Assess my case

FAQ: recover a hijacked .com domain after account compromise

FAQ: recover a hijacked .com domain after account compromise. UDRP and ccTLD domain recovery and defense across .com. Email the firm to assess your case.

Your registrar account was accessed without authorization. The domain was transferred out. You are watching a name you built traffic and brand equity around point at a stranger's page. How do you recover a hijacked .com domain after account compromise — and how fast does the clock run?

Recovering a hijacked .com depends on how quickly you act and which route fits the facts. The primary tools are registrar escalation for an emergency lock, a UDRP complaint before WIPO or the Forum where the recipient is a bad-faith actor, and — where arbitration cannot reach — US anticybersquatting litigation or a court-ordered injunction. Speed matters: unauthorized transfers can be reversed at the registrar level within days if reported promptly, but the window is short and evidence of the compromise must be preserved from the first hour.

The questions below cover the mechanics of each route for .com domains, what evidence decides the outcome, and when to escalate beyond the registrar.

When Can I Recover a Hijacked .com Domain After Account Compromise?

The right to pursue recovery arises the moment you can document that the transfer was unauthorized — but the specific route depends on where the domain now sits and what the recipient is doing with it.

If the domain was transferred within the last few days, registrar escalation is the first step. ICANN's transfer-dispute procedures give the losing registrar a mechanism to request reversal where the transfer violated the applicable transfer policy. That window is tight. Report the compromise to your registrar immediately, request an emergency domain lock, and preserve your authentication logs, email headers, and any phishing or social-engineering artifacts. The faster you act, the more realistic a direct reversal becomes.

If the domain has already moved beyond the registrar's direct reach — transferred to a different registrar, pointed at a live commercial site, or offered for resale — the procedural options shift. A UDRP complaint covers .com domains globally. Where the current holder is using the domain in bad faith, all three elements of Paragraph 4(a) of the UDRP must be satisfied: the domain is identical or confusingly similar to a mark you hold, the holder has no legitimate interest, and the domain was registered and is being used in bad faith. Domain theft, where a registrant acquires a name through account compromise rather than registration, requires careful framing under the Policy — the "registration" element must be addressed directly in the complaint.

When arbitration is not adequate — for example, where you need an injunction to freeze the domain or where you want monetary damages — US anticybersquatting litigation is the only path that reaches those remedies. We regularly advise brand owners and registrants on which route is proportionate to the facts and the value of the name at stake.

To assess whether registrar escalation, a UDRP complaint, or court action fits your situation, contact info@cognomenlaw.com.

Who Can Recover a Hijacked .com Domain After Account Compromise?

Any party who held the domain registration at the time of the unauthorized transfer and can demonstrate prior rights — including registered or common-law trademark rights, or simply a documented record of continuous registration — has standing to pursue recovery.

Under the UDRP, the complainant must show rights in a name that corresponds to the disputed domain. For a hijacked .com, that means your trademark registration, your evidence of brand use, and your registrar records showing you as the prior holder. A domain investor who holds a name as a portfolio asset without an accompanying mark will find the UDRP a harder fit; the registrar-escalation and court routes may be more direct in those circumstances.

For registrar-level reversal, you do not need a trademark. You need evidence that the transfer was unauthorized: authentication logs showing the request did not originate from your account in the ordinary course, evidence of a compromised password or social-engineering attack, and a formal report to the registrar's abuse or security team. If the current registrar is accredited, ICANN's transfer-dispute process provides a standardized framework for that escalation.

Where the hijacking has a criminal dimension — identity fraud, SIM-swapping, account takeover — a law-enforcement report can support the civil recovery and may accelerate registrar cooperation. In our practice, we often handle the registrar escalation in parallel with preparing a UDRP filing, so neither track waits on the other.

Does WIPO or a Court Decide a .com Dispute?

For .com domains, WIPO is the most widely used arbitral forum, but it is not the only option — and for some hijacking scenarios a court is the only forum that can deliver the relief you actually need.

WIPO administers the largest share of UDRP cases globally, with the Forum handling most of the remainder. Together they account for roughly 97% of all UDRP proceedings. A standard WIPO case for a single .com domain carries a filing fee of USD 1,500 for a single-member panel and typically concludes within about two months. The WIPO expedited option delivers a decision within roughly one month for eligible cases. The only remedies available through the UDRP are transfer or cancellation — no damages, no costs award.

A US court action is different in both cost and capability. It can issue an injunction to freeze the domain immediately, order monetary damages, and reach defendants who are unresponsive to arbitral process. The trade-off is time and cost: court proceedings run substantially longer and at higher legal expense than a UDRP filing. For a high-value .com where the domain is actively being monetized or used in fraud, the court route is often worth the investment. For a domain whose primary value is the name itself and where a transfer order satisfies the claim, the UDRP is usually the faster and more economical path.

The right answer depends on the domain's value, the identity and conduct of the current holder, and what remedy you actually need. A decision matrix: if the domain is a .com and transfer is the goal, WIPO or the Forum first; if you need an injunction or damages, US anticybersquatting litigation; if the current holder is unlocatable and the registrar is unresponsive, court action may be the only lever that works.

What Evidence Decides the Outcome of a Hijacked .com Recovery?

Evidence of account compromise is the foundation of a hijacking case — and it must be gathered before it disappears from logs, email servers, and registrar dashboards.

The core evidence set for a registrar escalation includes: authentication logs from your registrar account showing login activity, IP addresses, and timestamps of the unauthorized transfer request; email headers showing the phishing or social-engineering message that preceded the compromise; any MFA bypass or SIM-swap confirmation from your mobile carrier; and a chain-of-title record showing your continuous registration of the domain prior to the unauthorized transfer. Screenshots alone are rarely enough. Authenticated records from the registrar's own systems carry far more weight.

For a UDRP complaint, the evidentiary package expands. You need to establish your trademark or common-law rights in the corresponding name, demonstrate that the current holder has no plausible legitimate interest in the domain, and show bad-faith use or registration. A domain that was hijacked and immediately pointed at a pay-per-click parking page or used in a phishing scheme makes the bad-faith element straightforward. A domain that was hijacked and is now being passively held — no active website, no use — is harder but not impossible: panels have consistently held that passive holding in circumstances of obvious bad faith can satisfy the use element.

In a recent matter (a .com hijacking, early 2026), we assembled the authentication logs, the phishing email chain, and the brand's trademark registration record, filed a UDRP complaint at WIPO, and secured a transfer order. The registrant did not respond. The evidence of compromise carried the complaint through all three elements.

What If the Registrant Does Not Respond?

Default by the registrant does not mean automatic transfer — but it significantly shifts the analysis in the complainant's favor.

Under the UDRP, the respondent has 20 days to file a response after the case formally commences. If no response is filed, the panel proceeds on the complaint alone. The panel does not simply accept all allegations as proven; it must still be satisfied that the complaint meets the three-element test on the evidence presented. A well-constructed complaint with solid evidence of compromise will succeed in default. A thin complaint that relies on the default to carry the day may not.

What default does change is the burden in practice. Without a countervailing record, panels regularly draw adverse inferences from a respondent's silence, particularly where the registration pattern, the use of the domain, or the circumstances of the transfer are facially suspicious. An RDNH finding — where the panel concludes that the complaint was brought in bad faith to deprive a legitimate registrant — is essentially unavailable when the respondent defaults, because there is no one defending the name.

For hijacking cases specifically, a default respondent is common: the current holder obtained the domain through unauthorized means and has no legitimate story to tell. That pattern supports a strong complaint. We build hijacking complaints to stand alone on the evidence, treating every default as a case that might be defended at the last moment.

Can the Decision Be Appealed or Challenged?

A UDRP decision is not final in the way a court judgment is — either party can seek de novo review in a court of competent jurisdiction, but the window and the cost make that a limited safety valve.

After a transfer or cancellation order issues, ICANN's rules give the losing registrant a standard period to file a court action staying the implementation of the decision. If no court action is filed in that window, the registrar implements the transfer. In practice, court challenges to UDRP decisions are rare: the cost of litigating in a national court exceeds the value of most contested domains, and panels generally apply the Policy correctly enough that a legal challenge does not gain traction.

For complainants, there is no formal appeal within the UDRP itself. If a complaint is denied, the complainant can refile in certain circumstances — for example, where there is new evidence that was not available at the time of the original filing — but panels scrutinize refiled complaints carefully, and a second attempt on the same facts will ordinarily fail. The practical alternative is to pursue a court action.

An RDNH finding — available only where the complainant pursued the dispute in bad faith — carries no monetary penalty but is a lasting reputational mark on the complaint record. For respondents defending a hijacking case against a bad-faith complainant, RDNH is a real strategic tool. We have defended registrants against complaints that were RDNH on their face: where the complainant had no plausible trademark rights and was using the UDRP as leverage against a legitimate holder.

If a prior UDRP filing produced a denial or if you received an abusive complaint, email info@cognomenlaw.com to assess the options for a second action or a court route.

What Is the Deadline Once a Case Starts?

Under the UDRP, the respondent's deadline is 20 days from formal commencement of the case — not from filing, but from the date the provider confirms the complaint and notifies the respondent. That distinction matters: commencement can lag filing by several days if the complaint requires remediation.

For the complainant, there is no fixed deadline to file a UDRP complaint after a hijacking event — but delay carries practical risk. Evidence degrades. Registrar logs are purged. The domain may be transferred again, requiring an updated complaint. And the longer a bad-faith holder monetizes the domain, the more damage accumulates that a UDRP cannot compensate (because UDRP remedies are transfer or cancellation only, never damages). Filing quickly preserves optionality.

At the registrar level, speed is even more critical. ICANN's transfer-dispute process has its own timelines that run from the date of the unauthorized transfer. Missing the applicable window can extinguish the registrar-level reversal option entirely, leaving arbitration or court as the only routes. We advise clients to treat a discovered hijacking as an emergency: lock the account, report the compromise, preserve the evidence, and get counsel on the same day.

For court actions, the applicable limitations period depends on the jurisdiction and the cause of action. Describe these as qualitatively distinct from UDRP timelines and confirm the current period with counsel in the relevant jurisdiction.

Frequently asked questions

When can I recover a hijacked .com domain after account compromise?

Recovery is available as soon as you can document the unauthorized transfer. Registrar escalation can reverse a transfer within days if reported immediately. A UDRP complaint before WIPO or the Forum can order transfer of a .com domain where the three elements of Paragraph 4(a) are met. Court action is available where arbitration is insufficient or where you need an injunction or damages. Act on the day you discover the compromise — delays allow evidence to degrade and additional transfers to occur.

Who can recover a hijacked .com domain after account compromise for a .com domain?

The prior registrant who held the domain at the time of the unauthorized transfer has standing to pursue recovery. A trademark holder whose mark corresponds to the domain name has the clearest path through the UDRP. A domain investor without a trademark may rely on the registrar-escalation route or court action. In all cases the key requirements are documented proof of prior registration, evidence of unauthorized access, and a record showing the current holder's illegitimate claim to the name.

What is the deadline once a case starts?

Once a UDRP case formally commences, the respondent has 20 days to file a response. For the complainant there is no fixed UDRP filing deadline, but delay risks lost evidence and additional transfers. At the registrar level, ICANN's transfer-dispute windows run from the date of the unauthorized transfer and are strictly applied. For court actions the applicable limitations period depends on the jurisdiction; confirm the current period with counsel in the relevant forum.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.