Assess my case

FAQ: recover a .br domain used for phishing

FAQ: recover a .br domain used for phishing. UDRP and ccTLD domain recovery and defense across .br. Email the firm to assess your case. Transparent fees, respo…

A .br domain registered in your brand's name is redirecting visitors to a fake login page. Customers are being defrauded. You need it stopped – and ideally transferred. The question is which procedure governs recover a .br domain used for phishing and what it actually takes to succeed.

Brazil's .br registry, Registro.br (NIC.br), administers disputes through its own procedure – SACI-Adm – rather than the UDRP. To recover a .br domain, a complainant must show rights in a corresponding name or mark and that the registration is abusive. Phishing use is one of the clearest forms of bad-faith conduct a panel is likely to encounter. The UDRP's three-element test and its 20-day response window do not apply directly, but many of the underlying doctrines inform how SACI-Adm panels reason about evidence and intent.

The questions below address the governing procedure, the evidence that decides these cases, the realistic timeline, and the next steps for a brand owner or registrant facing this situation.

When can I recover a .br domain used for phishing?

You can seek recovery when you hold rights in a name or mark that corresponds to the disputed .br domain and the registrant is using it – or has registered it – in a way that takes unfair advantage of or causes unfair detriment to those rights. Phishing use, where the domain hosts a page impersonating your brand to harvest credentials or payments, is among the strongest factual bases for a complaint: it combines clear confusion with demonstrable harm to end users and to your mark's goodwill.

The key threshold is rights plus abusive use. Rights can rest on a registered trademark, a trade name with established recognition in Brazil, or in some cases an unregistered mark with significant secondary meaning. Phishing adds an aggravated dimension: it is not merely speculative or passive holding. It is active misuse directed at deceiving the public. Panels treating this class of case consistently regard it as evidence of both abusive registration and abusive use – the two-limb test that SACI-Adm applies.

One practical consideration: speed matters in phishing cases far more than in typical domain disputes. Every day the domain remains active, real harm is occurring. We regularly advise complainants to pursue emergency registrar-level escalation in parallel with any formal procedure, seeking a registrar lock or hold on the domain pending proceedings. That step does not itself transfer the domain, but it can interrupt the harm while the case proceeds.

Does SACI-Adm or a court decide a .br dispute?

SACI-Adm – the Brazilian administrative dispute-resolution procedure operated under NIC.br – is the primary administrative route for .br domain disputes; it is distinct from the UDRP and from Brazilian court proceedings, and is not administered by WIPO, the Forum, CAC, or ADNDRC. A complainant may also bring a civil action in the Brazilian courts seeking transfer or an injunction, which is often the stronger route where urgent interim relief is needed or where monetary damages are sought alongside the domain.

The two routes serve different goals. SACI-Adm is a purely administrative procedure: it can order transfer or cancellation of a registration, but it cannot award damages, impose costs, or issue an injunction. Brazilian civil litigation, handled with local litigation counsel in the relevant jurisdiction, can do all of those things, and a court can grant emergency relief very quickly if the phishing risk is documented. In our practice, we advise brand owners to treat the two routes as complementary rather than mutually exclusive: an SACI-Adm filing establishes the administrative record; a court application can act faster where customer harm is immediate and ongoing.

For comparison: if the same brand is being attacked across a .com and a .br simultaneously – a pattern we see regularly in financial-services phishing campaigns – the .com dispute falls under the UDRP (before WIPO, the Forum, or another accredited provider), while the .br dispute runs through SACI-Adm or the Brazilian courts in parallel. Coordinating those tracks requires attention to timing, evidence preservation, and the differing remedies available in each zone.

For a read on which procedure fits your .br situation, contact us at info@cognomenlaw.com.

What is the deadline once a case starts?

Under SACI-Adm, once a complaint is formally notified, the registrant is given a defined period – typically measured in days from notification – to file a response; failure to respond within that window generally allows the proceeding to continue on the record provided by the complainant. The precise procedural calendar is set by the current NIC.br rules, which should be confirmed with counsel before filing, as they differ from the UDRP's 20-day response period and the UDRP's approximate two-month case timeline.

What does that mean practically? A registrant running a phishing operation has little incentive to respond and defend: any response requires identifying themselves, which carries its own risks. Default rates in abuse-driven .br disputes are high. A default does not mean automatic transfer, however – the complainant's evidence still has to meet the applicable threshold. Weak documentation of rights, or an inadequate showing of abusive use, can still result in denial even where the respondent is silent.

On the complainant's side, the practical deadlines to watch are different: how quickly after discovering the phishing domain can you assemble the evidence and file? Every week of delay is a week of active harm. We have seen cases where delay in filing – sometimes because internal approval processes were slow – allowed the registrant to let the registration lapse, abandon the phishing infrastructure, and re-register a variant domain that had to be attacked separately.

What evidence decides a .br phishing domain case?

Evidence is the axis on which these cases turn. The complainant must document three things: that it holds the relevant rights, that the domain is confusingly similar to those rights, and that the registration and use are abusive. In phishing cases, the third limb is the least contested – but it still needs to be proven, not assumed.

Rights documentation should include trademark registration certificates, evidence of trademark use in Brazil, and where relevant, unregistered mark evidence (advertising spend, press coverage, market-recognition surveys). The confusing similarity showing is usually straightforward when the domain reproduces the mark verbatim or adds only generic terms ("secure-", "-bank", "-login") that reinforce rather than distinguish. The abusive use evidence is where phishing cases stand apart: screenshots of the fake login page, WHOIS/RDDS records showing registration after the complainant's mark became known, traffic logs or cybersecurity reports showing credential harvesting, and customer complaint records all go into the file. Independent cybersecurity investigation reports carry particular weight.

One evidence trap to avoid: screenshots taken at a single point in time. Phishing operators rotate or remove pages quickly once a complaint is filed or they detect monitoring. We advise clients to conduct multiple, dated captures using certified web-archiving tools, and to preserve any email headers from phishing messages sent using the domain. That second category of evidence – email abuse records – is often decisive in demonstrating that the domain was not merely parked but actively weaponized.

What if the registrant does not respond?

A non-responding registrant means the proceeding continues on the record before the panel, without any defense. Under SACI-Adm, as under the UDRP, default does not equal automatic transfer – the panel still applies the applicable standard, and the complainant bears the burden throughout. What default does mean is that there is no competing evidence to weigh: the panel decides on what the complainant has filed.

In practice, default in a phishing case cuts strongly in the complainant's favor. A registrant who operated a credential-harvesting page has no legitimate defense to offer. The panel's role is confirmatory: it reviews the evidence of rights and the evidence of abusive use and determines whether the threshold is met. Panels in this category of case have consistently found abusive registration where the domain mimics a well-known mark and the use pattern is demonstrably designed to deceive end users.

There is a secondary risk for the complainant in default cases, however. Without a response, there is no adversarial challenge to evidence quality. That sometimes leads complainants – and their advisers – to under-prepare the record, assuming the default will carry the day. In our experience, thin evidence produces thin decisions, and thin decisions are harder to enforce or build on if the registrant re-registers a variant and a second case is needed.

Can the decision be appealed or challenged?

An SACI-Adm decision can be challenged in the Brazilian courts. A registrant who loses an administrative transfer order can file a court action within the period set by Brazilian procedural rules to seek reversal; during that challenge the registrar may be directed to hold the transfer pending judicial resolution. This is a meaningful risk for a complainant who wins administratively but does not move quickly to consolidate control of the domain after transfer.

Court challenge is less common in phishing cases than in commercially motivated disputes, for an obvious reason: a registrant who ran a phishing operation is unlikely to file papers in a Brazilian court identifying themselves as the domain's registrant. The practical risk is low. But "low" is not "absent," and brand owners should be prepared for the possibility – particularly in cases where the domain has significant residual commercial value or where the registrant is a competitor making a strategic play under the cover of an abuse allegation.

From the complainant's side, the right to bring a court action if SACI-Adm denies a complaint is equally available. A denial in the administrative process does not preclude a separate civil action in Brazil seeking the same transfer, and the evidentiary bar in court may allow additional arguments – including damages claims – that the administrative procedure cannot reach. Coordination with local litigation counsel in the relevant jurisdiction is essential when that route is being considered.

To weigh your options across SACI-Adm and Brazilian court proceedings, email info@cognomenlaw.com.

How does a .br phishing dispute compare to a .com UDRP case?

If you are dealing with a phishing attack that spans both a .com and a .br registration – which is common – the two disputes run in entirely separate systems. The .com falls under the UDRP, with a USD 1,500 WIPO filing fee for a single-member panel covering up to five domains, a 20-day response window, and a typical case length of about two months. The remedies are transfer or cancellation only – no damages. The .br falls under SACI-Adm or the Brazilian courts, with different fees, different procedural calendars, and the additional option of damages and injunctive relief in court.

The difference in bad-faith framing matters too. The UDRP requires the domain to have been both registered and used in bad faith – a cumulative test that occasionally produces arguments about intent at registration where the domain was initially benign. SACI-Adm's abusive-registration concept operates differently, and phishing use – which is plainly abusive from the moment it begins – tends to satisfy the test on the use limb without the need to reconstruct registration-era intent. That doctrinal difference can affect how the evidence file is structured.

What the two systems share is the fundamental dynamic: a brand owner with documented rights, facing a registrant with no legitimate purpose, in a procedure that offers transfer as the primary remedy. The strategic question is always the same – which forum, which route, and what evidence makes the file strong enough to win without leaving a gap the registrant can exploit on appeal or on the next variant registration.

Related at COGNOMEN

When can I recover a .br domain used for phishing?

You can seek recovery when you hold rights in a name or mark corresponding to the domain and the registrant has registered or used the domain in a way that is abusive – including operating a phishing page that impersonates your brand. Phishing use is among the strongest factual bases available, combining clear confusion with active harm to end users. Rights can rest on a registered mark, a trade name, or an established unregistered mark with significant recognition in Brazil.

Who can recover a .br domain used for phishing?

Any party with demonstrable rights in a name or mark corresponding to the disputed .br domain can file a complaint under SACI-Adm or bring a civil action in the Brazilian courts. There is no requirement that the complainant be a Brazilian entity, but demonstrating that the mark is known or used in Brazil strengthens the rights showing. International brand owners whose marks are recognized in Brazil regularly succeed in these proceedings when the evidence of rights and of abusive use is properly assembled.

What is the deadline once a case starts?

Once a SACI-Adm complaint is notified, the registrant has a fixed period under the current NIC.br procedural rules to file a response. That window differs from the UDRP's 20-day standard and should be confirmed with counsel before filing. Failure to respond allows the proceeding to continue on the complainant's record alone. On the complainant's side, the more important deadline is acting quickly after the phishing domain is discovered: delay allows active harm to continue and gives the registrant time to abandon the domain and re-register a variant.

About COGNOMEN

COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. Our focus is singular: domain disputes, across every zone, in every forum. To discuss a .br phishing domain or any domain dispute, contact info@cognomenlaw.com.

By Cordelia Roe – UDRP complainant practice, gTLD and ccTLD domain recovery.

Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.