Morrison & Foerster LLP successfully challenged the domain rmofo.com after the respondent used it to send fraudulent emails impersonating the law firm’s employees. The WIPO panel ordered the transfer of the domain, citing the respondent’s lack of legitimate interests and bad faith usage.
Case Snapshot
| Case Number | D2026-2507 |
|---|---|
| Complainant | Morrison & Foerster LLP |
| Respondent | Gary Mercy |
| Disputed Domain | rmofo.com |
| Threat Tactic | Phishing and Email Fraud |
| Decision Date | 2026-07-23 |
| Panelist | Stefan Naumann |
| Outcome | Transfer |
| Official Source | https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2507 |
Business and Reputation Risks in Targeted Email Impersonation
The registration of the domain ‘rmofo.com’ highlights a precise threat to the operational integrity and client trust of Morrison & Foerster LLP. By utilizing a domain that closely mirrors the firm’s established digital identity, the respondent engaged in sophisticated impersonation tactics targeting the complainant’s business partners. These fraudulent communications, which incorporated the names and signature blocks of actual employees, demonstrate how bad-faith actors leverage typosquatting to create a veneer of professional legitimacy, effectively bypassing standard email security filters that might otherwise flag external or unrecognized domains.
Such impersonation poses severe risks beyond immediate identity theft, including the long-term erosion of client relationships and potential regulatory or ethical exposure resulting from unauthorized external communications. When business partners receive fraudulent messages originating from a domain designed to mimic a trusted legal entity, the resulting confusion can lead to the exposure of confidential information or, in more extreme scenarios, financial loss. Because the complainant operates globally across the United States, Asia, and Europe, the reputational impact of such impersonation is amplified, necessitating robust domain monitoring to detect and mitigate similar threats before they can compromise sensitive professional engagements.
Panel Reasoning: Evaluating Confusion, Legitimate Interests, and Malicious Intent
To succeed in a UDRP proceeding, the Complainant must satisfy all three criteria under paragraph 4(a) of the Policy. In this matter, the Panel confirmed that the disputed domain name, ‘rmofo.com’, is confusingly similar to the Complainant’s established ‘MOFO’ trademark. The inclusion of the ‘r’ prefix does not sufficiently distinguish the domain from the Complainant’s mark, particularly when the domain is used to facilitate digital impersonation. The Panel recognized the Complainant’s rights in its U.S. trademark registrations, which date back to 2001, effectively establishing clear priority and a recognized brand identity that the Respondent sought to mimic.
Regarding the second element, the Panel determined that the Respondent lacked any rights or legitimate interests in the disputed domain. The evidence demonstrated that the Respondent was not commonly known by the name, nor was there any evidence of a bona fide offering of goods or services. The use of the domain solely for impersonating the Complainant’s employees in communications with business partners serves as a primary indicator that the Respondent’s activities were unauthorized and illegitimate, failing to meet the criteria for legitimate interest under the Policy.
The finding of bad faith was predicated on the specific manner in which the domain was used following its registration. By employing the domain to send fraudulent emails—complete with the misappropriated names and signature blocks of the Complainant’s employees—the Respondent actively attempted to deceive the Complainant’s business partners. The Panel concluded that this conduct constitutes bad faith, as it demonstrates a clear intent to capitalize on the Complainant’s reputation for the purpose of professional impersonation. This pattern of usage, aimed at disrupting business relationships and compromising firm security, provides sufficient grounds for the transfer of the domain name to the Complainant.
Strategic Enforcement Against Domain-Based Corporate Impersonation
The success of the Morrison & Foerster LLP strategy centered on providing concrete evidence of bad faith use linked directly to the firm’s protected MOFO trademarks. By documenting that the disputed domain, rmofo.com, was utilized to send fraudulent emails—specifically incorporating the actual names and signature blocks of the firm’s employees—the complainant established a clear nexus between the domain registration and malicious impersonation. This approach effectively neutralized any potential argument for legitimate interest, as the panel recognized the activity as a deceptive practice rather than a bona fide offering of goods or services. The evidence of trademark seniority, supported by registrations dating back to 2001, provided a robust foundation that allowed the complainant to satisfy the UDRP criteria for confusing similarity.
From a procedural standpoint, the case illustrates the efficacy of rapid action when a domain is weaponized for social engineering. By filing the complaint shortly after the May 13, 2026, registration date, the firm minimized the duration the domain remained under the respondent’s control. The panel’s reliance on the documented pattern of phishing and the respondent’s subsequent default demonstrates that aggressive, evidence-backed submissions are highly effective in securing the transfer of domains involved in active fraud. For brand owners, this case highlights that the combination of verifiable trademark usage and direct documentation of identity theft is sufficient to overcome jurisdictional hurdles and achieve a favorable UDRP outcome without needing to quantify exact financial damages.
Practical Recommendations
- Deploy DMARC, SPF, and DKIM protocols across all corporate domains to authorize legitimate email traffic and make it harder for attackers to spoof firm-affiliated email addresses.
- Implement proactive domain monitoring services that trigger alerts for new registrations containing brand variants or ‘typosquats’ to initiate early UDRP or takedown actions before fraud is executed.
- Conduct regular cybersecurity training for business partners and clients to identify red flags in email communications, such as suspicious sender domains that deviate slightly from the official firm URL.
- Maintain a clear record of internal employee signature blocks and official corporate communication channels to facilitate the rapid collection of evidence for UDRP proceedings should impersonation occur.
- Leverage the UDRP ‘bad faith’ precedent established in cases like D2026-2507 to expedite domain transfer requests, focusing on documented instances where the domain is used specifically for fraudulent impersonation.
Frequently Asked Questions (FAQ)
Why was the domain ‘rmofo.com’ considered confusingly similar to the trademark owned by Morrison & Foerster LLP?
The panel determined that the disputed domain incorporated the Complainant’s well-established ‘MOFO’ trademark, adding only the prefix ‘r’. This structure created a clear potential for confusion, as it closely mirrors the branding used by the firm in its international business activities.
What evidence confirmed that the Respondent lacked legitimate rights or interests in the domain?
The Respondent failed to provide any evidence of rights or legitimate interests. The panel noted that the Respondent was not commonly known by the name ‘rmofo’ and was not authorized by Morrison & Foerster LLP to use their trademark, rendering the registration unauthorized.
How did the panel establish that the domain was registered and used in bad faith?
Bad faith was demonstrated by the actual use of ‘rmofo.com’ to send fraudulent emails to the firm’s business partners. By utilizing the names and signature blocks of Morrison & Foerster LLP employees to impersonate the firm, the Respondent clearly engaged in malicious activity that does not constitute a bona fide offering of goods or services.
What was the tactical outcome of this UDRP proceeding for the complainant?
Following a rapid 28-day resolution process, the sole panelist ordered the transfer of ‘rmofo.com’ to Morrison & Foerster LLP. This successful action effectively halted the active impersonation campaign and mitigated further risk to the firm’s professional reputation and partner trust.
Is your firm being impersonated in email communications?
Protect your professional reputation and prevent social engineering attacks. Our experts can help you assess and address domain-based brand fraud like that seen in the rmofo.com case.
This case note is for informational purposes only and is not legal advice.



