12 September, 2026

Defending IBM Against Unauthorized Trademark Use in Domain Portfolios

UDRP Cases

International Business Machines Corporation successfully recovered five domains (bia-ibm.com, etc.) used by a respondent to impersonate the brand for cryptocurrency solicitation. The panel ordered the transfer of all domains after finding bad faith use of the IBM trademark and logo.

Case Snapshot

Case Number D2026-3298
Complainant International Business Machines Corporation
Respondent lei lei
Disputed Domain
bia-ibm.combie-ibm.combio-ibm.combir-ibm.combit-ibm.com
Threat Tactic Corporate Impersonation
Decision Date 2026-09-07
Panelist Benoit Van Asbroeck
OutcomeTransfer
Official Source https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-3298
UDRP Legal Assistance

Facing Unauthorized Domain Registrations or Brand Abuse?

Our domain dispute attorneys represent trademark owners and businesses worldwide before WIPO, Forum (NAF), and CAC. Explore our Domain Name Disputes and Enforcement & Takedowns services, or request a free case evaluation.

Request Case Evaluation

Strategic Risks of Brand Impersonation and Cryptocurrency Fraud

The registration of five domain names incorporating the IBM trademark, such as ‘bia-ibm.com’ and ‘bit-ibm.com’, highlights a severe corporate impersonation threat designed to misappropriate established brand equity. By deploying the Complainant’s proprietary eight-bar logo as a favicon and prominently featuring it on sites soliciting cryptocurrency service sign-ups, the Respondent created a deceptive digital environment. This tactic poses an immediate risk to consumer trust, as users are led to believe that these unauthorized financial offerings are sanctioned or endorsed by the Complainant, potentially exposing them to phishing or other sophisticated fraudulent activities.

Beyond immediate consumer impact, this case demonstrates how brand assets are exploited to facilitate commercial gain through illicit association. The use of high-profile trademarked identity, combined with the Registrar verification findings showing inconsistent contact information, underscores the challenges posed by anonymous bad actors utilizing domain portfolios for brand dilution. While two domains remained inactive, their registration as part of a larger cluster indicates a persistent effort to mirror the Complainant’s brand architecture, necessitating vigilant, proactive monitoring to detect such variations before they can be leveraged to compromise corporate reputation.

Strategic Enforcement: Leveraging Asset Mimicry and Procedural Agility

The Complainant’s successful strategy rested on documenting granular evidence of brand impersonation beyond mere domain registration. By cataloging the respondent’s specific unauthorized use of the iconic eight-bar logo as a website favicon and throughout site imagery, the Complainant provided the panel with irrefutable proof of intent to deceive. This visual evidence of brand misappropriation, combined with the solicitation of users to ‘Sign up now’ for cryptocurrency services, established a clear pattern of bad faith that effectively linked the domain portfolio to a broader phishing or fraud operation. Such evidentiary rigor turns a generic typosquatting dispute into a compelling narrative of corporate identity theft, leaving little room for the respondent to claim any legitimate interest in the domains.

Procedurally, the Complainant demonstrated operational agility by responding promptly to registrar verification notices. When the registrar disclosed registrant data that conflicted with the initial complaint details, the Complainant quickly filed an amendment to ensure the correct party was addressed. This proactive management of administrative hurdles ensured that the procedural history remained clean and that the panel could move directly to a substantive review. By efficiently correcting the respondent information, the Complainant avoided potential delays or jurisdictional challenges, allowing for a swift resolution that effectively halted the ongoing misuse of the IBM brand and its association with unauthorized financial solicitation.

Practical Recommendations

  • Implement proactive ‘new registration’ monitoring alerts for domain strings containing ‘IBM’ plus common prefixes or suffixes to detect typosquatting before active phishing sites are deployed.
  • Utilize automated visual brand monitoring tools that scan for the unauthorized use of proprietary assets, specifically the ‘eight-bar’ logo and company favicons, across external domain registries.
  • Establish a standardized response protocol for UDRP filings that immediately triggers a registrar verification request to unmask underlying registrants hiding behind privacy/proxy services.
  • Prioritize the takedown of domains displaying infringing content, while simultaneously pursuing the transfer of associated, currently inactive domains in the same batch to prevent future ‘re-activation’ of the phishing scheme.
  • Incorporate a ‘brand-impersonation’ assessment into digital risk reporting, focusing on domain-based cryptocurrency solicitation as a high-priority threat vector for customer fraud.

Frequently Asked Questions (FAQ)

Why were the domains bia-ibm.com, bie-ibm.com, bio-ibm.com, bir-ibm.com, and bit-ibm.com found to be confusingly similar to the IBM trademark?

The WIPO panel determined that these domains incorporate the famous IBM trademark in its entirety. The inclusion of hyphenated prefixes (e.g., ‘bia-‘, ‘bie-‘) does not mitigate the confusing similarity, as the core IBM brand remains the primary identifier in the domain string.

What evidence confirmed the Respondent’s bad faith in this case?

Bad faith was established through the Respondent’s intentional unauthorized use of the IBM eight-bar logo as a website favicon and primary site imagery. Furthermore, the active domains were used to host fraudulent cryptocurrency service promotions, signaling a clear intent to capitalize on IBM’s reputation to deceive consumers.

Did the Respondent possess any legitimate rights or interests in these domain names?

No. The panel found that the Respondent had no authorization from IBM to use the trademark. The Respondent was not commonly known by these names, nor were they using the domains for a legitimate non-commercial or fair use, as evidenced by the deceptive sign-up solicitations displayed on the sites.

What tactical lesson does this case provide regarding brand asset monitoring?

The case highlights the risk of ‘brand-plus-keyword’ variations and the importance of monitoring beyond just primary domain names. By identifying the misuse of specific brand assets like favicons and logos, IBM was able to provide compelling evidence of impersonation, leading to the successful transfer of all five domains.

Is your brand being leveraged for unauthorized cryptocurrency schemes?

Corporate impersonation often involves the misuse of official assets, such as logos and favicons, to build false credibility for illicit financial services. If you have identified domains that mimic your identity, our team can assist with a formal UDRP eligibility assessment.

Assess impersonation threat

Get Expert UDRP & Domain Dispute Assistance
Request a confidential case evaluation from our domain dispute attorneys. We will review your domain situation and reply within 24 hours.

    Thank You for Your Request!
    Our legal team is reviewing your dispute details and will contact you via email shortly.
    Image
    This site uses cookies to improve your experience. By continuing, you agree to our Privacy Policy.

    Privacy settings

    When you visit websites, they may store or retrieve data in your browser. This storage is often required for basic website functionality. Storage may be used for marketing, analytics and site personalization purposes, such as storing your preferences. Privacy is important to us, so you can disable certain types of storage that may not be necessary for the basic functioning of the website. Blocking categories may affect the performance of the website.

    Manage settings


    Necessary

    Always active

    These cookies are necessary for the website to function and cannot be disabled in our systems. They are usually only set in response to actions you take that constitute a request for services, such as adjusting your privacy settings, logging in, or filling out forms. You can set your browser to block these cookies or notify you about them, but some parts of the site will not work. These cookies do not store any personal information.

    Marketing

    These elements are used to show you advertising that is more relevant to you and your interests. They can also be used to limit the number of ad views and measure the effectiveness of advertising campaigns. Advertising networks usually place them with the permission of the site operator.

    Personalization

    These elements allow the website to remember your choices (such as your username, language or region you are in) and provide enhanced, more personalized features. For example, a website may provide you with local weather forecasts or traffic news by storing data about your current location.

    Analytics

    These elements help the website operator understand how their website works, how visitors interact with the site and whether there may be technical problems. This type of storage usually does not collect information that identifies the visitor.