Assess my case

Step-by-step: recover a hijacked .br domain after account compromise

Step-by-step: recover a hijacked .br domain after account compromise. UDRP and ccTLD domain recovery and defense across .br. Email the firm to assess your case.

Your .br domain was registered years ago. This morning it resolves to a stranger's page, the registrar account password no longer works, and the WHOIS/RDDS contact has quietly changed. That scenario – account compromise followed by unauthorized transfer – is the opening fact pattern we see most often in .br hijacking matters. The question is not whether you can fight back. The question is which step comes first, and which trap is hiding inside it.

To recover a hijacked .br domain after account compromise, you must move through four sequential phases: emergency registrar escalation with NIC.br, evidence preservation, the SACI-Adm administrative dispute procedure, and – where that route is insufficient – Brazilian court action for injunctive relief and transfer reversal. Each phase has a clock. Missing the first 24 to 72 hours of the escalation window makes every subsequent phase harder. The governing body for .br is NIC.br (the Network Information Center Brazil), which operates the SACI-Adm procedure for .br disputes.

This guide walks each step in sequence, names the trap inside it, and tells you what evidence actually decides the outcome.

What governs .br domain disputes – and why it is not the UDRP?

The .br ccTLD is managed by NIC.br under the authority of CGI.br, Brazil's Internet Steering Committee. Unlike zones such as .me or .tv, .br has not adopted the UDRP. The standard UDRP procedure available at WIPO, the Forum, or CAC does not apply here. This is the first trap: brand owners who file a UDRP assuming it covers .br will see the complaint rejected or returned as outside jurisdiction.

Instead, NIC.br operates its own administrative dispute-resolution mechanism known as SACI-Adm (Sistema de Administração de Conflitos de Internet). SACI-Adm handles disputes over .br registrations through an independent panel, applying Brazilian rules. The procedure is distinct in both substance and structure from the UDRP. The evidentiary standards, timelines, and remedies follow NIC.br's published rules, not ICANN policy. Verify the current rules with counsel before filing, as NIC.br periodically updates the procedure.

There is a further complication specific to hijacking cases. A pure SACI-Adm trademark dispute assumes the registrant is a knowing bad actor. A hijacking case is different: the original legitimate registrant is disputing unauthorized access, not a third-party registration. That distinction shapes which route takes priority and what evidence you need first.

Step 1 – Emergency escalation to NIC.br: how do you stop the bleeding?

The first step is a lock request to NIC.br, submitted within the first 24 to 72 hours of discovering the compromise. A registrar lock freezes the domain against further transfers, DNS modification, and contact changes. In practical terms, it stops the hijacker from moving the domain to a second registrar and burying the trail further. This is the stage where urgency is not rhetorical – it is procedural.

The trap at this step is documentation sequencing. Registrants often call NIC.br without first screenshotting the current WHOIS/RDDS record, capturing DNS resolution data, and logging the exact timestamp of discovery. NIC.br and any subsequent panel or court will want a chain of evidence showing the state of the record at the moment you found the problem. Take those screenshots before you make a single call or change a single password.

Your escalation to NIC.br should include: your original registration confirmation (showing your name, entity, and registration date), a notarized copy of a government-issued identity document, evidence of the unauthorized contact change (a before/after WHOIS comparison if available), and a written narrative of how and when you discovered the compromise. If you are a legal entity, include corporate registration documentation. NIC.br may require Portuguese-language submissions, so arrange translation early.

The lock request does not itself restore the domain. It creates breathing room. Do not let anyone tell you the lock alone resolves the matter.

Step 2 – Evidence preservation: what actually decides the outcome?

Evidence quality is the single variable that separates a successful recovery from a prolonged dispute. At this step the trap is selective collection – gathering only what feels obviously relevant and discarding the rest.

Collect and preserve all of the following before anything else changes.

Once collected, store copies in at least two locations – ideally with a time-stamped delivery to counsel. Evidence that exists only on the compromised account has evidentiary problems; it may have been altered by the person now controlling that account.

For an assessment of your domain dispute, contact info@cognomenlaw.com.

Step 3 – SACI-Adm or court: which route fits your situation?

Once the lock is in place and evidence is preserved, you face a route decision. That decision is fact-dependent, and the wrong choice loses time – sometimes the domain.

The right route depends on the nature of the dispute and the urgency of relief. Consider three situations.

Situation A: clear account compromise, domain still with the same NIC.br-accredited registrar. This is the strongest case for the SACI-Adm administrative route. The procedure is designed to adjudicate disputes within the .br system, the record is traceable, and NIC.br can implement a transfer order without a court. The administrative route is faster and less expensive than litigation. The trap here is assuming SACI-Adm is as fast as the UDRP – verify current timelines with NIC.br, as they differ from the roughly 45–60 day UDRP standard.

Situation B: the domain has been moved to a foreign registrar. This is where the administrative route hits a jurisdictional wall. NIC.br can instruct a registrar within its accredited network. A registrar outside Brazil and outside NIC.br's contractual reach is a different matter. Here, Brazilian court action for an injunction and a compelled transfer order becomes necessary, typically run with local litigation counsel in the relevant jurisdiction. The court route is slower and carries substantially higher legal costs than the SACI-Adm path, but it reaches further.

Situation C: the hijacked domain is being used for fraud, phishing, or criminal impersonation. Where the domain is actively harming the brand owner or third parties, a court injunction can be sought on an emergency basis in parallel with the SACI-Adm filing. The two routes are not mutually exclusive. A court can issue a preservation or suspension order while the administrative proceeding runs its course. This is the most resource-intensive path, but it is sometimes the only one that stops active harm quickly enough.

In a matter we handled in early 2025 (a .br registration, spring of that year), a business owner regained control of a hijacked domain roughly eight weeks after initial escalation – the domain had been re-pointed to a phishing page, and a parallel administrative and court strategy was needed to obtain a suspension before a transfer order followed. No single route alone would have moved quickly enough.

Step 4 – Filing the SACI-Adm complaint: what does the panel need to see?

A SACI-Adm panel adjudicating a hijacking claim – as distinct from a trademark dispute – will center its analysis on two issues: whether you were the legitimate registrant, and whether the transfer was unauthorized. Both require affirmative evidence, not just denial.

The trap at this step is treating the complaint as a narrative document rather than an evidence-based submission. Panels work from the record. Everything in the complaint that lacks documentary support carries reduced weight.

Your submission should address the following points in sequence.

  1. Proof of original registration. Original confirmation emails, NIC.br-issued registration certificates, and any renewal documentation establish the baseline that you were the registrant before the compromise.
  2. Proof of continuous legitimate use. Web archive records, hosting invoices, email traffic through the domain, and third-party confirmations of the domain's operation under your control all support the legitimate-use narrative. Panels are persuaded by continuity.
  3. Evidence of the unauthorized event. Login history, IP anomalies, password-reset sequences, and changes to the administrative contact all point to the specific unauthorized act. The more granular the timeline, the better.
  4. Absence of any consent. If there was any prior commercial discussion about the domain – even an informal inquiry – that history needs to be addressed directly. A hijacker may argue a sale occurred. The absence of a written agreement, any escrow transaction, or any consideration paid defeats that defense if properly documented.
  5. Relief requested. State the precise remedy: transfer back to your registrant details, deletion of the unauthorized contact, and a registrar lock pending implementation. Be specific; panels generally limit their orders to what is requested.

Submissions to NIC.br and SACI-Adm may require Portuguese. If you are operating from outside Brazil, that translation requirement is a procedural trap of its own – factor it into your timeline from the first day.

Step 5 – Court action: when does escalation to Brazilian courts become necessary?

Brazilian courts can grant injunctive relief that the SACI-Adm procedure cannot reach – most importantly, orders binding parties or registrars outside the NIC.br network. They can also address related harms: financial damages caused by the hijacking period, reputational injury, and criminal referrals where the hijacking involved identity fraud.

The trap here is overestimating how quickly a court moves. Brazilian civil procedure, even for urgent applications, is not measured in weeks. Interim injunctions can issue more quickly than full hearings, but the process requires properly constituted local litigation counsel in the relevant jurisdiction, Portuguese-language pleadings, and appropriate service of process. Cost is substantially higher than the administrative route. For that reason, court escalation is reserved for situations where the domain is actively causing harm, where the SACI-Adm route is procedurally unavailable, or where the hijacker's position crosses into criminal conduct.

At COGNOMEN, we coordinate with local litigation counsel in Brazil for court-stage matters. We manage the strategy, the evidence architecture, and the cross-border coordination; local counsel handles the pleadings and court filings under Brazilian procedural rules.

To weigh the administrative route against a court action for your case, email info@cognomenlaw.com.

What myth should you discard before you start?

The most common misconception we encounter is that recovering a hijacked .br domain is primarily a technical problem – one that the registrar will simply fix once you call and explain. It is not. NIC.br is an organized registry with published dispute rules and evidentiary requirements. Registrars in this system are not authorized to reverse a transfer unilaterally on the basis of a phone call, however compelling the circumstances.

The corollary myth is that because Brazil has no UDRP, there is no formal mechanism for recovery. That is also wrong. SACI-Adm exists precisely to provide an administrative adjudication pathway, and Brazilian courts provide a civil remedy for cases that exceed its reach. The absence of the UDRP does not mean the absence of recourse. It means the recourse is different, and requires a practitioner who knows the Brazilian procedure rather than the standard ICANN pathway.

A second working myth is that time pressure favors the registrant who acts slowly and carefully. The opposite is true. Every day the hijacker holds the domain, additional traces may be erased, the DNS records may be further modified, and a second unauthorized transfer may occur. Speed in the first 72 hours and patience in the evidentiary phase are not contradictory; they apply to different stages.

In a recent .br matter (autumn 2025), a registrant delayed the NIC.br escalation by five days while seeking informal resolution with the hijacker directly. By that point, the administrative contact had been changed twice and the original email-account evidence was partially overwritten. The case was still won, but the evidentiary reconstruction took significantly longer than it would have otherwise.

Cross-zone considerations: does the hijacking touch a .com or other zone?

Hijackers targeting a Brazilian brand frequently register or repurpose domains in parallel zones – the corresponding .com, .net, or a new gTLD variant – to compound the confusion and monetize multiple registrations simultaneously. Where the hijacking extends to a .com, the UDRP becomes available in that zone even though it does not apply to the .br. This creates a genuine strategic opening.

The .com can be attacked through a UDRP complaint at WIPO, the Forum, or CAC, with the USD 1,500 WIPO filing fee for a single-member panel covering one to five domains. A transfer order on the .com does not solve the .br problem, but removing the parallel registration reduces the hijacker's foothold and can form part of a coordinated recovery across zones. The two proceedings run on separate timelines – the UDRP at roughly 45–60 days for a standard matter, the SACI-Adm on the NIC.br schedule – but the evidence assembled for one supports the other.

Where the brand extends into Europe and the hijacker also holds a .eu, the EURid ADR.eu procedure provides a third avenue. Where a .uk is involved, the Nominet DRS applies, with its free mediation stage before any expert decision. Each zone has its own rules, its own remedies, and its own evidentiary expectations. Multi-zone hijacking is a complexity multiplier, but it is also a situation where coordinated recovery across procedures yields the most complete result.

For a deeper analysis of how the hijacking evidence framework plays out in a comparable ccTLD context, see our analysis of domain recovery in the .au zone.

Related at COGNOMEN

Frequently asked questions

How do I start to recover a hijacked .br domain after account compromise?

Start within the first 24 to 72 hours by requesting a registrar lock from NIC.br to freeze the domain against further transfers or contact changes. Before making that call, screenshot the current WHOIS/RDDS record and capture login-history data from the registrar account and any associated email provider. Those records are the foundation of every subsequent stage – administrative complaint, SACI-Adm proceeding, or court action. Once the lock is in place, assemble original registration documentation, identity proof, and evidence of the unauthorized event, then assess with counsel whether the SACI-Adm route or Brazilian court action is the faster path given where the domain currently sits.

What are the realistic outcomes when you recover a hijacked .br domain after account compromise?

The range of outcomes depends on the evidence quality, the speed of the initial escalation, and whether the domain has been moved outside the NIC.br accredited-registrar network. Where the domain remains within NIC.br's reach and the evidence of compromise is clear, an administrative transfer order through SACI-Adm is achievable. Where the domain has been moved to a foreign registrar or is being used for active fraud, a Brazilian court injunction may be needed, with longer timelines and higher costs. No outcome can be guaranteed; the result turns on the specific facts and the decisions of the panel or court handling the matter.

How do fees split if the case escalates?

The SACI-Adm procedure carries its own published filing fees set by NIC.br; verify the current rate with NIC.br directly, as it is not the same as UDRP pricing. Legal fees for the administrative phase are a separate item and depend on the complexity of the evidence record and the number of zones involved. Court escalation in Brazil is substantially more expensive and is billed on an hourly or retainer basis by local litigation counsel. For a multi-zone matter – SACI-Adm plus a UDRP for a parallel .com – the WIPO filing fee for a single-member panel starts at USD 1,500 and is charged on top of the .br procedure costs. Discuss the fee structure in detail before filing anything.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.