Step-by-step: recover a hijacked .uk domain after account compromise
Step-by-step: recover a hijacked .uk domain after account compromise. UDRP and ccTLD domain recovery and defense across .uk. Email the firm to assess your case.
Your registrar account was accessed without your authority. The domain – a .uk you have held for years, tied to your trading name, your email, your customers – has been transferred to a stranger. The new registrant is unreachable or demanding money. Every hour the hijacked domain is out of your control, it can be pointed anywhere: a phishing page, a competitor's site, a parked monetization farm. The damage compounds.
To recover a hijacked .uk domain after account compromise, you have three routes: an emergency registrar escalation to freeze and reverse the transfer; a Nominet DRS complaint under the abusive-registration test (which, unlike the UDRP, requires only that the domain was registered or used abusively, not both cumulatively); and, where those routes cannot deliver, an application to the courts. The right sequence depends on how the compromise occurred, how much time has passed, and where the domain now sits. Speed on the registrar-escalation step – typically measured in hours, not weeks – materially affects all outcomes that follow.
This guide walks each step, names the trap hidden in each one, and explains what evidence decides the outcome.
What "account compromise" means and why it changes the legal picture in .uk
Account compromise, in the context of a .uk hijacking, means unauthorized access to the registrar account or reseller panel that held the domain – through credential stuffing, phishing, SIM-swapping, or exploitation of weak authentication – followed by a domain transfer the true owner never authorized. That is not a contractual dispute between two parties who disagree about ownership. It is theft of a digital asset. The legal distinction matters because it shapes both the urgency of the response and the forum that can help you fastest.
Nominet's DRS is designed primarily for trademark-based abusive registration disputes: a brand owner versus a cybersquatter. It can, and does, handle hijack scenarios where the current registrant has no color of right to the name – but it was not built for real-time emergency relief. The DRS process typically runs about 8–12 weeks from filing to decision once an expert is engaged. A registrar or Nominet emergency intervention, if the facts support it, can move in days.
A second distinction: Nominet's DRS applies the "abusive registration" test, which asks whether the registration or use of the domain took unfair advantage of, or was unfairly detrimental to, the complainant's rights. The trap here is that a hijack may not, on its face, look like a traditional abusive registration. The thief did not register a domain similar to your trademark to ride its coattails. They took the domain itself. Your case therefore needs to be framed – carefully – to satisfy the DRS test as well as the factual narrative of unauthorized transfer. We handle exactly this framing challenge in our practice.
Step 1: Lock everything immediately – and watch the trap in "immediately"
The first move is to lock the domain at the registrar level and prevent any further transfer or DNS change. Contact your registrar's abuse or security desk, not the standard support queue. Escalate to a named security contact. State clearly that an unauthorized transfer occurred, provide your account credentials and historical registration data, and request an emergency registrar lock.
The trap: most registrars have a transfer-dispute window – commonly 60 days from the transfer date – during which a reversal may be available without a formal proceeding. Miss that window and the registrar will typically tell you that you need a court order or a DRS decision before they will act. That shifts you from a fast administrative remedy to a longer legal process. If you are reading this within days of discovering the compromise, the clock is running.
A second trap: registrars vary enormously in how they handle hijack reports. Some have dedicated domain-security teams that act within hours. Others route the ticket through a standard support process that takes days. In our practice, we have seen compromised domains transferred a second time – from the initial thief to a third-party buyer – during the delay caused by slow registrar support. The moment a domain moves to a third party who claims to have purchased it in good faith, the legal picture becomes substantially more complicated. Get outside counsel engaged as early as the registrar escalation step, not after it fails.
Step 2: Compile the evidence of compromise – this is what decides the outcome
Before you file anything – DRS, court application, ICANN complaint – you need a coherent evidence file. What you can gather in the first 48 hours will shape every subsequent step.
The core evidence bundle for a .uk hijack recovery includes:
- Historical WHOIS / RDDS records showing you as the registrant over time, including dated screenshots and registrar confirmation emails.
- The original domain registration confirmation and any renewal receipts.
- Server logs, access logs, or registrar account-activity logs showing the unauthorized access event: timestamp, IP address, and the transfer-out action.
- Authentication records: evidence that two-factor authentication was bypassed, that a password-reset flow was exploited, or that a social-engineering call was made to the registrar's support team.
- Correspondence with the registrar after the event, including any ticket numbers and the registrar's response.
- RDDS records for the domain since the transfer, showing changed nameservers, DNS changes, or new contact details.
- Any ransom demand, communication from the new registrant, or listing of the domain for sale at a price that suggests it was taken for resale.
The trap here is preservation. Browser-rendered WHOIS results are not durable evidence. Take timestamped PDF exports and screenshots with the full URL bar visible. If your registrar stores account-activity logs, request a full export immediately – many providers purge logs on a 90-day rolling basis.
In autumn 2025, we assisted a UK-based retailer whose .co.uk had been transferred through a SIM-swap attack on the mobile number tied to the registrar account. The most critical piece of evidence was the mobile carrier's authentication log, which the client would have lost had they not requested a preservation hold within the first week. That single document established the mechanism of compromise and anchored both the registrar escalation and the subsequent DRS filing.
How does Nominet DRS apply to a .uk hijack case?
Nominet's DRS is the correct arbitral route for .uk domain disputes, and it is the route most likely to produce a transfer order faster and at lower cost than litigation. But the DRS was designed for trademark-based abusive registrations, and a pure hijack case requires deliberate framing to fit the test.
The DRS test asks whether the complainant has rights in a name or mark that is identical or similar to the domain, and whether the domain's registration or use amounts to an abusive registration – one that took unfair advantage of, or was unfairly detrimental to, the complainant's rights. In a hijack case, your "rights" are your prior registration and use of the domain, plus any trademark or trading name rights you can demonstrate. The "abusive registration" is the unauthorized transfer and continued holding or misuse by the thief.
A key difference from the UDRP: the DRS reads "registered OR used" abusively. You do not need to show both, which is a lower bar than the UDRP's cumulative registered-and-used-in-bad-faith requirement. That said, the DRS is not a theft-recovery mechanism in a pure legal sense; it is a contractual arbitration procedure binding on Nominet registrants. The expert's powers are limited to directing Nominet to cancel or transfer the domain. No monetary damages are available.
The DRS process starts with a free mediation stage. Where a response is filed, Nominet automatically opts both parties into mediation. In a hijack scenario where the current registrant is a criminal or an unreachable broker, mediation is unlikely to resolve anything – but it is a mandatory step that adds time. If mediation fails or the respondent defaults, the complainant pays the expert fee: GBP 750 plus VAT for a full expert decision in a single-expert case, or GBP 200 plus VAT for a summary (undefended) decision. An appeal to a three-expert panel costs GBP 3,000 plus VAT and the panel rarely admits new evidence, so getting the first filing right is essential.
For an assessment of whether your .uk hijack case meets the DRS abusive-registration test, contact info@cognomenlaw.com.
The steps above cover the standard arbitral path. The zone and the registrant's conduct decide whether that path is sufficient or whether a court application is required alongside it. To weigh the DRS against a court action for your case, email info@cognomenlaw.com.
Step 3: File the Nominet DRS complaint – and the trap in the timing
Once you have the evidence bundle in order, the DRS complaint is the primary filing for a .uk hijack recovery. The complaint identifies the domain, states the complainant's rights, and explains why the current registration is abusive. In a hijack case, you need to do more than assert prior ownership: you need to walk the expert through the mechanism of compromise, the evidence that the transfer was unauthorized, and why the current registrant has no color of right to the name.
The trap: the DRS complaint is not automatically supplemented by new evidence after filing. You get one submission. If the respondent files a response raising a point you did not anticipate, you can request permission to reply – but the expert may decline. Build your case comprehensively on the evidence you have at the time of filing.
A second trap specific to hijack cases: if the domain has been transferred from the original thief to a third party who claims bona fide purchase, the abusive-registration finding becomes harder to establish against that third party. Nominet's rules do address the situation where a domain is passed down a chain, but the factual and legal analysis is more demanding. The earlier you file – before a second or third transfer occurs – the cleaner the case.
The DRS typically runs about 8–12 weeks from filing to decision in a defended case, and somewhat faster if the respondent defaults. An undefended summary decision can arrive more quickly. There is no WIPO Expedited option for .uk; Nominet's own process sets the pace.
When does a court route beat the DRS for a .uk hijack?
The DRS is faster and cheaper than litigation in most cases. But there are four situations where a court application is the better route, or a necessary complement.
First: if you need an interim injunction to prevent further DNS changes or a third-party transfer while the DRS proceeds, only a court can grant one. The DRS has no power to grant interim relief. A domain actively being used for fraud – redirecting your clients, harvesting credentials on a cloned site – may justify an urgent court application for an interim order within days.
Second: if the domain has already been transferred to a third party outside the UK, or the chain of title now involves parties in multiple jurisdictions, the DRS may lack practical reach. Nominet can only direct the current registrant of a .uk domain; it cannot reach foreign registrars or intermediaries.
Third: if you want monetary damages alongside a transfer order, only a court can award them. The DRS's only remedies are transfer and cancellation.
Fourth: if the compromise involved criminal conduct – identity fraud, computer misuse – a police referral and a court proceeding may be appropriate as parallel tracks, not alternatives. We work with local litigation counsel where court action is required.
The choice between DRS, court, or both turns on the facts and timeline of your specific compromise. In a winter 2025 matter involving a .co.uk and a fraudulent registrar-support call, we coordinated a DRS filing with a parallel court application for an interim injunction, because the domain was being actively used to intercept business email within hours of the transfer. The DRS ultimately produced the transfer order; the court application produced the interim relief that prevented further damage while the DRS ran its course.
What happens after the DRS decision or court order?
A DRS expert decision directing transfer goes to Nominet, which instructs the registrar to implement it. Nominet's standard implementation timeline is short – typically a matter of days after the decision issues. The trap here is confirming that the transfer has actually completed: check the RDDS record, verify nameserver control has returned to you, and confirm DNS propagation to your intended hosting.
After recovery, secure the domain immediately. Change all registrar-account credentials, enable two-factor authentication on a separate device from the one that was compromised, review all account-recovery contacts, and set a registrar-level transfer lock. If the compromise was via an auth code or registrar social-engineering call, report it to Nominet and the registrar's security team so the vector is documented.
Review the rest of your domain portfolio. An attacker who targeted one domain in your account may have targeted others. Check your registrar account's full list of domains for unauthorized changes, and review any email accounts linked to the registrar login.
Consider whether the .uk name is also registered in adjacent zones – .com, .co.uk if you hold .uk, or national ccTLDs in markets where you trade. A hijacker who fails to hold a .uk long-term may pivot to squatting adjacent zones. Portfolio monitoring services can flag new registrations of confusingly similar names across zones before they cause harm. We advise on both the recovery and the post-recovery hardening steps.
If a prior registrar escalation or DRS filing did not recover your domain, a focused second read can often find the element that was missed. For a read on the next step available in your case, reach us at info@cognomenlaw.com.
Step-by-step decision guide: which route first?
The right sequence is not the same in every hijack. Consider the following decision path based on the facts of your case.
If the transfer occurred within the past 60 days and the domain is still with the original thief at your registrar, the registrar emergency escalation is the first move. It is the fastest potential remedy and costs nothing beyond professional time. If the registrar declines or is unresponsive, move immediately to the DRS filing rather than waiting.
If the domain is being actively misused – fraud, phishing, credential harvesting, redirecting live traffic – file a court application for interim injunctive relief in parallel with the registrar escalation. Do not wait for the DRS. The DRS cannot grant emergency orders, and the damage caused by an active misuse of your domain compounds daily.
If the domain has been transferred to a third party claiming purchase for value, the DRS analysis becomes more complex. You still have grounds – a thief cannot convey good title to a domain they stole – but the evidence burden is higher, and the timeline may be longer. Court action may be more appropriate as the primary route.
If the compromise involved a Nominet-accredited registrar's failure (a social-engineering call that bypassed proper verification, for example), there may also be a complaint to Nominet against the registrar's conduct under the registrar's obligations in the Nominet registrar agreement. That is not a recovery mechanism in itself, but it can produce registrar cooperation and is evidence of the abusive-registration chain.
For .uk domains held through a reseller rather than a direct Nominet-accredited registrar, the escalation path runs first through the reseller, then through the underlying accredited registrar. The reseller layer adds friction. Know which accredited registrar holds the registry-level record before any incident occurs.
The cross-zone dimension: if the same attacker has taken both a .uk and a .com using the same compromise, the .com is governed by the UDRP – a separate process, a separate filing, a different forum. WIPO or the Forum handles the .com; Nominet's DRS handles the .uk. They can run in parallel, but each complaint is an independent filing with its own evidence, its own timeline, and its own forum fee. We manage both tracks where needed.
Related at COGNOMEN
Frequently asked questions: recovering a hijacked .uk domain after account compromise
How long does it take to recover a hijacked .uk domain after account compromise?
Timeline varies by route. A successful registrar emergency escalation can produce a reversal within days if acted on immediately and within the registrar's transfer-dispute window. A Nominet DRS case in a defended matter typically runs about 8–12 weeks; an undefended summary decision arrives faster. A court application for interim injunctive relief can produce an order within days in urgent circumstances, though the full proceeding takes longer. Acting quickly matters: if the domain is transferred to a third party before you escalate, all routes become harder and slower.
What does it cost to recover a hijacked .uk domain after account compromise at Nominet DRS?
Nominet's DRS includes a free mediation stage. If mediation fails or the respondent defaults and the case proceeds to an expert, the complainant pays the expert fee: GBP 200 plus VAT for an undefended summary decision or GBP 750 plus VAT for a full single-expert decision. An appeal costs GBP 3,000 plus VAT. These are forum fees only; legal preparation costs are separate and depend on the complexity of the evidence and the conduct of the respondent. The DRS is substantially less expensive than court litigation in almost every hijack scenario.
Do I need a lawyer to recover a hijacked .uk domain after account compromise?
You are not legally required to use counsel for a DRS filing – the procedure is designed to be accessible. In practice, hijack cases are more factually complex than standard cybersquatting complaints, and a poorly framed complaint that fails at the DRS may leave you with fewer practical options. The evidence bundle, the framing of the abusive-registration test, the timing relative to any transfer window, and the decision whether to seek interim court relief all benefit from specialist input at the earliest stage. The cost of a mishandled first filing is typically higher than the cost of getting advice before you file.
COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures including the Nominet DRS, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. Our practice covers both the registrar-escalation step and the DRS or court proceedings that follow it, across .uk and other zones. To discuss a hijacked domain, contact info@cognomenlaw.com.
Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.