Football Clubs and Cybersquatting: When a Domain Name Becomes the Infrastructure of Abuse

Football clubs have become prime targets for cybersquatters, but abusive domain names are no longer used merely to divert web traffic or exploit a club's reputation. Increasingly, they form part of a broader criminal infrastructure supporting phishing campaigns, counterfeit merchandise, fake ticket sales, fraudulent streaming platforms, cryptocurrency scams and other forms of online fraud. Drawing on an analysis of more than one hundred UDRP decisions involving football clubs from around the world, this article identifies the principal patterns of abuse, the domain name strategies adopted by cybersquatters, and the legal reasoning developed by UDRP panels. It highlights how attackers exploit supporters' trust by combining famous club names with terms relating to tickets, official stores, memberships, academies, streaming services or digital assets. Beyond the case law, the article argues that domain names have become a critical component of cybercrime ecosystems. It therefore examines the practical implications for brand owners and rights holders, emphasizing the importance of proactive domain name strategies, continuous monitoring and rapid enforcement mechanisms. The article concludes with practical recommendations to help football clubs and other rights holders strengthen their online brand protection in an increasingly complex digital environment.

COSHIELD: The Scope of the UDRP in Trademark Disputes

Not every dispute involving a trade mark and a domain name amounts to cybersquatting. In Polyco Healthline Limited v. David Beatson (WIPO Case No. D2026-1893), the panelist denied the complaint brought against coshield.com, a domain used since 2020 to sell personal protective equipment in the very sector where the complainant has exploited its SHIELD trade mark since 1997, and despite a settlement agreement concluded between the parties in 2021. The decision turns on the moment of acquisition: created in 2014, the domain name appears to have changed hands in May 2020, at the outset of the COVID-19 pandemic, and the combination of “Co” and “Shield” could describe the business rather than target Polyco. The evidence being “finely balanced”, bad faith was not established. This article examines why trade mark infringement and cybersquatting are two paths that do not necessarily converge.

23 August 2026
Initially published on iptwins.com

What the BVLGARI Case Teaches About Domain Extension Strategy

The expansion of the domain name system has fundamentally changed the legal significance of top-level domains (TLDs). While UDRP panels have traditionally regarded the TLD as a largely technical element that plays little role in assessing confusing similarity, the decision concerning bvlgari.bar and bvlgari.baby demonstrates that this approach is evolving. The panel considered that the semantic meaning of the extensions reinforced the association with BVLGARI’s business activities, making the disputed domain names more likely to mislead Internet users and supporting findings of confusing similarity, lack of rights or legitimate interests, and bad faith registration and use. Beyond analysing the decision itself, the article argues that not all domain name extensions carry the same legal or commercial significance. As the number of descriptive and industry-specific TLDs continues to expand, their contextual meaning may increasingly influence cybersquatters’ strategies, consumers’ perceptions and panels’ reasoning. The article concludes that brand owners should adopt a more selective and risk-based approach to domain name portfolio management, prioritising defensive registrations and monitoring efforts in extensions that are particularly relevant to their products, services or industry.

12 July 2026
Initially published on iptwins.com

DNS Abuse: How Can Domain Names Linked to the Same Actor Be Connected?

On 18 August 2026, ICANN published for public comment the Initial Report of its DNS Abuse Mitigation Policy Development Process (PDP 1). Among its proposals are Associated Domain Checks: when a registrar acts on an abuse report, it should also examine the other domain names held by the same customer. In its comments of 25 September 2026, the WIPO Arbitration and Mediation Center supports the approach but points out its main limitation: the checks stop at the edge of a single registrar's portfolio. Bad actors know this and spread their registrations across several registrars, which hampers consolidated UDRP proceedings. WIPO suggests exploring cross-registrar mechanisms without saying which data could link the names. The article argues that payment data, pseudonymised, could serve as that common denominator, while acknowledging its limits (prepaid cards, fraud, multiple payment methods): an indicator rather than proof. It marks a shift from a one-domain, one-investigation logic to a network approach.

28 September 2026
Initially published on iptwins.com

DNS and Web3: How Can We Avoid Importing Cryptosquatting into the DNS?

The DNS and blockchain-based alternative naming systems are converging, with projects such as .BLOCKCHAIN and the .ROBOT cryptoTLD seeking to operate the same string in both worlds. In August 2026, ICANN's Technical Study Group released an Initial Report on integrating gTLDs with alternative naming systems, built on a "string + controller" principle: the same name must remain under the same control across systems, with its status kept in sync. In September 2026, the SSAC supported this synchronisation but noted that applying the UDRP and the URS becomes difficult when a registrant exists only in an alternative system, without conventional registration data. The WIPO Arbitration and Mediation Center warns that cybersquatting is already widespread in these systems: mapping names automatically into the DNS would import existing infringements. Trademark owners therefore need functionally equivalent protection mechanisms, including a way to prevent infringing names from being activated, as initiatives like Unstoppable Domains joining GlobalBlock have begun to show.

24 September 2026
Initially published on iptwins.com

Article Information

Author

Emmanuel Gillet

Publication Date

19 July 2026

Jurisdiction

Industry

Related Decision(s)

Please select listing to show.

Filter articles

Filter for Topics
Filter for Industries
Filter for Jurisdictions