How to recover a stolen .global domain under the applicable domain rul
How to recover a stolen .global domain under the applicable domain rul. UDRP and ccTLD domain recovery and defense across .global. Email the firm to assess you…
Your .global domain disappeared overnight. The registrar account was compromised, a transfer was pushed through without your authorization, and the name now resolves to a stranger's page – or to nothing at all. The question is not whether you have a case. The question is which route gets the domain back fastest, before the registrant sells it on or lets the record go cold.
To recover a stolen .global domain you have two primary paths: a UDRP complaint filed before WIPO (the .global registry has appointed WIPO as its dispute-resolution provider, and the standard Policy and Rules apply), and a parallel or alternative registrar-escalation track that pursues a transfer reversal on the ground of unauthorized account compromise. A standard UDRP case at WIPO runs roughly two months, the single-member filing fee is USD 1,500, and the only remedies are transfer or cancellation – there are no damages. Where arbitration cannot reach the theft – because the thief has sold the domain to a third party or because criminal conduct is involved – court action becomes the necessary supplement.
This page covers the governing rules for .global, the registrar-lock and transfer-reversal mechanics, the evidence that decides the outcome, and the realistic next step for a registrant who wants the domain back.
What rules govern .global domain disputes?
The .global registry has designated WIPO as its dispute-resolution provider, which means the Uniform Domain Name Dispute Resolution Policy applies in full. That is the same three-element test used for .com, .net, .org, and the overwhelming majority of generic top-level domains. To prevail in a transfer order under the UDRP, a complainant must satisfy all three elements of Paragraph 4(a): the domain is identical or confusingly similar to a trademark in which the complainant has rights; the registrant has no rights or legitimate interests in the domain; and the domain was registered and is being used in bad faith.
Domain theft presents a specific wrinkle here. The original registrant – the person whose account was compromised – is now the complainant seeking a transfer back. The trademark question is usually easy: your registration or common-law mark covers the name. The bad-faith question is equally clear when the transferee is a thief or a downstream buyer who had no legitimate basis to receive a transfer. The harder evidentiary issue is often the "registered and used" prong applied to the thief's brief possession of the domain. Panels have consistently held that an unauthorized transfer obtained through account compromise constitutes bad-faith registration and use. The absence of any plausible legitimate interest by a party who acquired a domain by hacking is, in the consensus view, self-evident.
One nuance worth flagging: if your stolen .global name ended up in the hands of a good-faith purchaser after the initial theft, the UDRP's remedies run against the current registrant of record. The strength of your position against that party depends on what they knew – or should have known – at the time of acquisition. We regularly advise registrants in exactly that fact pattern, and the evidence of the original compromise becomes central to rebutting any good-faith defense.
How does registrar-lock and transfer-reversal work?
Registrar escalation is the first move in any stolen-domain recovery, and it must happen within hours, not days. The moment you confirm unauthorized access, you should contact your current registrar – and the gaining registrar if the domain has already moved – to request an immediate registrar lock. A locked domain cannot be further transferred, modified, or deleted. That lock buys time for every other step that follows.
ICANN's Transfer Policy gives registrars the authority – and in some cases the obligation – to reverse an unauthorized transfer when the registrant of record at the time of the transfer can demonstrate that the move was not authorized. The key evidence the registrar needs to see is: (1) proof of your original registration (invoices, confirmation emails, historical WHOIS/RDDS data, registrar account screenshots dated before the incident); (2) documentation of the compromise event (security logs, account-access alerts, a phishing or SIM-swap record); and (3) a timely complaint, meaning days after discovery, not weeks.
In our practice, the registrar channel and the UDRP are not mutually exclusive. Filing an ICANN-level complaint while simultaneously preparing a UDRP complaint keeps maximum pressure on every party who holds the domain. Registrars have their own abuse teams and ICANN compliance incentives; they often act faster on documented account compromise than on a formal arbitration filing alone.
For an immediate assessment of your .global domain theft, contact info@cognomenlaw.com.
When does a court route beat arbitration for a stolen .global domain?
The UDRP is powerful and fast for clear-cut cases. It is also limited: the only remedies are transfer or cancellation, there are no damages, there is no injunction, and the panel has no subpoena power to compel disclosure from a registrar, a host, or a third party. Those limits become critical in three scenarios.
First, if the domain theft is connected to broader criminal conduct – account fraud, wire fraud, or unauthorized computer access – then a court in the relevant jurisdiction can impose interim injunctive relief, compel discovery, and refer the matter to law enforcement. A UDRP panel cannot do any of these things. Second, if the thief has already sold the domain multiple times and a chain of downstream buyers exists, a court action can name multiple defendants and bind them all. A UDRP complaint covers only the current registrant. Third, if you want damages – compensation for lost business, diverted traffic, or reputational harm – the UDRP offers nothing. Only a court action reaches money.
For .global domains, US anticybersquatting litigation is one route where the underlying server infrastructure or the responsible party has a US connection. Where the registrar or the bad actor is based elsewhere, local litigation counsel in the relevant jurisdiction handles the court proceedings. Our role is to coordinate the arbitration and the court strategy so they reinforce rather than undermine each other – UDRP filings and court actions can proceed in parallel, though the timing requires careful management to avoid arguments that one forum has mooted the other.
The right route depends on the zone and the goal. If the .global domain is currently held by the original thief and you want it back quickly, a UDRP at WIPO is usually the fastest path to a transfer order, at the filing fee of USD 1,500 for a single-member panel. If the domain has changed hands and you need discovery to trace the chain of title, court action with a DENIC-style registry hold (not applicable to .global, but the analogy holds: a registry-level lock request through WIPO's interim-measures procedure) is the better opening move. If you want damages and transfer, both tracks run concurrently. In our practice we have coordinated exactly this combination for registrants whose domains were held for ransom, with the UDRP securing the transfer while a separate court proceeding addressed the financial harm.
What evidence decides the outcome of a .global domain theft case?
Evidence of original ownership and evidence of the compromise event are the two pillars of a stolen-domain recovery. Neither alone is sufficient; both together are nearly always decisive. Panels have consistently treated documented, timestamped proof of unauthorized access as sufficient to establish bad faith on the part of the acquiring party, regardless of the acquiring party's claimed ignorance.
The evidence checklist we assemble for every theft recovery includes, at minimum:
- Historical WHOIS/RDDS records showing your name as registrant before the incident, with dates.
- Registrar invoices, renewal notices, and account emails predating the theft by at least one renewal cycle.
- Security logs showing unauthorized login, IP geolocation anomalies, or phishing artifacts at the time of compromise.
- Email or ticket correspondence with the registrar from the period of the incident, documenting your contemporaneous objection.
- Evidence of your trademark rights: registration certificates, first-use dates, or consistent commercial use of the mark corresponding to the domain.
- Archived copies of the domain's prior DNS configuration, website screenshots, and any use-in-commerce evidence from before the theft.
- The current registrant's WHOIS/RDDS record and any public content now displayed at the domain, showing either continued exploitation or deliberate concealment.
In a recent matter (a .global account-compromise case, spring 2025), we assembled a transfer-reversal demand based on registrar logs and pre-theft renewal invoices. The gaining registrar reversed the transfer within days, before a UDRP filing was even necessary. Speed and documentation density are the factors that separate a quick resolution from a protracted arbitration.
What loses cases? Three patterns recur. First, delay: registrants who wait more than two or three weeks after discovering the theft give bad actors time to sell the domain on, complicate the registrant-of-record question, and let evidence age. Second, incomplete evidence: a UDRP panel reviewing a stolen-domain claim must find bad faith in the current registrant; without concrete documentation of the compromise event, the panel is left to infer what happened, and inferences can cut either way. Third, choosing the wrong forum: a registrant who tries to run a self-represented UDRP while simultaneously pressing the registrar with informal emails often achieves nothing at either window.
To plan recovery of a stolen or hijacked .global domain, contact info@cognomenlaw.com.
Can the UDRP be used offensively against a legitimate registrant – and what is the RDNH risk?
Reverse Domain Name Hijacking (RDNH) is the flip side of a stolen-domain case. If your .global domain was registered in good faith – you held it legitimately, used it commercially, and a third party files a UDRP to strip it from you – you have not only a defense but potentially an RDNH finding. A panel that determines the complaint was brought in bad faith, to deprive a legitimate registrant of a domain the complainant had no right to claim, may declare RDNH. The finding carries no monetary penalty under the Policy, but it is on the public record and it is a reputational sanction against the complainant and, in some cases, their counsel.
In our practice we handle both sides of this question. For a registrant wrongly accused of cybersquatting in a .global dispute, we build the legitimate-interest record, document good-faith registration, and where warranted seek an RDNH finding. Understanding the RDNH risk also matters to complainants: a theft-recovery complaint grounded in solid evidence of account compromise carries no such risk, but a speculative filing against a registrant with a plausible legitimate interest in the name can backfire. We assess both sides before advising either to file.
What does it cost to recover a stolen .global domain?
The costs break into two parts: the forum filing fee and the legal fee. They are entirely separate.
At WIPO, the filing fee for a single-member panel covering one .global domain is USD 1,500. A three-member panel costs USD 4,000. If you and the other side split the three-member fee under the Rules, each side pays half of the applicable portion. If the case is withdrawn or settled before panel appointment, WIPO typically refunds a significant portion of the filing fee – commonly around USD 1,000 of the USD 1,500 single-member fee.
Legal fees for a UDRP complaint in a straightforward single-domain case typically run in the USD 3,000–7,000 range, depending on the factual complexity, the number of exhibits required, and whether a supplemental filing or a three-member panel is in play. Theft-recovery cases are often more demanding than ordinary cybersquatting complaints because the evidence record – security logs, registrar correspondence, abuse-team filings – requires careful organization and authentication before it reaches a panel. Cases requiring concurrent court proceedings are substantially more expensive and are priced on an hourly or matter-specific basis.
We publish these ranges because we believe transparent pricing is the baseline for any honest assessment of whether a recovery effort is economically rational. A USD 1,500 filing fee plus legal fees is a defensible investment for a domain that anchors an enterprise brand. It is a harder call for a speculative registration. We will tell you which situation you are in before any filing is considered.
What are the cross-zone considerations for a stolen .global domain?
A brand that operates at .global frequently also holds corresponding .com, .net, or national ccTLD registrations. When a theft or cybersquatting attack hits one zone, it often targets others simultaneously, or the bad actor parked the stolen .global and is separately infringing through a .com or a ccTLD. That multi-zone exposure requires a coordinated response.
For the .com or .net registrations, the UDRP applies in the same way. A single UDRP complaint may cover multiple domains if the same registrant of record holds all of them – a single filing fee covers up to five domains with a single-member panel at WIPO. For national ccTLDs, the governing procedure varies by registry. A .uk domain dispute goes through Nominet's DRS, which has its own "abusive registration" test and a mediation stage before any expert decision. A .eu domain dispute goes through the ADR.eu platform at the Czech Arbitration Court. A .de domain has no UDRP equivalent: disputes belong in German courts, with a DENIC DISPUTE entry to block transfer while the case is litigated.
Where the theft was account-level – an attacker compromised a single registrar account holding multiple domain names across multiple TLDs – the registrar-escalation track is the first response across all zones simultaneously. The UDRP or ccTLD filings follow, zone by zone, once the registrar lock has been secured. In our practice, the coordination of registrar escalation across multiple zones is one of the most time-sensitive tasks in a stolen-domain recovery, and it is where the first hours after discovery matter most.
In a recent matter (a multi-zone portfolio theft involving a .global and two regional ccTLDs, autumn 2024), we coordinated simultaneous registrar-lock requests across three registrars within the first business day of the client's discovery. The .global and one ccTLD were returned through the registrar channel. The remaining ccTLD required a formal dispute under the applicable national procedure, resolved within approximately ten weeks. The domain was restored to the original registrant in each case.
Related at COGNOMEN
Frequently asked questions
Is it worth it to recover a stolen .global domain?
It depends on the commercial value of the domain and the cost of the recovery route. A UDRP at WIPO costs USD 1,500 in filing fees plus legal fees typically in the USD 3,000–7,000 range for a straightforward single-domain case. If the .global name anchors a brand or a revenue-generating operation, the investment is usually rational. If it is a speculative registration with limited active use, the cost-benefit analysis is tighter. We assess both situations honestly before advising a filing.
What are the most common mistakes when you recover a stolen .global domain?
Three patterns cause the most damage. First, delay: waiting more than a few days after discovering the theft gives bad actors time to sell the domain and complicate the registrant-of-record question. Second, incomplete evidence: a panel or registrar needs timestamped proof of original ownership and documented evidence of the compromise event; informal accounts of what happened are not enough. Third, choosing the wrong forum: running a self-represented UDRP while also pressing the registrar with informal emails often stalls both tracks. Legal coordination from the outset is consistently faster.
Can a three-member panel change the outcome?
A three-member panel gives both parties more decision-making power than a single panelist, at higher cost. Under the UDRP Rules, either party may request a three-member panel; if only the respondent requests it, the parties generally split the USD 4,000 WIPO fee. In a stolen-domain case with strong documentation, a single-member panel is usually sufficient. A three-member panel becomes worth the additional cost when the case turns on a contested factual question – such as whether a downstream buyer had notice of the theft – or when the record is dense enough that you want three sets of eyes on it.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.