Under the UDRP, cybersquatting requires three facts: the domain is identical or confusingly similar to a trademark, the registrant lacks legitimate rights, and the domain was registered and used in bad faith to profit from that mark. WIPO recorded 6,192 domain-name cases in 2023, showing that the problem remains an active business risk rather than an outdated trademark dispute.
A founder may discover the problem on an ordinary workday. A customer forwards an email from a lookalike address, an employee notices a suspicious login page, or a search result leads to a domain that resembles the company's name. The site may ask customers to “update” payment details, send fake invoices, or sit unused while its owner demands money.
That's why the question what is cybersquatting needs a modern answer. It's not merely someone reserving a desirable web address and waiting for a buyer. A confusingly similar domain can become part of a phishing operation, a payment fraud scheme, or a credibility attack against a young company that hasn't yet built strong customer recognition.
Your Brand Was Just Stolen And It Was Cheap
A startup founder launches a product, chooses a name, commissions a logo, and begins sending the domain to prospective customers. Then the founder discovers that the matching domain was registered first. The page may display advertising, a message offering the domain for sale, or a login screen designed to resemble the company's customer portal.
The emotional reaction is predictable. The domain feels like part of the business, yet the company may have no immediate way to use it. A founder might consider paying to keep a launch on schedule. That can solve the short-term branding problem, but it may also reward the very conduct that created the conflict.

The domain is more than a web address
Cybersquatting is the bad-faith registration of another party's trademark as a domain name. The legal issue isn't merely that two businesses use similar words. The decisive question is whether the registrant chose the domain to exploit another party's trademark goodwill without a legitimate reason.
A parked page with advertisements can divert people who expect to find the startup. A sales offer can indicate that the registrant acquired the domain because the trademark owner might pay for it. A lookalike website creates a more urgent problem because customers may provide credentials, payment information, or confidential business details.
Practical rule: Treat a suspicious domain as both an intellectual-property issue and a potential security incident.
Founders should preserve the evidence before contacting the registrant. Screenshots, copies of email messages, registration history, and records of customer confusion can become important later. The company should also review its broader brand protection strategy, including trademark coverage and related domains.
The available tools include the UDRP administrative process and a federal claim under the Anticybersquatting Consumer Protection Act. Neither tool automatically transfers every disputed domain. The strength of the case depends on trademark rights, legitimate-use evidence, and proof of bad faith.
The Legal Framework Behind Cybersquatting
The legal analysis begins with the Uniform Domain Name Dispute Resolution Policy, commonly called the UDRP. Under the policy, a complainant must prove three elements:
- Confusing similarity: The domain name is identical or confusingly similar to a trademark in which the complainant has rights.
- No legitimate interest: The registrant lacks rights or legitimate interests in the domain.
- Bad faith: The domain was registered and is being used in bad faith.
WIPO's explanation of the UDRP elements makes clear that all three requirements matter. A domain containing a company's word may still have a legitimate descriptive, fan, criticism, or bona fide business use. Similarity alone doesn't win the case.
UDRP focuses on the domain remedy
The UDRP is an administrative procedure handled through approved dispute-resolution providers, including WIPO. It's designed for disputes where the central objective is to cancel or transfer a domain name. The process can be useful when the registrant is outside the United States or when a startup needs a focused domain remedy without pursuing a full federal lawsuit.
Evidence often includes trademark registrations, business records showing use of the mark, screenshots of the disputed site, domain registration information, and communications offering the domain for sale. A registrant's use of false contact details, a pattern of similar registrations, or an attempt to sell the domain can support a bad-faith argument. Those indicators are discussed in the ICANN overview of cybersquatting.

ACPA adds a federal litigation route
The Anticybersquatting Consumer Protection Act, or ACPA, is a United States federal statute. Congress enacted it on November 29, 1999, creating civil liability for registering, trafficking in, or using a domain name with bad-faith intent to profit from another party's mark. The legislative record expressly addressed “cyberpiracy” and “cybersquatting,” and the statute applied retroactively to domains registered before enactment. The congressional record for the ACPA documents that legal milestone.
ACPA litigation can address conduct beyond the transfer of a domain. Depending on the facts, a trademark owner may seek injunctive relief and monetary remedies. The claim still requires careful proof of the mark, the domain's confusing relationship to it, and the registrant's bad-faith intent to profit.
A domain disagreement can also involve broader trademark questions. Founders evaluating related conduct should distinguish cybersquatting from the wider analysis involved in what is trademark infringement.
UDRP vs ACPA Choosing Your Legal Path
Choosing between the UDRP and ACPA depends on the desired remedy, urgency, evidence, and resources. A startup seeking control of one domain may prefer an administrative proceeding. A company facing impersonation, customer losses, or conduct that requires court orders may need litigation.
The UDRP generally moves faster and carries a narrower objective. It can result in cancellation or transfer of the domain, but it doesn't award monetary damages. ACPA litigation takes place in federal court and can address a broader dispute, but it demands more extensive pleadings, discovery, motion practice, and trial preparation.
Comparison at a glance
| Factor | UDRP | ACPA |
|---|---|---|
| Forum | Administrative dispute-resolution proceeding | Federal court |
| Primary target | Transfer or cancellation of the domain | Domain-related relief, injunctions, and potential damages |
| Proof | Confusing similarity, no legitimate interest, and bad faith | Trademark rights, confusing similarity, and bad-faith intent to profit |
| Typical speed | Often about two to three months | Often substantially slower, depending on the court and dispute |
| Administrative fees | About $1,500 to $4,000, depending on panel size | Court and litigation costs, including legal fees |
| Monetary recovery | No monetary damages | Statutory damages may reach $100,000 per domain |
| Best fit | A focused domain-control dispute | Fraud, continuing harm, broader relief, or damages |
The stated UDRP timing and fee ranges are practical estimates commonly associated with the process, not guarantees. The ACPA statutory-damages ceiling is established by the statute, but an award depends on the court's findings and the record.
Washington founders should assess the whole dispute
A federal claim may not be the only option for a Washington business. Consumer confusion, deceptive communications, or payment-related conduct can raise state-law issues, although the right claim depends on the evidence and the parties involved. Counsel should evaluate those issues rather than adding a state claim automatically.
The choice also shouldn't be made by comparing headline costs alone. A cheaper proceeding may not address an active phishing campaign, while a lawsuit may be disproportionate when the only objective is obtaining a dormant domain. Founders should weigh the decision with the same care used in mediation vs litigation, focusing on the business result rather than the label of the process.
Why Cybersquatting Is Still Growing in 2026
Legislation didn't eliminate cybersquatting. WIPO reported a record 6,192 domain-name cases in 2023, more than 7% higher than 2022 and 68% above the level at the onset of the COVID-19 pandemic. WIPO also reported that its total cybersquatting-related caseload reached 67,625 cases since the UDRP was created. These figures appear in WIPO's 2023 domain dispute reporting.
The next year remained active. WIPO's 2024 Domain Name Report recorded 6,168 cases filed by trademark owners from 133 countries under the UDRP and national ccTLD variations, and said WIPO had administered more than 68,000 cases involving over 124,000 domain names since the policy began. That caseload is summarized in WIPO's 2024 Domain Name Report.
The risk now reaches operations
A founder may think of cybersquatting as a demand for a purchase price. That view misses the operational danger. A similar domain can support a fake vendor request, a fraudulent invoice, a customer credential prompt, or an email address that appears to belong to an employee.
WIPO's recent materials connect domain disputes with phishing and fake-invoice abuse. The practical consequence is significant for startups and small businesses. A company doesn't need to be famous for a lookalike domain to cause damage. It only needs customers, vendors, or employees who trust the company's name.
A domain dispute can begin as a trademark problem and become an accounts-payable problem within the same business day.
The international nature of the caseload also matters. WIPO's 2025 materials reported more than 6,200 domain-name cases, the highest annual caseload on record, and said the parties came from more than 142 countries in 2025, as described in WIPO's 2025 dispute update. A U.S. startup may therefore face a registrant, registrar, hosting provider, and affected customers in different jurisdictions.

The supplied graphic contains projections and figures that aren't part of the verified data available for this article. Those figures shouldn't be treated as established facts. The verified record supports a narrower conclusion, but it's still an important one: domain abuse remains a recurring, global enforcement and security issue.
Real Cases That Show What Cybersquatting Looks Like
Cybersquatting cases usually turn on intent, not just visual similarity. Consider two hypothetical fact patterns that reflect the practical difference between an abusive registration and a legitimate domain dispute.
In the first, a registrant chooses a domain that differs only slightly from a recognized brand, places pay-per-click advertisements on the page, and offers the domain to the trademark owner for an inflated price. If the registrant has no independent business reason for the name, those facts create a strong bad-faith narrative. The company can preserve the page, capture the sales offer, and assess a UDRP complaint or ACPA claim.
The second situation is less clear. A small business registers a domain containing words that resemble another company's mark, but uses the words in their ordinary descriptive sense. The business operates under its own name, publishes content consistent with that meaning, and doesn't suggest an affiliation with the trademark owner. Similarity may exist, but the registrant's legitimate interest can defeat a cybersquatting claim.

What separates the two
The following evidence often determines which story is credible:
- Registration purpose: Was the domain selected for an actual business, descriptive, fan, or commentary use?
- Website behavior: Does the site sell legitimate goods, display unrelated advertising, imitate the brand, or collect credentials?
- Communications: Did the registrant approach the trademark owner with a sales demand?
- Pattern evidence: Has the registrant acquired several confusingly similar domains?
- Contact information: Are the registration details accurate, or do they appear deliberately false?
The first pattern may also trigger fraud-response work if customers receive deceptive messages. WIPO's recent reporting highlights that domain disputes increasingly overlap with phishing and fake-invoice abuse. That overlap makes technical containment and customer communication as important as the trademark analysis.
Not every uncomfortable domain conflict is cybersquatting. A lawyer should test the evidence against all three UDRP elements before a company spends money on a demand letter or complaint.
What to Do If Your Domain Has Been Squatted
A founder who discovers a suspicious domain should resist the urge to negotiate immediately. The first response should protect evidence and limit customer exposure.
Preserve the record
Capture the website as it appears, including the address bar, page content, forms, advertisements, and contact details. Save suspicious emails with their headers when possible, record customer reports, and document every offer or demand from the registrant.
Run a WHOIS or registration lookup and save the result. Registration data can change, privacy services may obscure the underlying party, and a later investigation may depend on showing what was publicly available at the time.
Apply the legal test
Compare the domain with the company's trademark. Then ask whether the registrant has any plausible legitimate interest. Finally, identify facts showing bad faith, such as a sales offer, impersonation, false contact information, confusing redirects, or a pattern of related registrations.
A strong case usually has a coherent evidence trail rather than one suspicious screenshot. The company should also check whether the conduct is causing active harm. If customers are entering passwords or paying invoices, security, finance, and customer-support teams should respond while counsel evaluates legal remedies.
Choose a proportionate path
UDRP proceedings commonly resolve in about two to three months, with administrative fees ranging from about $1,500 to $4,000, depending on the panel size. ACPA litigation may take six to eighteen months and can cost $20,000 or more in legal fees, depending on the dispute's complexity. Those ranges are planning figures, not promises, and litigation costs can rise substantially with contested discovery or emergency relief.
Founders should avoid four common mistakes:
- Paying before preserving evidence: A payment may resolve possession but can destroy negotiating power and reward repeat conduct.
- Threatening the registrant publicly: Public accusations can complicate negotiations and create avoidable legal exposure.
- Assuming a trademark guarantees transfer: The complainant still must prove the UDRP elements.
- Ignoring the security side: A legal filing won't reset compromised credentials, warn customers, or stop fraudulent payments.
Washington startups should consult intellectual-property counsel familiar with domain disputes, federal law, and Washington consumer-protection issues. The right adviser can help determine whether the immediate priority is containment, a negotiated resolution, a UDRP filing, federal litigation, or a combination of business and legal measures.
Protecting Your Brand Before Squatters Strike
Prevention starts before launch. A founder should search the proposed name, secure the primary domain, and evaluate variations that customers could reasonably type or recognize. The goal isn't to buy every possible extension. It's to control the domains that create meaningful confusion or present a realistic impersonation risk.
Build a focused domain portfolio
Reserve the primary .com when it's available, then consider common misspellings, hyphenated forms, phonetic variations, and strategically important alternative extensions. A brand with customers in multiple countries may also need to assess relevant country-code domains. The portfolio should have an owner, renewal process, and documented business purpose.
A registrar with renewal alerts, transfer protections, and privacy features can reduce preventable mistakes. Keep registration contact information accurate, because a privacy service shouldn't become an excuse to lose renewal notices or miss a registrar communication.
Monitor names and customer-facing abuse
Domain monitoring can identify confusing registrations before customers report them. Brand monitoring should also cover search results, social profiles, email impersonation, and websites that copy logos or product language. For a practical overview of the broader process, founders can consult this brand monitoring guide.
Trademark registration strengthens the company's position by establishing clearer rights and improving the evidence available in a UDRP or ACPA dispute. It doesn't prevent every similar registration, and it doesn't replace monitoring. It gives counsel a stronger foundation for evaluating confusing similarity and priority.
Founders should also document approved logos, product names, domains, and authorized payment instructions. That record helps employees and customers distinguish genuine communications from fake invoices. Guidance on protecting creative brand assets is available through how to copyright a logo and name, although copyright and trademark protection address different rights.
Budget advice: Spend first on the names and controls that prevent customer confusion, then expand coverage as the company's markets and risks grow.
By Design Law Firm & Legal Consultancy, PLLC can help Washington startups evaluate trademarks, domain portfolios, monitoring, dispute strategy, and related technology-law risks. Prevention is usually easier to budget than recovering a domain after a phishing campaign or a demanding registrant has already created business disruption.
By Design Law Firm & Legal Consultancy, PLLC advises startups and established businesses on trademark protection, domain disputes, brand monitoring strategy, and cyber incident response. Visit By Design Law Firm & Legal Consultancy, PLLC to discuss a focused plan for protecting the company's name and responding when a suspicious domain threatens customers or operations.


