Assess my case

Step-by-step: recover a hijacked .net domain after account compromise

Step-by-step: recover a hijacked .net domain after account compromise. UDRP and ccTLD domain recovery and defense across .net. Email the firm to assess your ca…

You log in to your registrar account and the domain is gone. Or you receive a transfer-confirmation email you never requested. Within hours, a domain your organization has held for years — pointing at your infrastructure, embedded in your email certificates, listed on your invoices — is under a stranger's control. That is account-compromise hijacking, and it moves faster than most incident-response plans anticipate.

To recover a hijacked .net domain after account compromise, you must act on two parallel tracks simultaneously: registrar escalation to freeze further transfer and document the unauthorized event, and legal action — either a UDRP complaint before WIPO or another accredited forum, or court proceedings — to compel the return of the name. The clock matters: ICANN's transfer-dispute mechanism and the UDRP both impose procedural windows, and delay hands the hijacker time to move the domain again. This guide walks each step, flags the trap hidden in it, and tells you what the outcome actually depends on.

The steps below follow the sequence a practitioner works through in a live hijacking matter — from the first call to the registrar through to implementing a transfer order.

Step 1: What makes a .net hijacking different from an ordinary domain dispute?

A .net domain is accredited under ICANN's generic top-level domain system, which means the UDRP applies — but a hijacking case is not a standard trademark dispute, and the distinction shapes every decision that follows. In a classic UDRP complaint, a brand owner argues that an outside registrant intentionally targeted its mark. In a hijacking, the complainant owns the domain legitimately; what happened is theft — unauthorized access to the registrar account, followed by a transfer the rightful holder never authorized.

That factual difference matters at two levels. First, the UDRP's bad-faith element under Paragraph 4(a)(iii) is not automatically satisfied just because the transfer was unauthorized. Panels require the complainant to demonstrate that the current registrant — whoever now holds the name — registered and is using it in bad faith. Where the domain has already been resold to an apparent good-faith buyer, the analysis becomes more complicated. Second, the registrar's own transfer-dispute procedure runs separately from, and often faster than, any arbitration or court route. Missing the registrar window can cost you the quickest path back.

In our practice, we have seen hijacked .net domains change registrars twice within 72 hours of the initial compromise. Velocity is the defining feature of these cases. The legal strategy must match it.

For an assessment of your domain dispute — including whether registrar escalation, UDRP, or a court route best fits your situation — contact info@cognomenlaw.com.

Step 2: How do you lock the domain immediately, and where is the trap?

The first operational step is to request an emergency registrar lock from your current or losing registrar — the one that held the domain before the unauthorized transfer. A registrar lock prevents further outbound transfers and, in some cases, can trigger a hold on the domain while the dispute is investigated. File this request in writing and by telephone simultaneously; document every contact with a timestamp.

The trap in Step 2 is assuming that the losing registrar has authority to reverse a completed transfer. It generally does not act unilaterally. Under ICANN's Transfer Policy, if the domain has already moved to a new registrar, the gaining registrar must cooperate in any reversal. That cooperation is not guaranteed. You must therefore contact both registrars at once — the losing registrar to initiate the dispute and preserve evidence, and the gaining registrar to request a hold pending resolution.

What evidence does the losing registrar need? Expect to produce: government-issued identity documentation for the account holder; proof of prior ownership (old WHOIS/RDDS records, registration invoices, renewal receipts, DNS records); a detailed timeline of the compromise; and, where available, any forensic indication of the intrusion (IP address logs from the registrar, suspicious login alerts, or phishing emails that preceded the event). The stronger this documentation, the faster a registrar acts — and the stronger your UDRP or court file becomes in the later steps.

Step 3: When should you file an ICANN transfer-dispute complaint versus a UDRP complaint?

Two procedural routes run in parallel for a hijacked .net. The first is the ICANN Transfer Dispute Resolution Policy (TDRP), which is narrow: it addresses whether a transfer was conducted in compliance with ICANN's Transfer Policy, not who has the superior claim to the domain. The TDRP is a compliance mechanism against the registrar, not a recovery mechanism against the hijacker.

The UDRP, administered before WIPO or the Forum for .net domains, is the primary recovery route. A WIPO filing costs USD 1,500 for a single-member panel covering one to five domains. The respondent has 20 days to file a response once the case commences. A standard single-panel case is typically decided within about two months. The filing fee for a three-member panel rises to USD 4,000 — worth the cost when the domain is high-value or the opposing registrant appears well-resourced.

Which is better? If the hijacker is using the domain commercially — directing your customers elsewhere, monetizing your brand's traffic — the UDRP complaint addresses both the registration and the use in bad faith. If the domain has already been transferred to a secondary market buyer who can credibly claim to be a good-faith purchaser, a UDRP alone may not reach them. That is when the court route deserves serious consideration.

We regularly advise domain owners on this exact choice. The answer turns on three variables: the current registrant's identity and apparent knowledge, the commercial use of the domain post-hijacking, and whether you need monetary relief — which the UDRP cannot provide. The UDRP offers only transfer or cancellation.

Step 4: What evidence decides the outcome under the UDRP in a hijacking case?

The UDRP's three elements under Paragraph 4(a) each carry specific evidentiary demands in a hijacking fact pattern, and each harbors a distinct failure point.

Element 1 — Confusing similarity to your mark. In a hijacking, this is usually the easiest element: the domain is your own name, and you hold the mark. Submit your trademark registration certificate (or evidence of unregistered but well-established common-law use), and confirm the domain is identical or confusingly similar. Where hijackers have modified the domain name before resale — adding a hyphen, a letter, or a term — the analysis shifts and you should address it directly.

Element 2 — No rights or legitimate interests. This element is almost always met in a hijacking scenario, because the current registrant acquired the domain through a tainted chain. Document the chain: show that the transfer originated from unauthorized access, not a voluntary commercial transaction with you. Evidence of the account compromise — phishing records, unauthorized login timestamps, support tickets — directly supports this element.

Element 3 — Registered and used in bad faith. This is where hijacking cases diverge most sharply from standard disputes. Panels have consistently held that a registrant who knowingly acquires a domain through a compromised chain acts in bad faith even if the registrant personally did not execute the initial theft. Passive holding after the compromise — parking the domain, leaving it pointed nowhere, or redirecting it to unrelated content — can satisfy the use prong under the consensus view. Submit evidence of the current use of the domain: screenshots, RDDS records at various dates, any communications from the new registrant or broker offering to sell.

One trap here: if you delay filing while gathering evidence, the domain may be transferred again. Use the registrar lock to stabilize the situation, and file promptly with the best evidence in hand. Supplemental filings after the complaint are permitted in limited circumstances but are not guaranteed to be admitted.

Step 5: When does a court route beat arbitration for a .net hijacking?

Four situations make a court action preferable — or necessary — alongside or instead of a UDRP complaint.

First, if you need monetary damages. A company that loses six weeks of e-commerce revenue while a .net domain points to a competitor sustains measurable financial harm. The UDRP cannot touch that. US anticybersquatting litigation can reach the hijacker's profits and your actual losses, though the costs of litigation are substantially higher and the timeline longer.

Second, if the hijacker is using the domain to commit fraud — issuing invoices under your brand, intercepting your business email, or impersonating your organization to third parties. In those circumstances, criminal referral and civil interim injunction may be the only tools that move fast enough to stop ongoing harm.

Third, if the domain has passed through multiple registrations and the current holder's good-faith-purchaser argument is strong enough to complicate a UDRP panel's analysis. Courts have greater latitude in examining chain-of-title questions.

Fourth, if the losing registrar itself failed to comply with its own transfer-authorization procedures and bears some responsibility for the compromise. That potential claim runs against the registrar, not the hijacker, and it belongs in court.

COGNOMEN handles the arbitration side of these matters directly. For litigation before a US or other national court, we work with local litigation counsel in the relevant jurisdiction. We coordinate the strategy across both tracks so the filings reinforce rather than undermine each other.

Consider the decision in concrete terms: a UDRP at WIPO on a single .net domain costs USD 1,500 in forum filing fees, takes roughly two months, and returns the domain. A court action costs substantially more, takes longer, but can deliver damages and an injunction. In our practice, the two routes are not mutually exclusive — parallel filing is sometimes the right answer, depending on whether the court will impose a stay pending the arbitration outcome.

To weigh UDRP against a court action for your case, email info@cognomenlaw.com.

Step 6: How do you manage the registrar and ICANN escalation while the legal case runs?

Registrar escalation and legal proceedings must stay coordinated, not sequential. While a UDRP case is pending, the domain is typically locked against transfer by the registrar at the instruction of the forum — this is the "locked status" routinely applied after a case commences. Confirm with both the registrar and the forum that the lock is in place before the response period closes. A domain that moves during a pending UDRP proceeding creates jurisdictional and procedural complications that cost time and money to resolve.

Keep a written log of every contact with the registrar: date, time, representative name (if given), channel (telephone, ticket, email), the request made, and the response received. This record serves two purposes. It documents your diligence — relevant to any argument that you acted promptly — and it creates evidence of the registrar's conduct, which may be relevant if a court action against the registrar becomes necessary later.

If the registrar does not cooperate, escalate to ICANN's Contractual Compliance team. This route is slow and does not itself return the domain, but the formal complaint creates a paper trail and sometimes motivates the registrar to act. ICANN's Contractual Compliance process runs separately from the UDRP and does not substitute for it.

Step 7: What is the realistic outcome, and what does the recovery process cost?

The realistic outcome of a well-documented hijacking complaint before WIPO or the Forum — where the complainant holds a registered mark, the transfer was unauthorized, and the hijacker is using the domain commercially — is transfer. Panels have consistently ordered transfer in cases where the evidence of account compromise is clear and the current registrant cannot demonstrate a legitimate claim. Default — where the registrant files no response — is common in hijacking cases and generally results in transfer without the need for extended panel analysis.

That said, outcomes depend on the specific facts and panel discretion. No result is guaranteed. Where the chain of title is obscured, where the current registrant has colorable arguments, or where the evidence of account compromise is thin, the panel may deny the complaint. In that event, a court route may still succeed.

On cost: the WIPO filing fee for a single-member panel is USD 1,500, separate from any legal fee. Legal fees for a UDRP complaint on a single, straightforward domain are commonly in the USD 3,000 – 7,000 range in the market, depending on complexity, evidence volume, and the need for supplemental briefing. Court litigation costs substantially more. The cost calculus should be weighed against the domain's commercial value — both the revenue it generates and the damage its misuse causes to your brand and customer relationships.

In a recent hijacking matter — a .net domain used for a software-as-a-service platform, spring 2025 — we secured a transfer order approximately eight weeks after filing the UDRP complaint at WIPO, following a default by the registrant who had acquired the domain through a compromised broker account. The domain had already been pointed at a competing product. The evidence of prior ownership and unauthorized transfer was decisive.

Related at COGNOMEN

Frequently asked questions

When should I recover a hijacked .net domain after account compromise?

Start immediately — within hours of discovering the unauthorized transfer, not days. Registrar transfer windows and ICANN's own procedural mechanisms operate on strict timelines. Delay allows the hijacker to move the domain to a new registrar, complicate your evidence chain, and place it beyond the reach of the fastest recovery routes. File the registrar dispute and begin assembling your evidence on day one. The UDRP complaint can be prepared in parallel. Waiting for certainty before acting almost always worsens the position.

What happens if the other side ignores the case?

If the registrant files no response to a UDRP complaint — a common outcome in hijacking cases — the panel decides on the complainant's submissions alone. A default does not mean automatic transfer; the panel must still be satisfied that all three elements of Paragraph 4(a) are met. In practice, a well-documented hijacking complaint with clear evidence of prior ownership, account compromise, and post-hijacking bad-faith use routinely results in a transfer order after default. The forum filing fee and timeline are unchanged; no additional hearing is required.

How is WIPO different from a national court for .net?

WIPO's UDRP procedure is faster — roughly two months for a standard case — and cheaper than court litigation, but it offers only transfer or cancellation of the domain. No monetary damages are available, no injunctions, and no costs awards. A national court action takes longer and costs substantially more, but it can reach financial losses caused by the hijacking, compel third parties to cooperate, and examine chain-of-title questions with greater depth. For a .net hijacking where the primary goal is recovering the domain, WIPO is usually the correct first move. Where ongoing fraud or damages are at stake, court proceedings run alongside or after the UDRP.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.