By Steve Levy
A recent UDRP decision offers a warning about the risks created when a company registers a domain name that incorporates a famous trademark for arguably well-intentioned purposes. The case concerns the domain name <equifax-credit.com>, which the Respondent, a cybersecurity company, claimed it registered for possible use in simulated phishing exercises offered to its corporate clients. Although the domain name never resolved to an active website, the Panel found that the registration and intended use still amounted to bad faith under the Policy.
The Panel accepted that the Respondent operates a legitimate business that provides security awareness training, including simulated phishing attacks. It also acknowledged that these exercises often rely on realistic content. But the Panel drew a firm line at the use of a well-known trademark like EQUIFAX in a domain name that the Respondent held for its own commercial purposes. The Panel emphasized that the Respondent’s business model depends on selling training services to customers and that the disputed domain name was part of the content library that supports those services. In other words, the domain name was not held for a neutral, noncommercial, or informational purpose. It was held because it had value within a for-profit training platform. That was enough for the Panel to conclude that the Respondent had gone too far and used the Equifax trademark for its own commercial gain.
The Panel also rejected the Respondent’s argument that its use was harmless because the domain name did not resolve to an active website and because simulated phishing emails would immediately inform users that the exercise was part of a training program. The Panel noted that the Policy does not require a domain name to resolve to an active site in order to find bad faith. The mere act of registering a domain name that incorporates a famous trademark without permission can, itself, constitute bad faith when the registrant intends to use the domain name in a manner connected to its own business.
Perhaps the most important part of the decision is the Panel’s concern about the broader implications of allowing cybersecurity companies to register famous trademarks for training purposes. The Panel warned that accepting the Respondent’s rationale could create a slippery slope. If one company could register a well-known mark for simulated phishing exercises, then countless others could do the same or at least claim that they are doing so. The result could lead to widespread ownership of domain names that mimic major brands, all justified under the banner of “training”. The Panel found that such a practice would undermine the stability of the domain name system and erode the rights of trademark owners.
Although a challenging and nuanced case, this decision sends the message that security training companies may need realistic scenarios, but they cannot appropriate famous trademarks in domain names to support their commercial services without the permission of those brand owners.