Assess my case

How to recover a stolen .br domain under the applicable domain rules

How to recover a stolen .br domain under the applicable domain rules. UDRP and ccTLD domain recovery and defense across .br. Email the firm to assess your case.

A registrant in Brazil wakes to find the .br domain backing its business has been transferred to a stranger. No sale was authorized. No transfer email was requested. The WHOIS record now shows an unknown entity, and the site is live under new ownership. The question is not whether something wrong happened – it almost certainly did. The question is how quickly and through which mechanism that domain comes back.

To recover a stolen .br domain, the governing procedure is administered by NIC.br and Registro.br, Brazil's national registry, which operates its own domain dispute mechanism known as SACI-Adm. This is a distinct administrative procedure, separate from the UDRP, with its own rules on standing, evidence, and relief. A parallel or alternative route is a direct action before Brazilian courts, particularly where the SACI-Adm pathway is unavailable, too slow, or where damages are also sought. The registrar-lock and transfer-reversal mechanics are the critical first step in either case.

This page covers the SACI-Adm procedure, registrar-lock escalation, the evidence that decides outcomes, and the decision between administrative and court routes — so a brand owner, registrant, or domain investor facing a .br theft can assess the right path and act fast.

What governs domain disputes and domain theft in the .br zone?

The .br ccTLD is governed by NIC.br, Brazil's Network Information Center, through its domain management arm Registro.br. Unlike many ccTLDs that have adopted the UDRP by reference, .br operates entirely under its own domestic rules. The UDRP does not apply to .br domains. A complainant filing a WIPO UDRP complaint targeting a .br name will be rejected at intake because WIPO has no jurisdiction there.

The applicable administrative mechanism is SACI-Adm (Sistema de Administração de Conflitos de Internet). SACI-Adm is Registro.br's own dispute-resolution procedure for .br domains. It is modeled loosely on arbitral principles but operates under Brazilian rules, applies to .br domains exclusively, and its scope covers abusive or fraudulent registration and, in defined circumstances, domain theft scenarios. The procedure is conducted in Portuguese. All filings, evidence, and communications are in Portuguese, which immediately distinguishes it from a UDRP proceeding that can be conducted in the language of the registration agreement.

Alongside SACI-Adm, Brazilian civil and criminal courts retain jurisdiction over .br domain disputes. Where a domain has been stolen through account compromise, phishing, or unauthorized transfer, a court injunction can compel Registro.br to freeze or reverse the registration while the matter is decided on the merits. In our practice, we have seen the court route become the only viable path when the theft is recent, the registrant has no direct contractual standing in the SACI-Adm mechanism, or damages are part of the relief sought.

One more boundary to note: if your brand name or trademark is at stake and the same bad actor holds a .com or another gTLD alongside the .br name, those separate domains may be attacked through a UDRP complaint at WIPO or the Forum while the .br is handled domestically. Coordinating parallel proceedings in different zones is something we regularly handle for clients with multi-zone exposure.

How does a .br domain get stolen and what evidence do you need immediately?

Domain theft in .br typically follows one of three patterns: account compromise (the registrant's Registro.br login credentials are phished or brute-forced), social engineering of the registry or registrar's support staff, or corporate identity fraud where documents are forged to convince Registro.br to update the registrant record. All three produce the same outcome – an unauthorized outbound transfer or a registrant-record change that strips control from the legitimate holder.

The evidence you preserve in the first 72 hours after discovering the theft often decides the entire case. That evidence includes:

Why does this preservation matter? Because SACI-Adm requires the complaining party to establish legitimate rights in the domain and demonstrate that the current registration is abusive or unauthorized. A Brazilian court considering an injunction will ask the same question: does the applicant hold a prior, demonstrable right to this name? Evidence gathered weeks after the theft – when logs have been rotated, emails deleted, and WHOIS history obscured – is structurally weaker than evidence locked down on day one.

In a recent matter (a .br corporate name theft, early 2025), we secured an interim registry lock for a Brazilian business within three business days of engagement by presenting the original registration history and a certified corporate registry extract to Registro.br's incident team. The domain was frozen pending formal proceedings. That result depended entirely on the client having preserved their original registration confirmation and identity documents.

To assess whether your evidence supports an immediate lock request or a SACI-Adm filing, contact info@cognomenlaw.com. COGNOMEN handles .br domain recovery alongside parallel gTLD proceedings where both zones are affected.

What is the SACI-Adm procedure and how does it apply to stolen .br domains?

SACI-Adm is the administrative dispute-resolution procedure published and administered by Registro.br for .br domain names. It applies when a complainant holds a right – typically a registered trademark, a corporate name, or a trade name recognized under Brazilian law – that conflicts with the current registration of a .br domain. For a theft or account-compromise scenario, the procedure's application requires careful framing, because SACI-Adm is primarily structured around abusive registration rather than unauthorized transfer.

The distinction matters. In a classic abusive-registration case under SACI-Adm, a cybersquatter registers a .br domain that matches a brand owner's mark. The brand owner files a complaint, the panelist or arbitrator reviews the three-part test under the applicable .br rules, and the domain is transferred or cancelled. That test under SACI-Adm asks whether the complainant has a prior right in the name, whether the current registration conflicts with that right, and whether the current registrant lacks a legitimate basis for holding the domain.

In a theft case the facts are different: the legitimate original registrant is the complainant, and the current "registrant" is a bad actor who obtained control through unauthorized means rather than a fresh registration. SACI-Adm can still reach that scenario – the current holder plainly lacks legitimate rights and the registration is abusive by definition – but the evidence strategy must be adapted. You are not just showing a conflicting trademark. You are reconstructing the chain of custody of the domain and proving the break in that chain.

Proceedings under SACI-Adm are conducted in Portuguese before qualified panelists appointed by Registro.br. The applicable rules, the filing requirements, and the time limits are set by Registro.br and are subject to change; verify the current rules with counsel before filing. Broadly, the procedure involves a written complaint, a response period for the current registrant, a decision by the appointed panelist, and implementation by Registro.br if the complaint succeeds. Remedies include transfer of the domain to the complainant or cancellation.

A key practical point: SACI-Adm is not a substitute for a criminal complaint where the theft involved fraud, identity forgery, or unauthorized computer access. Brazilian criminal law addresses those acts separately. Filing a criminal complaint or a civil claim in parallel does not preclude the administrative route, and in complex theft cases pursuing both tracks simultaneously often produces a faster registrar lock while the administrative matter runs its course.

When does a court route beat administrative recovery for a stolen .br domain?

Administrative proceedings are faster and cheaper in most .br dispute scenarios. A court route becomes the better or necessary choice in specific situations.

First, where the domain is being actively weaponized – redirecting customers, sending fraudulent invoices from the hijacked email, or distributing malware – the harm is ongoing and a court injunction operates faster as an emergency measure. Brazilian courts can issue a tutela de urgência (urgent provisional measure) that compels Registro.br to freeze the domain transfer or restore it to the prior registrant pending a full hearing. This is not a UDRP. It is a civil court order under Brazilian procedural rules, and it requires a showing of urgency and risk of irreparable harm, both of which are usually easy to establish when the domain powers live business operations.

Second, where damages are at stake. SACI-Adm, like the UDRP, awards no monetary relief. If the theft caused commercial loss – diverted customer payments, brand damage, loss of contracts – only a court can order compensation. A court proceeding thus serves two purposes simultaneously: it recovers the domain and it prices the harm.

Third, where the thief's identity is unclear or the transfer trail runs through multiple jurisdictions, a court proceeding allows for discovery tools unavailable in administrative arbitration. Ordering disclosure of registrar records, obtaining law-enforcement assistance, and freezing associated bank accounts are court remedies.

The decision between the two routes is not always binary. We regularly advise clients to pursue both: an immediate court application to freeze the domain, followed by a SACI-Adm filing to achieve a final administrative transfer once the court has preserved the status quo. That sequence avoids the risk of the domain being re-transferred during the months that a court case alone might take to reach final judgment.

In a second matter we handled (a .br e-commerce domain theft, autumn 2024), the client's site had been taken live by the bad actor within 48 hours of the transfer. A court injunction froze the domain within one week. The SACI-Adm proceeding produced a transfer order roughly six weeks later. The parallel approach prevented the bad actor from profiting from the site during the administrative window.

How does the registrar-lock and transfer-reversal process work for .br?

Registro.br is the sole registrar of record for all .br domain names. There are no third-party registrars in the .br zone. This centralization means that a registrar-lock request goes to a single point of contact, which is both a structural advantage and a potential bottleneck.

The immediate step on discovering a .br domain theft is to contact Registro.br's security or incident-response channel and request a domain lock – an administrative hold that prevents any further transfer, delegation change, or registrant update while the matter is investigated. Registro.br's published procedures require the requesting party to identify themselves as the prior registrant, supply supporting documentation, and describe the nature of the unauthorized event.

If the lock request is accepted, the domain is frozen. That freeze does not restore the domain to the prior registrant – it simply prevents the situation from deteriorating further while a formal proceeding is prepared. Restoration to the prior registrant requires either a SACI-Adm order, a court order, or Registro.br's own internal administrative determination that the transfer was unauthorized.

What if Registro.br declines the lock request or does not respond promptly? That is when a court injunction directed at Registro.br becomes the practical mechanism. Brazilian courts have jurisdiction over Registro.br as a domestic entity, and a well-supported urgent application can produce a court order compelling the lock within days. We work with local litigation counsel in Brazil for the in-court procedural steps, combining their domestic filing capability with our domain-specific evidence strategy and cross-zone coordination.

Documentation required for a lock request typically mirrors the evidence list above: proof of prior registration (original confirmation email, historical WHOIS records), identity documents matching the prior registrant, and a factual description of when and how the theft was detected. In our experience, a request submitted with all documentation on first contact is processed materially faster than one requiring Registro.br to follow up for missing records.

What evidence decides the outcome under SACI-Adm and in court?

Across both the administrative and court routes, the same core evidentiary question recurs: who held a prior, legitimate right to this domain and when did the unauthorized break in custody occur? The strength of the available evidence on those two points drives the outcome.

On the prior-right side, the strongest evidence combines: (1) the original Registro.br registration confirmation in the complainant's name, with the registration date predating any activity by the current holder; (2) active use – invoices, email traffic, website analytics – from before the theft; and (3) a trademark registration, corporate name registration, or trade name record that links the registrant's legal identity to the domain name by language or acronym.

On the unauthorized-break side, the key is demonstrating that no legitimate transfer occurred. Evidence includes: timestamps of suspicious login attempts or password-reset requests that the legitimate registrant did not initiate; Registro.br's own transfer logs, obtainable through formal legal channels; any phishing communications used to extract credentials; and, where identity documents were forged, forensic evidence of the forgery or a statement from the relevant government registry confirming the documents are false.

Two types of evidence that panels and courts frequently find insufficient to overcome a well-documented theft claim: (a) the current holder presenting a purchase receipt from a resale marketplace, where the chain of title leading to that sale is itself fraudulent; and (b) the current holder claiming that the domain was registered independently with no knowledge of the prior registrant. Both defenses can be neutralized by the registration date and use evidence of the legitimate prior holder.

A practical note on Brazilian court proceedings: Brazilian procedural rules allow for documentary evidence, witness testimony, and expert evidence. In complex account-compromise cases we have supported expert evidence on digital forensics – mapping the IP addresses, device identifiers, and authentication tokens used in the unauthorized transfer – to close the narrative gap between "the domain moved" and "the domain was stolen."

If a prior filing or response in a .br matter has produced a bad outcome, a focused second read of the evidence record can identify the element that was missed. Email info@cognomenlaw.com with the case history.

Choosing between SACI-Adm and a court action: a decision matrix

The right route for a stolen .br domain depends on four variables: how urgently the domain must be frozen, whether damages are sought, how complex the chain of theft is, and whether parallel gTLD names are also at risk.

If the domain is frozen by Registro.br on first contact and the theft is recent with clean documentation, a SACI-Adm filing is typically the faster and less expensive path to a transfer order. The administrative procedure avoids the cost and timeline of full civil litigation and produces a final decision from Registro.br's panelists without a court hearing. This is the standard path for a straightforward identity theft with a clear prior right and a cooperating registry.

If Registro.br has not locked the domain, the site is live and causing ongoing harm, or the bad actor is moving the domain through intermediaries, a court injunction should be filed immediately – ideally the same day the theft is confirmed – with a SACI-Adm filing prepared in parallel. The court injunction arrests deterioration; the administrative proceeding delivers the permanent result. That parallel track costs more in legal fees than a stand-alone administrative filing, but the risk of waiting is a domain that is transferred again before any order can be implemented.

If damages are the goal alongside recovery, a court proceeding is the only route and should be filed as the primary proceeding, with all evidence preserved for the damages quantification as well as the recovery claim.

If the same bad actor also holds a .com or another gTLD matching the same brand, a coordinated UDRP complaint – filed at WIPO with a filing fee starting at USD 1,500 for a single-member panel covering up to five domains – can run alongside the .br domestic proceedings. The UDRP applies to the gTLD names; the domestic rules apply to .br. The two proceedings are independent but the evidence record overlaps heavily, which means preparation costs are not doubled.

What about the URS? The Uniform Rapid Suspension procedure applies to new gTLDs only. It does not reach .br or any other established ccTLD. If the stolen domain is purely a .br, URS is not available.

What myths about .br domain recovery most often delay action?

Two misconceptions consistently delay action by legitimate .br domain holders and allow bad actors to consolidate control.

The first is that a UDRP complaint will recover a stolen .br domain. It will not. The UDRP has no jurisdiction over .br. Filing at WIPO against a .br name wastes time and the filing fee, while the domain remains in the bad actor's hands and the evidence window closes. The applicable procedure is SACI-Adm or a Brazilian court proceeding, depending on the circumstances above.

The second is that a police or criminal report alone is sufficient to recover the domain. A criminal complaint against the perpetrator for fraud or unauthorized computer access is often appropriate and worth filing. But Registro.br will not unilaterally restore a domain on the basis of a police report. A formal administrative or judicial order directing the registry is required. The criminal complaint can support the evidence record for a court injunction – showing urgency and unlawful conduct – but it does not substitute for the civil or administrative proceeding.

A third misconception, less common but damaging, is that the passage of time reduces the legitimate registrant's claim. In our practice, we have defended clients who waited months before seeking advice and were told informally that the delay extinguished their rights. That is incorrect as a general proposition. The strength of the evidence is time-sensitive; the legal right to challenge an unauthorized transfer is not automatically extinguished by delay alone. Acting sooner is always better, but acting late is still worth doing with the right evidence strategy.

Related at COGNOMEN

Frequently asked questions: recovering a stolen .br domain

Is it worth it to recover a stolen .br domain?

For most operating businesses, yes. A .br domain carries the ccTLD trust signal that Brazilian consumers and partners associate with domestic credibility. Loss of that domain can divert email, redirect customer traffic, and enable fraud in the business's name. The cost of SACI-Adm proceedings or a court injunction is generally modest relative to the commercial harm of an ongoing theft. The threshold question is whether the legitimate registrant can assemble the prior-right and custody-break evidence needed to sustain the claim. If the evidence is solid, recovery is a realistic outcome, though no result can be guaranteed because outcomes depend on the specific facts and the decision-maker's assessment.

What are the most common mistakes when you recover a stolen .br domain?

The three most common errors are: (1) filing a UDRP complaint at WIPO, which has no jurisdiction over .br and wastes critical time; (2) failing to preserve the original registration confirmation, account logs, and authentication history in the first days after discovery – evidence that degrades quickly; and (3) waiting for a criminal complaint outcome before pursuing civil or administrative relief, when the two tracks should run in parallel. A fourth frequent error is submitting a lock request to Registro.br without full documentation on first contact, which delays the freeze while the bad actor retains operational control of the domain.

Can a three-member panel change the outcome?

Under SACI-Adm, Registro.br's rules govern panel composition, which differs from the UDRP's structure where parties can elect a three-member panel. Under the UDRP for gTLD names, a three-member panel can sometimes shift an outcome in borderline cases – it broadens the deliberative base and is often requested in high-value or complex matters. For .br disputes administered through SACI-Adm, verify the current panel composition options with counsel, as the procedure is governed by Registro.br's own published rules, not the UDRP Rules. For parallel gTLD matters under the UDRP, requesting a three-member panel adds cost but may be warranted where a case presents close factual questions on bad faith or legitimate interest.

About COGNOMEN

COGNOMEN is an independent boutique focused exclusively on domain-name disputes. We recover, defend, and transact internet domains across generic and country-code zones, before WIPO, the Forum, CAC, ADNDRC, and national procedures, and in court where arbitration cannot reach. We act for brand owners, domain investors, and registrants – including respondent-side defense and reverse domain name hijacking. For .br domain theft and recovery matters, we coordinate the administrative strategy with local litigation counsel in Brazil when court proceedings are required. To discuss a stolen or compromised .br domain, contact info@cognomenlaw.com.

By Adrian Harland – COGNOMEN's domain theft recovery and court anticybersquatting practice, focusing on registrar escalation, transfer reversal, and cross-jurisdiction recovery strategy.

Disclaimer: This article is general information about domain-name dispute procedures and does not constitute legal advice. Outcomes depend on the specific facts, the zone, and panel or court discretion. For advice on your domain, contact info@cognomenlaw.com.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.