Cybersquatting Is Surging: Why Domain Monitoring Has Become Essential
In 2025, WIPO administered more than 6,200 domain name dispute cases—the highest annual volume ever recorded by the organisation.
Over twenty-five years, the World Intellectual Property Organization has handled more than 80,000 cases, including over 70,000 involving generic extensions such as .com, .net and .org, and almost 10,000 involving country-code extensions.
For trademark owners, domain name monitoring is no longer merely a defensive precaution. It has become a core component of protecting the brand, its customers and its digital operations.
What is cybersquatting?
Cybersquatting generally involves the abusive registration or use of a domain name that matches a trademark, or is sufficiently similar to create a likelihood of confusion. The aim may be to exploit the trademark’s reputation, divert traffic, deceive customers or pressure the rights holder into paying for the domain.
Exact trademark registrations
A third party may register an exact trademark under an extension that the rights holder has not reserved. A company using brand.fr could, for example, discover registrations such as:
brand.shop;brand.store;brand.online;brand-support.com.
The growing number of available extensions mechanically increases the range of variants that can be exploited.
Typosquatting
Typosquatting relies on typing errors, spelling variations or visual alterations of a trademark. Fraudsters may:
- remove or add a letter;
- reverse two characters;
- replace a letter with a similar-looking character;
- add a hyphen or generic term;
- combine the brand with words such as “login”, “support”, “shop” or a country name.
These domains are designed to deceive users who mistype an address or fail to inspect a link carefully before clicking it.
Misleading descriptive domains
A domain may also combine the trademark with an activity, product or territory—for example, brand-shop.com, brand-france.shop, brand-products.net or brand-customer-service.com. Even without reproducing the trademark exactly, it may suggest an official website, authorised reseller or company-owned service.
Domains used as technical infrastructure
Some domain names display no visible website but may still be used to:
- send fraudulent emails;
- host a temporary login page;
- redirect visitors to another store;
- run advertising campaigns;
- circumvent an earlier takedown;
- prepare a future phishing campaign.
The absence of visible content does not necessarily mean that a domain is inactive or harmless.
Why have domain disputes reached a record level?
WIPO’s record caseload confirms the growing pressure on brands across the domain name ecosystem. Several structural factors make abuse easier: rapid registration, low costs, automation, the multiplication of extensions and the ability to move an operation quickly from one domain to another.
Infringements are also less likely to be isolated. A single operator may use several domains, online stores, social media accounts and advertising infrastructures. When one website is suspended, another may take over using the same content and payment methods.
The domain name therefore becomes one component of a broader fraud, counterfeiting or brand impersonation operation.
What risks do businesses face?
Consumer deception
A website reproducing a brand’s name, logo and visual identity may appear authentic. Consumers may buy counterfeit goods or disclose personal and payment information.
Traffic and sales diversion
A lookalike domain may divert prospects, capture sales, collect affiliate commissions or promote competing products.
Phishing and impersonation
A misleading domain can create credible email addresses, deliver fraudulent payment requests or imitate a customer portal.
Reputational damage
Fraud, undelivered orders or dangerous products can directly undermine trust in the legitimate brand.
Persistent reappearance
Taking down one website does not necessarily end the operator’s activity. They may register a new domain, change hosting provider or use another extension. One-off action therefore has limited impact unless supported by continuous monitoring.
Why is manual searching no longer enough?
Occasionally searching for the exact trademark in a search engine reveals only part of the risk. Effective monitoring must simultaneously cover:
- spelling variants and likely typing errors;
- relevant generic and country-code extensions;
- combinations of the trademark with commercial terms;
- new registrations and recently activated domains;
- redirections and email configurations;
- websites reappearing at new addresses.
It must also distinguish genuinely concerning registrations from legitimate, coincidental or inconsequential uses.
How to implement effective domain monitoring
1. Define the monitoring scope
The first step is to identify the assets to protect: word marks, trade names, product names, names of exposed executives, distinctive slogans, official domains and key language variants. Territories, extensions and associated terms should reflect the company’s actual markets.
2. Detect similar domains
Detection should combine exact matching, spelling similarity, character substitutions, word additions and extension analysis. This approach identifies both domains reproducing the trademark directly and variants designed to evade a basic search.
3. Assess every detection
Not every similar domain constitutes infringement. The assessment should examine:
- website content and use of brand logos or products;
- redirections and the existence of mail servers;
- the registrar, hosting provider and registration date;
- the targeted country and available contact details;
- links with other domains already identified.
This assessment establishes a risk level and focuses resources on priority cases.
4. Preserve evidence
Content may disappear quickly after initial contact. Before taking action, it is advisable to preserve the complete URL, dated screenshots, page content, legal notices, displayed contact details, offered products, observed redirections and relevant technical data.
An isolated screenshot is not always enough to reconstruct the full context. Evidence should be organised and connected to the domain, the suspected operator and any related infringements.
5. Choose a proportionate response
Depending on the risk and available evidence, possible measures include:
- enhanced monitoring or contact with the registrant;
- notice to the registrar or report to the hosting provider;
- a request to disable fraudulent content;
- action through a payment provider or online platform;
- an out-of-court proceeding or court action.
The appropriate response depends on the domain, its use, the rights held and the intended outcome.
The UDRP: a tool for domain recovery
The Uniform Domain Name Dispute Resolution Policy, or UDRP, is an administrative procedure for addressing certain abusive domain name registrations. It applies to generic extensions and some country-code extensions, while other country-code extensions have their own procedures.
To obtain the transfer or cancellation of a domain under the UDRP, a trademark owner must establish three cumulative elements:
Similarity alone is therefore insufficient to guarantee success. The actual use, registration context and quality of the evidence remain decisive.
WIPO reports that the United States, France and the United Kingdom were among the leading filing countries in 2025. The procedure is now a regularly used instrument for trademark owners seeking to protect their online operations.
Detecting a domain is not enough
An effective protection programme should not merely produce a list of domain names resembling a trademark. It should establish whether a domain is active, presents an immediate risk, uses the brand or its products, can send email, redirects to a store, is linked to other suspicious domains and which action offers the best prospect of success.
The objective is not to maximise the number of alerts, but to turn relevant detections into actionable cases.
Continuous monitoring enables earlier intervention
The earlier an abusive domain is detected, the greater the opportunity to act before it gains visibility, is used in advertising or deceives a significant number of consumers.
Continuous monitoring also helps identify repeat offenders and link multiple assets to the same operator. This consolidated view avoids treating each website separately when several are actually part of the same network.
The record of more than 6,200 WIPO domain name disputes in 2025 measures only part of global cybersquatting. It nevertheless confirms that domain names remain a major vector for impersonation, fraud and customer diversion.
IP DEFENDER centralises detection, assessment, evidence and enforcement tracking for online infringements in a single case file.
Request a demo Discover the solutionThis article provides general information and does not constitute legal advice. Whether a proceeding is appropriate must be assessed in light of the rights held, the domain concerned and the specific circumstances of each case.

