Celonis SE successfully reclaimed the domain appcelonis.com after a WIPO panel ruled that the respondent engaged in bad faith by impersonating the company. The respondent had used the complainant’s address on a site designed to mimic official business services, leading to a mandatory domain transfer.
Case Snapshot
| Case Number | D2026-2291 |
|---|---|
| Complainant | Celonis SE |
| Respondent | Matthew Roberts |
| Disputed Domain | appcelonis.com |
| Threat Tactic | Corporate Impersonation |
| Decision Date | 2026-07-15 |
| Panelist | WiIliam A. Van Caenegem |
| Outcome | Transfer |
| Official Source | https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2291 |
Risks of Corporate Impersonation Through Brand-Plus-Keyword Domains
The unauthorized registration and use of ‘appcelonis.com’ highlights a sophisticated risk wherein respondents leverage brand-plus-keyword tactics to facilitate corporate impersonation. By appending the term ‘app’ to the CELONIS trademark, the respondent crafted a domain name specifically designed to deceive internet users, customers, and business partners into believing the site was an official digital platform offered by Celonis SE. The danger here extends beyond simple traffic diversion, as the associated website actively reproduced the complainant’s legitimate physical address. This calculated inclusion of verified corporate information functions as a foundational element of a fraudulent scheme, designed to project an artificial veneer of authority that effectively lowers the guard of unsuspecting stakeholders.
Such impersonation tactics threaten to erode brand equity and diminish customer trust by creating a false sense of legitimacy in a domain that is entirely unaffiliated with the complainant. When a domain is used to offer services mirroring the business execution management and process intelligence solutions provided by the official entity, the threat to reputation is substantial. By presenting a fraudulent interface as an authentic business tool, the respondent creates a significant vector for potential social engineering or misinformation campaigns targeting investors and clients. The reliance on the complainant’s own physical contact data to validate this deception confirms that the domain was not merely a passive holding, but an active, malicious effort to misappropriate the company’s digital identity.
Legal Analysis of Confusing Similarity, Lack of Rights, and Bad Faith
The panel determined that the disputed domain ‘appcelonis.com’ is confusingly similar to the Complainant’s CELONIS trademark. Under established UDRP jurisprudence, the inclusion of the prefix ‘app’—a common descriptive term—does not distinguish the domain from the protected mark. The panel found that the Complainant’s mark remains clearly recognizable, and the mere addition of a generic descriptor fails to mitigate the risk of consumer confusion. Because Celonis SE holds multiple global registrations and established a primary online presence via ‘celonis.com’ in 2011, the likelihood of public deception is significant.
Regarding rights and legitimate interests, the Respondent failed to provide any evidence of a bona fide offering. The Complainant confirmed no authorization or affiliation exists between the parties. Given the Respondent is not commonly known by the name ‘appcelonis,’ and given the nature of the content hosted on the site, the panel concluded the Respondent lacks a legitimate interest. The use of the brand-plus-keyword format is inherently misleading, designed specifically to deceive users into believing the site serves as an official extension of the Complainant’s software platform.
Bad faith was conclusively established by the Respondent’s efforts to pass off the site as an official company presence. The panel highlighted the critical fact that the website reproduced the Complainant’s exact physical address, a deliberate act to foster a false impression of authority. This conduct proves the Respondent possessed actual knowledge of the Complainant’s brand at the time of registration. By mimicking the Complainant’s address and services, the Respondent engaged in a clear attempt to hijack brand equity, further exacerbated by their failure to respond to the formal complaint.
Strategic Analysis: Leveraging Evidence of Impersonation
The success of the Celonis SE strategy relied on demonstrating the respondent’s intentional effort to create a false aura of legitimacy. By highlighting that the disputed domain name, ‘appcelonis.com’, merely appended a descriptive prefix to a globally recognized trademark, the complainant established clear confusing similarity. However, the most persuasive element of the evidence was the respondent’s reproduction of the complainant’s physical corporate address on the site. This specific action served as definitive proof that the respondent had actual knowledge of the complainant’s business and was actively engaged in a deceptive scheme to impersonate the legitimate brand to potential customers, investors, and business partners.
From a procedural standpoint, the case illustrates the effectiveness of focusing on the substantive misuse of brand assets rather than relying solely on the domain registration itself. By documenting that the site offered services mimicking the complainant’s core business model—process intelligence and enterprise software—the complainant successfully rebutted any potential argument of legitimate interest or fair use. The panel’s decision to order a transfer was strengthened by the respondent’s failure to offer a defense, yet the strength of the complainant’s factual narrative regarding the calculated use of their address and business identity effectively removed any ambiguity, proving the registration and use of the domain constituted bad faith in alignment with UDRP standards.
Practical Recommendations
- Monitor for ‘brand + utility’ prefixes (e.g., ‘app’, ‘login’, ‘portal’) using automated brand protection software to detect unauthorized site mimicry early.
- Perform periodic ‘reverse address’ searches in WHOIS and website footer scans to identify if bad actors are hijacking your physical corporate address to establish false authority.
- Implement a defensive registration strategy for high-risk variants, specifically focusing on common application-related prefixes that align with your digital ecosystem.
- Document evidence of potential confusion, such as screenshots of deceptive websites reproducing your official address, to strengthen the ‘bad faith’ argument in expedited UDRP proceedings.
- Utilize UDRP filing as a primary enforcement tool when a respondent defaults, as the panel is more likely to grant a transfer when the domain structure and site content explicitly mimic your brand to deceive users.
Frequently Asked Questions (FAQ)
Why did the WIPO panel rule that ‘appcelonis.com’ was confusingly similar to the Celonis trademark?
The panel determined that the disputed domain name incorporates the CELONIS trademark in its entirety. The addition of the generic prefix ‘app’ does not mitigate the risk of consumer confusion, as users are likely to perceive the domain as an official, authorized mobile application or service platform of the Complainant.
What evidence proved the respondent had no rights or legitimate interests in the domain?
The Complainant confirmed that the Respondent is neither sponsored by nor affiliated with Celonis. The Respondent made no authorized use of the trademark and, by attempting to pass off the site as an official company resource, failed to demonstrate any legitimate non-commercial or fair use of the domain.
How was bad faith established in the case against Matthew Roberts?
Bad faith was demonstrated by the Respondent’s reproduction of the Complainant’s actual business address on the website. This, combined with the offer of similar services to those provided by Celonis, indicated clear knowledge of the Complainant and a deliberate intent to create a false impression of authority to mislead the public.
What is the practical outcome of this UDRP decision for Celonis SE?
The WIPO panel ordered the transfer of ‘appcelonis.com’ to Celonis SE. This successfully mitigates the immediate risk of brand dilution and corporate impersonation, preventing the Respondent from using the deceptive platform to conduct social engineering or fraud against Celonis customers.
Facing corporate impersonation through a domain?
Protect your brand integrity and client trust by identifying and remediating unauthorized domains that mirror your digital identity or business address.
This case note is for informational purposes only and is not legal advice.



