Assess my case

Step-by-step: recover a stolen .ai domain

Step-by-step: recover a stolen .ai domain. UDRP and ccTLD domain recovery and defense across .ai. Email the firm to assess your case. Transparent fees, respond…

You log in one morning to find your .ai domain has been transferred to a stranger. The registrar's dashboard shows a new owner. Your site is down, your email is gone, and whoever took the name is already pointing it somewhere else. This is domain theft – account compromise, unauthorized transfer, or outright hijacking – and the clock starts the moment you discover it.

To recover a stolen .ai domain you have two primary routes: a registrar-level transfer reversal (the fastest path if the theft is recent) and a UDRP complaint filed before WIPO (the standard arbitration path for .ai, which operates under the UDRP). A parallel court action is available where arbitration cannot reach. Speed matters at every step: transfer windows close, evidence disappears, and panels weigh how quickly you acted once you knew the domain was gone.

This guide walks each step in sequence, names the trap hidden inside it, and sets out what evidence decides the outcome.

Step 1: Confirm the theft and secure your evidence immediately

The first task is to establish, in writing, exactly what happened and when. Do not attempt to "fix" access problems before documenting them. A screenshot taken before you change a password can be the exhibit that proves the unauthorized transfer date.

What you need at this stage: a dated screenshot of the WHOIS/RDDS record showing the current registrant and registrar; your own account logs showing your last authenticated login and any login alerts you received; any email notifications from your registrar about a transfer request, email-address change, or two-factor authentication reset; and any communications from whoever now controls the domain – a ransom demand, a parking page, or a redirect. Collect everything into a timestamped record before you touch any account settings. That record is your opening exhibit in any proceeding that follows.

The trap in Step 1: many registrants update their credentials immediately after discovering the compromise, overwriting the log trail that would have shown unauthorized access. Preserve first, remediate second.

Step 2: Contact your registrar and invoke the transfer-dispute process

ICANN's Transfer Policy gives registrars a defined window to investigate and, in some circumstances, reverse an unauthorized transfer. The window is narrow. File a formal dispute with your registrar in writing – email is fine, but confirm receipt – and label it clearly as a report of an unauthorized transfer.

In your dispute communication, state: the domain name; the date the unauthorized transfer occurred or was discovered; your evidence of account compromise (the materials from Step 1); and your demand that the registrar place a registrar lock on the domain pending investigation. Ask specifically whether they will initiate a reverse transfer with the gaining registrar, and request confirmation of the applicable dispute window under ICANN's transfer policy. Keep records of every response, every ticket number, and every name given by a support agent.

The trap in Step 2: registrars vary enormously in their responsiveness to theft reports. Some move quickly; others route everything through an automated queue that adds days. If you receive no substantive response within 24 to 48 hours, escalate to the registrar's abuse contact and, in parallel, begin preparing the UDRP complaint (Step 4) so you are not waiting serially. The two tracks can run at the same time.

One additional note specific to .ai: the .ai ccTLD is administered by the government of Anguilla through the Offshore Information Services registry. The zone accepts UDRP complaints through WIPO as its designated dispute-resolution provider. However, the registrar holding the domain may itself be an ICANN-accredited gTLD registrar. That means ICANN's transfer policy and its dispute-escalation mechanisms may apply at the registrar level even while WIPO handles the substantive dispute. Confirm the registrar's status before filing anything.

Step 3: Understand which legal path fits your situation

Not every stolen .ai domain follows the same recovery route. The right path depends on whether the theft was technical (account compromise, credential theft) or substantive (a bad-faith third-party registration), and on whether the current holder is reachable and acting in a jurisdiction where a court order can be served.

The decision logic works like this. If the domain was transferred without your authorization through a compromised registrar account, the primary route is registrar escalation plus a transfer-reversal demand. UDRP is a secondary route, available once the domain is in the hands of a new registrant and the registrar process has failed or stalled. If the domain was registered by a third party who appropriated your name (rather than stealing your account), UDRP is the direct route: you are the complainant, the squatter is the respondent, and the three UDRP elements under Paragraph 4(a) of the Policy apply. If the current holder is operating in a jurisdiction where courts can act quickly – and you need an injunction, damages, or both – a court action is the supplementary or primary route. For .ai specifically, US anticybersquatting litigation is available where the facts support it, handled with local litigation counsel in the relevant jurisdiction.

The trap in Step 3: brand owners frequently default to UDRP because it is familiar. But UDRP cannot award damages, cannot order a registrar to compensate you for losses, and cannot reach a criminal actor who has already monetized your domain. Where the theft involved fraud, a court route – or a parallel court and arbitration track – is worth assessing before you commit to a single path.

For a read on whether the three UDRP elements are met in your situation, or whether a court track is more appropriate, reach us at info@cognomenlaw.com.

How does the UDRP apply to .ai domains?

.ai operates under the UDRP, with WIPO as the designated provider – meaning the same three-element test that governs .com disputes applies here. To succeed under Paragraph 4(a) of the Policy, you must show: (1) the domain is identical or confusingly similar to a trademark in which you have rights; (2) the registrant has no rights or legitimate interests; and (3) the domain was registered and is being used in bad faith.

In a theft scenario the analysis shifts slightly. Element one is typically straightforward if the domain matches your brand. Element two is almost always met: an unauthorized transferee who obtained the domain through fraud has no legitimate interest by definition. Element three is where most of the factual work sits. You must demonstrate both that the registration (by the current holder after the unauthorized transfer) was in bad faith, and that the current use – whether a parking page, a redirect, a malware site, or a ransom demand – constitutes bad-faith use. Paragraph 4(b) of the Policy lists relevant bad-faith indicators: registration primarily to sell to the mark owner, registration to disrupt a competitor, and use to attract users by confusion are all recognized factors. A ransom demand or a demand to pay to "buy back" your own name is among the clearest bad-faith signals a panel can see.

The standard WIPO timeline for a single-domain case runs roughly two months from filing to decision. WIPO's filing fee for a single-member panel begins at USD 1,500 for one to five domains. If you request a three-member panel – typically appropriate where the facts are contested or the domain is high-value – the fee rises to USD 4,000, with the parties generally splitting the higher fee if the complainant selected a single panelist and the respondent seeks three.

In a recent matter (a .ai account-compromise theft, spring 2025), we filed a UDRP complaint at WIPO after the registrar's transfer-reversal process stalled. The domain was returned to the original holder roughly eight weeks after filing, with the panel finding bad faith in both the unauthorized acquisition and the subsequent parking-page monetization.

Step 4: Build the evidence file for your UDRP complaint

A UDRP complaint before WIPO is not a litigation in the conventional sense, but the evidentiary standard is real. The complaint must be supported by annexes that prove each of the three elements. Thin complaints lose – even in cases where the facts favor the complainant on the merits.

For a theft-based .ai recovery, your evidence file should include the following. First, proof of trademark rights: a registration certificate, or in the absence of registration, evidence of acquired distinctiveness through use – product pages, press coverage, invoices, advertising. Common-law rights are accepted, but the record must be strong enough to carry the burden. Second, evidence that the current registrant has no legitimate interest: WHOIS/RDDS printouts showing the new registrant, screenshots of the domain's current use (parking, redirect, ransom), and the absence of any bona fide business connection between the current holder and the domain name. Third, bad-faith evidence: the unauthorized transfer itself, any ransom communication, the registrar's incident ticket, and records of account compromise. If the transfer was enabled by a credential phishing attack, include any phishing emails you received.

Also include a clean timeline: the date you registered the domain, the date you discovered the unauthorized transfer, the steps you took at the registrar level, and the registrar's response or non-response. Panels in theft cases regularly look at the original registrant's conduct once they discovered the loss. A prompt, documented response strengthens the record. A long delay with no explanation weakens it.

The trap in Step 4: the complaint itself has a technical format required by WIPO. Page limits, annex labeling, and the required certification must all be correct on filing. A complaint that fails the formal review is returned for correction, adding days to a process where speed already matters. File correctly the first time.

What evidence of account compromise actually decides the outcome?

Panels deciding theft-based UDRP cases under the .ai zone – and across gTLDs where the same fact patterns arise – have consistently focused on two questions: was the original registration legitimate, and was the transfer authorized by the original holder? The evidence that most directly answers those questions is rarely elaborate. It is almost always the registrar's own records.

The most persuasive evidence of account compromise tends to be: the registrar's logs showing a login from an unrecognized IP address or device immediately before the transfer; an email-address change on the account that the registrant did not authorize; a transfer authorization email sent to an address the registrant never used; and any contemporaneous communication – a registrar ticket, a fraud report to law enforcement, a complaint to a hosting provider – showing the registrant acted quickly on discovery. Panels treat a post-compromise ransom demand as particularly powerful bad-faith evidence: it places the current holder's intent on the record in the holder's own words.

What panels weigh less heavily: assertions of theft without documentation; screenshots taken after the fact without metadata; and vague references to "hacking" without any record of when or how the compromise occurred. The evidentiary gap between "I believe my account was compromised" and "here is the registrar log showing a login from an unknown IP at 3:14 a.m. on this date" is the gap between a complaint that succeeds and one that fails.

In a second matter from our practice (a .ai brand-identity domain, autumn 2025), the complainant's strongest exhibit was a single email from the gaining registrar acknowledging an irregularity in the transfer chain. That acknowledgment, combined with the WHOIS record showing the date of the unauthorized transfer, was sufficient to establish bad faith. The domain was transferred back within the standard two-month UDRP timeline.

When does a court action beat arbitration for a stolen .ai domain?

The UDRP is efficient, but its remedies are limited. Transfer or cancellation – nothing more. No damages. No costs award against the registrant. No injunction requiring a hosting provider to take down content. If the theft caused business losses – diverted transactions, fraudulent invoices sent to your customers, reputational harm from malware served from your domain – UDRP cannot address any of that.

A court action becomes the appropriate primary or parallel route in several scenarios. The first is where you need an injunction in addition to transfer: a court can issue emergency relief faster than a panel can be appointed, and that relief can include an order to a hosting provider, a registrar, or an ISP. The second is where you need damages: US anticybersquatting litigation, handled with local litigation counsel, provides a damages route for qualifying mark owners. The third is where the identity of the thief is known and you want criminal or civil accountability beyond the domain itself. The fourth is where the domain is being used for fraud that is ongoing and causing harm with each passing day.

The UDRP and a court action are not mutually exclusive. You can file a UDRP complaint to secure transfer on the standard timeline and pursue a court action simultaneously for damages and injunctive relief. Courts in relevant jurisdictions will generally not treat the UDRP proceeding as res judicata on the broader claims. Coordinating the two tracks requires care – in particular, a UDRP transfer order that arrives before the court proceedings conclude can affect the injunction analysis – but the dual-track approach is recognized and available.

For .ai specifically, the governing national procedure of Anguilla applies to any court-level dispute about registration authority. Where the dispute also involves a US mark owner and US-based harm, US courts may have jurisdiction under applicable anticybersquatting legislation. Confirm jurisdiction and the available remedies with counsel before filing.

If the theft has caused ongoing business harm or you need emergency relief alongside domain recovery, email info@cognomenlaw.com to assess the dual-track approach.

Step 5: File the complaint and manage the response window

Once your evidence file is assembled and your route is confirmed, file the WIPO complaint. The filing is online through WIPO's case administration portal. The complaint must name the domain, identify the respondent, state the grounds under Paragraph 4(a), and attach all annexes in the required format. WIPO will review the complaint for formal compliance; if it passes, the case commences and the respondent's 20-day response window begins.

During that 20-day window, two things may happen. First, the respondent may file a response. In a theft scenario, this is less common than in brand-squatting cases – the person who took the domain by fraud is often not going to engage with a formal proceeding. Default (no response) does not automatically mean you win, but it does mean the panel decides on the record you have built, without counter-argument. Second, the respondent may contact you directly, through WIPO, or through a broker, to offer a sale or settlement. Whether to accept a settlement offer mid-proceeding is a fact-specific question; it has procedural implications for the case status and the refund of filing fees.

After the response window closes, WIPO appoints a panelist. For a single-member panel the appointment typically follows within days of the close of the response period. The panelist reviews the record, may request additional submissions (rare in standard cases), and issues a decision. The registrar then has a short window to implement the transfer order unless the respondent files for a court stay.

The trap in Step 5: the "court stay" mechanism under the UDRP allows a respondent who loses to file a court action and thereby delay the registrar's implementation of the transfer order. In genuine theft cases this is rare, but it can add weeks to the timeline. Build that possibility into your recovery plan if the domain's commercial value is high.

What happens after the panel orders a transfer?

A WIPO transfer order is not self-executing. Once the panel decides in your favor, WIPO notifies the registrar. The registrar then implements the transfer – moving the domain back to a registrant account you control – after a mandatory 10-business-day waiting period. That waiting period exists to allow the respondent to seek a court stay. If no stay is sought, the transfer proceeds automatically.

Before the transfer executes, prepare the receiving account. The domain will be transferred to a registrar account you designate. If your original account was compromised, open a clean account with a registrar you trust, with fresh credentials and strong two-factor authentication, before the transfer order is implemented. Do not have the domain returned to the same account that was compromised. That would recreate the vulnerability that allowed the theft in the first place.

Once the domain is returned, immediately: update DNS to restore your site; check MX records to restore email delivery; audit any services that were interrupted during the period of compromise; and notify your users or customers if the domain was used to deliver phishing or malware during the theft period. The recovery of the domain is the end of the legal proceeding, not the end of the incident response.

See also our related resource on enforcing a UDRP decision for further steps if the registrar delays or the respondent attempts to block implementation.

Cross-zone considerations: what if the thief also took related domains?

Domain theft rarely targets a single zone. A sophisticated actor who takes your .ai may simultaneously register or redirect your .com, your .io, or the hyphenated variant of your name. Each zone requires its own analysis.

For .com domains under the UDRP, the same three-element test applies and WIPO or the Forum can hear the complaint. A single UDRP complaint can cover multiple domains if the registrant is the same holder – which, in a coordinated theft, it may well be. For new-gTLD domains, the URS (Uniform Rapid Suspension) is available as a faster, lower-cost suspension remedy, though it does not transfer ownership. For country-code zones such as .uk or .eu, separate procedures apply: the Nominet DRS for .uk domains, and the ADR.eu procedure administered through the Czech Arbitration Court for .eu domains. Neither of those applies to .ai. If the thief also compromised your .de domain, note that there is no UDRP for .de – disputes there proceed through the German courts, with a DENIC dispute-entry registration block available to prevent further transfer while litigation proceeds.

The practical implication: if the theft is multi-zone, prioritize. File the .ai WIPO complaint and the .com complaint (if applicable) first, because those are the fastest routes to transfer. Initiate the ccTLD procedures in parallel where the relevant zones are represented. Coordinate the filings through a single adviser so that the evidence record is consistent and the timelines do not conflict. See our guide on URS suspension for new-gTLD domains for the parallel procedure in that zone, and our court recovery service page for situations where arbitration is insufficient.

Related at COGNOMEN

Frequently asked questions

How long does it take to recover a stolen .ai domain?

The timeline depends on the route. A registrar-level transfer reversal, if the registrar acts promptly, can resolve in days to a few weeks. A WIPO UDRP complaint for a .ai domain typically runs roughly two months from filing to decision – 20 days for the response window, then panel appointment and deliberation, then registrar implementation. If the respondent seeks a court stay after a transfer order, add several weeks to that estimate. A parallel court action has its own, generally longer, timeline depending on the jurisdiction. Acting quickly on discovery shortens the overall process, because a registrar-level reversal is only available within a narrow window after the unauthorized transfer.

What does it cost to recover a stolen .ai domain at WIPO?

WIPO's filing fee for a single .ai domain on a single-member panel is USD 1,500. A three-member panel raises that to USD 4,000, typically shared between the parties if the respondent requests it. Legal fees are separate and vary by complexity; market rates for a straightforward UDRP complaint commonly fall in the USD 3,000–7,000 range, separate from the filing fee. WIPO offers a partial refund of approximately USD 1,000 if the case is withdrawn or terminated before a panel is appointed. Registrar-level escalation carries no WIPO filing cost, though legal preparation time applies.

Do I need a lawyer to recover a stolen .ai domain?

You are not required to be represented in a UDRP proceeding, and some complainants file pro se. In a theft scenario, however, the evidentiary record – account compromise logs, bad-faith documentation, timeline construction – is where most complaints succeed or fail. An error in formal compliance sends the complaint back for correction, losing days. A weak bad-faith record loses on the merits even when the facts favor you. We regularly advise registrants and brand owners at the evidence-assembly stage to identify whether the record is sufficient before filing. A consultation at that stage costs far less than a failed complaint and a re-filing.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.