Assess my case

How to recover a hijacked .ch domain after account compromise

How to recover a hijacked .ch domain after account compromise. UDRP and ccTLD domain recovery and defense across .ch. Email the firm to assess your case.

Your .ch domain has moved. The registrar account was accessed without your authority, a transfer request was pushed through, and the name now sits under a different registrant or a different registrar entirely. Every hour it points somewhere else, your Swiss customers see the wrong page – or your own brand working against you. Speed matters.

To recover a hijacked .ch domain after account compromise, the primary path runs through SWITCH, the .ch registry, combined with an immediate registrar escalation to freeze the chain of transfers. Where the registrar route stalls or the domain has already been re-registered to a third party, Swiss court action becomes the decisive tool. There is no UDRP for .ch – the governing procedure is determined by SWITCH's dispute-resolution rules and, where ownership must be litigated, the Swiss civil courts. The evidence that carries the case is the same in every route: proof of original registration, proof of unauthorized access, and a contemporaneous record of the compromise.

This page covers the SWITCH dispute route, the registrar-lock mechanics, when to escalate to Swiss court proceedings, what evidence decides the outcome, and how to protect a recovered name going forward.

Why .ch domains are different from .com: no UDRP, no standard arbitration

The UDRP does not apply to .ch. SWITCH, which manages the .ch country-code top-level domain under a mandate from the Swiss federal government, operates its own registration and dispute rules that differ in important ways from the generic domain arbitration system. This matters immediately when an account compromise occurs.

Under the SWITCH registration rules, a registrant who can demonstrate that a transfer was executed without its authorization can submit a formal dispute. The process is not a UDRP arbitration in the WIPO or Forum mold. It is a registry-level administrative procedure with its own timelines and evidentiary standards. Where that procedure cannot restore the domain – because a bad actor has already sold it onward, or because a court injunction is needed to freeze movement – Swiss civil litigation fills the gap.

We regularly advise brand owners and businesses that assume their .ch recovery will follow the same path as a .com recovery. It will not. The toolbox is different, and the opening move matters. A misrouted first filing can cost weeks while the domain changes hands again.

Compared with .com disputes, a .ch account-compromise case tends to move through a shorter administrative window at the registry level before a court filing becomes necessary. The practical consequence is that the paper you assemble in the first 48 hours often determines whether an administrative resolution is possible or whether you are going straight to a Swiss judge for interim relief.

For an assessment of your .ch domain dispute, contact info@cognomenlaw.com.

What governs a .ch domain dispute: SWITCH rules and the Swiss legal backdrop

SWITCH is the legal anchor. As the registry operator for .ch and .li, SWITCH sets the conditions under which domains can be registered, transferred, and challenged. Any recovery effort must engage SWITCH's published procedures from the outset – filing with the wrong forum first loses time and can prejudice the administrative record.

SWITCH's registration terms impose contractual obligations on registrars and registrants alike. A transfer executed through a compromised account breaches those terms because valid authorization was absent. That contractual breach is the foundation of both the administrative complaint and any civil claim.

The Swiss civil law backdrop matters when the administrative route is unavailable or insufficient. Swiss law recognizes both the contractual and the property-law dimensions of domain ownership. A registered domain holder has enforceable rights that a court can protect through interim measures – including a transfer freeze and a provisional order compelling the registrar to reverse the unauthorized move. The applicable national statutory framework for civil proceedings in Switzerland gives courts the authority to grant such measures urgently, without waiting for a full hearing on the merits, where the applicant can show a credible risk of irreparable harm.

One practical note: .ch disputes that reach the courts are handled by Swiss cantonal courts in the first instance, with the relevant venue depending on the registered seat of the parties or the registrar. Local litigation counsel in the relevant jurisdiction is required for Swiss court proceedings. COGNOMEN coordinates that relationship, assembles the domain-law record, and directs the strategy while local counsel handles the in-court procedural steps.

How does account compromise happen, and why does it matter for evidence?

Account compromise in the domain context usually takes one of three forms: credential theft through phishing, unauthorized access to the email account that controls registrar authentication, or a fraudulent support ticket submitted to the registrar impersonating the legitimate holder. Each leaves a different forensic trail – and that trail is the core of your recovery file.

Phishing attacks against domain account holders often exploit lookalike login pages or session-hijacking techniques. The attack leaves access logs, IP-address records, and sometimes device fingerprints in the registrar's system. Unauthorized email access leaves similar artifacts in the mail provider's audit trail. A fraudulent support ticket leaves a paper record with the registrar's own helpdesk.

Why does this matter legally? The SWITCH administrative process, and any subsequent Swiss court application, requires the claimant to show that the transfer was executed without valid authorization. Generic assertions are not enough. A forensic reconstruction – login timestamps that do not match the legitimate holder's usual access pattern, a transfer confirmation sent to a newly injected forwarding address, or a support ticket lodged from an IP in a jurisdiction where the registrant has never operated – is the evidence that tips the balance.

In our practice, the registrants who recover fastest are those who begin collecting and preserving this evidence within hours of discovering the compromise, not after a week of trying to resolve it informally with the registrar. We work with clients to identify exactly which records need to be requested, preserved under litigation hold, and presented in a form that both SWITCH and a Swiss court will accept.

The registrar escalation and transfer-reversal mechanics: what to do in the first 72 hours

The first practical step is not a legal filing. It is a registrar escalation. The moment an unauthorized transfer is identified, the legitimate registrant must contact the losing registrar – the one that processed the outgoing transfer – and invoke that registrar's abuse or dispute channel to request an immediate lock on further movement of the domain.

Most accredited registrars for .ch operate under SWITCH's rules, which require them to maintain transfer-reversal procedures for documented unauthorized transfers. The request must arrive quickly. Once a domain moves to a second registrar and then to a third party registrant, each hop adds a layer of complexity and reduces the practical window for an administrative reversal.

Parallel to the registrar escalation, the legitimate holder should file a formal dispute notification directly with SWITCH. This creates a registry-level flag on the domain and – critically – can trigger a domain lock that prevents any further transfers while the dispute is open. That lock is the equivalent of a standstill order. It buys the time needed to prepare the full evidential package and, if required, to seek interim relief from a Swiss court.

The escalation sequence, in practical order, is as follows. First, document everything: screenshots, email headers, access logs, account history. Second, contact the registrar's abuse channel in writing with a clear statement of unauthorized transfer and a request for an immediate domain lock. Third, notify SWITCH directly, in parallel, with the same documentation. Fourth, if the domain is already pointing to a live site causing active harm, consider whether an urgent court application for interim relief is warranted before the administrative process runs its course.

Do not wait for the registrar to acknowledge the first message before taking the next step. In our experience, running the registrar escalation and the SWITCH notification simultaneously produces the fastest result. Waiting sequentially hands time to the actor on the other side.

To plan recovery of a stolen or hijacked .ch domain, contact info@cognomenlaw.com.

When does a Swiss court action beat the administrative route?

The administrative route – SWITCH dispute procedure plus registrar escalation – works well when the unauthorized transfer has not yet been monetized and the domain is still held by the original bad actor. It is faster and cheaper than litigation. But there are specific situations where a court filing is not just preferable – it is the only viable path.

The first situation is a domain that has already been transferred to a bona fide third-party purchaser. If someone bought the domain for value without notice of the compromise, the administrative process may not reach that party directly. A Swiss court can, through a provisional measure, freeze the domain in the hands of the current holder while the ownership claim is litigated on the merits.

The second situation is a registrar that is unresponsive or located in a jurisdiction with weak enforcement mechanics. Where the current registrar has no meaningful incentive to comply with a SWITCH administrative request – and some domain theft operations deliberately route through less cooperative infrastructure – only a court order carries compulsory force.

The third situation is where the compromise has caused collateral harm: the domain was used to send phishing emails to your customers, or to redirect payments. In those cases, you may need both the domain back and a civil damages claim. An administrative procedure delivers neither damages nor an injunction against future harm. Only the courts do.

The decision between routes is not binary. In the most common scenario, we run the administrative track at full speed while preparing a court application in reserve. If SWITCH and the registrar deliver a lock and a reversal within the administrative window, the court filing never needs to be served. If they do not, the court file is already drafted and can be submitted without further delay.

Consider a recent matter: in early 2025, a Swiss-registered e-commerce business discovered its .ch domain had been transferred to a new registrar and was already redirecting traffic to a lookalike storefront. We escalated simultaneously to the losing registrar and SWITCH, securing a domain lock within approximately four business days. The lock allowed the court application – already prepared – to be filed as a precaution; it was not ultimately needed because the registrar reversed the transfer under SWITCH's procedure. The domain was restored to the legitimate holder in under three weeks from the date the compromise was first identified.

What evidence decides the outcome of a .ch domain recovery?

Evidence is the case. Whether the matter is resolved administratively at SWITCH, through registrar escalation, or in a Swiss court, the outcome turns on a single question: can the claimant demonstrate, with documentary proof, that the transfer was executed without the legitimate holder's authorization?

The core evidence package for a .ch domain recovery after account compromise typically includes the following categories.

One common gap is the absence of registrar-account access logs. Registrants frequently do not realize they can request these directly from the registrar under data protection frameworks applicable in Switzerland. We routinely submit those requests on clients' behalf, framed to capture exactly the forensic artifacts that establish unauthorized access.

The evidence standard under SWITCH's administrative process is not as demanding as the civil litigation standard on the merits – but it is not trivial. A bare assertion that "someone else changed my registrar details" is insufficient. The package must show the inconsistency between the legitimate holder's access pattern and the access that executed the transfer.

Cross-zone considerations: what if the hijacker also took your .com or .eu?

Domain hijacking operations rarely target a single zone. A coordinated compromise often sweeps a registrant's entire portfolio – the .ch, the .com, the .eu – in a single account breach. Each zone requires a separate recovery track, and the rules diverge sharply.

For a co-compromised .com, the UDRP is available if the domain has been transferred to a new registrant and is being used in bad faith – but account-compromise recovery for gTLDs more commonly runs through ICANN's registrar-accreditation obligations and, where necessary, US anticybersquatting litigation. The timeline for a UDRP complaint at WIPO is approximately two months, with a USD 1,500 filing fee for a single-member panel on a single domain. Account theft cases, however, often move faster through direct registrar escalation if the transfer was recent.

For a co-compromised .eu domain, the EURid / ADR.eu procedure applies. Like .ch, .eu has its own set of rules administered through the Czech Arbitration Court's ADR.eu platform. The .eu procedure allows a complaint based on a wider set of rights, but eligibility to hold .eu requires an EU or EEA nexus – and if the hijacked domain was already held in violation of that requirement, the recovery path bifurcates again.

The practical consequence for a registrant who has lost both a .ch and a .com in a single breach is that two parallel proceedings are almost always necessary. The .ch recovery does not automatically deliver the .com, and vice versa. We manage both tracks simultaneously, coordinating the evidence collection so that the forensic record built for one forum supports the other.

In a second recent matter – a .ch and .com dual-compromise discovered in spring 2025 – we ran the SWITCH administrative process and a UDRP complaint in parallel. The .ch returned through SWITCH's procedure in approximately three weeks; the .com required a full UDRP filing and was resolved roughly eight weeks after the complaint was submitted. No court action was required in either zone because the registrar-level locks held the domains stationary throughout.

Protecting a recovered .ch domain: preventing the next compromise

Recovery is the immediate task. Prevention is the lasting one. A domain recovered after account compromise that returns to the same registration environment – the same credentials, the same email account, the same registrar setup – is vulnerable to a repeat attack.

The structural defenses are well-established in the domain industry. At the registrar level: enable two-factor authentication on the registrar account, remove any secondary users who do not need access, and verify that the transfer-lock setting (sometimes called a registrar lock or domain lock) is active. A locked domain requires explicit authorization to transfer; many compromises succeed precisely because the lock was never set.

At the registry level: SWITCH provides a lock service for .ch and .li domains that prevents unauthorized transfers at the registry layer, separate from the registrar-level lock. This registry-level protection is underused. Activating it adds a second authorization step that an attacker who has breached only the registrar account cannot bypass.

At the email level: the registrar account's associated email address is frequently the weakest link. If that address is compromised, all registrar communications – including transfer-authorization emails – are visible to the attacker. A dedicated email address for domain management, held on a separate provider with its own strong authentication, materially reduces this exposure.

We also advise clients to implement portfolio monitoring after any recovery. A monitoring service tied to the domain's WHOIS data and DNS records generates an alert at the first sign of unauthorized change. In a hijacking scenario, an alert arriving within minutes of an unauthorized DNS change makes the difference between a same-day escalation and a three-day delay.

For registrants managing multiple zones – .ch plus a .com or .eu portfolio – we conduct a post-recovery audit of the entire portfolio: chain-of-title verification, lock status for each name, and a review of the administrative email addresses across all registrar accounts. The audit is not a precaution against a theoretical risk. It is a response to a demonstrated vulnerability.

Related at COGNOMEN

Frequently asked questions

What are the chances to recover a hijacked .ch domain after account compromise?

Recovery prospects are strongest when the domain has not yet moved beyond the original bad actor and when the legitimate holder acts within the first few days of discovering the breach. A well-documented compromise – with registrar access logs, email-account audit records, and a clear timeline – gives SWITCH's administrative procedure a solid factual basis. Where the domain has already passed to a third-party purchaser or the registrar is unresponsive, a Swiss court interim application becomes necessary. No outcome can be guaranteed; each case turns on the specific facts, the speed of the response, and the evidence available.

What evidence do I need to recover a hijacked .ch domain after account compromise?

The core package is: original registration records identifying you as the legitimate registrant; registrar-account access logs showing the unauthorized login or transfer request; email-account audit logs for the address tied to the registrar account; and a contemporaneous written record of when and how you discovered the compromise. Supporting business-nexus evidence – hosting records, DNS history, contracts identifying the domain – strengthens both the administrative claim and any civil damages claim. Gaps in the log record can often be filled by a formal data-access request to the registrar.

Can I recover a hijacked .ch domain after account compromise without going to court?

Yes, in many cases. The SWITCH administrative procedure, combined with a registrar-level escalation and an immediate domain-lock request, resolves a significant proportion of unauthorized-transfer cases without litigation. Court action becomes necessary when the domain has already been sold to a third party, when the registrar is unresponsive to an administrative request, or when the compromise has caused active ongoing harm that requires an injunction. We assess which route applies to your specific situation before any filing is made.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.