Assess my case

Step-by-step: recover a stolen .org domain

Step-by-step: recover a stolen .org domain. UDRP and ccTLD domain recovery and defense across .org. Email the firm to assess your case. Transparent fees, respo…

Your .org domain disappears overnight. The WHOIS record shows a stranger's name. The registrar's support queue is not moving. Every hour, your organization's email, donations page, or member portal points somewhere you did not choose. This is domain theft – and the window to reverse it is short.

Recovering a stolen .org domain requires moving through at least three distinct layers: immediate registrar escalation to freeze the name, a formal dispute or court filing to compel transfer, and a documented evidence record proving your prior ownership and the unauthorized nature of the transfer. For .org domains, ICANN's Transfer Policy provides a 60-day lock on outbound transfers in many circumstances, and WIPO administers UDRP proceedings against cybersquatters. Unauthorized account compromise – theft by credential hijack or registrar fraud – calls for a parallel registrar-escalation track before any arbitration is filed.

This guide walks each step in sequence, names the trap that hides in each one, and identifies when a court route overtakes arbitration as the faster or more effective path.

Step 1: Confirm the theft and stop the clock immediately

Before anything else, determine exactly what happened. Not every unexpected WHOIS change is theft. A lapsed payment, an expired authorization code, or a domain broker transfer you approved and forgot are each different problems requiring different responses.

Domain theft in the strict sense is an unauthorized transfer – someone changed the registrant record, moved the domain to a new registrar, or hijacked the underlying registrar account without your knowledge or consent. For .org, the registry operator is the Public Interest Registry (PIR), which follows ICANN's standard Transfer Policy. That policy imposes a 60-day inter-registrar transfer lock after any completed transfer, which cuts both ways: if the thief already moved the domain away, another transfer cannot happen for 60 days without special procedures, giving you a narrow but real window.

Within the first 24 to 48 hours, take these steps in parallel:

The trap in Step 1: many victims spend the first two days calling customer-support lines rather than filing written tickets with clear subject lines such as "URGENT: Unauthorized domain transfer – registrant verification required." A phone call leaves no audit trail. Written submissions do, and that record will matter in every proceeding that follows.

Step 2: Escalate through the registrar's internal channels – in writing

ICANN's Transfer Policy requires accredited registrars to follow a defined process when a registrant reports an unauthorized transfer. That process includes verification steps, a designated point of contact, and, in many cases, an obligation to initiate a dispute or reverse a transfer where clear evidence of fraud exists. The registrar's obligation does not guarantee a reversal, but it creates an enforceable procedure.

Contact both the losing and gaining registrar simultaneously. Your written submission should include:

  1. Your name and the exact domain name in the subject line of every message.
  2. The date range during which you last had confirmed control.
  3. Evidence of account compromise where available – phishing emails, password-reset confirmations you did not initiate, or unusual log-in notifications.
  4. A formal demand for the domain to be locked at the gaining registrar pending investigation.
  5. A copy of your ownership documentation.

Many registrars have an escalation path to their legal or compliance department separate from general support. Ask for it by name. If the registrar is an ICANN-accredited registrar (virtually all .org registrars are), you may file a Registrar Problem Report with ICANN's Contractual Compliance team if the registrar fails to respond within a reasonable period. This is not a dispute forum – it does not transfer the domain – but it documents non-compliance and occasionally accelerates registrar action.

The trap in Step 2: victims sometimes assume the registrar will act automatically once fraud is alleged. Registrars routinely respond that they cannot reverse a completed transfer without a formal legal or arbitration order. Know in advance that registrar escalation often buys time and freezes the domain rather than returning it. The formal proceeding in Step 3 is what actually forces a transfer back.

At this stage, the facts on the ground are still forming. To assess which formal route – UDRP, court order, or a combined strategy – fits your specific situation, contact info@cognomenlaw.com. We regularly advise domain owners in the hours immediately following a detected theft.

How does the UDRP apply to a stolen .org domain?

The UDRP applies to .org because .org is a gTLD administered by ICANN-accredited registrars, all of which incorporate the UDRP into their registration agreements. Stolen-domain cases, however, do not fit the UDRP's original design perfectly, and that mismatch is the single most important analytical step before you file.

The UDRP was built for cybersquatting: a bad actor registers a domain targeting a trademark owner. In a theft scenario, the bad actor did not register the domain at all – you did. The current registrant of record may be the thief, but the UDRP's three elements still apply: (1) the domain is identical or confusingly similar to a mark in which you have rights; (2) the respondent has no rights or legitimate interests; (3) the domain was registered and is being used in bad faith. The challenge is element three's cumulative test. Panels have debated whether a domain stolen from a legitimate owner meets the "registered in bad faith" limb when the original registration was entirely legitimate.

The emerging consensus view among UDRP panels is that where a respondent obtained a domain through fraud or identity theft and now holds it, the registration and use in bad faith requirement can be satisfied by the fraudulent acquisition itself. This view is not universal. A minority of panels has declined jurisdiction in pure theft cases, viewing them as ownership disputes beyond the UDRP's scope. That disagreement has a direct strategic implication: if the circumstances point toward a genuinely contested ownership question, a court action may be more reliable than UDRP arbitration.

For a straightforward credential-hijack case – where account compromise is well documented and the thief has no plausible claim to the name – WIPO is usually the faster route. WIPO administers the vast majority of .org UDRP proceedings. The WIPO filing fee for a single-member panel is USD 1,500 for up to five domains, and a standard case resolves in approximately two months. WIPO also offers an expedited option for single-panel cases of up to five domains that targets a decision within about one month.

The trap in Step 3: filing the UDRP without first confirming the panel-consensus position on your specific fact pattern. If the theft is ambiguous – contested by the registrar, disputed by the person now holding the domain, or complicated by a prior sale you cannot fully document – a UDRP loss leaves you worse off. It does not preclude court action, but it gives the opposing side a panel record to point to.

When does a court route beat UDRP arbitration?

The UDRP's only remedies are transfer or cancellation. No damages. No injunctions against the thief personally. No recovery of revenue generated while the domain was compromised. If any of those additional remedies matter to you, a court filing is not optional.

US anticybersquatting litigation is available in federal court and permits a complainant to seek damages as well as transfer. For an organization based in the United States whose .org domain serves a US audience, this route is worth a direct cost-benefit analysis against the UDRP. The UDRP is faster and less expensive; court is slower and more expensive but reaches money and personal liability. Where the thief is identifiable and demonstrably located within a US court's jurisdiction, the threat of a damages claim sometimes resolves the dispute before trial.

Outside the United States, local court action in the registrant's jurisdiction or the registry's jurisdiction may be available. For .org, PIR (the registry) is a US entity, which often means a US federal court has subject-matter jurisdiction even when the thief is abroad. For cross-border theft involving a thief in a jurisdiction without an effective legal process, the UDRP at WIPO is frequently the most practical available route.

A parallel strategy – filing UDRP to freeze and get the domain locked while court proceedings are prepared – is permissible under the Policy. The UDRP can be suspended once a court action is filed, and some complainants use a WIPO filing as a holding action to prevent further transfer while they build a damages case.

In a recent matter (a .org credential-hijack, spring 2025), we coordinated a UDRP filing at WIPO with a simultaneous registrar-compliance escalation for an organization whose nonprofit site had been redirected to a commercial solicitation page. The dual-track approach locked the domain within days of filing and produced a transfer order before the court track was needed. Each case is different; that outcome was specific to its facts.

If a prior filing or an initial registrar response produced a bad outcome, a focused second read of the evidence record can identify the element that was missed. Email info@cognomenlaw.com to discuss where the strategy stands.

What evidence decides whether you recover a stolen .org domain?

Evidence is where stolen-domain cases are won or lost. A clean, timestamped ownership record almost always wins. A fragmented record with gaps in renewal history gives the other side room to argue.

The evidence record for a .org theft case should contain the following categories:

The trap in Step 5: assuming that "everyone knows" you owned the domain is sufficient. Panels and courts work with the record before them. Missing evidence does not get filled in by common sense. We have seen otherwise strong cases narrowed significantly by a two-year gap in renewal documentation that the registrant could not explain.

What happens after the UDRP or court order – and can it go wrong?

A UDRP transfer order does not transfer the domain instantaneously. After a panel issues a decision, there is a 10-business-day implementation stay during which the respondent may file a court action to halt the transfer. If no court action is filed within that window, the registrar is obligated to implement the transfer. Implementation itself then takes additional days, depending on the registrar's processes.

A court order works differently. A federal court order directed at the registrar compels compliance, and the registrar has limited grounds for delay. In practice, implementation timelines under a court order can be faster than UDRP implementation where the registrar is in the same jurisdiction as the court.

After the domain is back in your control, the work is not finished. Change the registrar account password immediately. Enable two-factor authentication. Enable registrar lock (sometimes called domain lock or transfer lock) at the registry level. Audit the DNS records – a thief who held the domain may have added subdomains, modified MX records, or installed redirect rules that persist after the WHOIS record changes back to you. Review hosting and SSL certificate records for unauthorized changes.

In a recent matter (a .org domain used for a professional association's member portal, autumn 2024), the domain was returned via a transfer order in about eleven weeks from initial filing. Post-transfer, the DNS had been modified to include a secondary MX record routing a copy of inbound email to an external server. That record was discovered only during a post-recovery DNS audit. The association's IT team corrected it within hours of being notified. Had it gone undetected, member communications would have been intercepted.

How to choose between WIPO, the Forum, and court for your .org recovery

The decision among routes is a function of the fact pattern, the budget, and the remedy you need. Here is how to work through it in practice.

If the domain was taken by a stranger who is now using it to monetize traffic or to hold it for ransom, and your trademark or common-law rights in the name are clear, the UDRP at WIPO is usually the most cost-effective starting point. WIPO handles the large majority of .org disputes and its panelists are experienced with credential-hijack and unauthorized-transfer scenarios. The WIPO filing fee starts at USD 1,500 for a single-member panel. Legal fees for a straightforward single-domain UDRP complaint commonly fall in the USD 3,000 to USD 7,000 range in the market, separate from the forum fee.

If the facts are contested – the person holding the domain claims they purchased it from you, or the transfer was facilitated by someone inside your organization – the dispute is closer to a commercial ownership fight than a cybersquatting case. UDRP panels are reluctant to resolve genuine disputed-ownership questions. In that scenario, we generally advise moving directly to court.

The Forum (formerly the National Arbitration Forum) is a viable UDRP alternative for .org. Its filing fee begins at approximately USD 1,300 for one or two domains on a single-member panel. It handles a significant share of .org proceedings. The substantive law is the same – both forums apply the UDRP – but procedural differences in how supplemental filings and default responses are handled may influence forum selection in specific cases.

If you need damages, you need court. If you need speed above all else, you need WIPO's expedited option. If the case is strong on paper but the evidence record has a gap, you may need both – a UDRP to lock and transfer, and a parallel court track to recover losses. For domain theft that crosses borders, local litigation counsel in the relevant jurisdiction must be engaged alongside the UDRP or US court proceeding. We coordinate that engagement from the outset so that the two tracks are consistent, not contradictory.

Related at COGNOMEN

Frequently asked questions

What are the chances to recover a stolen .org domain?

Recovery prospects depend heavily on the quality of your ownership documentation and the clarity of the theft. Where account compromise is well evidenced – phishing logs, unauthorized password-reset notices, and unbroken renewal records – the outcome before a UDRP panel or a court is generally favorable. Where documentation has gaps or the circumstances suggest a contested sale rather than outright theft, the analysis is more fact-specific and the path may require court action rather than arbitration. No outcome can be guaranteed; panels and courts decide on the record before them.

What evidence do I need to recover a stolen .org domain?

The core evidence set is: original registration confirmation emails, continuous renewal receipts, DNS or hosting records showing ongoing control, evidence of unauthorized access (phishing emails, unexpected password-reset alerts), and pre-theft screenshots or archived pages showing the domain in legitimate use. Trademark registrations strengthen the rights element of a UDRP filing but are not required if common-law rights are established. Gaps in the renewal record are the most common vulnerability; address them proactively with whatever contemporaneous documentation is available.

Can I recover a stolen .org domain without going to court?

Yes, in many cases. The UDRP administered by WIPO is the standard route for .org domains and does not require court action. A registrar's internal transfer-reversal process may also produce a result without any formal proceeding where the theft is recent and the compromise is clear-cut. Court action becomes necessary when UDRP is unavailable or unsuitable – for example, in genuine disputed-ownership cases – or when you need damages in addition to domain recovery. The right route depends on the specific facts of the theft.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.