Step-by-step: recover a hijacked .co domain after account compromise
Step-by-step: recover a hijacked .co domain after account compromise. UDRP and ccTLD domain recovery and defense across .co. Email the firm to assess your case.
Your .co domain disappeared overnight. The registrar account was accessed by someone who was not you, the domain was transferred to a privacy-shielded registrant at a foreign registrar, and the nameservers now point to a parking page or, worse, a phishing site impersonating your brand. The window to act is narrow. Every hour the domain sits in new hands, the trail cools and the incoming registrar's lock period grows closer to vesting.
To recover a hijacked .co domain after account compromise, you must move through two parallel tracks: a registrar-level escalation to freeze the domain and reverse the unauthorized transfer, and – if the registrar track stalls – a formal dispute through WIPO's procedures that apply to .co, which operates under the UDRP. The 20-day response window that applies to UDRP proceedings means the registrant side also operates under tight deadlines, and assembling compromise evidence from the very first hours is what decides whether the legal route succeeds. No outcome is guaranteed; the facts, the zone mechanics, and the forum's discretion govern everything.
This guide walks each step, names the trap hidden inside it, and identifies the decision points where the route changes – from registrar escalation to WIPO UDRP, from arbitration to a court action where arbitration cannot reach.
What makes .co domain theft different from a generic cybersquatting dispute?
Hijacking is not cybersquatting. The legal distinction matters more than most brand owners realize when they first call us.
In a standard cybersquatting case, a third party registers a domain in their own name. The UDRP's three-element test – confusing similarity, no legitimate interest, and bad-faith registration and use – fits naturally. In a hijacking, the original registrant was you. Someone compromised your registrar account credentials and transferred your domain out without authorization. The domain was not registered in bad faith by the new holder; the original registration was legitimate. That creates a subtle but important wrinkle: the UDRP element requiring bad-faith registration at the time of registration may be harder to satisfy when the new holding is the product of a fraudulent transfer rather than an arms-length registration.
Panels under the UDRP have addressed fraudulent-transfer scenarios, generally treating the unauthorized transfer as a new "registration" for Policy purposes, or finding bad faith on the basis of the thief's receipt and use of the domain. The consensus approach under the Policy is that the Policy applies even where the respondent's holding resulted from account compromise. But the argument must be made explicitly and supported with evidence. We have seen complaints dismissed at this exact point because the complainant assumed the analysis was the same as a typosquat. It is not.
The .co zone is administered by Colombia's national registry, but .co has adopted the UDRP and designated WIPO and other ICANN-accredited providers as its dispute-resolution venues. That means the full UDRP rule set applies, including all three elements of Paragraph 4(a) and the Paragraph 4(b) bad-faith factors, with the wrinkle above in play throughout.
Step 1: Freeze the domain in the first 24 to 72 hours – and where the trap hides
The single highest-value action in the first hours is getting a registrar lock placed on the domain at the gaining registrar before any further transfer can occur. Do not assume the losing registrar (the one whose account was compromised) controls this.
Contact the gaining registrar's abuse or transfer-dispute desk immediately with a written notice of unauthorized transfer. Most registrars follow the ICANN Inter-Registrar Transfer Policy, which provides a dispute mechanism for domains transferred without authorization. The critical fact: a registrant who completes a transfer-in owns the domain under the gaining registrar's system, and the gaining registrar has no contractual obligation to transfer it back absent ICANN policy compliance or a court order.
The trap in Step 1 is the 60-day lock. After any registrar-to-registrar transfer, ICANN rules impose a 60-day lock period during which the domain cannot be transferred again. That lock protects you just as much as it could protect the thief. If you move quickly, you want that lock to snap shut before a second transfer moves the domain to yet another registrar, compounding the recovery chain. If you are too slow, the domain may be transferred again before you file anything, lengthening every subsequent step.
Document every action: timestamps, ticket numbers, email headers, and the WHOIS or RDDS snapshot showing the change of registrant. That documentation is your evidence foundation for every step that follows.
Step 2: Compile the compromise evidence – what decides the outcome
Account-compromise cases live or die on the quality of the evidence showing that you were the original, legitimate registrant and that the transfer was unauthorized. The legal test at the UDRP level, before any panel, will require that record to be complete and coherent.
What evidence matters most? First, original registration records: confirmation emails, invoices, and renewal receipts from your losing registrar going back to the original registration date. Second, account-access logs: any logs the losing registrar can supply showing the IP address and device that initiated the transfer – often starkly different from your usual access pattern. Third, compromise indicators: phishing emails targeting your registrar login, password-reset notifications you did not trigger, or simultaneous email-account compromise (attackers commonly take the email address tied to the registrar account before initiating the transfer). Fourth, use evidence: invoices, branded materials, website analytics, and correspondence that show you operated a business or service under the domain continuously before the theft.
The trap in Step 2 is assuming the registrar will supply the logs automatically. They often will not. Request them in writing immediately and specifically – "all access and modification logs for account [X] for the period [Y] to [Z]." Registrars retain logs for varying periods. Waiting two weeks to ask may mean the logs have rotated out.
We regularly advise clients to treat the evidence-gathering step as a parallel track, not a later step. While the registrar escalation is in motion, a simultaneous evidence-preservation notice – covering email access logs, login records, and any associated payment fraud – should go out to every relevant platform.
For an assessment of your .co hijacking and what evidence you need to gather first, contact info@cognomenlaw.com.
Step 3: Choose the recovery route – registrar reversal, WIPO UDRP, or court action?
Three routes are available, and the right one depends on how the gaining registrar responds, who now holds the domain, and what you need as a remedy.
If the gaining registrar cooperates and acknowledges the unauthorized-transfer claim, a registrar-level reversal is by far the fastest path. It can resolve in days to weeks, costs relatively little beyond professional time, and does not require a formal filing. The trap here: registrar cooperation is voluntary and inconsistent. Many gaining registrars decline to act without a court order or a UDRP decision, particularly if the new registrant has contested the claim.
If the registrar will not act voluntarily, the WIPO UDRP route applies because .co has adopted the UDRP. The filing fee at WIPO is USD 1,500 for a single-domain, single-member panel case, with a standard case normally concluded within about two months. The upside: speed and cost relative to court litigation. The downside: the UDRP is limited to transfer or cancellation of the domain. There are no monetary damages, no injunction covering associated harm, and no recovery of losses caused by the phishing period.
If you also need damages – say, because the hijacked domain was used in a fraud that caused financial harm to you or your customers – a court action is the only route that reaches money. For a .co domain, the thief's identity and location may point toward a court action in Colombia (the country of the registry), in the thief's home jurisdiction, or in your own jurisdiction, depending on applicable law and the thief's identifiable presence. That work is handled with local litigation counsel in the relevant jurisdiction. We coordinate the strategy and the filing evidence; local counsel handles the in-court representation.
A fourth scenario: the domain has already been transferred a second time to a new registrant who may or may not have known it was stolen. This complicates the UDRP route because the UDRP may treat a good-faith purchaser differently from the original thief. In our practice, we have seen this scenario used deliberately as a laundering step. It does not make recovery impossible, but it does require a more detailed factual narrative before the panel.
Step 4: File a WIPO UDRP complaint for .co – the mechanics and the traps
If the UDRP route is the right path, the filing process at WIPO is structured and exacting. A missed requirement causes a deficiency notice and delay; in a theft scenario, delay is your enemy.
The complaint must satisfy all three elements of Paragraph 4(a): confusing similarity to a mark you hold (or common-law rights you can evidence), no legitimate interest in the domain on the respondent's part, and bad-faith registration and use. For an account-compromise case, the similarity element is usually straightforward – the domain is identical to your brand. The legitimate-interest and bad-faith elements require the argument explained in Step 1 above: the unauthorized transfer constitutes a registration-equivalent, and the respondent's knowing receipt of a stolen domain (or use of it) satisfies the bad-faith standard.
The respondent has 20 days to file a response once the case commences. In a theft case, the respondent may simply default – no response filed. Default does not mean automatic transfer; the panel still reads the complaint and evaluates the evidence. A well-drafted complaint with complete evidence is just as important in a default as in a contested case. Panels have denied complaints despite defaults where the complainant's evidence was thin.
After the response period closes (or the respondent defaults), the panel is appointed. For a single-member WIPO panel, the appointment and decision typically follow within the overall two-month window. Once the panel issues a transfer order, the gaining registrar and the .co registry implement it – unless the respondent files a court action to suspend implementation within the applicable window, which is a further trap: a bad-faith respondent can delay the transfer by filing a nominal court action in a convenient jurisdiction.
The trap specific to Step 4: the complaint must identify the domain's current registrar and registrant accurately. RDDS/WHOIS for .co may be privacy-shielded. WIPO has a process for requesting the underlying registrant data from the registrar; understanding that process in advance of filing – and including the correct procedural request in the complaint – avoids a deficiency that costs days.
In a recent matter (a .co hijacking after a credential-stuffing attack, summer 2025), we filed a WIPO UDRP complaint with a complete account-compromise narrative, access-log excerpts supplied by the losing registrar, and a continuous-use evidence package spanning three years. The domain was transferred back within approximately eight weeks of filing, with no court-action suspension attempt by the respondent.
To weigh the UDRP route against a court action for your .co case, email info@cognomenlaw.com.
Step 5: When a court action beats UDRP for .co recovery
The UDRP is an efficient tool. It is not always the right tool. Several scenarios favor a court action over – or alongside – a UDRP filing.
Where you need damages, a court action under the applicable anticybersquatting legislation or cybercrime statute in the relevant jurisdiction is the only path to monetary recovery. The UDRP explicitly excludes damages as a remedy. If the hijacking caused financial losses – customer diversion, fraud on your payment systems, or reputational harm from phishing traffic – those losses can only be addressed in court.
Where the respondent is identifiable and has assets in a reachable jurisdiction, a court action may also enable interim relief – an injunction preserving the domain's status quo while the case progresses. That interim relief can be obtained faster than a UDRP decision in some jurisdictions and prevents a further transfer or deliberate domain destruction (deletion, for example) while the case runs.
Where the UDRP route has already produced a transfer order but the respondent has suspended implementation via a court filing in their home jurisdiction, a parallel or reactive court action in that same or a more favorable jurisdiction may be required to break the suspension. We coordinate that work with local litigation counsel in the relevant jurisdiction, assembling the UDRP record as the evidentiary foundation for the court filing.
The cost trade-off is real. A court anticybersquatting action is substantially more expensive and slower than a UDRP filing. For a single .co domain whose market value is modest, court action may cost more than the domain is worth. The right analysis compares the value of the domain and the potential damages against the estimated litigation cost – and no honest adviser can give that estimate without seeing the specific facts.
Step 6: Evidence review, forum selection, and the pre-filing decision matrix
Before filing anything, run the evidence through a pre-filing decision matrix. The goal is to identify which route gives you the best combination of speed, remedy, and cost given the specific facts.
Situation A: You have strong compromise evidence (access logs, phishing trail, original registration records), the gaining registrar is uncooperative, and you only need the domain back. Route: WIPO UDRP. Timeline: approximately two months. Cost basis: USD 1,500 filing fee plus legal fees at market rates for the preparation and filing work. Risk: a thin evidence package, or a nuanced bad-faith argument that the panel does not accept, produces a denial.
Situation B: You have strong compromise evidence, the thief used the domain to commit fraud against your customers, and you need both the domain and financial recovery. Route: court action in the relevant jurisdiction, coordinated with local litigation counsel, with or without a parallel UDRP for speed on the domain itself. Timeline: substantially longer; describe qualitatively. Cost: substantially higher. Risk: jurisdiction, enforceability, and whether the thief can be identified and served.
Situation C: You have the domain back from the registrar voluntarily, but the thief also registered confusingly similar .com or other gTLD versions during the hijacking window. Route: a separate UDRP complaint for the additional registrations, with the theft narrative as supporting context for the bad-faith element. This scenario is more typical of a cybersquatting case grafted onto a theft – and we have seen hijackers attempt to monetize the interim period by registering variants while the original domain was in their control.
The cross-zone point is important. A .co domain dispute proceeds under the UDRP because .co adopted that Policy. A companion .com dispute also proceeds under the UDRP; the two cases may be consolidated into a single complaint if the registrant of record is the same holder across both zones. If the registrant differs – because the thief used a different identity for each – separate complaints are required, each with its own filing fee.
For a comparison of UDRP and URS options across global zones, see our analysis at analysis-urs-vs-udrp-global. For cases involving .eu domains recovered after hijacking, the approach in case-recover-hijacked-domain-eu illustrates how the evidence package transfers across zones.
What to do if the domain has already been deleted or transferred to a third-party buyer
Two scenarios significantly complicate recovery and deserve separate treatment.
First, deletion. A thief who cannot quickly monetize a domain may simply delete it, returning it to the registry's pool. Once deleted, .co follows the registry's drop cycle. Recovery then becomes a domain-auction or drop-catching exercise rather than a dispute. UDRP cannot address a domain that has been deleted and re-registered by a genuinely independent third party without notice of the prior history. Early action to freeze the domain, before deletion is possible, is the only prevention.
Second, sale to a good-faith third-party buyer. If the thief transferred the domain to a purchaser who paid market value with no knowledge of the theft, the UDRP analysis becomes significantly more complex. Panels have generally held that good-faith purchasers for value can assert a legitimate interest – but the threshold for demonstrating that the purchaser was truly unaware is exacting, and the original owner's ability to produce a clean audit trail of the theft matters enormously here. A court action against the original thief may be the more reliable route in that scenario, while the new registrant is not joined.
In our practice, we advise brand owners to treat domain-theft scenarios with the same urgency as a financial fraud – because that is what account compromise usually is. Speed in the first 72 hours shapes the entire recovery trajectory.
Related at COGNOMEN
Frequently asked questions
How do I start to recover a hijacked .co domain after account compromise?
Start within hours, not days. File an unauthorized-transfer dispute with the gaining registrar immediately and request all access logs from the losing registrar in writing. In parallel, preserve every piece of compromise evidence – phishing emails, password-reset notifications, IP-access anomalies, and original registration records. If the registrar will not act voluntarily, a WIPO UDRP complaint applies to .co because the zone has adopted the UDRP. An independent assessment of your evidence before filing determines which route – registrar reversal, UDRP, or court action – gives you the best chance of a successful outcome.
What are the realistic outcomes when you recover a hijacked .co domain after account compromise?
The UDRP's only available remedies are transfer or cancellation of the domain. There are no damages and no injunctions under the UDRP. If the registrar cooperates voluntarily, a reversal is possible in days. A WIPO UDRP case typically concludes within about two months, assuming no procedural complications. If you need monetary recovery for losses caused by the hijacking, a court action in the relevant jurisdiction is the only route that reaches damages – but it is substantially more expensive and slower than the UDRP. Outcomes depend on the evidence, the facts, and forum discretion; no result can be promised.
How do fees split if the case escalates?
The WIPO filing fee for a single-domain, single-member panel case is USD 1,500 – that is the forum fee, separate from legal fees for preparation and filing. If the respondent requests a three-member panel, both parties generally split the higher three-member panel fee. If the case escalates to court action, costs are substantially higher and depend on the jurisdiction, the complexity of the case, and the local billing structure of litigation counsel. A clear estimate requires a review of the specific facts; COGNOMEN provides transparent fee ranges at the assessment stage.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.