Free consultation

A phishing site under your brand does harm every hour, and taking it down is faster than recovering the domain through a dispute. Since 2024 an ICANN-accredited registrar is obliged to publish an abuse contact, confirm receipt of a complaint and, where there is evidence, act on it promptly (the amendments to ICANN's Registrar Accreditation Agreement, RAA); the duty covers gTLD domains and DNS abuse — phishing, malware, botnets, pharming and spam as their delivery channel. For clone sites, counterfeits or stolen content, and for .UA domains, there is no such duty — there the host, the platforms, the browsers and the Ukrainian procedures do the work. Our job is to gather the evidence and file the complaints where they will be acted on.

What people come to us with

  • phishing under a bank's or a shop's brand: the site collects card details and passwords
  • a clone site copying your design, texts and name
  • fake social media accounts in your name
  • counterfeit goods under your mark on marketplaces
  • stolen content: texts, photos, video, code

How we work

  1. Evidence within one working day. Time-stamped screenshots, RDAP data on the domain, the hosting, the certificate, the fraudsters' payment details. Without evidence a complaint is rejected, so we never skip this step.
  2. Complaints. To the registrar's abuse contact — the aim is clientHold status, after which the domain stops working. To the hosting provider or the CDN: Cloudflare usually passes the complaint on to the host. In parallel — NetBeacon, Google Safe Browsing, APWG and the platforms where the fake accounts or goods are.
  3. Ukraine. A report to CERT-UA and a statement to the cyber police (Arts. 190, 361 and 229 of the Criminal Code of Ukraine). If copyright is infringed — a statement under Art. 56 of the Law of Ukraine on Copyright and Related Rights: a legal entity files it only through an advocate or a patent attorney. The site owner has 48 hours to remove the material or send a reasoned refusal; if the owner does not react, we file the notice with the hosting provider, which forwards it to the owner within 24 hours — and if the owner still does nothing within 24 hours, the host restricts access itself.
  4. Registrant data. For a gTLD domain — a disclosure request to the accredited registrar under the Registration Data Policy: receipt is confirmed within 2 working days, the reply comes within 30 calendar days of the acknowledgment save for exceptional circumstances; or through RDRS — ICANN's voluntary system, which not all registrars have joined. For .UA and other country zones — under the registry's rules and the law.
  5. If the domain itself is valuable. A UA-DRP or UDRP complaint to have the domain transferred to you — on the trademark protection in domains page.

What matters

The registrar may refuse if the infringement is not obvious — for instance, the site resembles yours but does not copy it. Then we work through the host, the browsers (Google Safe Browsing) and the payment systems that serve the fraudsters. A registered trademark makes every complaint stronger; if there is none, we rely on copyright and the fact of fraud — and advise you to register the mark.

A complaint stops the harm but does not transfer the domain to you: for that there are UA-DRP and UDRP. Timelines depend on third parties — from hours at Safe Browsing to weeks if the host is abroad. According to DNSRF, 21% of abuse complaints are acted on within a day and 48% within a week (as of October 2026). We do not attack the site and do not negotiate with fraudsters — lawful procedures only.

Send the site address — we will tell you where and what to file, within one working day.

What it costs

Rapid assessment and action planevidence capture (timestamped screenshots, RDAP, hosting, certificate) and the list of recipients; within one business day
on request
Reports to the registrar, host and platforms — one domainthe registrar's abuse contact, the host or CDN, NetBeacon, Google Safe Browsing, APWG, social networks, marketplaces; follow-ups for 30 days included
on request
Notice under Art. 56 of the Copyright Actfiled through a patent attorney or an advocate; the site owner has 48 hours, then the host restricts access
on request
A cyberpolice or CERT-UA complaint and its follow-upArticles 190, 361, 229 of the Criminal Code; investigation timelines are not guaranteed
on request
Registrant data disclosure requestto the registrar under the Registration Data Policy (acknowledged within 2 business days, answered within 30 days) or through RDRS
on request
Brand protection retainer: monitoring and takedownmonthly; the number of domains and platforms by agreement
on request

The price is agreed before we begin, depending on the scope of work. Official fees and duties are paid separately.

Not sure where to start?

Leave your phone number — we will call back at a convenient time, answer your questions and suggest the right procedure. The consultation is free.