Assess my case

How to recover a hijacked .sg domain after account compromise

How to recover a hijacked .sg domain after account compromise. UDRP and ccTLD domain recovery and defense across .sg. Email the firm to assess your case.

Your .sg domain is gone. The registrar account was accessed without authorization, the domain was transferred to a stranger, and your Singapore business presence is now controlled by someone else. Every hour the hijacker holds the name, your customers see something you did not put there. The question is not whether to act – it is which action, in which forum, in what sequence, to get the name back.

To recover a hijacked .sg domain after account compromise, the primary path runs through SGNIC's Singapore Domain Name Dispute Resolution Policy (SDRP), registrar escalation for an emergency lock, and – where arbitration cannot reach – proceedings before the Singapore courts. Speed matters: a registrar lock blocks onward transfer; the SDRP provides a formal arbitral remedy; court injunctions can freeze the domain pending a full hearing. No outcome is guaranteed, but the strength of your compromise evidence is the single largest factor in how quickly the domain comes back.

This page covers each mechanism, the evidence that decides the outcome, the realistic cost and timeline, and the route that fits your specific situation.

What is .sg, and why does the zone create a distinct recovery path?

The .sg country-code zone is administered by SGNIC (the Singapore Network Information Centre), a subsidiary of the Infocomm Media Development Authority. Unlike .com, which falls under ICANN's UDRP, .sg operates under the SDRP – a distinct policy with its own eligibility requirements, procedural rules, and remedies. Eligibility to hold a .sg domain is restricted: registrants must have a Singapore nexus, typically a Singapore-registered entity or a Singapore citizen or permanent resident for certain second-level strings.

That eligibility restriction matters in a hijacking context. An unauthorized transferee who lacks the required Singapore connection cannot lawfully hold the domain regardless of how the transfer was effected. That fact becomes a powerful strand of your recovery argument. In our practice, we find that highlighting the transferee's ineligibility – not merely the account compromise – often accelerates the registrar's cooperation before any formal proceeding is filed.

The SDRP is not identical to the UDRP. It addresses abusive registrations, not account compromise directly. For a pure hijacking scenario – where the original registrant never consented to the transfer – the registrar's own dispute and reversal process, together with the Singapore courts' equitable jurisdiction, may be more direct routes than SDRP arbitration alone. The right combination depends on where the domain currently sits and how quickly it is moving.

What is the first step after discovering your .sg domain has been hijacked?

The first step is to request an emergency registrar lock – a hold that prevents the domain from being transferred again while you build your case. Contact your registrar of record immediately, in writing, referencing the unauthorized transfer and requesting suspension of all outbound transfers pending investigation. Do this within hours, not days. Many registrar abuse desks operate around the clock for account-compromise reports precisely because the reputational and legal risk of facilitating an ongoing theft is significant.

What should that notice contain? At minimum: your account credentials and identity verification, a timestamp of when you last had authorized access, a description of the compromise event (phishing email, credential breach, SIM-swap, or other vector), and a clear demand for an immediate registry lock. Attach any technical evidence you have – access logs, breach notifications, two-factor authentication records showing anomalous logins.

Simultaneously, check the WHOIS/RDDS record. If the registrant of record has already changed, note the new listed contact and the timestamp of the transfer. That timestamp is critical: it anchors your timeline and often reveals whether the transfer occurred outside normal registry operating hours or without the standard transfer-authorization email reaching your confirmed address. In a recent matter – a .sg e-commerce domain, early 2025 – the registrar lock was obtained within six hours of first contact, halting a second scheduled transfer before the hijacker could move the domain to a third-party registrar outside Singapore.

If your .sg domain has been moved without your consent, time is the enemy. For an immediate assessment of your recovery options, contact info@cognomenlaw.com.

How does the SDRP apply to a .sg domain hijacking case?

The Singapore Domain Name Dispute Resolution Policy is the formal arbitral mechanism for .sg disputes. Its test centers on whether a domain registration or use is "abusive" – that is, whether the registrant lacks rights or legitimate interests and whether the registration or use took unfair advantage of, or was unfairly detrimental to, the complainant's rights. The SDRP draws on the UDRP structure but is calibrated to Singapore law and the Singapore nexus requirement.

In a hijacking scenario, the SDRP argument is that the current registrant (the hijacker or whoever received the unauthorized transfer) has no rights or legitimate interests in the domain and that the current registration is itself abusive – because it was obtained by fraud rather than by any legitimate act. Panels administering the SDRP have recognized that a registration procured through unauthorized account access is not a bona fide registration at all; the hijacker cannot claim the safe harbors available to legitimate registrants.

The SDRP remedy, like the UDRP, is transfer or cancellation. It does not award damages. If you seek compensation for losses caused by the hijacking – diverted revenue, reputational harm, remediation costs – that requires a court action, not an SDRP proceeding. The SDRP is the faster, lower-cost route to recovering the name itself; the court is the route to money and to injunctive relief if the hijacker is actively moving the domain.

One structural point: the SDRP proceeding requires that the domain remain within the .sg registry's reach. If the hijacker has already transferred the domain out of the .sg zone – which would require circumventing SGNIC's eligibility controls – the procedural picture changes. In that unlikely but possible scenario, you may need to engage the Singapore courts and, if the recipient is overseas, coordinate with local litigation counsel in the relevant jurisdiction.

When does a court route beat arbitration for a hijacked .sg domain?

Arbitration under the SDRP is efficient when the domain is still in the .sg registry, the hijacker is identifiable, and the sole goal is getting the domain back. Courts become necessary – or decisively better – in four situations.

First, when you need an interim injunction immediately. A Singapore court can grant an ex-parte injunction freezing the domain (and the registrant's ability to deal with it) within days, before any arbitral panel can be constituted. Where the hijacker is visibly monetizing the domain or threatening to transfer it again, that interim relief is invaluable.

Second, when you want damages. The SDRP cannot order the hijacker to pay for lost business, diverted invoices, or security remediation. Only a court can reach those remedies. If the hijacking caused significant measurable loss, the court route has a financial upside that arbitration lacks.

Third, when the identity of the hijacker is unknown. A court can order the registrar to disclose the current registrant's identity through a Norwich Pharmacal or similar discovery order. The SDRP proceeding assumes you can serve the respondent; if you cannot identify them, you need a court to compel disclosure first.

Fourth, when the dispute has a criminal dimension. Account compromise involving phishing, unauthorized computer access, or identity fraud may trigger Singapore's computer misuse legislation. A police report can run in parallel with civil recovery and, in some cases, law-enforcement cooperation with the registrar accelerates the voluntary lock without any formal filing.

The decision between these routes is not binary. In our practice, we frequently run a registrar-escalation demand and a court injunction application in parallel, while preparing an SDRP complaint as the formal backstop. That sequencing extracts the fastest possible interim protection while preserving the arbitral remedy.

To weigh the SDRP route against a Singapore court action for your specific case, email info@cognomenlaw.com.

What evidence decides the outcome in a .sg hijacking recovery?

Evidence of account compromise is the foundation of every recovery route. The stronger and more contemporaneous that evidence, the faster the registrar responds and the more persuasively the SDRP or court case proceeds. There are five categories of evidence that consistently prove decisive.

Access logs and anomaly records. Registrar account logs showing an access event from an unfamiliar IP address, at an unusual time, or from a geolocation inconsistent with your known usage pattern are the most direct proof of unauthorized access. Obtain these from your registrar immediately; many purge logs after 30 to 90 days. If your email provider (through which the transfer-authorization message was routed) also holds access logs, gather those too.

Transfer authorization chain. A domain transfer in the .sg zone requires an authorization code (also called an EPP authcode or transfer token). Document who held that code, when it was last legitimately used, and whether the transfer request was associated with a phishing email or a session you did not initiate. If you never received or approved a transfer-authorization email, that gap is powerful evidence.

Registrant change timestamps. Historical WHOIS/RDDS snapshots showing the registrant of record before and after the transfer, with timestamps, establish the sequence. Third-party domain monitoring services often retain these snapshots; otherwise SGNIC may be able to provide registry-side logs. Correlating those timestamps with your own access records often reveals the exact window of the compromise.

Communications with the hijacker or intermediary. Any demand for payment, any "we can sell this back to you" communication, or any contact from the current registrant is evidence of bad faith. Preserve it without responding in a way that could be characterized as negotiation or partial authorization.

Proof of your prior rights and continuous use. Registration certificates, renewal receipts, DNS records, email records routing through the domain, website archives – all of these establish that you were the legitimate registrant and that the domain was in active, continuous use. This matters both for SDRP standing and for quantifying loss if you pursue damages in court.

In a recent matter – a .sg professional-services firm, autumn 2024 – access logs obtained within 48 hours of the hijacking showed an authenticated login from a foreign jurisdiction immediately followed by the transfer request. Combined with the registrant's lack of Singapore nexus, that evidence supported both a registrar lock and a successful SDRP complaint without a court filing.

How do transfer-reversal mechanics work at the registrar level?

Most gTLD registrars operating in the .sg space are ICANN-accredited and subject to transfer-dispute procedures under ICANN's Inter-Registrar Transfer Policy (IRTP). The IRTP provides a mechanism to reverse a transfer that was initiated without the registrant's authorization. If your .sg domain was held at an ICANN-accredited registrar, you can invoke this procedure by submitting a written dispute to both the gaining and losing registrar, documenting that the transfer was unauthorized.

The gaining registrar – the one that now holds the domain – is required to investigate and, if the unauthorized nature of the transfer is established, to return the domain to the losing registrar (and thus to your account). This process is registrar-driven, not SGNIC-driven, and it runs faster than a formal arbitral proceeding. The catch: it depends entirely on the gaining registrar's cooperation. If the gaining registrar is non-responsive, unregulated, or offshore, you may need to escalate to ICANN's Compliance department or proceed directly to SGNIC and the courts.

SGNIC itself maintains the registry-level ability to freeze or lock a domain on receiving a credible report of unauthorized transfer. Engaging SGNIC's registry operations team directly – in parallel with the registrar-level IRTP dispute – can prevent a second transfer while your formal proceedings are pending. The combination of a registrar lock and a registry-level freeze creates a belt-and-suspenders hold on the domain that gives you time to pursue the recovery route that fits your situation.

What does .sg domain recovery cost, and how long does it take?

Costs divide into three layers: registrar-escalation and registry correspondence (typically within your overall legal engagement), SDRP arbitration fees, and court costs if that route is taken. For the SDRP, the governing fees are published by the SDRP-appointed service provider and are distinct from UDRP fees – they are calibrated to Singapore dollar amounts and should be verified against the current SDRP schedule at the time of filing, as the published SDRP fee schedule falls outside APPENDIX A and varies by provider. Legal fees for a .sg domain recovery – covering registrar escalation, evidence assembly, and an SDRP filing – are fact-dependent but are generally comparable in range to other ccTLD proceedings in the region: a matter of meaningful professional investment, separate from the official filing fee.

Timeline: a registrar lock, once requested with strong evidence, can be in place within one to five business days. An SDRP proceeding, including the response period, panel appointment, and decision, typically runs several weeks to a few months – verify the current service provider's published schedule for the operative timeline. A Singapore court injunction application, if filed on an urgent basis, can produce an interim order within days; a full hearing on the merits takes longer and is governed by the Singapore courts' listing schedule.

The fastest complete resolution in our experience involves a registrar lock obtained within 48 hours, followed by an SDRP complaint that the hijacker does not contest. Where the hijacker responds and disputes the claim, the proceeding extends. Court actions add cost and time but may be necessary where arbitration is insufficient or where damages are sought.

What are the cross-zone and cross-border dimensions of a .sg hijacking?

The right route depends on the domain's current location and the hijacker's jurisdiction. Consider the four key scenarios.

If the domain remains in the .sg registry under a new registrant within Singapore, the SDRP and registrar-level IRTP dispute are the primary tools. The Singapore courts are available as supplementary relief or for damages. This is the cleanest scenario.

If the domain has been moved to a different .sg registrar but remains in the .sg zone, the IRTP dispute runs between the two registrars; SGNIC controls the registry lock. The SDRP proceeding is still available because the domain is still .sg. Legal work stays within Singapore law.

If the hijacker also registered a confusingly similar .com, .net, or new-gTLD domain using your brand – a pattern seen in sophisticated hijacking schemes – you may need a parallel UDRP complaint at WIPO or the Forum for those gTLD domains. The UDRP filing fee at WIPO starts at USD 1,500 for a single-member panel covering one to five domains; that is separate from any .sg SDRP proceeding and runs concurrently if needed.

If the hijacker is outside Singapore and the domain (or its proceeds) is outside the .sg registry's reach, Singapore court proceedings may need to be coordinated with local litigation counsel in the relevant jurisdiction. Cross-border enforcement of a Singapore judgment or injunction requires separate analysis of the foreign jurisdiction's rules on recognition and enforcement. COGNOMEN coordinates that analysis with local litigation counsel and does not provide foreign-law advice directly.

For brand owners who hold both a .sg and a .com or .sg and a regional ccTLD portfolio, the hijacking of one zone is often the signal that the other zones are also at risk. A domain portfolio audit – checking transfer locks, registrar security settings, and authorization-code hygiene across all zones – is a prudent parallel step while the .sg recovery is underway.

Related at COGNOMEN

Frequently asked questions about .sg domain hijacking recovery

What are the chances to recover a hijacked .sg domain after account compromise?

Recovery prospects depend primarily on the quality of your compromise evidence and how quickly you act. Where access logs, transfer-authorization records, and registrant-change timestamps clearly establish unauthorized access, registrar cooperation is typically prompt. SDRP proceedings in hijacking cases – where the hijacker has no Singapore nexus and no legitimate basis for holding the name – generally favor the original registrant. No outcome is guaranteed; panels and registrars exercise discretion based on the specific facts of each case. Speed of response is the factor most within your control.

What evidence do I need to recover a hijacked .sg domain after account compromise?

The most decisive evidence is access logs showing unauthorized account activity, the transfer-authorization chain (including any phishing or spoofed communication that triggered the transfer), historical WHOIS/RDDS timestamps showing the registrant change, and proof of your continuous prior use of the domain. Communications from the current registrant – particularly any demand for payment – are valuable supporting evidence of bad faith. Gather this material immediately; registrar log-retention windows are often short.

Can I recover a hijacked .sg domain after account compromise without going to court?

Often, yes. Registrar-level escalation under the Inter-Registrar Transfer Policy and an SDRP complaint are frequently sufficient to secure return of the domain without court involvement. Courts become necessary when you need an immediate interim injunction, when the hijacker's identity is unknown and requires compelled disclosure, when the domain has moved outside the .sg registry's reach, or when you seek damages beyond the domain transfer itself. Many .sg hijacking cases resolve through registrar cooperation and formal arbitration alone.

About COGNOMEN

COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. Our court-recovery practice handles domain theft, account compromise, and unauthorized transfer cases across gTLD and ccTLD zones, working with local litigation counsel where foreign court proceedings are required. To discuss a hijacked .sg domain, contact info@cognomenlaw.com.

Page authored by Adrian Harland, whose practice focuses on court-based anticybersquatting actions and domain theft recovery across gTLD and ccTLD zones.

Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.