13 August, 2026

Preventing Domain Impersonation: Lessons from SBM Offshore

UDRP Cases

Single Buoy Moorings Inc. successfully recovered the domain sbmoffshored.com after the respondent used the typosquatted domain to impersonate the company in fraudulent emails. The panel ordered the transfer of the domain, citing clear bad faith use.

Case Snapshot

Case Number D2026-2657
Complainant Single Buoy Moorings Inc.
Respondent Leo Cunnignham, sbm offshore
Disputed Domain
sbmoffshored.com
Threat Tactic Typo Domains
Decision Date 2026-08-10
Panelist María Alejandra López García
OutcomeTransfer
Official Source https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2657

Business Risk: Corporate Impersonation and Supply Chain Fraud

The registration of ‘sbmoffshored.com’ underscores a sophisticated threat where typosquatting serves as the technical foundation for active corporate impersonation. Although the domain remained inactive with no web content, the respondent configured Mail Exchanger (MX) records to facilitate deceptive email communications. By subtly altering the official brand name with the addition of a single letter, the respondent created a high-fidelity environment designed to deceive the complainant’s suppliers. This strategy moves beyond traditional traffic diversion, focusing instead on weaponizing email infrastructure to solicit illicit monetary benefits while masquerading as authorized personnel.

The operational danger posed by such tactics is substantial, particularly due to the direct targeting of the vendor ecosystem. Fraudulent solicitations originating from a domain that mimics a legitimate corporate identifier can bypass standard security filters, leading to significant financial exposure and erosion of business trust. Because the threat is executed through ‘silent’ infrastructure—lacking a public-facing website—these campaigns can remain undetected by automated brand monitoring tools that prioritize crawlable web content. Organizations must recognize that MX-configured domains represent an immediate risk to financial security, requiring proactive monitoring of look-alike domains even in the absence of active website development.

Strategic Leverage of Technical Indicators and Brand Protection

The successful recovery of the domain sbmoffshored.com by Single Buoy Moorings Inc. highlights the efficacy of using objective technical evidence to establish bad faith in UDRP proceedings. By documenting that the respondent configured MX records, the complainant successfully moved beyond the surface-level ambiguity of an inactive website, demonstrating that the domain was explicitly engineered for email-based fraud. This strategic focus on the functional, rather than the aesthetic, use of the domain effectively countered the respondent’s reliance on privacy services and inactivity. For brand owners, the case reinforces that detecting and documenting ‘silent’ infrastructure—such as misconfigured or active mail server settings—is critical for satisfying the UDRP requirements for demonstrating bad faith use when a website lacks substantive content.

Furthermore, the complainant’s strategy of anchoring its legal position in clear typosquatting evidence proved pivotal in overcoming the respondent’s deceptive practices. By framing the addition of a single character (‘d’) as a calculated attempt to exploit the well-known SBM OFFSHORE trademark, the complainant established a direct nexus between the domain registration and its subsequent misuse in targeting supply chain vendors. This narrative not only facilitated a finding of confusing similarity but also underscored the inherent lack of legitimate interests on the part of the respondent. The case serves as an analytical benchmark for professionals, emphasizing that linking minor variations in domain spelling to real-world corporate impersonation is a highly persuasive tactic for panels, particularly in cases involving industrial or B2B brands susceptible to supply chain phishing.

Practical Recommendations

  • Proactively monitor for new domain registrations containing brand misspellings (typosquatting) by utilizing registry-level alerts, as malicious actors often register these to set up infrastructure before a public-facing website exists.
  • Prioritize threat intelligence scanning for active MX record configurations on suspected typosquatted domains, as these records serve as clear evidence of planned email impersonation campaigns targeting your supply chain.
  • Implement DMARC (Domain-based Message Authentication, Reporting, and Conformance) at the ‘reject’ level across all corporate domains to make it harder for attackers to successfully impersonate your employees in external communications.
  • In UDRP filings, document evidence of ‘silent’ infrastructure—specifically MX record setups—to satisfy the requirement for showing ‘use’ in bad faith even when the domain resolves to an empty or inactive website.
  • Conduct quarterly outreach to high-value suppliers and vendors, explicitly educating them on your organization’s formal communication protocols and warning them that legitimate corporate requests will never originate from domains variations or non-official email addresses.

Frequently Asked Questions (FAQ)

Why did the panel consider ‘sbmoffshored.com’ confusingly similar to SBM Offshore’s trademark?

The panel determined that the addition of the letter ‘d’ to the end of the brand name was a minor typosquatting alteration that failed to distinguish the domain from the protected ‘SBM OFFSHORE’ trademark, effectively creating a high risk of consumer and supplier confusion.

How did the respondent demonstrate a lack of rights or legitimate interests in the disputed domain?

The respondent failed to provide any evidence of rights to the name and, conversely, used the domain as part of a fraudulent scheme to impersonate company employees, which is explicitly inconsistent with having a legitimate interest under UDRP policy.

What role did MX records play in the finding of bad faith?

The configuration of Mail Exchanger (MX) records, despite the domain having no active website content, served as critical evidence that the domain was specifically registered to facilitate phishing and email impersonation attacks against the complainant’s suppliers.

What is the primary business takeaway from the SBM Offshore case?

This case highlights that ‘silent’ infrastructure—domains lacking web content but configured for email—poses a significant risk. Companies should actively monitor for minor typosquatting variations, as these are increasingly used as tactical catalysts for high-fidelity corporate identity fraud.

Recovering Look-alike Domains Used for Fraud

As seen in the SBM Offshore case, minor typosquatting variations—like adding a single letter—can be powerful tools for email impersonation and supplier fraud. Don’t wait for a security incident to occur; identify and recover abusive domains targeting your infrastructure today.

Start domain recovery

Contact us
We will find the best solution for your business

    Thank you for your request!
    We will contact you within 5 hours!
    Image
    This site uses cookies to improve your experience. By continuing, you agree to our Privacy Policy.

    Privacy settings

    When you visit websites, they may store or retrieve data in your browser. This storage is often required for basic website functionality. Storage may be used for marketing, analytics and site personalization purposes, such as storing your preferences. Privacy is important to us, so you can disable certain types of storage that may not be necessary for the basic functioning of the website. Blocking categories may affect the performance of the website.

    Manage settings


    Necessary

    Always active

    These cookies are necessary for the website to function and cannot be disabled in our systems. They are usually only set in response to actions you take that constitute a request for services, such as adjusting your privacy settings, logging in, or filling out forms. You can set your browser to block these cookies or notify you about them, but some parts of the site will not work. These cookies do not store any personal information.

    Marketing

    These elements are used to show you advertising that is more relevant to you and your interests. They can also be used to limit the number of ad views and measure the effectiveness of advertising campaigns. Advertising networks usually place them with the permission of the site operator.

    Personalization

    These elements allow the website to remember your choices (such as your username, language or region you are in) and provide enhanced, more personalized features. For example, a website may provide you with local weather forecasts or traffic news by storing data about your current location.

    Analytics

    These elements help the website operator understand how their website works, how visitors interact with the site and whether there may be technical problems. This type of storage usually does not collect information that identifies the visitor.