3 September, 2026

Protecting Brand Integrity: Lessons from the HeyGen Impersonation Case

UDRP Cases

HeyGen Technology Inc. successfully reclaimed three domains—heygen.bet, heygen.pro, and heygen.win—after they were used to host fraudulent sites impersonating the company for illicit gambling services in Bangladesh. The WIPO panel ordered a transfer of the domains, citing bad faith and lack of legitimate interest by the respondent.

Case Snapshot

Case Number D2026-2831
Complainant HeyGen Technology Inc
Respondent jacklingling zhang
Disputed Domain
heygen.betheygen.proheygen.win
Threat Tactic Corporate Impersonation
Decision Date 2026-08-28
Panelist Ganna Prokhorova
OutcomeTransfer
Official Source https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2831
UDRP Legal Assistance

Facing Unauthorized Domain Registrations or Brand Abuse?

Our domain dispute attorneys represent trademark owners and businesses worldwide before WIPO, Forum (NAF), and CAC. Explore our Domain Name Disputes and Enforcement & Takedowns services, or request a free case evaluation.

Request Case Evaluation

Business Threat: Brand Impersonation and Data Security Risks

The registration of heygen.bet, heygen.pro, and heygen.win represents a severe business threat characterized by the unauthorized exploitation of the HEYGEN trademark to facilitate illicit commercial activities. By mirroring the Complainant’s corporate branding—including the HEYGEN logo, colors, and site ‘look-and-feel’—the Respondent created a high-risk environment for consumers. These fraudulent platforms targeted users in Bangladesh with online gambling and betting services, activities potentially subject to the country’s Cyber Security Ordinance of 2025 and Cyber Security Act of 2026. This association risks significant reputational damage to the Complainant, as their brand equity was hijacked to lend false legitimacy to services entirely unrelated to their legitimate AI video and image generation business.

Beyond the dilution of trademark rights, the strategy of deploying functional login and registration fields on these domains poses a direct threat to data security and customer trust. By soliciting personal information through a deceptive interface, the Respondent created a mechanism for potential identity theft and data harvesting, exposing the Complainant’s user base to substantial cyber risk. The use of gTLDs such as .bet and .win did not mitigate the risk of consumer confusion; rather, these domains served as an active funnel for traffic diversion. This systematic impersonation demonstrates an aggressive intent to monetize the Complainant’s reputation through fraudulent engagement, highlighting the necessity for proactive domain monitoring to safeguard against similar cross-border exploitation of corporate digital assets.

Strategic Enforcement Against Brand Impersonation and Traffic Diversion

The Complainant’s successful strategy relied on demonstrating a comprehensive pattern of bad faith that extended beyond simple domain registration. By meticulously documenting the Respondent’s unauthorized use of the HEYGEN mark on platforms that imitated the company’s corporate look-and-feel, the Complainant provided clear evidence of an intent to deceive. The inclusion of fraudulent copyright notices and the integration of login functions on sites promoting illicit gambling services created a high-risk scenario for consumer data security. This evidence allowed the Panel to easily distinguish between legitimate domain use and malicious traffic diversion, reinforcing that the .bet, .pro, and .win gTLDs were selected specifically to maximize the likelihood of consumer confusion in the targeted regional market.

From a business perspective, this case illustrates the efficacy of anchoring UDRP arguments in the intersection of trademark infringement and potential regulatory liability. By aligning the Complainant’s established global presence—comprising 40,000 customers and significant annual revenue—with the Respondent’s exploitation of the brand in high-risk, non-core sectors, the Complainant framed the dispute as a matter of brand integrity and regional safety. The documentation of the Respondent’s activities as potentially violating local laws, such as Bangladesh’s Cyber Security Act, served as a compelling technical indicator of bad faith. This holistic approach provided the Panel with sufficient grounds to favor a transfer, effectively protecting the Complainant’s digital identity from further dilution and limiting the risk of association with prohibited third-party services.

Practical Recommendations

  • Implement proactive domain monitoring specifically targeting high-risk gTLDs such as .bet, .win, and .pro to detect unauthorized registrations that utilize your trademark alongside industry-adjacent keywords.
  • Document technical evidence of impersonation, including screenshotting ‘look-and-feel’ mimicry, unauthorized logo usage, and deceptive copyright notices, as these are critical for establishing bad faith under UDRP policy.
  • Establish an immediate incident response protocol for sites collecting PII, which includes notifying law enforcement in the target region—such as the relevant cyber security authorities in Bangladesh—to reinforce the bad faith claim in UDRP proceedings.
  • Utilize cease-and-desist actions or UDRP filings to address unauthorized use in non-core sectors immediately, as allowing brand exploitation in high-risk categories like gambling creates significant legal and reputational liability.
  • Maintain a defensive registration strategy that protects core marks across a broad range of descriptive and popular gTLDs to prevent threat actors from securing domain names that mirror your primary digital infrastructure.

Frequently Asked Questions (FAQ)

Why were the disputed domain names heygen.bet, heygen.pro, and heygen.win considered confusingly similar to the HEYGEN trademark?

The WIPO panel found these domains confusingly similar because they incorporated the HEYGEN trademark in its entirety. The panel confirmed that the addition of generic Top-Level Domains (gTLDs) like .bet, .pro, and .win does not mitigate the risk of consumer confusion.

What evidence proved the respondent lacked rights or legitimate interests in the HeyGen domains?

The respondent had no affiliation, license, or authorization from HeyGen Technology Inc. to use the HEYGEN trademark. Furthermore, the respondent was not commonly known by the name ‘Heygen’ and used the sites to impersonate the company rather than to conduct a legitimate business.

How did the panel determine that the respondent acted in bad faith?

Bad faith was evidenced by the respondent’s intentional attempt to attract Internet users for commercial gain by mimicking HeyGen’s branding. By displaying the company’s logo, colors, and unauthorized copyright notices on sites promoting illicit gambling services in Bangladesh, the respondent actively misled users.

What specific business risks were addressed in the outcome of this UDRP case?

The case highlighted the danger of brand dilution and reputational damage caused by associating a reputable AI company with illegal gambling. The unauthorized collection of personal information on these fraudulent mirror sites also created significant data security liabilities for HeyGen’s customers.

Facing corporate impersonation through a domain?

Protect your brand integrity against bad-faith actors using your assets on fraudulent websites. Discover how proactive UDRP strategies can help reclaim your digital identity.

Assess impersonation threat

Get Expert UDRP & Domain Dispute Assistance
Request a confidential case evaluation from our domain dispute attorneys. We will review your domain situation and reply within 24 hours.

    Thank You for Your Request!
    Our legal team is reviewing your dispute details and will contact you via email shortly.
    Image
    This site uses cookies to improve your experience. By continuing, you agree to our Privacy Policy.

    Privacy settings

    When you visit websites, they may store or retrieve data in your browser. This storage is often required for basic website functionality. Storage may be used for marketing, analytics and site personalization purposes, such as storing your preferences. Privacy is important to us, so you can disable certain types of storage that may not be necessary for the basic functioning of the website. Blocking categories may affect the performance of the website.

    Manage settings


    Necessary

    Always active

    These cookies are necessary for the website to function and cannot be disabled in our systems. They are usually only set in response to actions you take that constitute a request for services, such as adjusting your privacy settings, logging in, or filling out forms. You can set your browser to block these cookies or notify you about them, but some parts of the site will not work. These cookies do not store any personal information.

    Marketing

    These elements are used to show you advertising that is more relevant to you and your interests. They can also be used to limit the number of ad views and measure the effectiveness of advertising campaigns. Advertising networks usually place them with the permission of the site operator.

    Personalization

    These elements allow the website to remember your choices (such as your username, language or region you are in) and provide enhanced, more personalized features. For example, a website may provide you with local weather forecasts or traffic news by storing data about your current location.

    Analytics

    These elements help the website operator understand how their website works, how visitors interact with the site and whether there may be technical problems. This type of storage usually does not collect information that identifies the visitor.