Assess my case

How to escalate a registrar lock to secure a .store domain

How to escalate a registrar lock to secure a .store domain. UDRP and ccTLD domain recovery and defense across .store. Email the firm to assess your case.

Your .store domain has been transferred without your authorization. The registrar account shows a new owner, the DNS points somewhere unfamiliar, and every hour that passes makes recovery harder. The question is not whether to act – it is how to escalate the registrar lock before the trail goes cold.

To escalate a registrar lock and secure a stolen or hijacked .store domain, you must move on two parallel tracks: an immediate registrar escalation to freeze the domain in place, and a formal legal process – typically a UDRP complaint before WIPO or, where arbitration cannot reach, court action – to compel the transfer back. The WIPO filing fee for a single-member panel starts at USD 1,500, and a standard case runs approximately two months. Speed and documented evidence of account compromise decide the outcome.

This page covers the mechanics of a registrar lock escalation for .store domains, the legal routes available, the evidence that matters, and the realistic next step for a registrant who needs to act now.

Why .store domains face a distinctive theft risk

.store is a new gTLD delegated under ICANN's generic top-level domain program, operated by Radix Registry. Because it is a gTLD, the UDRP applies in full – and so does the full registrar-transfer policy that governs when a domain may be moved between registrants and registrars. That is the legal architecture a hijacker exploits.

E-commerce brands register .store domains as primary storefronts, which means the domain carries live revenue. A hijacker who gains control of the registration record can redirect traffic, intercept email, and pivot to a fraudulent checkout page within hours. We regularly see account-compromise attempts target .store registrants specifically because the commercial value of the zone makes a five-figure buy-back demand credible.

The window for a clean recovery is narrow. Registrar transfer policies impose a 60-day lock after certain changes – but a hijacker who changes the account credentials and then initiates a further registrar-to-registrar transfer can move the domain beyond reach of a simple lock request. Acting within the first 24 to 48 hours of discovering the compromise is the single most important factor in a successful escalation.

What is a registrar lock, and when does escalation become necessary?

A registrar lock (formally, a "Registrar-Lock" or EPP status code "serverTransferProhibited") is a status applied to a domain registration that prevents unauthorized transfer to another registrar. It is a procedural hold, not a legal remedy. In ordinary circumstances it is the default state of a registered domain.

Escalation becomes necessary when the lock has been removed – or was never set – and the domain has already been moved, or is in the process of being moved, without the rightful registrant's consent. At that point the registrar's standard customer-service channel is insufficient. Escalation means a formal abuse report, a written demand invoking the registrar's transfer-dispute procedures under ICANN's inter-registrar transfer policy, and – if the registrar does not respond within hours – a complaint filed with ICANN's compliance team.

In our practice we treat registrar escalation and legal filing as simultaneous steps, not sequential ones. Waiting for the registrar to resolve the issue before filing a UDRP complaint loses days. The registrar escalation freezes the asset; the legal filing determines who keeps it.

If your .store domain has been transferred without consent, the first step is a documented freeze request to the registrar and gaining counsel at the same time. For an immediate assessment of your situation, contact info@cognomenlaw.com.

How does WIPO handle a .store domain theft complaint?

Because .store is a gTLD, WIPO has jurisdiction to administer a UDRP complaint, and the WIPO filing fee for a single-member panel on one to five domains is USD 1,500. The UDRP requires a complainant to prove all three elements of Paragraph 4(a): the domain is identical or confusingly similar to a mark in which the complainant has rights; the registrant has no rights or legitimate interests; and the domain was registered and is being used in bad faith.

A domain-theft case maps onto those elements differently from a classic cybersquatting complaint. The original registrant often holds the mark – their own business name or brand – and the hijacker plainly has no legitimate interest. Bad faith is usually demonstrated by the circumstances of the transfer: credential compromise, an unauthorized change of registrant contact, a subsequent transfer to a privacy-masked or fictitious holder, and an immediate monetization or ransom demand.

The WIPO expedited option can deliver a decision in approximately one month for single-panel cases of up to five domains. For a live e-commerce .store domain, that timeline may still feel long. That is why the registrar-lock escalation must run in parallel – WIPO cannot itself freeze the domain pending the proceeding, but a registrar that has received a proper escalation and abuse report will frequently apply a hold voluntarily.

Panels have consistently held that a registrant whose account was compromised and whose domain was then used to redirect users to fraudulent or unrelated sites satisfies the bad-faith element. The consensus view under the Policy is that a hijacker's conduct after obtaining the domain – phishing pages, pay-per-click parking aimed at the original brand's traffic, or a demand for payment to return the domain – each constitutes independent evidence of bad faith under Paragraph 4(b).

What evidence of compromise does a panel or court require?

Evidence quality determines the outcome. A well-documented file gives WIPO or a court the record it needs to order a transfer; a thin file invites a denial on the second or third element.

The evidence falls into four categories:

We assemble this file from the moment we are engaged. In a spring 2025 matter involving a hijacked .store domain for a mid-market retail brand, we secured a WIPO transfer order after documenting a fraudulent registrant-change request processed through a spoofed customer-service email – the registrar's own records showed the change had been initiated from an IP address in a different country than any prior login on that account.

When does court action outperform a UDRP complaint for a .store domain?

The right route depends on what you need and what the hijacker has done. The UDRP at WIPO delivers a fast, low-cost transfer order – but only that. No monetary damages. No costs award. No injunction against future conduct.

If the hijacker has intercepted customer payments, diverted business email, or caused quantifiable financial harm, a UDRP transfer order resolves the domain question but leaves the damage unaddressed. In those circumstances, US anticybersquatting litigation – or an action in the jurisdiction where the hijacker is located – is the path that reaches money. We handle that work with local litigation counsel in the relevant jurisdiction.

Court action is also the correct route when the hijacker is a known competitor who deliberately acquired the domain through a fraudulent transfer, and deterrence is as important as recovery. A court judgment on the record accomplishes something a UDRP decision does not.

The decision matrix in brief: if the .store domain is the only asset at stake and speed matters most, file at WIPO simultaneously with the registrar escalation. If the hijack caused financial harm or you need injunctive relief to prevent a repeat, add a court action – and use the UDRP as the fast lane to recover the domain while the litigation proceeds.

In a second matter from autumn 2024, a multi-brand e-commerce operator faced a coordinated attack across a .store domain and two related .com registrations. We filed UDRP complaints at WIPO for all three simultaneously. The complainant also pursued a court action for the financial damages caused by fraudulent checkout redirects. The UDRP resolved first, returning the domains; the court action addressed the revenue harm.

If you are weighing UDRP against court action for your .store domain, email info@cognomenlaw.com to assess which route fits your facts.

How does the transfer-reversal process work at the registrar level?

A successful registrar-level escalation produces one of two outcomes: the registrar restores the domain to its pre-compromise state, or it applies a hold that prevents further transfer while legal proceedings resolve the question of ownership.

The mechanics differ depending on whether the domain has been moved only within the same registrar (a registrant change) or transferred to a new registrar (a registrar-to-registrar transfer). A registrant change is easier to reverse because it remains within the originating registrar's authority. A completed registrar-to-registrar transfer requires either the gaining registrar's cooperation or an ICANN inter-registrar transfer dispute – a formal process that is slower and less predictable than a UDRP complaint.

ICANN's inter-registrar transfer dispute mechanism is not the same as the UDRP. It is an administrative process focused narrowly on whether the transfer complied with ICANN's transfer policy – not on the underlying ownership question. For .store domains it functions best as a procedural hold, not a recovery tool on its own.

The sequence we follow: (1) document the account state immediately, including RDAP records and DNS configuration; (2) file a formal abuse report with both the losing and gaining registrar; (3) invoke the ICANN transfer dispute process if the domain has crossed registrars; (4) file the WIPO complaint to establish the legal right to the domain; (5) monitor the registrar's response and escalate to ICANN compliance if no action is taken within 24 hours.

What are the cost and timeline expectations for a .store escalation?

The registrar escalation itself carries no official fee – it is a procedural demand. The legal cost is the WIPO filing fee plus counsel.

At WIPO, the single-member panel filing fee for one to five domains is USD 1,500. A three-member panel costs USD 4,000. In a domain-theft case involving a single .store domain, a single-member panel is usually appropriate unless the matter involves a complex factual dispute where a three-member composition adds credibility to the outcome.

Legal fees for a domain-theft UDRP complaint, separate from the forum filing fee, typically fall in the USD 3,000 – USD 7,000 range for a straightforward single-domain matter. The complexity of the evidence file – particularly when account-compromise forensics require assembling registrar logs, IP records, and email header analysis – can push that figure higher.

Total elapsed time, from filing to registrar implementation of a transfer order, is approximately two months for a standard WIPO case, or roughly one month under WIPO's expedited option. The registrar hold can be in place within hours of a successful escalation, even before WIPO renders a decision. That is why the two tracks – registrar escalation and legal filing – must run simultaneously.

Cross-zone considerations: what if the attack spans .store and a ccTLD?

Coordinated domain-theft attacks increasingly target multiple zones at once. A hijacker who gains access to a registrar account often transfers every domain in it – a .store, a .com, and perhaps a national ccTLD registered to the same holder.

For the .store and any other gTLD, the UDRP at WIPO applies. A single complaint can cover multiple domains, provided the registrant of record is the same holder – which in a coordinated theft it typically will be, at least initially.

For ccTLDs the governing procedure is zone-specific. A .uk domain follows the Nominet DRS, which has its own test and its own timeline. A .eu domain is handled through the ADR.eu procedure before the Czech Arbitration Court. A .de domain has no UDRP equivalent; disputes go to the German courts, with a DENIC DISPUTE entry used to block further transfer while the case proceeds. Each zone requires a separate filing under the applicable national procedure.

We identify the full zone picture at the outset and file simultaneously where the procedures allow it. For zones requiring local court action, we engage local litigation counsel in the relevant jurisdiction. The goal is to close every exit simultaneously so the hijacker cannot simply consolidate the stolen assets in the one zone that is moving slowest.

For a deeper look at how UDRP and national procedures compare for multi-zone situations, see our analysis of UDRP versus national procedures.

Can a registrant lose a domain permanently if they delay acting?

Yes – and it is the most avoidable outcome in domain-theft matters. Delay is the hijacker's primary defense.

A domain that has passed through two or three registrar-to-registrar transfers, with each gaining registrar having processed the transfer in apparent compliance with ICANN's transfer policy, presents a difficult factual record. Panels have held that the chain of transfers does not extinguish the original registrant's claim – but the evidentiary burden grows with each hop, and the practical difficulty of enforcing a transfer order against a registrar in a non-cooperative jurisdiction grows as well.

Laches is not formally recognized as a defense under the UDRP, and panels have generally declined to dismiss complaints solely because the complainant delayed in filing. However, delay in preserving evidence is a different matter entirely. Login logs and IP-access records at registrars are routinely purged on rolling 90-day or shorter windows. WHOIS historical records may not capture every registrant-change event. By the time a registrant files a complaint six months after a theft, the clearest evidence of account compromise may already be gone.

The myth that a registrant "can always get a stolen domain back later" is the most common and damaging misconception we encounter. Evidence windows close. Act within days, not weeks.

Related at COGNOMEN

Frequently asked questions

How long does it take to escalate a registrar lock to secure a .store domain?

A registrar escalation – a formal abuse report and lock request – can be submitted within hours of discovering the theft, and a cooperative registrar may apply a hold the same day. The legal proceeding that determines ownership typically takes approximately two months at WIPO under the standard UDRP process, or roughly one month under WIPO's expedited option for single-panel cases of up to five domains. The registrar hold and the legal filing should run simultaneously; one does not wait for the other.

What does it cost to escalate a registrar lock to secure a .store domain at WIPO?

The registrar escalation carries no official fee. The WIPO UDRP filing fee for a single-member panel on one to five domains is USD 1,500; a three-member panel costs USD 4,000. Counsel fees for a domain-theft complaint typically fall in the USD 3,000 – USD 7,000 range for a single-domain matter, depending on the complexity of the evidence file. All figures are separate line items; the forum filing fee is paid to WIPO, not to counsel.

Do I need a lawyer to escalate a registrar lock to secure a .store domain?

The UDRP does not require legal representation, and a registrar abuse report can be filed without counsel. In practice, domain-theft cases are among the most evidence-intensive UDRP proceedings: the complainant must document account compromise, the unauthorized transfer, and bad faith use, all while assembling registrar records that may require formal preservation requests. The cost of an unsuccessful pro se complaint – or a registrar escalation that is too vague to trigger a hold – almost always exceeds the cost of proper representation from the outset.

Speak with Cognomen Law

For a scoped view of your domain matter, contact info@cognomenlaw.com. Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@cognomenlaw.com.