31 July, 2026

Protecting Pharmaceutical Brands Against Email Impersonation and Typosquatting

UDRP Cases

Chiesi Farmaceutici successfully recovered the domain chiesii.com from a Respondent who registered it to impersonate the brand. While the site was inactive, the presence of MX records indicated a high risk of fraudulent email activity, resulting in a transfer decision by the WIPO panel.

Case Snapshot

Case Number D2026-2525
Complainant Chiesi Farmaceutici S.p.A.
Respondent Thanks Lord, THANKS LORD INC
Disputed Domain
chiesii.com
Threat Tactic Phishing and Email Fraud
Decision Date 2026-06-27
Panelist Levan Nanobashvili
OutcomeTransfer
Official Source https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2525

Threat Assessment: Corporate Impersonation via Dormant Domain Infrastructure

The registration of the domain chiesii.com presents a critical business threat centered on the potential for sophisticated email-based impersonation. Although the domain never resolved to an active website, the configuration of Mail Exchange (MX) records suggests the infrastructure was primed for the delivery of fraudulent communications. For a multinational biopharmaceutical entity like Chiesi Farmaceutici, which operates across extensive supply chains, the use of a near-identical typosquatted domain for email represents a significant risk to organizational integrity and partner trust. Such tactics allow malicious actors to intercept sensitive communications, solicit fraudulent payments, or propagate malware under the guise of an authentic corporate sender, even without hosting a traditional landing page.

This case underscores the danger of passive domain holdings that serve as ‘sleeper’ assets for credential harvesting or social engineering. By utilizing a domain that mirrors the Complainant’s brand, the Respondent established a foundation to deceive stakeholders, partners, or employees who might fail to distinguish between the legitimate chiesi.com and the infringing chiesii.com. The absence of a response from the Respondent to cease-and-desist communications further validates the inference of bad faith, indicating that the domain was intended for strategic deception rather than legitimate commerce. Proactive monitoring of such typosquatted infrastructure, particularly when MX records are identified, remains an essential defense against the erosion of brand reputation and the mitigation of secondary fraud risks in the pharmaceutical sector.

Strategic Enforcement Against Dormant Infrastructure

The success of Chiesi Farmaceutici S.p.A. in case D2026-2525 demonstrates the effectiveness of technical forensic monitoring even when a disputed domain lacks active web content. By identifying that the respondent had configured Mail Exchange (MX) records, the complainant successfully moved the evidentiary focus from website-based impersonation to the credible threat of email-based phishing. The panel recognized that even in the absence of a live landing page, the infrastructure was clearly primed to facilitate fraudulent communications, allowing the complainant to meet the burden of proof for bad faith registration and use despite the respondent’s silence.

Proactive engagement also served as a critical component of the legal strategy. By sending a formal cease-and-desist letter followed by multiple reminders prior to initiating the UDRP filing, the complainant demonstrated a good-faith effort to resolve the dispute, which the respondent ignored. This evidentiary trail—complemented by the registrar’s intervention that placed the domain in ‘clientHold’ status—strengthened the case by highlighting the lack of legitimate interest and the respondent’s failure to rebut clear evidence of brand exploitation. This approach underscores the necessity for brand owners to monitor for non-web-facing technical indicators, such as MX records, as part of a comprehensive digital asset protection strategy.

Practical Recommendations

  • Implement automated MX record monitoring for newly registered domains containing your core brand name, as configured mail exchange records in otherwise ‘inactive’ domains are strong indicators of prospective phishing or impersonation attacks.
  • Develop an active defensive registration program for common typosquatted variants (e.g., doubling end letters) to preemptively neutralize bad-faith registration opportunities before they are seized by third parties.
  • Standardize the use of cease-and-desist letters with embedded time-bound reminders as a preliminary procedural step, establishing a record of non-responsiveness that strengthens the ‘bad faith’ evidence in subsequent UDRP filings.
  • Leverage registrar-level domain suspensions (‘clientHold’) immediately upon detection of suspicious MX configurations if the domain is being utilized for infrastructure-level threats that pose direct harm to corporate communications.
  • Archive snapshots of DNS configurations, including dormant status and MX records, during the discovery phase to provide concrete evidence to the Panel regarding the Respondent’s intent, even in the absence of an active phishing website.

Frequently Asked Questions (FAQ)

Why was the domain ‘chiesii.com’ found to be confusingly similar to Chiesi Farmaceutici’s trademark?

The WIPO panel determined that ‘chiesii.com’ is confusingly similar because it contains the entirety of the complainant’s well-known ‘CHIESI’ trademark, with the mere addition of an extra ‘i’ at the end, a common typosquatting tactic intended to deceive internet users.

How did the panel establish that the respondent acted in bad faith without an active website?

The panel inferred bad faith by noting that ‘chiesii.com’ has no meaning in English, indicating an intent to target the Chiesi brand. The presence of configured MX records on the inactive domain served as evidence that the respondent intended to facilitate fraudulent email impersonation.

What evidence was used to determine the respondent had no rights or legitimate interests?

The respondent failed to provide a response to the complaint, and the panel found no evidence that the respondent was a licensee of the complainant, had any prior rights to the ‘CHIESI’ name, or was making a legitimate non-commercial or fair use of the domain.

What practical lessons does this case offer for pharmaceutical brand protection?

The case highlights the importance of monitoring infrastructure-level threats like MX records, even when domains are parked. Proactive identification of dormant domains configured for email allows companies to intervene before actual phishing fraud occurs.

Concerned about fake email or invoice fraud?

Even inactive domains with configured MX records pose a serious threat to your brand’s security, serving as silent staging grounds for sophisticated phishing campaigns. Don’t wait for a security incident to occur—our team can help you monitor and recover look-alike domains before they are weaponized against your employees or partners.

Request phishing analysis

Contact us
We will find the best solution for your business

    Thank you for your request!
    We will contact you within 5 hours!
    Image
    This site uses cookies to improve your experience. By continuing, you agree to our Privacy Policy.

    Privacy settings

    When you visit websites, they may store or retrieve data in your browser. This storage is often required for basic website functionality. Storage may be used for marketing, analytics and site personalization purposes, such as storing your preferences. Privacy is important to us, so you can disable certain types of storage that may not be necessary for the basic functioning of the website. Blocking categories may affect the performance of the website.

    Manage settings


    Necessary

    Always active

    These cookies are necessary for the website to function and cannot be disabled in our systems. They are usually only set in response to actions you take that constitute a request for services, such as adjusting your privacy settings, logging in, or filling out forms. You can set your browser to block these cookies or notify you about them, but some parts of the site will not work. These cookies do not store any personal information.

    Marketing

    These elements are used to show you advertising that is more relevant to you and your interests. They can also be used to limit the number of ad views and measure the effectiveness of advertising campaigns. Advertising networks usually place them with the permission of the site operator.

    Personalization

    These elements allow the website to remember your choices (such as your username, language or region you are in) and provide enhanced, more personalized features. For example, a website may provide you with local weather forecasts or traffic news by storing data about your current location.

    Analytics

    These elements help the website operator understand how their website works, how visitors interact with the site and whether there may be technical problems. This type of storage usually does not collect information that identifies the visitor.