Squire Technologies, Inc. successfully recovered the domain getsquireapp.com after the Respondent used it to impersonate the brand in a phishing campaign via SMS. The WIPO panel ordered the transfer of the domain due to bad faith use and lack of legitimate interests.
Case Snapshot
| Case Number | D2026-3152 |
|---|---|
| Complainant | Squire Technologies, Inc. |
| Respondent | Stefon Barnes |
| Disputed Domain | getsquireapp.com |
| Threat Tactic | Phishing and Email Fraud |
| Decision Date | 2026-09-02 |
| Panelist | Harrie R. Samaras |
| Outcome | Transfer |
| Official Source | https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-3152 |
Facing Unauthorized Domain Registrations or Brand Abuse?
Our domain dispute attorneys represent trademark owners and businesses worldwide before WIPO, Forum (NAF), and CAC. Explore our Domain Name Disputes and Enforcement & Takedowns services, or request a free case evaluation.
Request Case EvaluationDirect Phishing and Impersonation Risks to Brand Trust
The registration and active use of the domain ‘getsquireapp.com’ by the Respondent highlights a significant risk to Squire Technologies’ customer base through coordinated SMS-based phishing. By impersonating the official SQUIRE brand and visual identity, the Respondent attempted to deceive users with fraudulent offers, specifically promising $500 in ‘Squire Business Credits’ to solicit engagement with malicious links. This tactic leverages mobile messaging as an attack vector, bypassing traditional email security filters to target users directly, creating a high-risk environment where unauthorized parties can harvest sensitive information or facilitate illicit financial transactions related to the brand’s payment processing ecosystem.
The potential for reputational damage is compounded when such domains are used to mimic legitimate services, as seen by the subsequent ‘Warning | Suspected Phishing’ browser notifications now associated with the disputed domain. Such labels serve as a stark indicator to consumers that the brand has been compromised, even if the activity was perpetrated by an external bad actor. Because Squire Technologies processes over USD 1 billion in payments, any association with fraudulent activity or phishing warnings threatens to erode long-term customer trust. The lack of response from the Respondent in this proceeding suggests that the domain was likely part of a disposable infrastructure, emphasizing the necessity for rapid, proactive monitoring to detect and mitigate these ‘brand-mimicking’ sites before they can reach the broader user base.
Panel Reasoning: Navigating Confusing Similarity, Legitimate Interests, and Bad Faith
In evaluating the first UDRP criterion, the Panel applied the standard threshold test for confusing similarity, noting that the disputed domain name ‘getsquireapp.com’ incorporates the Complainant’s SQUIRE trademark in a manner that creates a clear association. By comparing the Mark directly with the disputed domain, the Panel concluded that the inclusion of the term ‘app’ fails to mitigate the likelihood of confusion, effectively establishing the Complainant’s standing to proceed with the dispute.
Regarding the second element, the Panel addressed the Respondent’s lack of rights or legitimate interests. The record established that Squire Technologies, Inc. never licensed or authorized the use of the SQUIRE mark by the Respondent. Furthermore, the Respondent offered no evidence of a legitimate noncommercial or fair use of the domain, nor were they commonly known by the name. The absence of any documented connection to the Complainant’s trade name or services reinforced the conclusion that the Respondent’s registration was unauthorized and inherently lacked a legitimate commercial basis.
The third element, bad faith, was definitively established by the Respondent’s active use of the domain to facilitate deceptive phishing campaigns. By impersonating the Complainant’s official website and soliciting sensitive user information via deceptive SMS offers of ‘business credits,’ the Respondent clearly sought to mislead consumers. The Panel’s findings were bolstered by the fact that the Respondent failed to file a response to the complaint. Given the current ‘suspected phishing’ warning now associated with the domain, the Panel confirmed that the domain was both registered and used in bad faith to exploit the brand’s reputation for illicit gain.
Strategic Enforcement Against SMS-Based Phishing and Brand Impersonation
Squire Technologies, Inc. effectively leveraged its established trademark portfolio to secure the transfer of the disputed domain getsquireapp.com. The complainant’s strategy relied on a precise demonstration that the respondent’s use of the domain, combined with deceptive SMS marketing offering fake ‘business credits,’ directly mimicked the company’s legitimate brand identity. By mapping the disputed domain to its U.S. Trademark Registration No. 5,169,439 for the ‘SQUIRE’ mark, the complainant established a clear case of bad-faith registration. The panel accepted this argument, noting that the respondent’s addition of the descriptive term ‘app’ to the core trademark did not mitigate the confusing similarity, but rather reinforced the intent to impersonate the complainant’s mobile-centric software services.
The successful outcome was reinforced by the complainant’s proactive documentation of the respondent’s unauthorized activity, which included phishing warnings and evidence of impersonation that the registrar failed to resolve independently. By providing a clear narrative of how the domain functioned as the landing page for an SMS phishing campaign, the complainant successfully shifted the burden of proof to the respondent. Because the respondent failed to provide a defense to these claims, the panel was able to definitively conclude a lack of legitimate interests. This case illustrates the efficacy of using clear, evidence-backed links between mobile-targeted phishing tactics and specific trademark infringements to streamline UDRP proceedings.
Practical Recommendations
- Implement a defensive registration strategy by securing common ‘brand-app’ and ‘get-brand’ variations across multiple TLDs to preemptively block phishers from using these predictable naming patterns.
- Integrate brand protection monitoring with SMS and messaging intelligence platforms to identify deceptive URLs in text-based communications before they scale into wider customer phishing campaigns.
- Develop an automated ‘Cease and Desist’ and registrar-takedown protocol triggered specifically by domains impersonating core service URLs or displaying branded assets, reducing reliance solely on the lengthy UDRP process.
- Audit all customer-facing communications to establish an official, authenticated channel list, educating users that legitimate promotional offers will never originate from domains outside the company’s verified primary domain.
- Prioritize UDRP filings for domains exhibiting clear phishing markers—such as impersonated login pages or fraudulent credit offers—as these facilitate rapid findings of bad faith and streamline the transfer of disputed assets.
Frequently Asked Questions (FAQ)
Why was the domain ‘getsquireapp.com’ considered confusingly similar to the Complainant’s brand?
The WIPO panel found that the domain incorporated the SQUIRE trademark in its entirety and added the term ‘app,’ which directly relates to the mobile software and business management services provided by Squire Technologies, Inc., thereby creating a high risk of consumer confusion.
How did the panel determine that the Respondent lacked rights or legitimate interests in the domain?
The panel noted that Squire Technologies, Inc. did not license or authorize the Respondent to use the SQUIRE mark. Furthermore, the Respondent had no registered trademark rights in the term ‘squire’ and failed to provide any evidence of a legitimate noncommercial or fair use of the domain.
What evidence was used to prove the domain was registered and used in bad faith?
Bad faith was evidenced by the Respondent’s use of deceptive SMS messages to lure customers to a phishing site that impersonated the Complainant’s official website, promising fake ‘Squire Business Credits’ to harvest sensitive user information.
What is the practical takeaway from this case regarding brand protection and SMS-based threats?
This case highlights the growing danger of ‘domain-plus-keyword’ impersonation where attackers combine a brand name with terms like ‘app’ to facilitate phishing. The outcome underscores the necessity of proactive domain monitoring and the importance of documenting evidence of fraudulent SMS-linked redirects to secure a successful UDRP transfer.
Concerned about fake email or invoice fraud?
Protect your customers from fraudulent SMS and phishing campaigns that mimic your brand identity. Learn how UDRP proceedings can neutralize deceptive domains used in impersonation attacks.
This case note is for informational purposes only and is not legal advice.



