. Customers were already receiving fraudulent invoices routed through the hijacked name. The financial and reputational exposure was immediate.
Two complications made this matter harder than a standard transfer-reversal. First, the receiving registrar was located outside the client's home jurisdiction, which limited the reach of any domestic court order in the short term. Second, the attacker had already updated the WHOIS/RDDS record to reflect a shell registrant identity, obscuring the chain of events that would otherwise be straightforward to trace.
What Was the Strategy?
The first priority was containment, not litigation. We filed an emergency registrar-lock escalation with the original registrar within hours of engagement, documenting the account-compromise sequence – access logs, timestamp anomalies, and the registrant-email change that preceded the transfer request. That request asked the original registrar to assert a transfer-dispute hold with the receiving registrar under the inter-registrar transfer policy.
At the same time, we prepared a WIPO complaint under the UDRP. The .global zone operates under the UDRP, so the standard three-element framework of Paragraph 4(a) was available: the domain was identical to a trademark the client held, the attacker had no legitimate interest, and the registration and use in bad faith were clear from the phishing activity. A WIPO single-member complaint carries a filing fee of USD 1,500 and a standard timeline of roughly two months – too slow on its own for a live phishing attack, but valuable as a parallel record and as leverage.
The cross-border dimension shaped the advice. The receiving registrar's jurisdiction offered a court route that could deliver a temporary restraining order faster than a UDRP decision would arrive. We identified local litigation counsel in the relevant jurisdiction, briefed them on the access-log evidence and the RDDS anomaly, and they filed for emergency relief. That court filing named the receiving registrar and sought an order requiring it to freeze the domain pending a full hearing.
Why pursue both tracks? The UDRP produces a transfer order enforceable through the registrar chain. The court order freezes the domain immediately and prevents a second transfer while the UDRP ran. Neither route alone was sufficient. Together they closed the window for the attacker to move the domain again.
The evidence bundle assembled for both proceedings included: the original registration records predating any dispute; the client's trademark registration certificates; access-log data from the compromised account documenting the unauthorized login; the timestamp sequence showing the lock removal and transfer request; and archived screenshots of the phishing page.
If your domain has been transferred without authorization – whether under .global or another zone – the first step is an immediate registrar escalation combined with a review of your evidence of compromise. To plan recovery of a stolen or hijacked domain, contact info@cognomenlaw.com.
What Was the Outcome?
The court order in the receiving registrar's jurisdiction issued within approximately five business days of filing. It required the registrar to place a transfer-hold on the domain pending further order. The phishing page went dark shortly after the hold took effect, as the attacker lost control of DNS management.
The WIPO proceeding continued in parallel. The panel found all three Paragraph 4(a) elements satisfied: the domain was identical to the client's registered mark, the attacker presented no legitimate-interest defense, and the use of the domain for credential harvesting was unambiguous bad-faith use under Paragraph 4(b). A transfer order issued approximately eight weeks after filing.
Once both orders were in hand, the receiving registrar cooperated with the transfer back to the original registrar. The domain was returned to the client's control, the RDDS record was restored, and a new registrar lock was placed. Total elapsed time from our engagement to domain recovery was just under four months – long by normal standards, but shortened materially by the parallel strategy.
The myth that a UDRP alone is sufficient for a theft-and-transfer scenario is one we encounter often. When the receiving registrar is outside the complainant's home jurisdiction and the attacker is actively monetizing the domain, a court order is frequently the faster and more reliable emergency remedy. The UDRP then functions as the instrument for formal title restoration.
For a read on whether the three UDRP elements are met in your situation, or to assess the court-route options for your jurisdiction, reach us at info@cognomenlaw.com.
Related at COGNOMEN
Frequently asked questions
What was the situation?
A professional-services group lost control of its flagship .global domain after a credential-stuffing attack on the registrant account. The attacker removed the registrar lock, transferred the domain to a second registrar in a foreign jurisdiction, and pointed it at a phishing page mimicking the client's login portal – all within a four-hour window. Customers began receiving fraudulent invoices within days.
What did the firm do?
COGNOMEN filed an emergency registrar-lock escalation with the original registrar on the same day as engagement, documenting the account-compromise sequence. In parallel, a WIPO UDRP complaint was prepared – the .global zone operates under the UDRP – and local litigation counsel in the receiving registrar's jurisdiction filed for an emergency court order to freeze the domain. Both tracks ran concurrently to close the window for a second transfer.
What was the outcome?
A court-issued transfer-hold took effect within approximately five business days, taking the phishing page offline. The WIPO panel then issued a transfer order roughly eight weeks after filing, finding all three Paragraph 4(a) elements satisfied. With both orders in hand, the domain was returned to the client's registrar account. Total recovery time was just under four months from initial engagement.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.