How to recover a stolen .store domain under the applicable domain rule
How to recover a stolen .store domain under the applicable domain rule. UDRP and ccTLD domain recovery and defense across .store. Email the firm to assess your…
Your .store domain is gone. Access to the registrar account vanished overnight, the WHOIS record now shows a stranger's name, and the storefront you built is pointing somewhere else. The damage is immediate – customers are misdirected, revenue stops, and the brand you built around that name is in someone else's hands. The question is not whether to act but which tool gets it back fastest and with the least risk of losing it permanently.
To recover a stolen .store domain you have two primary routes: registrar escalation and transfer reversal under ICANN's registrar transfer dispute rules, and – where the theft involved unauthorized access to the underlying trademark – a UDRP complaint before WIPO or another accredited forum. The .store extension operates under the standard gTLD regime, which means all three UDRP elements apply in any abusive-registration scenario, and ICANN's transfer-dispute procedures govern unauthorized account-level moves. A standard WIPO case runs about two months from filing; registrar-level escalation can move faster if the compromise is documented clearly.
This page sets out the rules that govern .store, explains the registrar-lock and transfer-reversal mechanics, maps the UDRP route against the court alternative, and tells you precisely what evidence you need to start the process.
Why .store operates under the gTLD rulebook – and what that means for recovery
The .store registry is a generic top-level domain, delegated by ICANN, which means every accredited registrar offering .store is contractually bound to ICANN's dispute-resolution framework. That framework includes the Uniform Domain Name Dispute Resolution Policy (UDRP), the ICANN Transfer Policy, and the domain-deletion safeguards under the registrar contractual obligations. Unlike a country-code extension – a .de that sits entirely outside the UDRP – .store gives you a reliable, internationally recognized procedure from day one.
Theft in the .store space typically takes one of two forms. The first is account compromise: a credential-stuffing attack, a phishing email, or a SIM-swap drains the registrar login and the attacker initiates an unauthorized registrar-to-registrar transfer. The second is an abusive registration that was never legitimately yours but replicates your brand closely enough to divert traffic. The recovery route differs sharply between the two. Confusing them is the most expensive mistake a brand owner can make early on.
Account compromise calls for registrar escalation first and a court action or ICANN complaint second if the registrar fails to act. Abusive registration by a third party calls for a UDRP complaint addressing the three Paragraph 4(a) elements. Both scenarios can overlap, and in our practice we regularly advise brand owners who discover that what looked like a typosquat was in fact an account hijack – or vice versa.
For an assessment of your domain dispute, contact info@cognomenlaw.com.
How does the UDRP apply to a stolen or abusively registered .store domain?
The UDRP requires a complainant to satisfy all three elements of Paragraph 4(a): the domain must be identical or confusingly similar to a trademark in which the complainant has rights; the registrant must have no rights or legitimate interests in the domain; and the domain must have been registered and used in bad faith. All three must be present – a failure on any one is a failure in full. The only remedies available are transfer to the complainant or outright cancellation. There are no monetary damages, no legal costs awarded, and no injunction through the UDRP.
In a theft scenario the second and third elements are usually the strongest arguments. An attacker who hijacked your account and then transferred the domain plainly has no legitimate interest in a name that was yours, and the act of unauthorized transfer itself is powerful evidence of bad faith under Paragraph 4(b). Panels have consistently held that registration obtained through fraudulent account compromise satisfies the bad-faith standard, because no innocent explanation survives the documented chain of events.
What can trip a complainant in the .store context? The first element – the trademark similarity test – occasionally creates friction when the brand exists only as a common-law mark or a pending application rather than a registered trademark. Panels do accept evidence of common-law rights, but the evidence must be concrete: sales figures, press coverage, customer declarations, and dates of first use. A .store brand built entirely on the domain itself, with no surrounding trademark use, may struggle on element one.
WIPO and the Forum together handle the overwhelming majority of UDRP proceedings. The Czech Arbitration Court (CAC) offers the lowest entry-level filing fee for .store disputes, making it a viable option where cost is a constraint and the case is straightforward. The right forum choice depends on the complexity of the evidence, the domicile of the registrant, and the likely panel pool – factors we assess for each matter before filing.
What are the registrar-lock and transfer-reversal mechanics for a stolen .store domain?
When an attacker initiates an unauthorized registrar-to-registrar transfer of a .store domain, ICANN's Transfer Policy gives the losing registrar – and the true registrant – tools to challenge the move. The window is short. Acting immediately after discovering the compromise is not optional; delay weakens the argument that the transfer was unauthorized and gives the attacker time to move the domain again, resell it, or lock it behind privacy services that slow enforcement.
The first step is a written abuse report to the losing registrar, attaching every piece of authentication documentation you have: account creation records, billing history, prior WHOIS screenshots, the original registration confirmation email, and any anomaly logs from the account (suspicious login timestamps, unrecognized IP addresses, emails you did not send). Registrars are required by ICANN contract to maintain transfer records and to cooperate with legitimate dispute inquiries. They are not required to reverse a transfer on demand, and many will defer to the formal dispute process.
If the registrar does not reverse the transfer, the next lever is an ICANN Transfer Dispute. This is a formal channel that can result in the transfer being cancelled or the domain locked pending resolution. In parallel, filing a UDRP complaint establishes a registrar lock on the domain that prevents further transfers during the proceeding – a critical protection where the attacker is actively trying to move the name to an uncooperative registrar in a permissive jurisdiction.
In a recent matter involving a .store domain (spring 2025), we documented an account compromise through a phishing event, secured an immediate registrar lock by filing a UDRP complaint within 48 hours of discovery, and achieved transfer back to the legitimate registrant within approximately ten weeks. The phishing evidence – headers, timestamps, and a chain of custody for the original registrar credentials – was the decisive factor. Speed mattered; the attacker had already listed the domain for sale on a secondary market.
When does a court action beat the UDRP for recovering a stolen .store domain?
The UDRP is fast and cost-effective, but it has hard limits. The only remedies are transfer or cancellation. If you need monetary relief – damages, an accounting of profits, or an injunction against the attacker personally – court action is the only path there. For a .store brand that generated material revenue before the theft, a court proceeding may recover losses that a UDRP panel cannot touch.
The decision matrix is straightforward in principle, though fact-specific in application. If the .store domain is the only asset at stake and you simply want it back, file a UDRP complaint. The USD 1,500 WIPO filing fee for a single-member panel covers up to five domains, and the process runs to a decision in roughly two months. If the attacker also monetized the domain – ran fraudulent storefronts, collected customer payments, or diverted affiliate commissions – then a court action, handled with local litigation counsel in the relevant jurisdiction, is the route that reaches the money. In the US context, anticybersquatting litigation provides a statutory avenue for damages and transfer in the same proceeding.
A third scenario: the registrant against whom you would file a UDRP is a legal entity that has since dissolved, a privacy service that refuses to disclose the underlying owner, or an attacker in a jurisdiction with no meaningful enforcement of panel decisions. Here, a court injunction may be the only instrument with teeth. Courts can compel registrar compliance in ways a UDRP panel cannot.
Can both routes run simultaneously? Yes, subject to the UDRP's own rules. The UDRP does not prevent a complainant from pursuing a court action in a competent jurisdiction. Filing a UDRP complaint locks the domain against transfer while the case runs; if the court action produces an order first, the registrar will implement it. Sequencing matters, and that sequencing depends on facts that are specific to each case – jurisdiction, the registrant's location, and the urgency of getting the domain off the attacker's nameservers.
What evidence decides the outcome when you recover a stolen .store domain?
Evidence is the difference between a successful recovery and a panel finding against you. Panels decide .store UDRP cases on the written record alone – there is no oral hearing, no cross-examination, and no opportunity to introduce late evidence without a formal supplemental filing request that most panels will refuse. Getting the evidence right before you file is not administrative housekeeping. It is the case itself.
For the trademark similarity element, gather: the trademark registration certificate (or, for a common-law mark, dated commercial records showing use in commerce before the domain was registered), the domain registration date, and a side-by-side showing the domain string against the mark. For the legitimate interest element, gather: any communications showing the registrant had no prior relationship with your brand, any pay-per-click or parking pages the domain displayed, and any third-party reports of confusion.
For the bad-faith element in a theft scenario specifically, gather: the phishing emails or malware logs showing how the account was compromised; the authorization-code request you did not initiate; WHOIS records showing the registrant change; any demand for payment the attacker made after taking the domain; and any screenshots of the domain being listed for resale at a price no legitimate registrant would seek. Paragraph 4(b) of the UDRP identifies a pattern of registering domains to sell to mark owners as a per-se bad-faith indicator – document any other domains the attacker holds that follow the same pattern.
In a second .store matter we handled (autumn 2024), the complainant initially submitted only the trademark certificate and a single WHOIS comparison. The panel issued a procedural request for additional evidence on the bad-faith limb. We supplemented with the registrar's transfer-authorization logs and email headers confirming the complainant had not initiated the transfer. The panel transferred the domain. Without that supplemental evidence, the outcome would have been a close call. The lesson: build the bad-faith record as if the panel will ask for it – because it may.
How do you choose between WIPO, the Forum, and CAC for a .store UDRP filing?
All three accredited forums apply the same UDRP rules to .store disputes, but they differ in fee, procedural culture, and practical speed. The choice of forum is a tactical decision that should reflect the specific case, not habit or cost alone.
WIPO is the most widely used forum, with the broadest panel pool and the deepest published jurisprudence. The USD 1,500 filing fee covers a single-member panel for up to five .store domains. WIPO also offers an expedited single-panel option delivering a decision in approximately one month. Where the bad-faith record is clean and the trademark is registered, WIPO's panel pool and published overview are strong anchors for a predictable outcome.
The Forum applies a slightly different procedural culture and its filing fees begin at around USD 1,300 for a single-member panel covering one or two domains. For complainants with an established US trademark enforcement program, the Forum may be the default choice based on prior panel experience.
CAC offers the lowest entry point – fees beginning in the USD 500–800 range – making it worth considering for straightforward .store matters where cost is a genuine constraint. It is the least used of the three major forums, which means the panel pool is smaller, though not less qualified.
If the respondent requests a three-member panel after the complainant filed for a single-member panel, the parties generally split the higher three-member fee. A three-member panel adds procedural cost and some time, but it can also produce a more fully reasoned decision – relevant if the outcome is likely to be contested or if Reverse Domain Name Hijacking is a concern in the opposite direction.
To weigh UDRP against a court action for your .store case, email info@cognomenlaw.com.
What mistakes most often derail an attempt to recover a stolen .store domain?
Several recurring errors consistently reduce the chance of a successful recovery – and most are avoidable with early planning. The myth that UDRP is simply a "fast trademark claim" is one of the more costly misconceptions in this space. The UDRP is a narrow, evidence-driven procedure with strict rules about what the panel can and cannot consider. Treating it as a shortcut without building the evidentiary record first usually ends in a denial – or worse, an RDNH finding if the complaint looks opportunistic rather than meritorious.
The first and most common error is delay. Every day after discovering a compromise is a day the attacker can move the domain to a new registrar, resell it, or build out a fraudulent storefront that complicates the factual record. Filing a UDRP complaint or an ICANN Transfer Dispute locks the domain against further transfers. That lock is worth pursuing even before the full evidence package is assembled – you can refine the complaint in the filing, but you cannot reverse a second transfer that happened while you were gathering evidence.
The second error is conflating the UDRP with a general intellectual property action. UDRP panels do not issue injunctions, award damages, or adjudicate trademark infringement. A complainant who asks for relief the panel cannot grant wastes panel attention and signals to experienced panelists that the complaint was not carefully prepared.
The third error is filing without a clear theory on the bad-faith limb. "Someone stole our domain" is a conclusion, not a legal theory. The bad-faith showing must map to one of the Paragraph 4(b) factors or to the broader consensus view that unauthorized transfer itself satisfies the standard. Panels have found against complainants who filed on a theft theory but submitted no evidence of the unauthorized transfer – a registration-confirmation email, a transfer-authorization log, or an account-access history can be the difference.
The fourth error is underestimating the respondent's safe-harbor arguments under Paragraph 4(c). If the current holder can show it has been commonly known by the .store domain name, or that it operated a bona fide business under the name before receiving notice of the dispute, the complainant's second-element case collapses. Pre-filing research into the respondent's actual use of the domain – the sites it resolved to, the business registrations under the name, and the duration of use – is not optional.
Is a UDRP the only way to recover a .store domain, or are there other routes?
The UDRP is the most direct arbitration route for .store, but it is not the only one. The right route depends on the nature of the theft, the attacker's location, the trademark situation, and whether money damages are part of the goal.
Registrar escalation and the ICANN Transfer Dispute process are pre-arbitration tools that can resolve an unauthorized transfer without a full UDRP filing – provided the registrar cooperates and the documentation is clear. Many legitimate account-compromise cases are resolved at this stage in a matter of weeks, at no filing fee. They should always be attempted in parallel with, or before, the UDRP filing unless the registrar is unresponsive or the domain has already left the original registrar's platform.
Court action – anticybersquatting litigation, handled with local litigation counsel in the relevant jurisdiction – reaches remedies the UDRP cannot: damages, injunctions, contempt-of-court powers, and subpoenas to unmasked identity. It is slower and substantially more expensive than UDRP, but where the attacker is identifiable and the economic harm is real, it is the instrument with the most teeth.
For .store domains held by a registrant in a jurisdiction with a robust national court system, a court injunction can also compel the registry or registrar to freeze the domain pending litigation – independent of any UDRP outcome. Some brand owners run a UDRP complaint and a parallel court filing simultaneously, using the UDRP lock to prevent transfer and the court action to pursue damages. Sequencing that dual-track approach requires care, and the details turn on facts we assess individually.
A note on the URS: the Uniform Rapid Suspension system is available for new gTLDs, including .store. The URS remedy is suspension for the remainder of the registration term – not transfer. The evidentiary standard is higher ("clear and convincing"), and the filing fee is lower than the UDRP. URS is suited to clear-cut infringement cases where getting the domain offline quickly matters more than ownership transfer. For a theft scenario where you want the name back, the UDRP's transfer remedy is almost always the right primary route.
Related at COGNOMEN
Frequently asked questions
Is it worth it to recover a stolen .store domain?
Whether recovery is worth pursuing depends on the commercial value of the domain, the strength of your trademark evidence, and how quickly you act. A .store domain that anchors an active e-commerce business typically justifies the cost of a UDRP filing – the WIPO filing fee starts at USD 1,500 for a single-member panel, plus legal fees. Where the domain has low commercial value or the trademark evidence is thin, registrar escalation alone may be a proportionate first step. We assess each situation individually before recommending a route.
What are the most common mistakes when you recover a stolen .store domain?
The most common errors are: waiting too long after discovering the theft (allowing the attacker to move the domain again); filing a UDRP complaint without building the bad-faith evidence record first; and treating the UDRP as a general IP action capable of producing damages or injunctions. The UDRP delivers only transfer or cancellation. A complaint that asks for more, or that arrives without documented proof of the unauthorized transfer, risks a denial or a finding that the complaint was brought without a meritorious basis.
Can a three-member panel change the outcome?
A three-member panel produces a fuller deliberative record and is less likely to be reversed if either party challenges the outcome in a national court. It adds cost – the parties generally split the higher three-member fee if the respondent requests it after the complainant filed for a single-member panel – and some additional time. For a straightforward theft case with clean documentation, a single-member panel is usually sufficient. For a contested case involving significant assets or a credible RDNH risk, the three-member route may be worth the additional investment.
Speak with Cognomen Law
For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter
Related
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.