Assess my case

How to recover a hijacked .store domain after account compromise

How to recover a hijacked .store domain after account compromise. UDRP and ccTLD domain recovery and defense across .store. Email the firm to assess your case.

A .store domain is stolen through account compromise more often than through any legal dispute. Someone obtains the registrar credentials – through phishing, credential stuffing, or a compromised email account – and pushes the domain to a new registrar or a new owner before the legitimate registrant even notices. The clock starts immediately, and every hour the registrar lock is absent is an hour the domain travels further from reach.

To recover a hijacked .store domain after account compromise, the immediate step is a registrar escalation to freeze the domain and initiate a transfer reversal under the registry's ERRP (Expired Registration Recovery Policy) and applicable inter-registrar transfer rules. If the domain has already crossed into a second registration cycle or a third party claims ownership, a UDRP proceeding before WIPO – where .store operates under the UDRP as a new gTLD – or a court action for injunctive relief may be necessary. The WIPO filing fee starts at USD 1,500 for a single-member panel. Timeline and route depend entirely on how far the theft has progressed at the moment you act.

This page covers every stage: the registrar-level freeze, evidence assembly, the UDRP route at WIPO, the court route when arbitration cannot reach the outcome you need, and the decision between them.

What does account compromise look like in the .store zone – and why does it matter?

An account compromise in the .store zone typically follows a predictable pattern. The attacker gains access to the registrar account, disables two-factor authentication (or never faced it), changes the registrant contact email, removes any registrar lock, and initiates an outbound transfer. The .store registry – operated by Radix – runs under the standard ICANN inter-registrar transfer policy, which means an unauthorized transfer can be completed in as little as five to seven days once the gaining registrar processes the authorization code (auth code).

Why does the zone matter? Because .store is a new gTLD, the UDRP applies directly, and WIPO has jurisdiction to hear a complaint. That is the good news. The complication is that the UDRP was designed for cybersquatting – registration and use in bad faith – not for theft. A purely stolen domain where the attacker has not begun to use it commercially may present a thin bad-faith-use case. The strongest legal theory in an account-compromise hijacking is often the registrar-level reversal or a court-based injunction, not the UDRP alone. Knowing which route fits the facts is the first decision.

We regularly advise registrants who discover a .store domain has moved without their knowledge. The pattern is consistent: the account email was compromised first, which meant the transfer approval notification went to the attacker, not the owner. Catching the transfer at the gaining-registrar stage – before a court action is needed – is always the faster and less costly outcome.

How does the registrar-lock and transfer-reversal process work for a hijacked .store domain?

The registrar-level freeze is the first and most time-sensitive action. The moment account compromise is suspected, the legitimate registrant should file an emergency abuse or hijacking report with the losing registrar (the registrar from which the domain was taken) and simultaneously contact the gaining registrar if identifiable through RDDS (WHOIS) data. Both registrars are bound by ICANN's Inter-Registrar Transfer Policy and the relevant registry agreement; an unauthorized transfer is reversible if the transfer was completed without the genuine authorization of the registered name holder.

The gaining registrar has the domain in its system but does not yet have a clean title. The key mechanics are these: the transfer was initiated using an auth code that the attacker obtained either by generating it after compromising the account or by phishing it directly. The losing registrar – if presented with timely, documented evidence that the account was compromised – can request a transfer reversal from the gaining registrar through an official dispute. ICANN's rules impose cooperation obligations on both registrars in a documented hijacking scenario.

What evidence moves a registrar? A contemporaneous log of the compromise: email access logs showing the account was accessed from an unexpected IP or geography, authentication records showing a password reset or removal of 2FA that the legitimate holder did not initiate, and any communications from the attacker attempting to monetize the domain. The faster this evidence is assembled and submitted, the higher the probability of a registrar-level reversal without escalation to WIPO or court.

In a recent matter (a .store domain, spring 2025), we assembled the account-compromise evidence package within 48 hours of the hijacking being reported, submitted it formally to both registrars, and the gaining registrar reversed the transfer within the same week. No UDRP proceeding was necessary. That outcome is not guaranteed – it depends on registrar responsiveness and on whether the domain has already been further transferred – but it is the fastest path and should always be attempted first.

If your .store domain has just been moved without your authorization, act immediately. To assess the registrar-level reversal route and the evidence you need, contact info@cognomenlaw.com.

When does a UDRP complaint at WIPO apply to a stolen .store domain?

A UDRP complaint at WIPO becomes the primary route when the registrar-level reversal has failed or is unavailable – because the gaining registrar is unresponsive, the domain has been transferred to a third party who now uses it, or the attacker has pointed the domain at a commercial site to generate revenue. In those circumstances, the hijacking has crossed into cybersquatting territory, and the UDRP elements are potentially satisfied.

The three elements of Paragraph 4(a) must all be proved. First, the domain is identical or confusingly similar to a trademark in which the complainant holds rights – which in a hijacking case means you must have trademark rights, whether registered or unregistered, in the name corresponding to the .store domain. Second, the person now holding it has no legitimate interest. Third, the domain was registered – or, in a hijacking, re-registered by the attacker – and is being used in bad faith. The third element is where hijacking cases can become legally intricate: if the attacker simply holds the domain passively after the theft, demonstrating "use" in bad faith requires relying on the consensus doctrine of passive holding combined with circumstances indicating bad faith.

Panels have consistently held that where a domain is taken from a legitimate trademark owner through unauthorized means and pointed at a parking page or held for sale to a third party, the bad-faith element is satisfied. The weight of the evidence – the account-compromise documentation, the change of contact records, the temporal sequence of the transfer – functions as the factual backbone of the complaint. A strong complaint in this setting leads with the compromise facts first, treats the trademark element as straightforward (you owned the name before the hijacking), and then addresses the registrant's absence of any plausible legitimate claim.

The filing fee at WIPO for a single-member panel on one domain is USD 1,500. A standard UDRP case resolves in approximately two months. WIPO also offers an expedited option delivering a decision in about one month for eligible single-panel cases of up to five domains. The only UDRP remedies are transfer or cancellation – no damages, no costs award.

What evidence decides the outcome of a .store hijacking case?

The evidence record in a .store hijacking recovery is the fulcrum of the entire case. At the registrar level, it drives the reversal decision. At WIPO, it forms the factual basis of the complaint. In court, it supports the preliminary injunction motion. The same evidence package serves all three routes, so assembling it immediately – before any of these filings – is the highest-priority action.

The core evidence set breaks down into four categories. Ownership history: RDDS records showing you as the original registrant, renewal payment records, and prior correspondence with the registrar confirming the account. Compromise indicators: email access logs, unusual login events, password-reset confirmations sent to an address you do not control, and any phishing communications you received. Transfer mechanics: the timestamp and IP of the auth-code generation or access, the transfer-approval notification that went to the compromised email, and the date the gaining registrar completed the transfer. Post-hijacking conduct: what the domain now resolves to, any ransom or sale demand received from the attacker, and any revenue-generating or brand-damaging use of the domain after theft.

What panels and courts look for is the chain of custody from your legitimate ownership to the unauthorized transfer. A gap in that chain – such as an absence of renewal records, or a registrant contact that was already changed before the theft – can weaken the case. We have seen matters where the registrant's own account hygiene (reused passwords, no registrar lock, no 2FA) was raised by the other side. That does not defeat a hijacking claim, but it requires pre-emptive framing in the submission.

When does a court action outperform UDRP for recovering a hijacked .store domain?

The UDRP is fast and focused, but it has hard limits. No monetary damages. No contempt mechanism if the attacker ignores a transfer order by moving the domain again. No ability to bind a third-party registrant who was not the original attacker. If the hijacking has caused quantifiable business harm – diverted sales, damaged customer trust, fraudulent invoices issued in your name – or if the attacker is within a jurisdiction where a court injunction can be served, court action may be the right escalation.

US anticybersquatting litigation is the clearest example: it allows damages and a court-ordered transfer, and the court can hold a defendant in contempt if the transfer is not effected. For .store domains, where the registry infrastructure is operated through ICANN-accredited channels, a US court order directed at the registry or the gaining registrar is often enforceable as a matter of registrar compliance. Where the defendant is outside the US, local litigation counsel in the relevant jurisdiction handles the cross-border piece.

The decision between UDRP and court turns on three factors. First, what outcome do you need: transfer only, or damages too? Second, where is the attacker, and can they be served? Third, has the domain moved beyond the UDRP's reach – for instance, does a bona fide third-party purchaser now hold it, having bought without notice of the hijacking? A bona fide purchaser complicates a UDRP complaint; a court action for title recovery may be the only viable path.

In a recent matter (a .store e-commerce domain, summer 2025), the domain had been transferred to a nominal holding company after the hijacking and was being used to divert the legitimate brand's customers at checkout. The registrar reversal route was exhausted. We filed a court action alongside a UDRP complaint, using the dual-track approach to freeze the domain via a consent order while the WIPO proceeding ran. Transfer was secured within three months of the hijacking being discovered.

If the registrar route has failed or the domain is already in active use by the attacker, a UDRP or court action may be the next step. To weigh UDRP against a court action for your case, email info@cognomenlaw.com.

How does the decision matrix work across registrar, WIPO, and court?

The right route depends on the stage of the hijacking and the goal. If the domain was stolen in the last seven to thirty days and the gaining registrar is reachable, the registrar-escalation route is always the first move: it is the fastest, at no forum fee, and produces the cleanest outcome – a reversal with clear provenance back to the original holder.

If the registrar route has been refused or the domain has moved to a third party who is using it commercially, a UDRP complaint at WIPO applies. The WIPO filing fee is USD 1,500 for a single-member panel on one .store domain, and a decision issues in approximately two months. The remedy is transfer or cancellation. UDRP is the right choice when the goal is ownership transfer, the attacker is not reachable for court service, and damages are not the priority.

If the domain use is causing active business harm – revenue diversion, customer deception, fraudulent invoicing under your brand – and you need damages or an immediately enforceable injunction, court action is the stronger instrument. The timeline and cost are higher: court proceedings in most jurisdictions run substantially longer than two months, and legal fees are hourly rather than flat. The trade-off is a wider range of remedies and a contempt mechanism if the transfer order is ignored.

A combined approach – registrar escalation immediately, UDRP filed within days, court motion filed in parallel – is appropriate where the domain carries significant commercial value and the attacker is actively monetizing it. The two proceedings do not conflict; panels are aware of parallel court actions and may suspend the UDRP pending court outcome, or proceed to a decision on the record.

For new-gTLD domains outside .store – if you are also dealing with a compromised .dev, .app, or .shop domain – the same UDRP route and escalation logic applies. See our related analysis on the URS vs. UDRP choice for new gTLDs for zone-specific nuances that affect the threshold between URS suspension and full UDRP transfer.

What is the respondent's position – and can the attacker claim legitimate interests?

An attacker who obtained a domain through account compromise cannot claim legitimate interests under Paragraph 4(c) of the UDRP. The safe harbors – a bona fide offering before notice of the dispute, being commonly known by the name, or legitimate noncommercial or fair use – require a baseline of lawful acquisition. A registrant who obtained the domain through identity theft or unauthorized account access does not clear that baseline.

However, a default or non-response by the attacker does not automatically mean the complainant wins on every element. Panels still independently assess the record. The complainant must still demonstrate trademark rights, the absence of legitimate interest, and bad faith. Where the complaint rests entirely on bare ownership history without trademark evidence – for instance, a registrant who held the .store domain as a generic commercial domain without a corresponding registered mark – the first element may be harder to satisfy than expected.

Reverse domain name hijacking (RDNH) is not a realistic risk in a documented account-compromise case. RDNH findings are reserved for complainants who misuse the UDRP to seize a domain from a legitimate holder. Where the factual record of the compromise is clear, an RDNH finding is implausible. But if the case is brought as a UDRP when the underlying facts support a purely contractual dispute with the registrar rather than a trademark dispute, a panel might decline to find bad faith – which is different from RDNH but equally costly in outcome.

How do you prevent a second hijacking after recovery?

Recovery without hardening the account against a repeat attack is an incomplete result. The attacker who compromised the account once has the original credential-theft method; if the underlying vulnerability is not closed, the domain can be re-stolen after the UDRP transfer or registrar reversal is executed.

The immediate post-recovery actions are: change all account credentials at the registrar and the associated email account; enable the highest available 2FA on both; apply a registrar lock (sometimes called a "domain lock" or "transfer lock" at the registrar level, and separately a "Registry Lock" at the registry level for domains that support it – .store domains support registry-level locking through the Radix registry for domains on qualifying accounts); and update registrant contact details to a fresh email address not associated with the compromised credentials.

ICANN's inter-registrar transfer policy imposes a 60-day lock on a domain following a registrant contact change. That lock applies automatically after certain registrant data changes and prevents outbound transfer during the period. Understanding when it applies and when it can be waived matters if you are planning to move the domain to a preferred registrar after recovery. We advise clients on the post-recovery account structure as part of the dispute engagement, not as an afterthought.

Portfolio-level protection is a separate but related question. If the .store domain is part of a larger portfolio – including .com, .net, and other new-gTLD variants of the same brand name – each domain's account security should be audited after a single compromise. A single credential breach at one registrar often gives the attacker enough information to attempt lateral access at others.

How does the .store zone compare to .com and other ccTLDs in hijacking recovery?

The .store zone sits in a legally comfortable position for hijacking recovery: it is a new gTLD, so the UDRP applies in full, and WIPO has extensive experience with UDRP proceedings involving .store domains. The zone offers a cleaner recovery path than, for example, .de (where no UDRP applies and recovery proceeds through German courts, with a DENIC DISPUTE entry to block transfer during litigation) or .eu (where the ADR.eu procedure and EURid registry rules govern, and complainant eligibility requirements apply).

Compared to .com, the practical difference in a hijacking case is minimal – both zones operate under the UDRP, both are served by WIPO, and the filing fees are identical. The registrar ecosystem for .store is smaller, which can mean either faster informal escalation (fewer registrars to track) or slower response (if the gaining registrar operates primarily for new-gTLD domains and has thinner abuse procedures than a major .com-focused registrar). The ICANN-mandated abuse contact requirement applies across all accredited registrars regardless of zone.

For a brand that holds the same name across .store, .com, and a national ccTLD – say .de or .uk – a coordinated hijacking across multiple zones is possible if the attacker has access to a single registrar account managing all three. In that scenario, the UDRP can cover the .com and .store in a single complaint (provided the same registrant holds both), while the ccTLD recovery requires the applicable national procedure run in parallel. We handle the coordination between the UDRP proceeding and the national procedure, working with local litigation counsel in the relevant jurisdiction where a court step is required.

See our general overview of court recovery and domain theft for how the same evidence package supports both the UDRP filing and any parallel court or national-procedure action across zones.

For a step-by-step account of the technical and legal process when an outbound transfer was not authorized, see our guide on how to reverse an unauthorized domain transfer.

Related at COGNOMEN

Frequently asked questions

How do I start to recover a hijacked .store domain after account compromise?

The first step is a written, documented abuse report to both the losing registrar (where your account was held) and the gaining registrar (where the domain now sits), submitted within hours of discovering the theft. Include your account-compromise evidence: login anomalies, unauthorized password resets, and any outbound transfer notifications you received. If the registrar does not respond within 24–48 hours or refuses to reverse the transfer, escalation to a WIPO UDRP complaint or a court-based injunction is the next stage. Contact info@cognomenlaw.com to begin an assessment immediately.

What are the realistic outcomes when you recover a hijacked .store domain after account compromise?

The range of outcomes depends on how quickly action is taken and how far the hijacking has progressed. An early-stage registrar reversal can restore the domain within days at no forum fee. A WIPO UDRP proceeding, if the registrar route fails, typically produces a transfer order in approximately two months; the filing fee is USD 1,500 for a single-member panel. A court action extends the timeline but adds remedies including damages and injunctive contempt. No outcome is guaranteed – the record and the facts decide – but acting within the first 48 to 72 hours materially improves all three options.

How do fees split if the case escalates?

The fees break into two distinct categories. The WIPO forum filing fee is USD 1,500 for a single-member panel on one domain; that fee is paid by the complainant and is not recoverable even if you prevail, since the UDRP awards no costs. Legal fees for preparing and filing a UDRP complaint in a hijacking matter are separate and vary by complexity; market rates for a straightforward single-domain complaint typically fall in the USD 3,000–7,000 range. Court action carries a materially higher cost – hourly legal fees plus filing costs in the relevant jurisdiction – and should be budgeted for separately. We provide a clear fee estimate before any filing is authorized.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.