Step-by-step: recover a hijacked .shop domain after account compromise
Step-by-step: recover a hijacked .shop domain after account compromise. UDRP and ccTLD domain recovery and defense across .shop. Email the firm to assess your…
Your .shop domain disappears overnight. The registrar account that held it shows a login from an unfamiliar device, a changed email address, and a transfer-out that completed before any alert reached you. The domain now sits in a foreign registrar account, pointing at a phishing page or a parking lot. You want it back — fast — and you need to know exactly which steps to take and where each one hides a trap.
Recovering a hijacked .shop domain after account compromise follows a defined sequence: immediate registrar escalation, evidence preservation, a formal registrar dispute or UDRP complaint at WIPO, and — where arbitration cannot reach — court action through local litigation counsel. The .shop registry is ICANN-accredited, which means the UDRP applies to .shop domains, WIPO accepts .shop complaints, and the registrant has 20 days to respond once a case commences. Speed in the first 48 hours is the single variable most within your control.
This guide walks each step in sequence, names the trap hidden in each one, addresses the evidence that decides the outcome, and explains when a court route is the better path than arbitration.
Step 1: Contain the breach — what to do in the first 48 hours
The first task is not to file a complaint. It is to stop the hijacker from moving the domain a second time. A domain transferred out of a compromised registrar account can be transferred again within days; once it crosses two registrar hops, recovery becomes significantly more complicated.
Act in this order. First, secure every associated email account immediately — change credentials, revoke sessions, and enable multi-factor authentication. The hijacker's first move was almost always a compromised inbox; leaving it open gives them continued access to any recovery link you trigger. Second, contact the losing registrar (the one the domain left from) by phone and by written ticket on the same day. Request an emergency registrar lock and ask them to flag the transfer as potentially unauthorized. Most ICANN-accredited registrars have an abuse or security escalation path distinct from standard support.
Third, capture a complete screenshot record — WHOIS/RDDS output showing the current registrant details, any emails from the registrar showing the transfer request, and any device or IP logs you can pull from your account. This evidence bundle is what every forum and every court will ask for first.
The trap at this step: waiting for the registrar to respond before taking any other action. Registrar response times vary widely. Begin documenting and begin drafting the formal complaint simultaneously. Do not treat a support ticket as a hold on the situation.
Step 2: Invoke the ICANN registrar dispute process — and know its ceiling
ICANN's Registrar Transfer Dispute Resolution Policy (the TDRP) provides a formal mechanism for challenging a transfer that violated the registrar's obligations. The losing registrar may have failed to obtain proper authorization; the gaining registrar may have accepted a fraudulent transfer request. Either failure is potentially actionable under the TDRP.
Submit a written dispute to both registrars within the timeframe their published policies specify. The written submission should identify: the account holder of record, the date of unauthorized transfer, the specific ICANN transfer-authorization rule the registrar breached, and the evidence of compromise. Include any email headers showing the source of a forged authorization request.
Know the ceiling. The TDRP process depends on registrar cooperation. If the gaining registrar is unresponsive or located in a jurisdiction where ICANN enforcement is slow, this route stalls. It is a starting point, not a complete solution. In our practice, we treat the registrar dispute as a parallel track — running at the same time as the next step — not as a prerequisite to it.
The trap at this step: believing the TDRP alone will recover the domain. It often does not. The TDRP can produce a finding that a transfer was unauthorized; it rarely compels an immediate return of the domain to your control. For that, you need the next track.
If you have already filed a registrar dispute without result, or if the gaining registrar has simply ignored the ticket, a UDRP complaint or court action may now be the faster path. For an assessment of your domain dispute, contact info@cognomenlaw.com.
Step 3: File a UDRP complaint at WIPO — how the .shop rule applies
The .shop gTLD is fully subject to the UDRP, and WIPO is the forum most commonly used for .shop recovery matters. A UDRP complaint allows the rightful trademark or business-name holder to seek transfer or cancellation of the domain from whoever currently holds it — regardless of how the domain got there.
To succeed, you must satisfy all three elements of Paragraph 4(a) of the UDRP: (1) the domain is identical or confusingly similar to a mark in which you hold rights; (2) the current registrant has no rights or legitimate interests in the domain; and (3) the domain was registered and is being used in bad faith. In a hijacking scenario, element (2) and element (3) are typically strong — the hijacker has no rights whatsoever, and the act of theft followed by use for phishing or parking is squarely within the Paragraph 4(b) bad-faith factors. Element (1) requires you to show the mark itself — registered or unregistered, but supported by evidence of use.
The WIPO filing fee for a .shop complaint covering a single domain is USD 1,500 for a single-member panel. The respondent — whoever currently holds the domain — has 20 days to file a response. A standard case is normally resolved within approximately two months, absent supplemental filings or panel complications. WIPO also offers an expedited option delivering a decision within roughly one month for qualifying single-panel, single-domain cases.
In a recent matter — a .shop domain hijacked through a SIM-swap attack, spring 2025 — we assembled the compromise evidence, filed at WIPO, and received a transfer order in under eight weeks. The hijacker defaulted; the default did not automatically produce a win, but the strength of the uncontested evidence record carried the case.
The trap at this step: treating a UDRP complaint as automatically equivalent to a theft-recovery proceeding. The UDRP asks whether the current registrant has rights and legitimate interests and whether registration and use are in bad faith — it does not ask "was this domain stolen?" as a standalone question. You must fit the facts of the compromise into the three-element framework. If your trademark rights are weak or unregistered and undocumented, element (1) becomes the obstacle, not the hijacker's conduct.
How does the evidence of account compromise change the UDRP analysis?
Strong compromise evidence — login logs, IP geolocation data, device fingerprints, forged authorization emails — anchors the bad-faith finding, but it plays differently across the three elements. Under element (3), panels have consistently held that a registrant who acquires a domain through deception or theft cannot claim good-faith registration. The mere fact of unauthorized acquisition places the current holder squarely within the Paragraph 4(b) bad-faith catalogue.
Under element (2), the compromise evidence eliminates any plausible legitimate-interest argument. The Paragraph 4(c) safe harbors — bona fide offering of goods or services, being commonly known by the name, legitimate noncommercial use — are each foreclosed when the holder acquired the domain by fraud. A panel seeing a clean chain of compromise evidence rarely struggles on this element.
Under element (1), the compromise evidence is largely irrelevant. What matters here is your rights in the name. Assemble: trademark registration certificates, filed applications with priority dates, evidence of use in commerce, domain registration history predating the hijack, and any web archive captures showing your legitimate use of the .shop domain before the theft. The longer the documented history of your rightful use, the stronger the element (1) case.
What evidence typically decides the outcome? Panels look hard at the WHOIS/RDDS timeline — when did registrant details change, and by how much? They look at the website content now appearing at the domain — parking pages monetizing your brand traffic are a textbook bad-faith indicator. And they look at whether the current holder responded at all. A default does not compel transfer, but it removes the only counter-narrative from the record.
When should you take court action instead of — or alongside — UDRP?
The UDRP has a hard ceiling: the only remedies are transfer or cancellation of the domain. No monetary damages. No injunction against the hijacker personally. No costs award. If you need more than the domain returned — if you have suffered measurable loss from a phishing scheme operating at your domain, or if you need to freeze assets or identify the hijacker — court action is the only route that reaches those remedies.
Four situations point toward court as the primary or parallel track. First, when the hijacker is identifiable and in a jurisdiction with a functioning court system, and the financial harm justifies litigation costs. Second, when a UDRP complaint has already failed — perhaps on a disputed element (1) — and the losing party has a right to challenge the panel decision in court anyway (the UDRP preserves that right explicitly). Third, when the domain has moved through multiple registrar hops and the registry lock cannot be triggered without court intervention. Fourth, when you need injunctive relief faster than the UDRP timeline — a US court, for example, can issue a temporary restraining order in a matter of days in a clear cybersquatting case, faster than any arbitral forum.
Court anticybersquatting actions are substantially more expensive than UDRP proceedings and require local litigation counsel in the relevant jurisdiction. We coordinate that engagement when the facts warrant it. The decision matrix is not UDRP or court; it is almost always UDRP and court, sequenced by speed and remedy need.
What about running both simultaneously? Filing a UDRP complaint does not waive your right to file a court action, and a court action does not automatically stay a pending UDRP proceeding, though a court injunction ordering a stay of the arbitral process will pause it. In our practice, we regularly advise clients who need both tracks opened within the same week, with the UDRP providing the faster path to domain recovery and the court action providing the broader remedies.
To weigh UDRP against a court action for your case, email info@cognomenlaw.com.
Step 4: Secure the domain once the transfer order issues
A WIPO transfer order does not move the domain automatically. The order goes to the registrar of record, and the registrar has a defined period to implement it — absent a court filing by the current holder to stay implementation. That stay window matters: a hijacker who receives notice of the panel decision may file a court action in a chosen jurisdiction specifically to trigger the stay and delay return of the domain.
Once the domain returns to your registrar account, act immediately. Enable registrar lock (transfer-prohibited status) at the registry level, not just at the registrar-account level. Rotate all credentials. Set the domain to auto-renew. Review any glue records or DNS configurations the hijacker may have altered — a restored domain sometimes still points at the hijacker's nameservers if the DNS configuration is not separately reviewed.
The trap at this step: treating the transfer order as the end of the matter. It is the end of the UDRP proceeding. It is not the end of the security posture question. A domain recovered once through a hijacking is a demonstrated target. The registrar account security, email account security, and domain lock settings all need a hard reset.
Step 5: Post-recovery — what to put in place so it does not happen again
Domain hijacking through account compromise is almost always preventable with the right registrar and account settings. After recovery, the minimum baseline is: multi-factor authentication on the registrar account and the associated email address; registrar-level transfer lock; registry-level lock where the registry offers it (the .shop registry, operated by GMO Registry, supports standard ICANN transfer-lock mechanisms); and a documented renewal calendar so the domain never lapses into grace-period vulnerability.
Beyond the individual domain, consider portfolio monitoring if you hold multiple .shop domains or operate across zones. A hijacking of one domain is sometimes the first probe in a broader targeting of a brand's domain portfolio. We regularly advise registrants who discovered a .shop hijacking only after checking why their .com was also displaying unusual DNS behavior — the two incidents were connected.
Pre-acquisition due diligence also applies to recovery: once you have the domain back, run a chain-of-title review to confirm no third-party claims attached to the domain during the period it was out of your control. A hijacker who used the domain for phishing may have created downstream dispute risk that follows the domain back to you.
Related at COGNOMEN
Frequently asked questions
When should I recover a hijacked .shop domain after account compromise?
You should begin the recovery process within 24 to 48 hours of discovering the hijacking — the moment you confirm unauthorized access and an outbound transfer you did not authorize. The ICANN 60-day transfer lock (triggered by a recent transfer) may still be in effect at the gaining registrar during that window, which gives a narrow opportunity to request a reversal before the domain moves again. Delay reduces your options at every stage: registrar escalation, TDRP filing, and UDRP evidence preservation all benefit from contemporaneous documentation. Time is the variable most within your control in the first hours after discovery.
What happens if the other side ignores the case?
A UDRP respondent who does not file a response within the 20-day response window is in default. The panel proceeds on the complaint record alone. Default does not mean automatic transfer — the panel still reviews whether the three elements are satisfied on the evidence presented. In hijacking cases the evidence record is typically strong, and panels have consistently found bad faith and lack of legitimate interest where the domain was demonstrably acquired through unauthorized account access. An absent respondent removes the only possible counter-narrative, which generally benefits the complainant. For court proceedings, local rules on service of process and default judgment apply and are jurisdiction-specific.
How is WIPO different from a national court for .shop?
WIPO administers the UDRP and delivers decisions in approximately two months, with remedies limited to transfer or cancellation of the domain — no damages, no costs award, no personal injunction against the hijacker. A national court takes longer and costs substantially more, but it can award monetary damages, identify parties through discovery, issue injunctions that freeze assets, and reach conduct beyond the domain itself. The two routes are not mutually exclusive: a WIPO complaint recovers the domain quickly while a parallel court action pursues broader remedies. For .shop domains, WIPO is almost always the faster first step unless the financial harm or the need for personal relief makes court action the immediate priority.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.