20 August, 2026

Addressing B2B Email Fraud and Brand Impersonation Risks

UDRP Cases

Rolls-Royce Plc successfully recovered two typosquatted domains, rolls-roycs.com and rolls-royse.com, through a WIPO UDRP process. The panel ordered the transfer after finding the respondent used these domains to impersonate company employees and defraud business partners.

Case Snapshot

Case Number D2026-3227
Complainant Rolls-Royce Plc
Respondent Name RedactedName Redacted
Disputed Domain
rolls-roycs.comrolls-royse.com
Threat Tactic Phishing and Email Fraud
Decision Date 2026-08-17
Panelist Fabrizio Bedarida
OutcomeTransfer
Official Source https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-3227

Threats to Business Integrity through Impersonation and B2B Fraud

The use of typosquatted domains such as ‘rolls-roycs.com’ and ‘rolls-royse.com’ poses a severe risk to corporate supply chain security and partner trust. By registering these domains, bad actors engaged in targeted impersonation, utilizing the names of actual Rolls-Royce employees to send deceptive communications to the company’s suppliers and business partners. This tactic extends beyond simple brand dilution, as it leverages the trusted identities of internal staff to bypass standard security filters and deceive legitimate stakeholders into interacting with malicious infrastructure.

This campaign highlights a sophisticated effort to compromise B2B relationships through the unauthorized appropriation of employee identities and corporate reputation. The respondent’s actions, which included leveraging identical technical infrastructure—such as shared IP addresses, ASNs, and name servers—across multiple domains, demonstrate a coordinated effort to facilitate fraud. Such activities not only threaten to disrupt commercial operations but also force organizations to expend significant resources to identify, monitor, and mitigate the damage caused by actors operating under the guise of their own workforce and brand equity.

Strategic Enforcement Against Typosquatting and Business Email Impersonation

The success of the Rolls-Royce Plc strategy centered on mapping disparate technical indicators to demonstrate a unified bad faith campaign. By meticulously documenting that the disputed domains—rolls-roycs.com and rolls-royse.com—shared identical infrastructure, including IP addresses, Autonomous System Numbers (ASN), and name servers, the Complainant effectively neutralized any argument of independent or benign registration. This technical convergence, coupled with the temporal proximity of the domain registrations, provided the Panel with a clear evidentiary foundation to conclude that the domains were under common control and established for a coordinated, malicious purpose rather than legitimate commercial activity.

Furthermore, the Complainant reinforced its legal standing by providing direct evidence of identity theft and corporate impersonation targeting its business ecosystem. By demonstrating that the Respondent actively leveraged the names of actual Rolls-Royce employees to deceive suppliers and partners via fraudulent emails, the Complainant transformed the case from a standard trademark dispute into a critical matter of supply chain security. This evidence of passing off and B2B fraud proved essential, leading the Panel to recognize the severity of the threat and affirm that such actions are definitive evidence of registration and use in bad faith, ultimately necessitating the immediate transfer of the domains.

Practical Recommendations

  • Implement proactive domain monitoring tools to identify newly registered typosquatted variants of primary brand names immediately upon registration.
  • Correlate domain registration data with technical infrastructure indicators—such as shared IP addresses, ASN, and name servers—to proactively flag potential multi-domain malicious campaigns.
  • Establish clear protocols for documenting and preserving deceptive email headers and content from impersonation attempts to provide actionable evidence for UDRP submissions.
  • Adopt DMARC, SPF, and DKIM protocols rigorously to prevent threat actors from successfully leveraging registered typosquatted domains to spoof organizational email addresses.
  • Conduct periodic supplier and business partner education sessions to verify the authenticity of email communication domains, especially for high-stakes business processes or financial transactions.

Frequently Asked Questions (FAQ)

Why were the domains rolls-roycs.com and rolls-royse.com considered confusingly similar to the Rolls-Royce trademark?

The panel determined the disputed domain names were typosquatted versions of the ROLLS-ROYCE trademark. By omitting or altering characters, the respondent created domains highly likely to deceive users, satisfying the UDRP’s standing requirement for confusing similarity.

How did the respondent attempt to establish legitimacy, and why did the panel reject it?

The respondent provided no defense, and the panel found no evidence of rights or legitimate interests. The domains were used to impersonate Rolls-Royce employees, which the panel ruled cannot constitute a bona fide offering of goods or services or fair use.

What evidence was used to prove that the domains were registered and used in bad faith?

Evidence of bad faith included the intentional use of the domains to send fraudulent emails to business partners and suppliers. The panel also noted technical evidence of common control—such as shared IP addresses, ASN, and name servers—confirming a coordinated campaign of passing off and impersonation.

What was the broader tactical objective of this domain registration campaign?

The registrant aimed to facilitate B2B fraud through executive impersonation. By using names of actual Rolls-Royce employees to register the domains, the attacker sought to leverage the trusted brand reputation to manipulate the company’s supply chain partners.

Concerned about fake email or invoice fraud?

Rolls-Royce recently neutralized a campaign where typosquatted domains were used to impersonate internal staff and defraud business partners. Protect your supply chain and corporate identity by proactively monitoring for look-alike domains and unauthorized use of employee personas.

Request phishing analysis

Contact us
We will find the best solution for your business

    Thank you for your request!
    We will contact you within 5 hours!
    Image
    This site uses cookies to improve your experience. By continuing, you agree to our Privacy Policy.

    Privacy settings

    When you visit websites, they may store or retrieve data in your browser. This storage is often required for basic website functionality. Storage may be used for marketing, analytics and site personalization purposes, such as storing your preferences. Privacy is important to us, so you can disable certain types of storage that may not be necessary for the basic functioning of the website. Blocking categories may affect the performance of the website.

    Manage settings


    Necessary

    Always active

    These cookies are necessary for the website to function and cannot be disabled in our systems. They are usually only set in response to actions you take that constitute a request for services, such as adjusting your privacy settings, logging in, or filling out forms. You can set your browser to block these cookies or notify you about them, but some parts of the site will not work. These cookies do not store any personal information.

    Marketing

    These elements are used to show you advertising that is more relevant to you and your interests. They can also be used to limit the number of ad views and measure the effectiveness of advertising campaigns. Advertising networks usually place them with the permission of the site operator.

    Personalization

    These elements allow the website to remember your choices (such as your username, language or region you are in) and provide enhanced, more personalized features. For example, a website may provide you with local weather forecasts or traffic news by storing data about your current location.

    Analytics

    These elements help the website operator understand how their website works, how visitors interact with the site and whether there may be technical problems. This type of storage usually does not collect information that identifies the visitor.