Assess my case

Step-by-step: recover a stolen .info domain

Step-by-step: recover a stolen .info domain. UDRP and ccTLD domain recovery and defense across .info. Email the firm to assess your case. Transparent fees, res…

Your .info domain goes dark overnight. The registrar account password stopped working at 3 a.m., the WHOIS record now shows a stranger's name, and there is a buy-back demand in your inbox before you have had your first coffee. Domain theft – account compromise followed by an unauthorized transfer – is not a hypothetical. It happens to .info registrants who hold commercially valuable names, and the recovery window closes faster than most owners expect.

To recover a stolen .info domain you must work two tracks simultaneously: a registrar-level lock and transfer-reversal request pursued within hours of discovering the theft, and a parallel legal remedy – typically a UDRP complaint filed with WIPO or the Forum, where the UDRP's three elements under Paragraph 4(a) must be satisfied, or in some circumstances a court action where arbitration cannot reach the conduct. The WIPO filing fee for a single .info domain is USD 1,500 for a single-member panel. Every hour of delay reduces the probability of a clean reversal.

This guide walks each step, names the trap hidden in it, and explains what evidence decides the outcome.

Step 1: What applies to .info – and why it matters immediately

.info is a generic top-level domain (gTLD) fully subject to the UDRP and administered through ICANN-accredited registrars. That is the good news. WIPO, the Forum, and the Czech Arbitration Court (CAC) all accept complaints involving .info domains, and the same three-element test that governs .com disputes governs yours. The WIPO filing fee for a single-domain complaint, single-member panel, is USD 1,500 – identical to a .com dispute. The mechanism is standardized.

The trap in Step 1: registrants sometimes assume that because .info is a gTLD, the theft is automatically easier to reverse than a ccTLD theft. It is not. The speed of the registrar's escrow of the domain – called a transfer lock or registrar lock – is entirely dependent on how fast you notify the losing registrar. Some registrars respond within hours; others require formal abuse reports before initiating any hold. Knowing the losing registrar's escalation path before you call customer support is not a detail. It is the difference between a 24-hour hold and a secondary transfer that puts the domain out of reach for weeks.

The other variable: if the theft involved a privacy service obscuring the registrant record, the WHOIS or RDDS data you pull immediately after discovering the theft is the most useful snapshot you will have. That data changes fast once the hijacker learns you are aware. Pull it now and preserve it with timestamps.

Step 2: How do you lock down the domain within the first 24 hours?

Stopping the clock on further transfers is the first concrete action, and the first 24 hours determine whether you preserve a clean reversal path. Most gTLD registrars impose a 60-day lock after any registrant-initiated transfer – but a hijacker who initiates a second transfer before you file an abuse report can defeat that lock. Your immediate actions, in sequence, are:

  1. Document the compromise. Screenshot every warning email, password-reset request, phishing attempt, and the current WHOIS record. Note exact timestamps in UTC.
  2. Contact the losing registrar's abuse or security desk – not the standard support queue – and request an emergency transfer lock under ICANN's transfer policy. Use the word "unauthorized transfer" explicitly; it triggers a different internal workflow at most registrars.
  3. Contact the gaining registrar (identified from the live WHOIS) and submit a parallel abuse report. Request that the domain be placed on hold pending investigation.
  4. If both registrars are unresponsive within four hours, escalate to ICANN's Contractual Compliance function. File an informal complaint. The act of filing creates a record that matters later.
  5. Preserve the compromised account evidence: authentication logs, session tokens if you have access to them, and any two-factor-authentication bypass indicators.

The trap in Step 2: many registrants skip the gaining registrar step because it feels confrontational or futile. It is neither. The gaining registrar has its own ICANN obligations regarding unauthorized transfers. A formal abuse report puts them on constructive notice. If you later file a UDRP complaint and the domain has been further transferred again after your report, that conduct is powerful evidence of bad faith under Paragraph 4(b).

In our practice, we have handled matters where the losing registrar imposed a hold within six hours of a properly worded abuse report and the domain was reversed through the registrar channel alone – no UDRP required. Those cases are the exception. Do not plan for the exception.

Step 3: Is the UDRP the right legal route, or does a court action fit better?

Choosing the legal route is not a simple question. The UDRP is designed for cybersquatting disputes, not account compromises – and that distinction shapes which facts the panel will weigh most heavily. Under Paragraph 4(a) of the UDRP, you must still prove all three elements: confusing similarity to a mark you hold, no legitimate interest by the current registrant, and registration and use in bad faith. In a pure theft scenario, elements two and three are usually straightforward. Element one – trademark rights – is where the trap hides.

What if your .info domain is a descriptive term, a surname, or a phrase for which you hold no registered trademark? Panels have consistently held that common law or unregistered rights can satisfy element one, but the evidentiary burden is higher. You need proof of use in commerce, consumer recognition, and secondary meaning. If your evidence of those rights is thin, a UDRP complaint carries meaningful risk of denial – and a denial does not bar future litigation, but it is a wasted filing fee and, more importantly, a wasted six to eight weeks.

The decision matrix runs like this. If you hold a registered trademark and the domain is confusingly similar, the UDRP at WIPO or the Forum is usually the fastest and most cost-efficient route: a standard case resolves in roughly two months, and the filing fee is known in advance. If you hold no registered mark, or if the theft involved wire fraud, identity impersonation, or computer-intrusion conduct that you want a court to address with injunctive or monetary relief, a court action is the stronger path. Courts can award damages under applicable anticybersquatting legislation and can compel registrar compliance in ways an arbitral panel cannot. The trade-off is substantially greater cost and time. We coordinate with local litigation counsel in the relevant jurisdiction when court action is necessary.

A third scenario: both. We have run a registrar escalation in parallel with a UDRP filing, with a court action held in reserve pending the arbitral outcome. That approach demands precise sequencing – a pending court case can complicate a UDRP proceeding if the panel treats it as an attempt to use parallel process strategically. The sequence should be designed by counsel before any filing, not assembled reactively.

For a read on whether the three UDRP elements are met in your .info theft scenario, reach us at info@cognomenlaw.com. We assess the trademark evidence and the registrar record before recommending a route.

Step 4: What evidence actually decides the outcome?

Evidence of compromise is the core of any .info domain theft recovery. A panel or court deciding this type of case is not asking only whether the domain was registered in bad faith in the abstract – it is asking whether the current holder has any colorable legitimate claim. That question is answered by the chain of custody, not by rhetoric.

The evidence that matters most, ranked by practical impact:

The trap in Step 4: registrants often submit what they have, rather than building the evidentiary record strategically before filing. A panel has no discovery power. What you submit in the complaint is what you get. Missing evidence cannot usually be introduced later, except in narrow supplemental-filing scenarios where the panel exercises discretion to admit it. Compile the full record before you file.

In a recent matter – a .info theft, spring 2025, involving a registrant who had held the name for nearly a decade – we reconstructed the compromise timeline from archived WHOIS snapshots, the client's email headers, and the registrar's authentication log. The current holder had parked the domain and sent a five-figure buy-back demand within 48 hours of the transfer. The panel found bad faith on all four Paragraph 4(b) factors and ordered the transfer.

Step 5: How do you file the UDRP complaint without triggering common procedural traps?

A UDRP complaint is a formatted legal document filed through the forum's electronic submission system. WIPO's eComplaint platform is the dominant venue: it accepts .info complaints, generates a case reference immediately on submission, and notifies the current registrant within days of commencement. The response window – 20 days from commencement – begins automatically. If the current holder does not respond, the panel decides on the complainant's submissions alone, and panels generally treat default as consistent with a finding of bad faith, though they still verify the three elements independently.

The procedural traps worth naming explicitly:

The trap in Step 5 that we see most often: a registrant or brand owner files the complaint the same day they discover the theft, before the registrar escalation has run its course. The two tracks are not mutually exclusive, but filing a UDRP before exhausting the registrar channel means you are spending USD 1,500 on a proceeding that might have been unnecessary. Run the registrar escalation first, in parallel where the timeline demands it, but give the abuse report at least 48 hours before treating it as failed.

If a registrar escalation has stalled or you have already received a rejection, email info@cognomenlaw.com to assess whether a UDRP complaint or a court filing is the appropriate next step.

Step 6: What happens after the decision – and what can go wrong at implementation?

A UDRP transfer order is not self-executing. The panel issues a decision; WIPO notifies the registrar; the registrar then implements the transfer after a mandatory waiting period – typically ten business days – during which either party can initiate a court proceeding in the jurisdiction specified in the registration agreement to stay the transfer. If the losing party (the hijacker) files a court case in those ten days, the transfer is suspended until that litigation resolves.

In practice, hijackers rarely litigate to preserve a stolen domain. The stay mechanism is almost never invoked in theft cases. But "almost never" is not never. We have seen scenarios where a hijacker, having received a notice of the UDRP transfer order, immediately transferred the domain to a third party in a jurisdiction with weak enforcement. If the transfer was made after WIPO notified the registrar, the registrar should refuse to process it and should implement the original order. Whether the registrar actually does so depends on its internal compliance procedures. Follow up directly with the registrar's transfer team, in writing, after the decision issues.

The trap in Step 6: the client treats the decision as the end. It is not. Monitor the WHOIS record daily from the date of the decision until you confirm that the domain has been transferred back to an account you control. If the transfer has not occurred within 15 business days of the decision, contact both the registrar and the forum. An unimplemented transfer order is a procedural anomaly that the forum will address – but only if you report it promptly.

For matters where the registrar is unresponsive to an implementation request, or where the domain is held at a registrar in a jurisdiction with weak ICANN oversight, a court order may be necessary to compel compliance. That is the scenario in which a court action is not an alternative to the UDRP but a sequel to it. We coordinate that escalation with local litigation counsel in the relevant jurisdiction when the registrar is beyond reach through ICANN's compliance process alone.

Step 7: What is the realistic timeline and cost from discovery to recovery?

Setting realistic expectations is part of the work. The timeline for a .info theft recovery depends on which track succeeds first.

Registrar channel alone, if it works: resolution in 48 to 72 hours from a well-executed abuse report. Cost: your time and the cost of counsel to draft the escalation letters. This is the fastest scenario and the one worth pursuing in every case before moving to the next track.

UDRP channel: from filing to decision, a standard single-panel WIPO case runs roughly two months. Add the WIPO filing fee of USD 1,500 and legal preparation costs that, for a well-documented single-domain matter, typically fall in a market range comparable to what a competent specialist charges for a straightforward gTLD complaint – a figure that is always separate from the forum fee. Then add the ten-business-day implementation window. Total elapsed time from filing to domain back in your account: typically ten to twelve weeks in the ordinary case.

Court action: substantially longer and more expensive. The appropriate use of a court route is when the UDRP cannot reach the conduct – account compromise with no trademark rights, a registrar refusing to comply with arbitral orders, or a theft involving provable fraud for which you want monetary relief. Describe the costs of this route qualitatively: they are jurisdiction- and fact-dependent, and no range number is honest without knowing the specific forum and the contested issues.

A practical note on cost-benefit: a .info domain's recovery is worth pursuing if the domain has commercial value – a branded term, a significant SEO history, an established audience. For a domain with minimal traffic and no trademark connection, a UDRP filing at USD 1,500 plus legal fees is a rational investment only if recovery would produce a clear commercial benefit. We assess that question directly in our initial consultations. We do not recommend a filing that the facts do not support.

Related at COGNOMEN

Frequently asked questions: recover a stolen .info domain

Is it worth it to recover a stolen .info domain?

Recovery is worth pursuing when the domain has demonstrable commercial value – an established brand, meaningful traffic history, or significant SEO equity. The UDRP filing fee at WIPO starts at USD 1,500 for a single domain, and legal preparation adds to that. For domains with marginal commercial value and no trademark connection, the cost-benefit calculation is less clear. A pre-filing assessment of the trademark rights, the domain's value, and the strength of the bad-faith evidence helps decide whether to proceed and through which route.

What are the most common mistakes when you recover a stolen .info domain?

The three most consistent errors we see are: failing to contact the gaining registrar immediately after the theft (not only the losing registrar); filing a UDRP complaint before compiling a complete evidentiary record, since panels have no discovery power; and treating a UDRP transfer order as self-executing without monitoring registrar implementation. A fourth error – less common but more damaging – is filing a complaint where trademark rights are unestablished, producing a denial that weakens the subsequent litigation position.

Can a three-member panel change the outcome?

It can. A three-member panel introduces two additional panelists into the deliberation, which tends to favor complainants with strong but legally nuanced records and respondents who have a credible legitimate-interest defense. For a clear theft case with solid trademark evidence and documented compromise, a single-member panel is usually sufficient. Where the trademark rights are contested, the registration history is ambiguous, or the case turns on a close call about bad faith, the additional scrutiny of a three-member panel – and the precedent value of a reasoned panel majority decision – can justify the higher WIPO fee of USD 4,000.

About COGNOMEN

COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. Our practice covers domain theft and account compromise recovery across gTLDs including .info, with the registrar escalation, UDRP filing, and court coordination that each case demands. To discuss a domain, contact info@cognomenlaw.com.

By Adrian Harland – domain theft recovery and court anticybersquatting practice.

Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.