How to recover a stolen .io domain under the applicable domain rules
How to recover a stolen .io domain under the applicable domain rules. UDRP and ccTLD domain recovery and defense across .io. Email the firm to assess your case.
A developer wakes to find the .io domain behind their SaaS product has been transferred to a stranger overnight. The registrar account was compromised, the transfer lock bypassed, and the domain is now parked or pointed elsewhere. The brand, the product, and live customer traffic are all attached to that name. Every hour it stays away costs something real.
To recover a stolen .io domain you have two main paths: an emergency registrar escalation to reverse an unauthorized transfer, and – where the transfer was enabled by fraud or account compromise – a UDRP complaint filed through WIPO, which administers disputes for .io under an agreement with the registry. The registrant must act fast: registrar-level reversal windows are short, and WIPO's standard timeline runs approximately two months. A court route becomes necessary when arbitration cannot reach the specific facts of the theft. The recovery process turns on evidence of the compromise – access logs, authentication records, and the timeline of events.
This page sets out each route, what evidence you need, how the two-month arbitration path works alongside the registrar escalation, and when a court action is the right move instead.
Why .io domains can be recovered through WIPO
The .io ccTLD – historically associated with the British Indian Ocean Territory and widely adopted by technology and startup businesses – operates under a registry that has designated WIPO as a dispute-resolution provider. That means the UDRP applies to .io disputes in substantially the same way it applies to .com or .net. A complainant can file at WIPO, invoke the Policy's three-element test, and seek transfer or cancellation of the domain.
That designation matters in a theft context. Where a domain was registered by the legitimate owner and then transferred away without authorization – whether by account compromise, social engineering against the registrar, or fraudulent transfer requests – the UDRP's bad-faith element can be met by the post-theft conduct of the party now holding the domain. Panels have consistently recognized that a respondent who obtains a domain through unauthorized means cannot claim legitimate interest, and that passive holding or monetization after an unauthorized transfer satisfies the bad-faith-use requirement.
The three elements under Paragraph 4(a) of the UDRP remain the same: the domain must be identical or confusingly similar to a mark in which the complainant has rights; the registrant-of-record must have no rights or legitimate interests; and the domain must have been registered and used in bad faith. In a theft scenario the first element is straightforward – the complainant's trademark matches the stolen domain. The second and third are met by documenting the unauthorized nature of the transfer.
You are ready to act. For an immediate assessment of your .io theft case, contact info@cognomenlaw.com.
What does registrar-level escalation achieve, and how fast must you move?
Registrar-level escalation is the first step – and often the fastest one. Registrars that are accredited under ICANN's rules are bound by transfer policies that include provisions for reversing unauthorized transfers. A domain that was transferred away within the past several days may be recoverable without any arbitration filing at all, if the original registrant moves immediately and with the right documentation.
Speed is everything here. ICANN's inter-registrar transfer policy imposes time windows; once a domain has been accepted at a new registrar and a grace period closes, the registrar's unilateral ability to reverse the transfer diminishes sharply. In our practice, the cases where a registrar reversal succeeded without arbitration all shared one feature: the account holder notified the registrar and filed a formal complaint within days of the unauthorized transfer, not weeks.
The escalation file should include: a written timeline of the compromise (when access was lost, when the transfer notification arrived, when the account holder first detected the change); evidence of account ownership (registration records, payment history, historical WHOIS data); and any evidence of the attack vector – phishing emails, spoofed support tickets, or SIM-swap documentation where a phone number was used for two-factor authentication.
Where the receiving registrar is unresponsive or the original registrar disputes liability, ICANN's Compliance function accepts formal complaints. That is not an adjudication – it is a pressure mechanism. It works best when the documentation is tight and the timeline is clear. Alone, it rarely produces a transfer order; combined with a WIPO filing, it can accelerate registrar cooperation.
How does the UDRP process work for a .io theft case?
A WIPO UDRP complaint for a stolen .io domain follows the standard five-stage procedure: complaint filed and reviewed for formal compliance, case commenced, 20-day response window for the registrant of record, panel appointment, decision, and registrar implementation. The standard single-panel case runs approximately two months end to end from filing to a transfer order.
In a theft scenario the complainant is typically the original registrant, not a separate brand owner filing against a cybersquatter. That framing shapes the evidence package differently. The complaint must establish: the complainant's prior trademark or unregistered rights in the name; the complainant's original registration of the domain; the unauthorized nature of the transfer that placed the domain in the respondent's hands; the absence of any legitimate basis for the current registrant to hold the domain; and the bad-faith element – which in a theft case is usually the registrant's knowledge that the domain was not legitimately acquired and any monetization or use that followed.
WIPO does offer an expedited option delivering a decision within approximately one month for single-panel cases covering up to five domains. Where business continuity depends on the domain – because live customer-facing infrastructure is attached to it – that accelerated path is worth assessing, though it is not available for all matters and is fact-dependent.
The WIPO filing fee for a single domain, single-member panel, is USD 1,500. Legal fees for preparing and filing a complaint are separate and, for a theft case with a documented evidence trail, typically fall within the market range for a straightforward UDRP matter. The only remedies WIPO can order are transfer or cancellation. The panel cannot award damages or costs, and it cannot pursue the party who stole the domain.
In a recent matter – a .io domain theft, spring 2025 – we filed at WIPO within 72 hours of a client's registrar escalation failing. The unauthorized transfer had occurred after a phishing attack compromised the registrant's email account. The case proceeded on a single-member panel, and a transfer order was issued in under ten weeks. The evidence anchor was a set of server access logs showing no login from the registrant in the hours when the transfer was initiated, combined with a phishing email recovered from the registrant's email provider.
When does a court route beat arbitration for a stolen .io domain?
Arbitration under the UDRP cannot do everything. The three situations where a court action is the stronger choice are: when you need an emergency injunction to freeze the domain before a further transfer to a third party; when you want monetary relief against the person who stole the domain; and when the factual dispute is so contested – including competing claims of original registration – that a court's discovery powers are necessary to establish the truth.
A UDRP panel cannot grant a temporary restraining order or a preliminary injunction. If the person holding the stolen domain is about to sell it onward to a bona fide purchaser for value, the UDRP's two-month timeline may be too slow. A court in a competent jurisdiction can issue an emergency order within days, locking the domain in place while the underlying merits are resolved.
Identifying the right court depends on where the theft occurred, where the domain's registrar is located, and what jurisdiction's law governs the underlying claim. US anticybersquatting litigation provides a court route that can reach monetary damages and a transfer order in a single proceeding. Where the relevant actors are in other jurisdictions, local litigation counsel in the relevant jurisdiction must be retained. We coordinate that engagement and provide the domain-dispute analysis that underpins the court papers.
The decision matrix runs like this. If the .io domain is frozen in the current registrant's account and the theft is documented: UDRP at WIPO, standard timeline, USD 1,500 filing fee, outcome limited to transfer or cancellation. If the domain is at risk of onward transfer or if you need damages: court action, higher cost, longer timeline, broader remedies. If the registrar's own conduct contributed to the unauthorized transfer: a parallel registrar complaint to ICANN Compliance, combined with either of the above. Where both the arbitration and the court route are viable, we assess which produces the better risk-adjusted outcome on the specific facts.
If the domain is at immediate risk of onward transfer, email info@cognomenlaw.com now. We assess the emergency options first.
What evidence actually decides a stolen .io recovery?
Evidence of the compromise is the spine of any successful recovery claim. The stronger the documentation of the unauthorized access, the less work the complainant must do on the bad-faith element, because the inference is nearly automatic once the facts are established.
The evidence categories that panels and courts find most persuasive in a theft scenario are:
- Authentication logs – server or account logs showing the IP addresses, timestamps, and device identifiers at the time of the transfer request, compared against the legitimate account holder's normal access pattern.
- Transfer notification records – the registrar's email or push notification of the transfer, showing the time it was sent and the time the domain was accepted at the receiving registrar.
- Account compromise evidence – phishing emails, credential-stuffing indicators, SIM-swap carrier records, or compromised-password alerts from breach notification services.
- Chain of registration – WHOIS/RDDS history showing the complainant's continuous registration of the domain before the unauthorized transfer, ideally including renewal payment records.
- Trademark or rights documentation – a registered trademark matching the domain, or – where the registrant relies on unregistered rights – evidence of commercial use of the name prior to the theft (product pages, press mentions, invoices, user accounts).
- Current use by the respondent – screenshots of what the domain resolves to after the theft: parking pages with revenue links, redirects to a competitor, or simply a static page asserting the new registrant's ownership.
What is notably absent from the losing cases we have reviewed: complainants who filed without authentication logs and relied solely on a timeline narrative. A narrative of events is a starting point, not a substitute for contemporaneous records. If the registrar's logs are not in your possession, they can often be obtained through a formal written request to the registrar, through ICANN Compliance, or – in a court proceeding – through discovery.
Is there a myth worth addressing here? What the ".io is different" concern actually means
Some registrants believe that because .io is a country-code TLD, the UDRP does not apply and recovery is harder or slower than for a .com. That concern is understandable but it is not accurate. The registry's agreement with WIPO means the UDRP applies to .io disputes in the same way it applies to any gTLD. The filing procedure, the three-element test, the forum fees, and the two-month timeline are all the same.
What is genuinely different about .io? The registrar ecosystem tends to be narrower – several popular .io registrars are boutique or technology-focused, and their escalation procedures can be less practiced than those of the large gTLD registrars. That can slow the first-response stage if the initial theft report is not directed to the right contact inside the registrar. It does not affect the WIPO path at all.
There is also a structural reality worth noting: because .io is popular among technology companies, stolen .io domains often have measurable commercial value attached to them almost immediately – existing user bases, API keys, CDN configurations, and revenue-generating applications. The urgency of recovery is therefore higher than for a parked .com registered speculatively. Our work on .io theft matters reflects that urgency in how we prioritize the registrar escalation alongside the WIPO filing, not sequentially.
In a second matter from our recent practice – a .io domain used by a software development company, late 2025 – the domain had been transferred to a registrar in a different jurisdiction and re-pointed to a site harvesting user credentials. We filed at WIPO and simultaneously pursued a DMARC-level alert to the registrar through ICANN Compliance. The panel issued a transfer order within the standard two-month window. The parallel Compliance filing contributed to the receiving registrar cooperating with the WIPO interim registrar lock.
How does the process work when both a UDRP and a court action proceed in parallel?
Parallel proceedings – a UDRP complaint and a court action filed simultaneously or in close sequence – are permitted under the Policy. The UDRP panel may, in its discretion, stay the arbitration pending the court outcome. More commonly, both proceed on independent tracks. A court's emergency injunction locks the domain in place while the UDRP resolves the underlying merits, which is often the most efficient arrangement.
The UDRP panel will not be bound by the court's findings, and the court will not be bound by the panel's. That independence is a feature, not a bug, when the two are used strategically. A UDRP complaint that is filed first creates a public record of the complainant's assertion of rights, which can support the court's analysis of the merits when an emergency application is made.
The cost calculus shifts significantly in a parallel proceeding. The USD 1,500 WIPO filing fee is fixed. The court costs are substantially higher – counsel fees, court filing fees, potential emergency hearing costs – and are hourly in nature. The decision to run both tracks should be grounded in a clear view of what the UDRP alone cannot deliver: primarily an emergency freeze or monetary relief.
Where the legitimate registrant's evidence is strong and the respondent is clearly the post-theft holder with no credible claim, the UDRP alone is usually sufficient. The parallel court track is a tool for cases where the stakes are high enough and the risk of onward transfer is real enough to justify the additional cost.
Related at COGNOMEN
Frequently asked questions
How do I start to recover a stolen .io domain?
Start with two parallel actions: notify your registrar in writing immediately, citing the unauthorized transfer, and begin assembling your evidence file – access logs, account ownership records, and any phishing or compromise documentation. If the registrar does not respond or cannot reverse the transfer within days, a WIPO UDRP complaint is the standard next step for .io domains. We assess whether the registrar escalation alone is likely to succeed before recommending the WIPO filing, because the filing fee and timeline differ significantly. Contact info@cognomenlaw.com to triage the facts.
What are the realistic outcomes when you recover a stolen .io domain?
WIPO can order transfer of the domain back to you or cancellation of the current registration. It cannot award damages, costs, or an injunction. If the domain has been re-sold to a third party after the theft, the outcome depends on whether that third party had notice of the theft – a fact a panel will weigh carefully. A court action is the route to monetary relief. Outcomes in any proceeding depend on the specific facts, the evidence of compromise, and panel or court discretion. No outcome is guaranteed.
How do fees split if the case escalates?
The WIPO filing fee for a single .io domain, single-member panel, is USD 1,500, paid by the complainant. Legal fees for preparing the complaint are separate and depend on the complexity of the evidence and the factual record. A court escalation – whether for an emergency injunction or for full anticybersquatting litigation – carries substantially higher costs, typically billed hourly. Where both tracks run in parallel, the WIPO fee is fixed and the court costs are variable. We provide a fee estimate at the assessment stage before any commitment to proceed.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.