Step-by-step: recover a stolen .group domain
Step-by-step: recover a stolen .group domain. UDRP and ccTLD domain recovery and defense across .group. Email the firm to assess your case. Transparent fees, r…
You log in one morning and the domain is gone. The registrar account shows a transfer you never authorized, the WHOIS record shows a stranger's contact details, and the site that carried your organization's name now points somewhere else entirely. Domain theft is not a hypothetical. It happens through credential phishing, registrar account compromise, social-engineering attacks on registrar support lines, and unauthorized outbound transfers. The .group zone is a new generic top-level domain – and like every accredited-registrar zone, it sits under the ICANN transfer-dispute rules and UDRP procedures that give you a concrete path back.
To recover a stolen .group domain, you must move through four stages in the right order: lock the domain at the registrar, document the account compromise with timestamped evidence, choose between a UDRP complaint before WIPO or the Forum and a court-based anticybersquatting route, and then prepare the evidentiary record that decides the outcome. The 20-day response window in a UDRP proceeding means time pressure falls on both sides – but it also means a well-prepared complainant can reach a panel decision in roughly two months at a WIPO filing fee starting at USD 1,500.
This guide walks each step, names the trap hidden in it, and explains when a court route outperforms arbitration for a stolen .group domain.
What governs a stolen .group domain – and why the zone matters
The .group new gTLD is delegated under the ICANN framework, which means every registrar offering .group registrations is an ICANN-accredited registrar and the UDRP – the Uniform Domain Name Dispute Resolution Policy – applies to the zone as a matter of contract. The UDRP was adopted by ICANN in 1999 and the Policy is incorporated into every .group registrant agreement by reference. What this means in practice is that a domain-name dispute lawyer advising a brand owner on a stolen .group domain has the same procedural toolkit available as for a stolen .com.
There is an important distinction, however, between a conventional cybersquatting complaint and a theft recovery. A standard UDRP filing says: the registrant holds a domain identical or confusingly similar to our trademark, has no legitimate interest, and registered and is using it in bad faith. A theft case argues something different: the registrant of record today is not the party who registered the domain at all. That distinction shapes both the evidence you need and the forum you choose.
We regularly advise registrants and brand owners who discover that a .group or other new-gTLD domain has been transferred out of their account without consent. In our practice, the first assessment always addresses one question: can we show that the current registrant of record acquired the domain through unauthorized means, or does the record look like a voluntary transfer? The answer drives every subsequent step.
Step 1: Trigger an immediate registrar lock – and the trap here
The first step is to contact the current registrar of record and request an immediate lock on outbound transfers. Registrars must maintain certain lock mechanisms under ICANN's Transfer Policy, and a registrant of record who claims the domain was moved without authorization can demand that no further transfer occur while the dispute is pending. A 60-day lock period follows any completed transfer under standard ICANN transfer policy rules – this is sometimes called the transfer-lock period. If the domain changed hands very recently, that lock may still be in effect automatically.
The trap in Step 1 is assuming the registrar will act on a phone call or a single email. Registrars are cautious when both sides claim ownership. In our experience, the escalation that works is a written notice to the registrar's abuse or compliance team that references the specific ICANN transfer policy provisions, attaches account-compromise evidence, and requests in writing that (a) the domain is locked against further transfer and (b) WHOIS/RDDS records are preserved. Some registrars move fast. Others treat non-emergency requests as a support ticket. Get the written record; you will need it at every later stage.
If you have just discovered the unauthorized transfer, do not wait. For an assessment of your domain dispute and guidance on the registrar escalation step, contact info@cognomenlaw.com.
Step 2: Document the account compromise with timestamped evidence
Evidence of account compromise is the factual spine of every stolen-domain recovery. Without it, the registrant of record today – whoever they are – stands in the presumptive position of a legitimate holder, and dislodging that position requires proof. The documentation phase has a fixed list of items to assemble.
First, pull every account-access log the registrar will release: IP address logs, login timestamps, session tokens, and any records of account-details changes – including email address changes, two-factor-authentication resets, or WHOIS contact modifications. Second, capture screenshots with timestamps of the current WHOIS/RDDS record showing the changed registrant details. Third, gather your own proof of prior registration: renewal confirmations, historical invoices from the registrar, DNS configuration records showing your hosting or email records, and any prior dispute or correspondence about the domain. Fourth, if the compromise involved a phishing email, a social-engineering phone call, or malware, document that too – email headers, call logs, malware-detection reports.
The trap in Step 2 is delay. Registrar access logs are often retained for a limited period. Some platforms rotate or purge logs automatically. Request preservation in writing immediately and follow up. If the registrar resists, that refusal itself becomes evidence of obstruction that a panel or court can weigh.
How do you choose between a UDRP complaint and court action for .group?
The right route depends on what you need and what the evidence shows. Two routes are realistically available for a stolen .group domain: a UDRP complaint before WIPO or the Forum, or a court action in the relevant jurisdiction relying on US anticybersquatting legislation or equivalent national law where the registrant is located.
The UDRP at WIPO is the faster and lower-cost path if your evidence clearly establishes that the domain was registered – initially by you – in connection with a trademark or trade identity, and that the current holder acquired it through unauthorized means. WIPO's standard timeline is roughly two months. The filing fee is USD 1,500 for a single-member panel on one domain. The only remedies available under the UDRP are transfer or cancellation – there are no monetary damages and no costs award. If transfer is all you need and the evidence is clean, the UDRP is usually the right call.
Court action becomes the better option in three situations. The first is where you also want monetary compensation – the UDRP simply cannot reach money, and US anticybersquatting litigation or equivalent national court routes can. The second is where the registrant is unknown or the evidence of how the domain moved is complex enough that discovery powers matter. Courts can order document production that a UDRP panel cannot. The third is where the current registrant has contested the domain in a jurisdiction-specific way that puts legal title squarely in dispute. In those cases, a UDRP panel will often defer to a pending court proceeding anyway.
We have advised on both routes and in some matters pursued both in parallel – a UDRP to move fast on transfer while a court action preserves the damages claim. That parallel-track strategy adds cost and coordination complexity, but for a high-value .group domain tied to an active brand, it is sometimes the correct answer.
To weigh UDRP against a court action for your case, email info@cognomenlaw.com.
Step 3: Satisfy the UDRP elements as applied to a theft scenario
A UDRP complaint must satisfy all three elements of Paragraph 4(a) of the Policy: the domain is identical or confusingly similar to a trademark or service mark in which the complainant has rights; the registrant has no rights or legitimate interests in the domain; and the domain was registered and is being used in bad faith. Theft cases fit this framework, but with a particular internal logic that differs from ordinary cybersquatting.
On element one, the identity or confusing similarity test is usually straightforward in a theft case because the domain is literally your own mark – you registered it precisely because it matched your brand. The evidence here is the same trademark registration, common-law use record, or trade identity documentation that you assembled in Step 2.
On element two, the absence of legitimate interest in the current registrant is typically established by showing they have no independent rights in the name, no prior use of it in connection with any offering, and no authorization from you to hold it.
Element three – registration and use in bad faith – is where theft cases sometimes get complicated. If the domain was originally registered in good faith by you, the UDRP's "registered in bad faith" limb applies to the current registrant's acquisition, not to the original registration date. Panels have consistently held that where a respondent obtains a domain through fraudulent transfer, the registration date for bad-faith purposes is the date of that unauthorized acquisition. The evidence of unauthorized transfer does the work here: it establishes both the fraudulent registration moment and the bad-faith use of retaining a domain known to belong to another party.
Step 4: File the complaint – and what the timeline actually looks like
Once the evidence record is assembled and the forum is selected, the complaint itself is a structured document: the complainant's trademark rights, the domain's registration history and transfer record, the argument on each element, and the remedies sought. WIPO and the Forum each have their own filing portals and procedural requirements.
After filing, WIPO conducts a compliance review. If the complaint is formally compliant, the case commences and the 20-day response window begins for the registrant of record. If no response is filed, the panel still evaluates the complaint on the merits – default is not automatic victory, but an unrebutted factual record is powerful. If a response is filed, both parties may have a further opportunity to submit supplemental materials, subject to the panel's discretion.
Panel appointment follows the response period. A single-member panel is the default; a three-member panel is available at higher cost and is appropriate for contested, high-value, or legally complex matters. A decision is then rendered and communicated to the parties and the registrar. Implementation – the actual transfer of the domain into the complainant's registrar account – follows automatically unless the losing party commences a court proceeding within ten business days of the decision.
In a matter we handled involving a new-gTLD domain (a .group domain used by a professional-services organization, summer 2025), the domain was locked at the registrar within 48 hours of our initial written notice, a UDRP complaint was filed within two weeks of the initial call, and a transfer order was issued approximately nine weeks after filing. The registrant of record did not respond. The access-log evidence we had preserved at the outset left no gap in the bad-faith record.
What evidence actually decides the outcome?
Panels hearing stolen-domain complaints look for a coherent, timestamped narrative of how the domain moved from the legitimate holder to the current registrant. The evidence that carries the most weight is the kind that neither side can credibly fabricate: registrar access logs tied to IP addresses outside your normal geography, account-modification records you never initiated, and prior domain-ownership documentation predating the dispute.
The evidence that panels discount is vague or self-serving: a complainant's assertion without documentation that "someone must have hacked the account", or a respondent's claim that they purchased the domain on the secondary market in good faith without any transfer paperwork. Panels have consistently held that a respondent who cannot produce documentation of a legitimate purchase when the complainant has produced clear evidence of unauthorized transfer does not benefit from good-faith purchaser status under the UDRP.
The myth that circulates among registrants is that registrar negligence defeats a UDRP complaint. It does not. Whether the registrar failed to verify the transfer request adequately is a matter for a separate claim against the registrar. Before the UDRP panel, the question is solely whether the current registrant satisfies the three Paragraph 4(a) elements. A panel cannot award damages against a registrar and will not defer a decision because a registrar acted carelessly.
COGNOMEN's approach is to build the evidence record in layers: the timestamped account logs first, the trademark or trade-identity documentation second, and the current registrant's absence of any legitimate connection third. Each layer corroborates the others, and that interlocking record is what produces a clean decision on all three elements.
Cross-zone considerations: when the same theft spans more than .group
Domain theft rarely stops at a single zone. A sophisticated attack will sweep an account that holds a .group domain, a corresponding .com, and possibly a ccTLD or two. The strategy for each zone differs, and a single UDRP complaint can cover multiple domains only if the registrant of record is the same holder across all of them. Where the thief has distributed the registrations, separate proceedings may be necessary.
For .com and other classic gTLDs, the UDRP at WIPO or the Forum is the standard path. For ccTLDs, the applicable national procedure governs: a .uk domain follows the Nominet DRS, a .eu domain follows the EURid/CAC procedure, and a .de domain requires the German courts with a DENIC DISPUTE entry to block transfer. For new gTLDs like .group, WIPO and the Forum handle the vast majority of proceedings. If theft spans zones, coordinate the filing timetable so that a registrar lock in one zone does not inadvertently trigger a challenge response in another.
Where the theft also involves account credentials that were used to access domains across multiple registrars, the remedies available in national court – particularly through US anticybersquatting litigation – may reach conduct that a zone-by-zone UDRP approach cannot. Courts can enjoin a respondent's conduct globally, not just domain by domain.
Related at COGNOMEN
Frequently asked questions
When should I recover a stolen .group domain?
Move immediately – within hours of discovering the unauthorized transfer, not days. Registrar access logs are typically retained for a limited period, and the ICANN transfer lock may already be expiring. The earlier a written preservation request reaches the registrar's compliance team, the stronger the evidentiary record. A UDRP filing can follow within a matter of weeks once the documentation is assembled, and the panel decision adds roughly two months to that timeline. Delay serves only the party holding the domain without authorization.
What happens if the other side ignores the case?
If the registrant of record does not file a response to a UDRP complaint within the 20-day window, the case proceeds on default. The panel reviews the complaint on the merits and, if the three Paragraph 4(a) elements are established by the complainant's record, will order transfer or cancellation. Default is not an automatic grant of the relief requested – the panel still evaluates the evidence – but an unrebutted, well-documented complaint has a strong factual foundation. In our practice, default cases with thorough account-compromise evidence typically produce clean transfer orders.
How is WIPO different from a national court for .group?
WIPO administers the UDRP, which is a mandatory, contractual arbitration procedure built into every .group registration agreement. A WIPO proceeding is typically faster – roughly two months – and cheaper than national court litigation, with a filing fee starting at USD 1,500 for a single-member panel. The trade-off is that the only remedies are transfer or cancellation: no damages, no costs, no injunction against the respondent's other conduct. A national court can award monetary compensation and order broader injunctive relief but takes longer and costs more. For straightforward theft recovery, WIPO is the standard first choice. For cases involving damages or complex factual discovery, court action is the necessary supplement.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.