International Business Machines Corporation successfully recovered five domains (bia-ibm.com, etc.) used by a respondent to impersonate the brand for cryptocurrency solicitation. The panel ordered the transfer of all domains after finding bad faith use of the IBM trademark and logo.
Case Snapshot
| Case Number | D2026-3298 |
|---|---|
| Complainant | International Business Machines Corporation |
| Respondent | lei lei |
| Disputed Domain | bia-ibm.combie-ibm.combio-ibm.combir-ibm.combit-ibm.com |
| Threat Tactic | Corporate Impersonation |
| Decision Date | 2026-09-07 |
| Panelist | Benoit Van Asbroeck |
| Outcome | Transfer |
| Official Source | https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-3298 |
Facing Unauthorized Domain Registrations or Brand Abuse?
Our domain dispute attorneys represent trademark owners and businesses worldwide before WIPO, Forum (NAF), and CAC. Explore our Domain Name Disputes and Enforcement & Takedowns services, or request a free case evaluation.
Request Case EvaluationStrategic Risks of Brand Impersonation and Cryptocurrency Fraud
The registration of five domain names incorporating the IBM trademark, such as ‘bia-ibm.com’ and ‘bit-ibm.com’, highlights a severe corporate impersonation threat designed to misappropriate established brand equity. By deploying the Complainant’s proprietary eight-bar logo as a favicon and prominently featuring it on sites soliciting cryptocurrency service sign-ups, the Respondent created a deceptive digital environment. This tactic poses an immediate risk to consumer trust, as users are led to believe that these unauthorized financial offerings are sanctioned or endorsed by the Complainant, potentially exposing them to phishing or other sophisticated fraudulent activities.
Beyond immediate consumer impact, this case demonstrates how brand assets are exploited to facilitate commercial gain through illicit association. The use of high-profile trademarked identity, combined with the Registrar verification findings showing inconsistent contact information, underscores the challenges posed by anonymous bad actors utilizing domain portfolios for brand dilution. While two domains remained inactive, their registration as part of a larger cluster indicates a persistent effort to mirror the Complainant’s brand architecture, necessitating vigilant, proactive monitoring to detect such variations before they can be leveraged to compromise corporate reputation.
Legal Analysis: Confusing Similarity, Lack of Rights, and Bad Faith Registration
In evaluating the threshold for confusing similarity, the panel determined that the inclusion of the IBM trademark in its entirety, paired with additional letters and hyphens, failed to distinguish the disputed domain names from the Complainant’s established marks. Consistent with standard UDRP precedent, the panel disregarded the generic Top-Level Domain (.com) as part of the substantive assessment. By incorporating the trademark alongside variations such as ‘bia’, ‘bie’, and ‘bit’, the Respondent created a high risk of consumer confusion regarding the source and affiliation of the domain names.
The Complainant successfully established that the Respondent possesses no rights or legitimate interests in the disputed domain names. The evidence confirmed that the Complainant never authorized the use of its trademark or the registration of domains containing the ‘IBM’ designation. Furthermore, the Respondent was not commonly known by these names, nor was there any indication of a bona fide offering of goods or services prior to the notice of the dispute, as the sites were clearly established to impersonate the Complainant’s brand identity rather than pursue a legitimate commercial enterprise.
The panel found clear evidence of bad faith, noting that the Respondent should have been aware of the Complainant’s global trademark rights at the time of registration. The combination of using the Complainant’s specific eight-bar logo as a favicon and on-site imagery, alongside the promotion of cryptocurrency services, demonstrated a deliberate intent to solicit users through deception. Because the Respondent failed to provide a defense or justify the use of the trademarks, the panel concluded that the registration and active misuse of these domains were intended to exploit the IBM reputation for unauthorized commercial gain, warranting the transfer of all five domain names.
Strategic Enforcement: Leveraging Asset Mimicry and Procedural Agility
The Complainant’s successful strategy rested on documenting granular evidence of brand impersonation beyond mere domain registration. By cataloging the respondent’s specific unauthorized use of the iconic eight-bar logo as a website favicon and throughout site imagery, the Complainant provided the panel with irrefutable proof of intent to deceive. This visual evidence of brand misappropriation, combined with the solicitation of users to ‘Sign up now’ for cryptocurrency services, established a clear pattern of bad faith that effectively linked the domain portfolio to a broader phishing or fraud operation. Such evidentiary rigor turns a generic typosquatting dispute into a compelling narrative of corporate identity theft, leaving little room for the respondent to claim any legitimate interest in the domains.
Procedurally, the Complainant demonstrated operational agility by responding promptly to registrar verification notices. When the registrar disclosed registrant data that conflicted with the initial complaint details, the Complainant quickly filed an amendment to ensure the correct party was addressed. This proactive management of administrative hurdles ensured that the procedural history remained clean and that the panel could move directly to a substantive review. By efficiently correcting the respondent information, the Complainant avoided potential delays or jurisdictional challenges, allowing for a swift resolution that effectively halted the ongoing misuse of the IBM brand and its association with unauthorized financial solicitation.
Practical Recommendations
- Implement proactive ‘new registration’ monitoring alerts for domain strings containing ‘IBM’ plus common prefixes or suffixes to detect typosquatting before active phishing sites are deployed.
- Utilize automated visual brand monitoring tools that scan for the unauthorized use of proprietary assets, specifically the ‘eight-bar’ logo and company favicons, across external domain registries.
- Establish a standardized response protocol for UDRP filings that immediately triggers a registrar verification request to unmask underlying registrants hiding behind privacy/proxy services.
- Prioritize the takedown of domains displaying infringing content, while simultaneously pursuing the transfer of associated, currently inactive domains in the same batch to prevent future ‘re-activation’ of the phishing scheme.
- Incorporate a ‘brand-impersonation’ assessment into digital risk reporting, focusing on domain-based cryptocurrency solicitation as a high-priority threat vector for customer fraud.
Frequently Asked Questions (FAQ)
Why were the domains bia-ibm.com, bie-ibm.com, bio-ibm.com, bir-ibm.com, and bit-ibm.com found to be confusingly similar to the IBM trademark?
The WIPO panel determined that these domains incorporate the famous IBM trademark in its entirety. The inclusion of hyphenated prefixes (e.g., ‘bia-‘, ‘bie-‘) does not mitigate the confusing similarity, as the core IBM brand remains the primary identifier in the domain string.
What evidence confirmed the Respondent’s bad faith in this case?
Bad faith was established through the Respondent’s intentional unauthorized use of the IBM eight-bar logo as a website favicon and primary site imagery. Furthermore, the active domains were used to host fraudulent cryptocurrency service promotions, signaling a clear intent to capitalize on IBM’s reputation to deceive consumers.
Did the Respondent possess any legitimate rights or interests in these domain names?
No. The panel found that the Respondent had no authorization from IBM to use the trademark. The Respondent was not commonly known by these names, nor were they using the domains for a legitimate non-commercial or fair use, as evidenced by the deceptive sign-up solicitations displayed on the sites.
What tactical lesson does this case provide regarding brand asset monitoring?
The case highlights the risk of ‘brand-plus-keyword’ variations and the importance of monitoring beyond just primary domain names. By identifying the misuse of specific brand assets like favicons and logos, IBM was able to provide compelling evidence of impersonation, leading to the successful transfer of all five domains.
Is your brand being leveraged for unauthorized cryptocurrency schemes?
Corporate impersonation often involves the misuse of official assets, such as logos and favicons, to build false credibility for illicit financial services. If you have identified domains that mimic your identity, our team can assist with a formal UDRP eligibility assessment.
This case note is for informational purposes only and is not legal advice.



