How to recover a hijacked .info domain after account compromise
How to recover a hijacked .info domain after account compromise. UDRP and ccTLD domain recovery and defense across .info. Email the firm to assess your case.
Your .info domain disappears overnight. The registrar account is accessed by someone else, the DNS is redirected, and the WHOIS record now names a stranger as the registrant. The clock is running. Every hour the domain stays in the wrong hands, your site traffic, your email, and your brand's credibility route somewhere else.
To recover a hijacked .info domain after account compromise, the fastest first move is a registrar escalation to freeze the domain under a registrar lock – stopping any further transfer while you document the breach. Where that fails, WIPO administers the UDRP for .info, giving you a formal arbitration route with a standard filing fee of USD 1,500 for a single-member panel. Where the theft involved fraud or the registrant is unresponsive, a court action for anticybersquatting or conversion may reach further than arbitration alone.
This page covers the registrar mechanics, the UDRP process at WIPO for .info, the evidence that decides the outcome, the cross-route decision, and how we approach each stage.
Why .info domain hijacking is a distinct problem
.info is an open, unrestricted generic top-level domain (gTLD) administered under the ICANN policy framework. That means all three UDRP elements of Paragraph 4(a) – similarity to a mark, no legitimate interest, and registered-and-used in bad faith – apply in full, just as they do for .com. The distinction from a standard cybersquatting complaint is what happened first: the domain was legitimately yours, then it was taken through account compromise rather than third-party registration.
That distinction matters in two ways. First, the UDRP was designed for recovery from third-party bad-faith registrants, not originally for theft disputes. Second, the registrar's own transfer procedures – the rules governing inter-registrar transfers, the lock periods, and the abuse-escalation paths – become the first and often the fastest line of recovery. A hijacking case therefore runs on two tracks simultaneously: the registrar track and the dispute-resolution or court track.
What is the threat that makes this urgent? The hijacker's objective is usually to monetize the domain quickly – through pay-per-click parking, a fraudulent storefront, or a fast resale on the secondary market. Once a .info domain transfers to a new registrar in a jurisdiction with weaker records, the chain of title evidence degrades. Speed at the registrar level is not optional.
What should you do in the first 48 hours after a .info domain is hijacked?
The first 48 hours determine whether registrar-level recovery is even possible. Act on these steps in sequence, and document every action with timestamps.
- Secure the underlying email account. Most .info domain hijacks begin with a compromised email address – the one associated with the registrar account. Reset credentials, enable multi-factor authentication, and preserve access logs showing unauthorized entry. This evidence will be central to every downstream proceeding.
- Contact the losing registrar's abuse team immediately. File a formal abuse report identifying the domain name, the account holder, the date of compromise, and the unauthorized transfer. Request an emergency registrar lock on the domain and a WHOIS history pull.
- Request a registrar lock and domain freeze. Under ICANN's transfer policy, registrars have authority to place a Registrar-Lock (clientTransferProhibited) status on a domain. If the domain has already moved to a gaining registrar, contact that registrar's abuse team and invoke ICANN's 2013 Transfer Policy – particularly the provisions on unauthorized transfers – to request a return.
- Preserve all evidence of ownership. Pull purchase receipts, renewal invoices, WHOIS records from before the compromise, DNS zone files, hosting account records, and any correspondence. This record of prior ownership is what distinguishes your case from a simple UDRP complaint.
- Assess whether the hijacker has registered the domain in a new name. If the WHOIS now shows a new registrant, that party is the respondent in any UDRP or court proceeding. Identify the registrar, the nameservers, and what the domain now resolves to.
In our practice, we have seen cases where a client's registrar-level escalation, submitted within hours of discovery, resulted in the registrar placing a hold before any further transfer occurred. That outcome is not guaranteed – registrars vary significantly in their abuse-response speed – but the window closes fast.
If your .info domain was taken through account compromise, the assessment of which recovery route fits your specific facts is the first thing to get right. Contact info@cognomenlaw.com to begin.
How does the UDRP work for .info domain recovery at WIPO?
.info operates under the UDRP, meaning WIPO – and, alternatively, the Forum, CAC, or ADNDRC – can decide a complaint to transfer or cancel the domain. For hijacking matters, the UDRP works where the hijacker has effectively become the "registrant" in name and the conduct since the unauthorized transfer constitutes bad faith use.
The three UDRP elements that must be satisfied under Paragraph 4(a) are:
- Element one – confusing similarity to your trademark. If you hold a registered mark for the same name as the .info domain, this element is usually straightforward. Complainants without a registered mark may rely on common-law rights, demonstrated through evidence of commercial use and recognition.
- Element two – no legitimate interest. The hijacker has none. The task is to make that clear on the record: no bona fide offering under the domain before the dispute arose, no common-law name corresponding to the domain, no noncommercial fair use.
- Element three – registration and use in bad faith. In a hijacking case, this element has a specific factual dimension. Bad faith is shown through the unauthorized nature of the registration change plus subsequent conduct – parking, misdirection, demand for payment, or resale attempts. Paragraph 4(b) bad-faith circumstances, including registration to sell to the mark owner and disruption of a competitor, are often present.
The WIPO filing fee for a single-member panel covering one to five domains is USD 1,500. A standard case runs to a decision in approximately two months, with the respondent given 20 days to file a response after commencement. WIPO's expedited option can deliver a decision in roughly one month for single-panel cases of up to five domains.
One procedural point matters for hijacking disputes in particular: a complaint may cover multiple .info domains only if they share the same registrant of record. If the hijacker has distributed the portfolio across shell accounts, separate complaints may be required.
When does a court action outperform UDRP for a hijacked .info domain?
The UDRP's only remedies are transfer and cancellation. No damages. No costs. No injunction against the person responsible. For many hijacking cases – especially where the attacker is identified, is in a reachable jurisdiction, and caused quantifiable business harm – that is not enough.
US anticybersquatting litigation reaches further: it can award statutory damages and compel transfer through a court order enforceable against the registrar. If the hijacker is in a jurisdiction where US courts have personal jurisdiction, or where a local court has analogous anticybersquatting authority, court action may be the correct primary route rather than a supplement to UDRP.
Consider the decision this way. If your .info domain has been parked with a pay-per-click feed drawing on your brand name's search traffic, and you can identify the person responsible, court proceedings produce both a transfer and an accounting for damages. If the hijacker is anonymous or in a jurisdiction where enforcement is impractical, UDRP at WIPO gives you the transfer order faster and at a predictable cost. Where the registrar refuses to act despite clear evidence of unauthorized transfer, a court order directed at the registrar is often the only instrument with real teeth.
In a matter we handled – a .info hijacking, spring 2025 – the registrar initially declined to act on our client's abuse report because the hijacker had completed a formal transfer process using a compromised authentication code. We filed a WIPO complaint and simultaneously placed the registrar on notice of a potential court action. The registrar reversed its position before the WIPO panel was appointed, and the domain was returned without a decision being issued.
The right path also depends on speed. A court action, even an expedited one, typically takes longer than WIPO arbitration to reach an order. If the domain is generating harm every day – through brand confusion, fraudulent invoicing, or email interception – a WIPO complaint filed as an emergency measure, alongside registrar escalation, is often the faster blunt instrument even if court proceedings are also warranted.
To weigh UDRP against a court action for your .info hijacking case, email info@cognomenlaw.com. We handle both tracks.
What evidence decides an .info hijacking recovery?
The quality of the evidence record is what separates a swift transfer order from a contested, fact-intensive dispute that drags on or fails. In our experience defending and prosecuting hijacking cases, the record needs to establish three things clearly: that you were the legitimate prior registrant, that the transfer was unauthorized, and that the current registrant has no independent claim to the name.
The evidence that most directly establishes prior, legitimate ownership includes:
- Registration and renewal receipts from the registrar, showing the original account holder's name, email, and payment method.
- Historical WHOIS records – captured by third-party WHOIS history tools – showing your contact information before the compromise date.
- DNS zone history: hosting provider records showing that you controlled the nameservers to which the domain previously pointed.
- Email account access logs: server-side logs from the email provider showing the unauthorized access event that preceded the domain transfer.
- The trademark registration itself, if applicable, or commercial-use evidence demonstrating common-law rights.
Bad-faith evidence against the hijacker is equally important at WIPO. What is the domain now resolving to? Is it a parking page with pay-per-click links, a fraudulent storefront impersonating your brand, or a blank page? Has the hijacker made contact demanding payment? Has the domain appeared for sale on a secondary marketplace within days of the transfer? Each of these is a Paragraph 4(b) bad-faith indicator, and documenting them contemporaneously – with dated screenshots, archived copies of the DNS records, and saved marketplace listings – strengthens the complaint significantly.
One evidence pitfall we see repeatedly: clients who wait to gather documents before filing the registrar report. The registrar's own internal logs – which can establish precisely when the transfer request was made, what authentication was used, and from which IP address – are among the most powerful pieces of evidence, but their preservation is time-limited. Request them immediately and in writing.
How does the registrar-lock and transfer-reversal process work in practice?
The registrar-level track runs on ICANN's Transfer Policy, separate from the UDRP. Under that policy, the losing registrar has authority – and in cases of demonstrably unauthorized transfers, an obligation – to request a return of the domain from the gaining registrar. The gaining registrar may resist, particularly if a transfer fee has been paid or if the new registrant contests the claim.
Where both registrars cooperate, a transfer reversal can complete in days. Where they do not, the next escalation is to ICANN itself, through a formal complaint to ICANN's compliance function. ICANN compliance has authority to require registrars to follow the Transfer Policy; it does not decide ownership, but it can compel the procedural return of a domain to its prior status while a dispute is resolved.
A registrar lock – clientTransferProhibited – does exactly what its name says: it prohibits any outbound transfer of the domain. Once placed, no one can move the domain to another registrar without the current registrar's active cooperation. Securing this lock as early as possible is the primary goal of the first 48-hour response. If you have access to the registrar account, place the lock yourself immediately. If you do not – because the hijacker changed the credentials – request it through the registrar's abuse channel and follow up by phone if the registrar provides that option.
In a second matter we managed (a .info domain, summer 2025), the hijacker had moved the domain to an overseas registrar within hours of the account breach. The original registrar cooperated fully, submitting a transfer-reversal request to the gaining registrar and providing us with the authentication log showing the compromised credentials. The gaining registrar initially delayed. We escalated to ICANN compliance. The domain was placed under a registrar hold within approximately two weeks of our escalation, well ahead of the WIPO filing we had placed in parallel.
Is there a cross-zone dimension – .info versus .com or a ccTLD held in the same name?
Many brand owners and domain investors hold both a .com and a .info under the same brand name. A hijacking attack frequently targets both simultaneously, or targets one as a gateway to compromise the other. When that happens, the dispute spans multiple zones and potentially multiple registrars.
For the .com and the .info, the UDRP applies to both, and WIPO can take a single complaint covering both if the same entity is listed as registrant. This avoids parallel proceedings with duplicated evidence and fees. The complaint must identify each domain and demonstrate that the same registrant controls them.
Where the hijacked portfolio includes a ccTLD – a .de, a .uk, or a .eu – the analysis changes. The UDRP does not apply to .de; disputes there go to the German courts, with a DENIC DISPUTE entry placed to block further transfer while litigation proceeds. For .uk, the Nominet DRS applies a different standard: abusive registration or use, assessed under a test that reads "registered or used" abusively – a lower bar than the UDRP's cumulative "registered and used in bad faith." For .eu, the ADR.eu platform at the Czech Arbitration Court administers the procedure, and the remedy may be transfer or revocation depending on eligibility.
The practical consequence is that a cross-zone hijacking case requires a coordinated recovery strategy that sequences the filings correctly. A WIPO complaint for the .com and .info, combined with a Nominet DRS complaint for the .uk, can be timed to run in parallel if the evidence is assembled first. Adding a court action for the jurisdictions where enforcement against the hijacker is realistic completes the picture. We regularly coordinate multi-zone filings for clients whose portfolios span gTLDs and ccTLDs, working alongside local litigation counsel where a court proceeding falls outside the WIPO or ccTLD arbitration track.
What are the realistic costs and timelines for recovering a hijacked .info domain?
Cost transparency matters here. The UDRP filing fee at WIPO for a .info domain – a single-member panel, one to five domains – is USD 1,500. A three-member panel costs USD 4,000. Legal fees for preparing a UDRP complaint in a straightforward case typically fall in the USD 3,000–7,000 range as a flat fee, separate from the forum filing fee. For a hijacking matter with extensive evidence assembly – forensic access logs, WHOIS history reconstruction, registrar correspondence – legal fees sit toward the upper end of that range.
A registrar escalation, including the ICANN compliance filing if needed, is a separate engagement. Where it succeeds without a WIPO complaint, it is typically the lower-cost path. Where it fails and a WIPO complaint is required, the registrar work informs the complaint and the evidence gathered is directly reused.
Court action is more expensive and more variable. US anticybersquatting proceedings are billed hourly and involve discovery, filing fees, and – where the defendant is overseas – service costs. The timeline extends to months, not weeks. For .info domains where the hijacker is identified and in a reachable jurisdiction, the additional cost buys the possibility of damages and a binding injunction. For cases where the hijacker is anonymous or unreachable, the UDRP is the more realistic path.
Timeline summary: a registrar reversal, where the registrar cooperates, can resolve in days to two weeks. A WIPO UDRP case runs approximately two months from filing to decision, with a further period for registrar implementation of any transfer order. A court action varies by jurisdiction; in the US, an expedited order can be sought but is not routine.
What does this mean for the decision you are facing? If the hijacking is recent, the registrar is reachable, and the evidence of unauthorized transfer is clear, start with the registrar track simultaneously with a WIPO complaint. Do not wait for one to conclude before filing the other. Time costs more than filing fees when a domain is live and in the wrong hands.
Related at COGNOMEN
Frequently asked questions
When should I recover a hijacked .info domain after account compromise?
Begin immediately – within hours, not days. The registrar escalation window is narrowest in the first 48 hours, when internal transfer logs are still fresh and a registrar lock can prevent further movement. A WIPO UDRP complaint can be filed in parallel and does not require the registrar escalation to be concluded first. Delay increases the risk that the domain moves to a second registrar or a jurisdiction where enforcement is harder.
What happens if the other side ignores the case?
A respondent who does not file a response within the 20-day window defaults. Under the UDRP, a panel does not automatically grant the complaint on default – it still requires the complainant to establish all three Paragraph 4(a) elements on the record submitted. In practice, a well-documented hijacking complaint with clear evidence of prior ownership and bad-faith use by the hijacker regularly succeeds on a default record. At WIPO, the panel may draw adverse inferences from a respondent's silence, but the substantive case still needs to be made.
How is WIPO different from a national court for .info?
WIPO arbitration under the UDRP delivers only transfer or cancellation of the domain – no damages, no costs award, no injunction against the person. It is faster (approximately two months) and the filing fee is USD 1,500 for a single panel. A national court – most relevantly a US court for anticybersquatting litigation – can award statutory damages and bind the registrar by court order, but takes longer and costs substantially more. The two routes are not mutually exclusive; where the hijacker is identifiable and in a reachable jurisdiction, both may be appropriate.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.