Equifax Inc. successfully obtained the transfer of equifax360.online after proving the domain was used for phishing. The site impersonated the brand to solicit sensitive user information, resulting in a WIPO decision confirming the respondent’s bad faith.
Case Snapshot
| Case Number | D2026-2353 |
|---|---|
| Complainant | Equifax Inc. |
| Respondent | Alejandro Martinez |
| Disputed Domain | equifax360.online |
| Threat Tactic | Phishing and Email Fraud |
| Decision Date | 2026-07-15 |
| Panelist | Manuel Wegrostek |
| Outcome | Transfer |
| Official Source | https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2353 |
Mitigating Risks to Customer Trust and Data Security
The registration of equifax360.online highlights a significant threat to consumer safety through the tactical use of brand impersonation. By prominently displaying the EQUIFAX trademark on an unauthorized platform, the operator sought to leverage the reputation of the Equifax brand to deceive unsuspecting users. The presence of a dedicated field for collecting document numbers indicates a sophisticated intent to capture sensitive personally identifiable information (PII), directly jeopardizing individual privacy and institutional data security.
Such phishing tactics pose a substantial risk to customer trust, as fraudulent login interfaces often appear indistinguishable from legitimate corporate portals to the average visitor. The fact that security vendors flagged this specific domain confirms the active, malicious nature of the site prior to its deactivation. For global entities like Equifax, maintaining constant vigilance against such domains is essential, as the misuse of official-looking interfaces can lead to significant reputational damage and the loss of customer confidence in the brand’s digital verification processes.
Legal Analysis: Establishing Bad Faith and Unauthorized Impersonation
The panel determined that the disputed domain name, ‘equifax360.online’, is confusingly similar to the Complainant’s established EQUIFAX trademark. The addition of the numeric identifier ‘360’ was insufficient to mitigate the likelihood of consumer confusion, as the primary trademark remained the dominant feature of the string. The Complainant successfully demonstrated that it never licensed, authorized, or otherwise granted permission to the Respondent to utilize its protected intellectual property, establishing the lack of any legitimate interest in the disputed domain.
Central to the finding of bad faith was the Respondent’s deployment of a deceptive portal designed to mirror the Complainant’s brand identity. The website featured the EQUIFAX mark alongside a specific data collection field that prompted users to input sensitive document numbers. This tactical implementation of a login interface, coupled with the Respondent’s subsequent default in the proceedings, confirms an intentional effort to deceive users and solicit personal information through unauthorized brand impersonation.
Furthermore, the Panel gave weight to the global reputation of the EQUIFAX trademark, which is supported by over 221 registrations spanning 56 jurisdictions and a 51-year history of commercial use. The use of a domain name that falsely appears associated with such a well-known entity, combined with reports from security vendors identifying the site as an active source of phishing, leaves no doubt regarding the Respondent’s bad faith. Consequently, the evidence of credential harvesting and the strategic exploitation of customer trust facilitated the Complainant’s request for a mandatory transfer of the domain.
Strategic Enforcement: Documenting Phishing and Trademark Infringement
The success of the complaint against equifax360.online relied heavily on the Complainant’s ability to capture and preserve evidence of the site’s functionality while it was active. By documenting that the domain featured the EQUIFAX trademark alongside a specific portal requesting document numbers for verification, the Complainant provided the panel with concrete proof of intent to deceive, despite the domain resolving to an inactive state at the time of the decision. This proactive preservation of historical usage data proved essential in establishing that the respondent’s activities constituted malicious impersonation rather than a bona fide offering of goods or services.
Beyond the specific evidence of phishing, the complainant bolstered its legal position by highlighting the vast scale of its brand identity, including over 221 global trademark registrations and a 51-year history of brand usage. This extensive portfolio made it virtually impossible for the respondent to claim any legitimate rights or interests in the domain. By demonstrating a direct nexus between the fraudulent document collection interface and the registered trademark, the complainant successfully satisfied the three-pronged UDRP requirement for bad faith registration and use, ultimately leading to the transfer of the domain.
Practical Recommendations
- Prioritize the capture and preservation of screenshots featuring login portals or data collection fields immediately upon discovery of a suspicious domain to establish bad faith intent.
- Utilize third-party security vendor threat reports as supplemental evidence in UDRP filings to substantiate claims of phishing and unauthorized brand impersonation.
- Implement proactive brand-adjacent domain monitoring to detect registrations containing the core trademark combined with common suffixes like ‘360’ before they are weaponized for phishing.
- Maintain a comprehensive, up-to-date schedule of global trademark registrations for use in UDRP submissions to demonstrate the scale and reputation of the brand, strengthening the case for bad faith.
Frequently Asked Questions (FAQ)
Why was the domain ‘equifax360.online’ considered confusingly similar to the Equifax brand?
The panel determined that the domain incorporated the well-known EQUIFAX trademark in its entirety. The addition of the suffix ‘360’ was found insufficient to distinguish the domain from the complainant’s established brand identity.
What evidence proved the respondent lacked legitimate interests in the domain?
The respondent failed to provide any response during the proceedings. Furthermore, evidence showed the domain was used to impersonate Equifax through a fraudulent login form, which is not a bona fide offering of goods or services.
How did the WIPO panel establish the respondent acted in bad faith?
The panel concluded bad faith existed because the domain was used to host a deceptive website that collected sensitive user document numbers under the guise of an official Equifax portal, effectively misleading the public for malicious purposes.
What was the strategic outcome of this UDRP action for Equifax?
Equifax successfully obtained the transfer of the domain, mitigating the risk of ongoing phishing campaigns. This action effectively neutralized a platform that had been flagged by security vendors for brand impersonation and potential identity theft.
Concerned about fake email or invoice fraud?
Protect your customers from credential theft and brand impersonation. Our team provides UDRP eligibility assessments to help you reclaim deceptive domains and mitigate active phishing threats.
This case note is for informational purposes only and is not legal advice.



