A UDRP case involving a .CEO domain

New gTLDs accounted for about 10% of WIPO's domain disputes in 2019, led by .online (64 cases), .xyz (49) and .win (48) — cheap extensions, where a name costs a few dozen dollars. The .CEO extension sits at the other end: at over one hundred dollars a year, it discourages volume cybersquatting, which makes AbbVie's case notable: the pharmaceutical company had to bring a UDRP to recover abbvie.ceo (Forum FA2007001906861, 25 August 2020). The economics of cybersquatting follow registration prices — but promotional pricing and high-value targets can make even premium extensions worth a fraudster's investment, and a brand.ceo name lends itself to convincing impersonations of executives, a known vector for fraud. The article's conclusion: factor the premium extensions into defensive registration strategies where the brand or its executives are exposed.

COSHIELD: The Scope of the UDRP in Trademark Disputes

Not every dispute involving a trade mark and a domain name amounts to cybersquatting. In Polyco Healthline Limited v. David Beatson (WIPO Case No. D2026-1893), the panelist denied the complaint brought against coshield.com, a domain used since 2020 to sell personal protective equipment in the very sector where the complainant has exploited its SHIELD trade mark since 1997, and despite a settlement agreement concluded between the parties in 2021. The decision turns on the moment of acquisition: created in 2014, the domain name appears to have changed hands in May 2020, at the outset of the COVID-19 pandemic, and the combination of “Co” and “Shield” could describe the business rather than target Polyco. The evidence being “finely balanced”, bad faith was not established. This article examines why trade mark infringement and cybersquatting are two paths that do not necessarily converge.

23 August 2026
Initially published on iptwins.com

Football Clubs and Cybersquatting: When a Domain Name Becomes the Infrastructure of Abuse

Football clubs have become prime targets for cybersquatters, but abusive domain names are no longer used merely to divert web traffic or exploit a club's reputation. Increasingly, they form part of a broader criminal infrastructure supporting phishing campaigns, counterfeit merchandise, fake ticket sales, fraudulent streaming platforms, cryptocurrency scams and other forms of online fraud. Drawing on an analysis of more than one hundred UDRP decisions involving football clubs from around the world, this article identifies the principal patterns of abuse, the domain name strategies adopted by cybersquatters, and the legal reasoning developed by UDRP panels. It highlights how attackers exploit supporters' trust by combining famous club names with terms relating to tickets, official stores, memberships, academies, streaming services or digital assets. Beyond the case law, the article argues that domain names have become a critical component of cybercrime ecosystems. It therefore examines the practical implications for brand owners and rights holders, emphasizing the importance of proactive domain name strategies, continuous monitoring and rapid enforcement mechanisms. The article concludes with practical recommendations to help football clubs and other rights holders strengthen their online brand protection in an increasingly complex digital environment.

19 July 2026
Initially published on iptwins.com

DNS Abuse: How Can Domain Names Linked to the Same Actor Be Connected?

On 18 August 2026, ICANN published for public comment the Initial Report of its DNS Abuse Mitigation Policy Development Process (PDP 1). Among its proposals are Associated Domain Checks: when a registrar acts on an abuse report, it should also examine the other domain names held by the same customer. In its comments of 25 September 2026, the WIPO Arbitration and Mediation Center supports the approach but points out its main limitation: the checks stop at the edge of a single registrar's portfolio. Bad actors know this and spread their registrations across several registrars, which hampers consolidated UDRP proceedings. WIPO suggests exploring cross-registrar mechanisms without saying which data could link the names. The article argues that payment data, pseudonymised, could serve as that common denominator, while acknowledging its limits (prepaid cards, fraud, multiple payment methods): an indicator rather than proof. It marks a shift from a one-domain, one-investigation logic to a network approach.

28 September 2026
Initially published on iptwins.com

DNS and Web3: How Can We Avoid Importing Cryptosquatting into the DNS?

The DNS and blockchain-based alternative naming systems are converging, with projects such as .BLOCKCHAIN and the .ROBOT cryptoTLD seeking to operate the same string in both worlds. In August 2026, ICANN's Technical Study Group released an Initial Report on integrating gTLDs with alternative naming systems, built on a "string + controller" principle: the same name must remain under the same control across systems, with its status kept in sync. In September 2026, the SSAC supported this synchronisation but noted that applying the UDRP and the URS becomes difficult when a registrant exists only in an alternative system, without conventional registration data. The WIPO Arbitration and Mediation Center warns that cybersquatting is already widespread in these systems: mapping names automatically into the DNS would import existing infringements. Trademark owners therefore need functionally equivalent protection mechanisms, including a way to prevent infringing names from being activated, as initiatives like Unstoppable Domains joining GlobalBlock have begun to show.

24 September 2026
Initially published on iptwins.com

Article Information

Author

Emmanuel Gillet

Publication Date

7 September 2020

Jurisdiction

Industry

Related Decision(s)

FA2007001906861Forum (NAF)AbbVie, Inc. v. Jack Gao (abbvie.ceo)2020-08-25
Please select listing to show.

Filter articles

Filter for Topics
Filter for Industries
Filter for Jurisdictions