Step-by-step: reverse an unauthorized transfer of a .group domain
Step-by-step: reverse an unauthorized transfer of a .group domain. UDRP and ccTLD domain recovery and defense across .group. Email the firm to assess your case.
A domain registrant logs in one morning to find their .group domain gone — transferred to a stranger without authorization, often within hours of a credential compromise. The registration history shows a new registrant, a new registrar, and a chain of WHOIS changes they never requested. Time matters immediately. The transfer-reversal window under ICANN's Inter-Registrar Transfer Policy is narrow, and inaction during those first hours forfeits the most powerful procedural tools available.
To reverse an unauthorized transfer of a .group domain, the legitimate registrant must act on three fronts in sequence: escalate with both registrars under ICANN's transfer-dispute procedure, build an evidence record documenting the account compromise, and — if registrar escalation fails — pursue a UDRP complaint before WIPO or file a court action where arbitration cannot compel the remedy. Speed and documentary proof decide the outcome; no route offers a guarantee, but registrants who act within the first 20 days consistently preserve more options.
This guide walks each step, names the trap inside it, and maps the realistic choice among registrar escalation, UDRP, and court.
What governs unauthorized transfers of .group domains?
The .group top-level domain is an ICANN-accredited new generic TLD. Its registrar agreements incorporate ICANN's Transfer Policy and, critically, the Uniform Domain-Name Dispute-Resolution Policy (UDRP) applies to .group domains — meaning WIPO, the Forum, and the Czech Arbitration Court (CAC) all have jurisdiction over .group disputes. That procedural reach is a significant asset for a victim of theft: unlike most ccTLDs, you have access to the full UDRP toolkit without needing a national court order to compel a registrar abroad.
ICANN's Transfer Policy sets a 60-day lock on transfers after a domain is registered or updated, but a compromised account can bypass that lock through technical manipulation of the registrar's own transfer-approval workflow. The policy also provides a "transfer dispute resolution" path for registrar-to-registrar disagreements. Understanding which rule applies — and where — determines whether you open with a registrar ticket, a UDRP complaint, or a court filing.
The trap at this step: many victims assume "UDRP" is the only route. In fact, for a domain theft (as distinct from cybersquatting), ICANN's registrar-level process and direct court action are often faster and more targeted. UDRP is best used when the theft has produced a re-registration under a new account that the original registrar cannot claw back on its own authority.
Step 1: Secure your accounts immediately — and document everything
Before filing anything, lock down the accounts the attacker used. Reset passwords, revoke active sessions, and enable multi-factor authentication on both the registrar account and any associated email address. This is not merely a security measure. It is evidence-preservation. A registrar's transfer-dispute team will want proof that the original registrant controlled the account before the breach and that the compromised transfer was unauthorized.
Gather the following within the first 24 hours:
- Screenshots of the RDDS (WHOIS) record before and after the unauthorized transfer, with timestamps.
- Your registrar's account-access logs, showing the IP addresses and timestamps of the unauthorized login or transfer-approval event.
- Email communications from the registrar confirming the transfer request — even if you never sent them.
- Any phishing messages, credential-theft notices, or linked account-compromise alerts from your email provider.
- Proof of your original registration: the original registration confirmation email, invoice, or registrar dashboard screenshot showing you as registrant at least through the day before the theft.
The trap at this step: victims often wait for the registrar to contact them and lose the account-access logs, which many registrars purge within days. Request the logs in writing — by email, creating a paper trail — within the first few hours. Describe the event explicitly: "an unauthorized transfer that I did not authorize," not merely "a problem with my account."
Step 2: File an Inter-Registrar Transfer dispute with the losing registrar
ICANN's Transfer Policy requires registrars to have a dispute process for unauthorized transfers. Contact your original (losing) registrar immediately and formally dispute the transfer. Most registrars have a designated abuse or legal team for this purpose. Your written dispute should state: (1) the domain name; (2) the date and time of the transfer; (3) the fact that you did not authorize it; and (4) a request for an immediate registrar lock pending investigation.
The losing registrar can, in some cases, initiate a "Transfer Emergency Action Contact" (TEAC) request to the gaining registrar to suspend or reverse the transfer. This is the fastest administrative path and costs nothing beyond the time to write the request. If the gaining registrar cooperates — which ICANN's agreements encourage — the domain may be returned within days, before any formal proceeding is needed.
The trap at this step: some registrars treat this as a standard support ticket. Escalate immediately to the abuse team, reference ICANN's Transfer Policy explicitly, and send the request by email to create an auditable chain. If you receive no substantive response within 48 hours, move to the next step without waiting for resolution. You can pursue both registrar escalation and formal proceedings simultaneously.
If the registrar's abuse team has not responded with a substantive hold or reversal within 48 hours, the procedural clock is running against you. To assess the fastest route — registrar escalation, UDRP, or court — email info@cognomenlaw.com.
Step 3: Assess whether UDRP or court action is the right escalation path
If registrar-level escalation fails or moves too slowly, you face a fork: file a UDRP complaint before an accredited provider (WIPO being the dominant choice), or initiate court proceedings in the relevant jurisdiction. Each route has a distinct profile, and the right choice depends on what the attacker has done with the domain since the transfer.
The UDRP route applies when the current registrant — the person who received the stolen domain — is using or holding it in a way that satisfies Paragraph 4(a) of the Policy: (1) the domain is identical or confusingly similar to a trademark you hold; (2) the new registrant has no rights or legitimate interests; and (3) the domain was registered (or re-registered) and is being used in bad faith. For a theft victim who also holds a trademark in the domain name, this three-part test is often met. The WIPO filing fee is USD 1,500 for a single-member panel covering up to five domains, and a standard case resolves in approximately two months. The only remedies are transfer or cancellation — no damages, no cost awards.
The court route applies when the UDRP's limits matter: you need damages, you need injunctive relief that a registrar will not voluntarily honor without a court order, or the bad-faith element cannot be cleanly established (perhaps the thief transferred the domain onward to an apparent third-party buyer). US anticybersquatting litigation is the principal court mechanism for .com and new gTLD disputes involving US parties, and it can reach monetary recovery — something the UDRP cannot. For non-US parties, local litigation counsel in the relevant jurisdiction may pursue equivalent national routes.
A worked example. In a matter handled in early 2025, a .group domain belonging to a professional services network was transferred to an overseas account through a compromised registrar session. The new registrant had already listed the domain for sale at a five-figure price. Because the legitimate registrant held a registered trademark in the domain name, the UDRP bad-faith element was straightforwardly met: offering the domain for sale at a price exceeding out-of-pocket registration costs, to the party with trademark rights, is a Paragraph 4(b) factor. A WIPO complaint filed within ten days of discovering the theft resulted in a transfer order.
The trap at this step: choosing court immediately because it feels more powerful. Court proceedings are slower and far more expensive than UDRP. For a .group domain where the trademark element is solid and the thief is holding (not yet monetizing) the domain, UDRP is usually the faster, lower-cost path to recovery. But if the domain has already been re-sold to a third party who may claim clean-hands status, or if you need damages, court action is where the case has to go.
How do I choose between WIPO and the Forum for a .group UDRP complaint?
WIPO and the Forum both accept .group UDRP complaints, and the substantive outcome does not depend on forum choice — the same Policy applies in both. The practical differences are cost, speed, and panel pool. WIPO's filing fee is USD 1,500 for a single-member panel (up to five domains); the Forum's fee begins around USD 1,300 for one to two domains, also single-member. WIPO's caseload — in 2025 it administered approximately 6,282 domain-name cases — supports the largest available pool of experienced panelists. In our practice, we file the majority of urgent single-domain theft cases at WIPO for that reason, and because WIPO offers an expedited option that can deliver a decision within about one month for eligible single-panel cases of up to five domains.
CAC (Czech Arbitration Court) is the lowest-cost accredited provider, with entry fees beginning around USD 500–800. For a straightforward .group theft case where cost is the primary constraint, CAC is a legitimate option. It is the least-used of the four accredited providers and carries a smaller panelist pool — a factor worth weighing against the fee saving.
The trap at this step: some registrants file with CAC on cost grounds and discover that a less-developed panelist pool produces less predictable outcomes in nuanced theft cases. If the facts are clean and the trademark-rights element is strong, the forum matters less. If the case involves complexity — passive holding, a re-sold domain, or ambiguous bad faith — WIPO's depth of precedent is worth the additional filing fee.
Step 4: Build the evidence record that decides the UDRP outcome
A UDRP complaint in a domain-theft context is won or lost on documentary evidence. The three-panel elements — rights, no legitimate interest, bad faith — each require specific proof, and the theft context adds a fourth layer: you must show the transfer itself was unauthorized. Panels have consistently held that a registrant who cannot document original registration and continuous control faces an uphill challenge, even in a clear theft scenario.
For the rights element, gather: your trademark registration certificate (any jurisdiction), first-use evidence if relying on common-law marks, or domain registration confirmations predating the dispute for a descriptive-mark argument.
For the legitimate-interest element, the attacker bears no burden — that burden shifts to the complainant to make a prima facie case. Document that the new registrant (the thief or the buyer) has no known business or identity connected to the domain name, holds no trademark in it, and has not used it for a bona fide purpose before notice of the dispute.
For bad faith, the most useful evidence in a theft scenario is: (a) the registrant offering the domain for sale at a price exceeding registration costs; (b) RDDS changes showing the domain was redirected to a pay-per-click parking page immediately after transfer; (c) the speed of the transfer — domains transferred within minutes or hours of a login event strongly suggest automated or scripted theft; and (d) the registrant's identity or location being obscured through privacy services activated immediately after transfer.
A second matter illustrates the evidence gap that kills otherwise strong cases. In a .group theft resolved in autumn 2025, the legitimate registrant had held the domain for several years but could not produce the original registration confirmation email — the relevant inbox had been deleted. Without clear proof of original registration date, the panel had to rely on secondary evidence: the historical RDDS archive and a hosting provider invoice. The complaint succeeded, but the evidential gap extended the timeline. Keep every registrar communication archived.
The trap at this step: assuming the panel will take judicial notice of "obvious" facts. Panels work from the filed record. If you do not submit it, they do not consider it. A well-organized complaint exhibits an evidence file that a panelist can work through in under an hour.
If a prior registrar ticket or informal dispute produced no result, a structured second review of the evidence record can identify the element that was missed. For a read on whether the three UDRP elements are met for your .group domain, reach us at info@cognomenlaw.com.
Step 5: File, monitor, and prepare for the registrar implementation stage
Once the complaint is filed and formally commenced, the respondent has 20 days to file a response. A thief often defaults — no response filed — and a default does not automatically guarantee a transfer, but panels do draw adverse inferences from it. If the respondent defaults, the panel proceeds on the complaint's record alone. A well-prepared complaint means the record is complete without needing a reply.
After the panel issues a decision ordering transfer, the implementation stage can introduce one more delay. The registrar has a standard implementation window under the UDRP Rules, typically around ten business days, during which the losing registrant can seek a court stay of implementation. That stay request is rare, but in theft cases — particularly where the thief has transferred the domain to a second party who may contest the panel's reach — it is worth anticipating. File your complaint in a way that documents the full transfer chain so the registrar's compliance team has clear authority to act.
The trap at this step: the domain is transferred to COGNOMEN's client account by the registrar to whom it was moved, not necessarily to the registrar the client originally used. Confirm in advance with your preferred registrar that they can accept an inbound UDRP-mandated transfer for a .group domain, and have your account credentials ready.
What to do when arbitration cannot reach the remedy you need
UDRP and registrar escalation cover most .group theft scenarios. But there are situations where neither is enough. If the domain has been re-sold multiple times and a downstream buyer claims good-faith purchase without knowledge of the theft, a UDRP panel may decline to order transfer — a panel's reach extends only to the named respondent. If you need monetary damages for business interruption, revenue diverted through a fraudulent landing page, or reputational harm, the UDRP cannot provide them. Those cases belong in court.
For US-based disputes, US anticybersquatting litigation is the named route. It can compel registrar compliance with a court order even across registrar changes, and it allows damages and attorney's fee awards that the UDRP explicitly excludes. For disputes involving parties in other jurisdictions, local litigation counsel in the relevant jurisdiction handles the equivalent national procedure. In either case, the DENIC DISPUTE analogue — where available under the applicable ccTLD rules — can block re-transfer of the domain while litigation proceeds, preserving the asset during what may be a longer proceeding.
The decision matrix in practice: if the domain is held by the original thief, the trademark element is clear, and you want it back quickly → UDRP at WIPO is the default. If the domain has been re-sold to a second buyer who may claim innocence → court action, possibly with an emergency injunction request, is the safer path even if slower. If you need damages in addition to recovery → court is the only route. If the domain value is modest and speed matters more than precision → registrar escalation alone, pushed hard, can sometimes produce a voluntary reversal within days at no filing cost.
We regularly advise registrants and brand owners who face exactly this fork. The choice between UDRP and court is not always obvious from the outside, and choosing the wrong path early can forfeit time that the other path needed.
Related at COGNOMEN
Frequently asked questions
What are the chances to reverse an unauthorized transfer of a .group domain?
No outcome can be guaranteed — every case turns on the specific facts, the evidence available, and the procedural path chosen. That said, registrants who act quickly (within the first 48 to 72 hours), who can document their original registration and account compromise clearly, and who hold a trademark in the domain name are in a substantially stronger position. UDRP panels have consistently ordered transfer in theft cases where all three elements of Paragraph 4(a) are met on a solid evidential record. Registrant defaults — where the thief files no response — allow the panel to draw adverse inferences from the complaint alone.
What evidence do I need to reverse an unauthorized transfer of a .group domain?
The core evidence record has five components: proof of your original registration (confirmation email, invoice, or dashboard screenshot); account-access logs from the registrar showing the unauthorized session or transfer-approval event; timestamped RDDS records before and after the transfer; your trademark registration or, for common-law claims, first-use evidence; and documentation of the new registrant's conduct — sale listings, PPC parking, or immediate privacy-service activation. Panels work from the filed record only. Evidence that is not submitted is evidence that does not exist for the panel's purposes.
Can I reverse an unauthorized transfer of a .group domain without going to court?
In most cases, yes. Registrar-level escalation under ICANN's Transfer Policy is the first step and costs nothing beyond the time to write the request. If escalation fails, a UDRP complaint before WIPO or the Forum can compel a transfer order without court involvement, at a filing fee of USD 1,500 (WIPO, single-member panel) and typically within about two months. Court action is necessary when the domain has been re-sold to an apparent good-faith buyer, when damages are sought, or when registrars will not comply without a judicial order.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.