Single Buoy Moorings Inc. successfully recovered the domain sbmoffshored.com after the respondent used the typosquatted domain to impersonate the company in fraudulent emails. The panel ordered the transfer of the domain, citing clear bad faith use.
Case Snapshot
| Case Number | D2026-2657 |
|---|---|
| Complainant | Single Buoy Moorings Inc. |
| Respondent | Leo Cunnignham, sbm offshore |
| Disputed Domain | sbmoffshored.com |
| Threat Tactic | Typo Domains |
| Decision Date | 2026-08-10 |
| Panelist | María Alejandra López García |
| Outcome | Transfer |
| Official Source | https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2657 |
Business Risk: Corporate Impersonation and Supply Chain Fraud
The registration of ‘sbmoffshored.com’ underscores a sophisticated threat where typosquatting serves as the technical foundation for active corporate impersonation. Although the domain remained inactive with no web content, the respondent configured Mail Exchanger (MX) records to facilitate deceptive email communications. By subtly altering the official brand name with the addition of a single letter, the respondent created a high-fidelity environment designed to deceive the complainant’s suppliers. This strategy moves beyond traditional traffic diversion, focusing instead on weaponizing email infrastructure to solicit illicit monetary benefits while masquerading as authorized personnel.
The operational danger posed by such tactics is substantial, particularly due to the direct targeting of the vendor ecosystem. Fraudulent solicitations originating from a domain that mimics a legitimate corporate identifier can bypass standard security filters, leading to significant financial exposure and erosion of business trust. Because the threat is executed through ‘silent’ infrastructure—lacking a public-facing website—these campaigns can remain undetected by automated brand monitoring tools that prioritize crawlable web content. Organizations must recognize that MX-configured domains represent an immediate risk to financial security, requiring proactive monitoring of look-alike domains even in the absence of active website development.
Legal Analysis: Establishing Deceptive Intent in Typosquatting and Email Impersonation
The Panel determined that the disputed domain name, ‘sbmoffshored.com’, is confusingly similar to Single Buoy Moorings Inc.’s ‘SBM OFFSHORE’ trademark. The addition of the letter ‘d’ to the trademarked term was characterized as a minor, calculated alteration that failed to distinguish the domain from the complainant’s brand. Instead, this specific variation—a clear instance of typosquatting—served as primary evidence of an intent to deceive, as the respondent targeted the complainant’s well-known reputation and official domain name, ‘sbmoffshore.com’.
Regarding rights or legitimate interests, the panel found that the respondent failed to satisfy any of the criteria set forth in Policy paragraph 4(c). The respondent’s use of the domain was not for a bona fide offering of goods or services, nor for a legitimate noncommercial or fair use. Crucially, the domain’s configuration of Mail Exchanger (MX) records, despite an otherwise inactive website, confirmed the respondent’s primary objective: to conduct a fraudulent scheme. By impersonating the complainant’s employees, the respondent aimed to manipulate the complainant’s supply chain for illicit financial gain.
The finding of bad faith registration and use was further solidified by the respondent’s awareness of the established SBM OFFSHORE trademark at the time of the domain’s registration in March 2026. The panel observed that the use of the domain as a vehicle for phishing and corporate impersonation constitutes inherently deceptive conduct. By leveraging privacy protection services to obscure their identity while simultaneously preparing the domain for active email fraud, the respondent exhibited a pattern of malicious behavior that left no doubt regarding their intent to exploit the complainant’s brand for profit.
Strategic Leverage of Technical Indicators and Brand Protection
The successful recovery of the domain sbmoffshored.com by Single Buoy Moorings Inc. highlights the efficacy of using objective technical evidence to establish bad faith in UDRP proceedings. By documenting that the respondent configured MX records, the complainant successfully moved beyond the surface-level ambiguity of an inactive website, demonstrating that the domain was explicitly engineered for email-based fraud. This strategic focus on the functional, rather than the aesthetic, use of the domain effectively countered the respondent’s reliance on privacy services and inactivity. For brand owners, the case reinforces that detecting and documenting ‘silent’ infrastructure—such as misconfigured or active mail server settings—is critical for satisfying the UDRP requirements for demonstrating bad faith use when a website lacks substantive content.
Furthermore, the complainant’s strategy of anchoring its legal position in clear typosquatting evidence proved pivotal in overcoming the respondent’s deceptive practices. By framing the addition of a single character (‘d’) as a calculated attempt to exploit the well-known SBM OFFSHORE trademark, the complainant established a direct nexus between the domain registration and its subsequent misuse in targeting supply chain vendors. This narrative not only facilitated a finding of confusing similarity but also underscored the inherent lack of legitimate interests on the part of the respondent. The case serves as an analytical benchmark for professionals, emphasizing that linking minor variations in domain spelling to real-world corporate impersonation is a highly persuasive tactic for panels, particularly in cases involving industrial or B2B brands susceptible to supply chain phishing.
Practical Recommendations
- Proactively monitor for new domain registrations containing brand misspellings (typosquatting) by utilizing registry-level alerts, as malicious actors often register these to set up infrastructure before a public-facing website exists.
- Prioritize threat intelligence scanning for active MX record configurations on suspected typosquatted domains, as these records serve as clear evidence of planned email impersonation campaigns targeting your supply chain.
- Implement DMARC (Domain-based Message Authentication, Reporting, and Conformance) at the ‘reject’ level across all corporate domains to make it harder for attackers to successfully impersonate your employees in external communications.
- In UDRP filings, document evidence of ‘silent’ infrastructure—specifically MX record setups—to satisfy the requirement for showing ‘use’ in bad faith even when the domain resolves to an empty or inactive website.
- Conduct quarterly outreach to high-value suppliers and vendors, explicitly educating them on your organization’s formal communication protocols and warning them that legitimate corporate requests will never originate from domains variations or non-official email addresses.
Frequently Asked Questions (FAQ)
Why did the panel consider ‘sbmoffshored.com’ confusingly similar to SBM Offshore’s trademark?
The panel determined that the addition of the letter ‘d’ to the end of the brand name was a minor typosquatting alteration that failed to distinguish the domain from the protected ‘SBM OFFSHORE’ trademark, effectively creating a high risk of consumer and supplier confusion.
How did the respondent demonstrate a lack of rights or legitimate interests in the disputed domain?
The respondent failed to provide any evidence of rights to the name and, conversely, used the domain as part of a fraudulent scheme to impersonate company employees, which is explicitly inconsistent with having a legitimate interest under UDRP policy.
What role did MX records play in the finding of bad faith?
The configuration of Mail Exchanger (MX) records, despite the domain having no active website content, served as critical evidence that the domain was specifically registered to facilitate phishing and email impersonation attacks against the complainant’s suppliers.
What is the primary business takeaway from the SBM Offshore case?
This case highlights that ‘silent’ infrastructure—domains lacking web content but configured for email—poses a significant risk. Companies should actively monitor for minor typosquatting variations, as these are increasingly used as tactical catalysts for high-fidelity corporate identity fraud.
Recovering Look-alike Domains Used for Fraud
As seen in the SBM Offshore case, minor typosquatting variations—like adding a single letter—can be powerful tools for email impersonation and supplier fraud. Don’t wait for a security incident to occur; identify and recover abusive domains targeting your infrastructure today.
This case note is for informational purposes only and is not legal advice.



