Carrefour SA successfully recovered the domain carrefour-pass-espace.com after the panel found the domain was registered and used in bad faith. The domain was held passively and the registrar verification process revealed likely third-party identity theft.
Case Snapshot
| Case Number | D2026-2926 |
|---|---|
| Complainant | Carrefour SA |
| Respondent | Name Redacted |
| Disputed Domain | carrefour-pass-espace.com |
| Threat Tactic | Passive Holding |
| Decision Date | 2026-09-01 |
| Panelist | Tobias Zuberbühler |
| Outcome | Transfer |
| Official Source | https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2926 |
Facing Unauthorized Domain Registrations or Brand Abuse?
Our domain dispute attorneys represent trademark owners and businesses worldwide before WIPO, Forum (NAF), and CAC. Explore our Domain Name Disputes and Enforcement & Takedowns services, or request a free case evaluation.
Request Case EvaluationBusiness Risks of Identity Theft and Passive Holding
The registration of ‘carrefour-pass-espace.com’ highlights critical operational risks for brand owners, specifically regarding the exploitation of third-party identities in the domain registration process. In this case (D2026-2926), registrar verification revealed that the identity data provided by the registrant differed significantly from the initial filing. The Panel’s subsequent finding of suspected identity theft indicates that malicious actors are increasingly utilizing the credentials of unsuspecting individuals to mask their activities, thereby complicating enforcement efforts and attribution. This tactical obfuscation increases the administrative burden for IP professionals, who must navigate complex disclosure discrepancies during the UDRP verification stage.
Furthermore, the use of the domain as a passively held asset—resolving only to an error page—serves as a recurring indicator of bad faith registration. While the domain currently lacks active content, its registration remains a strategic threat, acting as a potential precursor to future phishing or corporate impersonation campaigns. By securing domains that closely mirror trademarked financial services, bad actors create infrastructure that can be activated instantly for fraud. The additional procedural friction caused by linguistic differences between the registration agreement and the proceeding language further illustrates how bad actors leverage administrative hurdles to delay legal recourse. Brand owners should monitor these registrations as defensive indicators of intent, even when the current technical output of the domain appears inert.
Legal Analysis: Confusing Similarity, Lack of Interests, and Bad Faith Findings
In the dispute involving carrefour-pass-espace.com, the Panel conducted a foundational analysis of the three UDRP elements. Regarding confusing similarity, the Panel affirmed that the Complainant satisfied the standing requirement through a direct comparison of the CARREFOUR PASS trademark against the disputed domain. This threshold test confirmed that the domain name is confusingly similar to the Complainant’s mark, an established fact consistent with WIPO Overview 3.1, section 1.7. By meeting this initial burden, the Complainant successfully anchored the proceeding, setting the stage for deeper scrutiny into the Respondent’s conduct.
The Panel further determined that the Respondent lacks any rights or legitimate interests in the domain. Although the burden of proof typically rests with the Complainant, the Panel noted the difficulty of proving a negative, ultimately concluding that the absence of a bona fide offering of goods or services provided sufficient justification for this finding. The fact that the domain resolved to an inactive error page further solidified the Panel’s determination that the Respondent had failed to establish any legitimate use, thereby satisfying the second element of the policy.
Bad faith registration and use were established through the strategic, albeit passive, holding of the domain. While the domain lacked active content, the Panel applied paragraph 4(b) of the Policy, interpreting the inactive status within the broader context of the case. The Panel identified that the domain was not utilized for any bona fide commercial purpose, which, when coupled with the underlying evidence of third-party identity theft used to mask the true registrant during the acquisition at IONOS SE, provided sufficient evidence to satisfy the third element. This conclusion underscores that passive holding is a clear indicator of bad faith when used in conjunction with obfuscation tactics.
Procedurally, the Panel exercised its authority under paragraph 11(a) of the Rules to designate English as the language of the proceeding, notwithstanding that the initial registration agreement was in German. This was necessary to ensure fairness and efficiency, particularly in light of the suspected identity theft detected during the registrar verification phase. The Panel’s ability to navigate these complexities highlights the importance of rigorous registrar data disclosure in identifying bad actors who exploit administrative gaps in domain management to evade corporate enforcement efforts.
Strategic Enforcement Against Passive Holding and Identity Theft
The Complainant successfully navigated the procedural complexities of this dispute by proactively addressing the language of the registration agreement, which was originally in German. By requesting that the language of the proceeding be set to English, the Complainant ensured clarity throughout the legal process while the Respondent remained unresponsive. The persuasive strength of the case relied heavily on the Complainant’s ability to highlight the domain’s lack of active content, establishing a pattern of passive holding. Because the disputed domain only resolved to an error page, the Panel was able to readily infer bad faith, reinforcing that the mere registration of a mark-aligned domain without legitimate business intent constitutes an actionable infringement under the Policy.
A critical dimension of this strategy involved managing the fallout from identity theft during the domain registration phase. The Registrar, IONOS SE, disclosed registrant data that diverged significantly from the initial complaint, leading the Panel to identify that a third party had likely utilized a stolen identity to mask the true actor. By identifying these discrepancies early, the Complainant provided the Panel with sufficient evidence to substantiate the lack of rights or legitimate interests. This outcome underscores the necessity for brand owners to leverage registrar verification data to expose illicit registration practices, even when the underlying intent—such as future phishing—remains unverified. The subsequent decision to redact the Respondent’s name further confirms the severity of the identified identity theft.
Practical Recommendations
- Proactively monitor WHOIS data discrepancies during initial domain assessment to identify potential third-party identity theft as evidence of bad faith.
- Draft UDRP complaints to include specific requests for language of proceeding overrides early in the process when the registration agreement language differs from the Complainant’s primary operations.
- Leverage ‘passive holding’ of an inactive or error-page domain as a core pillar of your bad faith argument, supported by the lack of any bona fide offering of goods or services.
- Maintain a robust evidence collection log including screenshots of inactive pages and registrar verification results to substantiate claims of registration in bad faith.
- Implement automated alerts for new domain registrations containing core trademark strings to trigger early intervention before potential phishing or impersonation tactics mature.
Frequently Asked Questions (FAQ)
Why was the domain carrefour-pass-espace.com considered confusingly similar to the Complainant’s brand?
The Panel determined that the disputed domain name incorporates the ‘CARREFOUR PASS’ trademark in its entirety, which satisfies the threshold requirement for confusing similarity under the UDRP policy.
How did the Panel establish bad faith given that the website was inactive?
The Panel found that the passive holding of the domain, combined with the lack of any bona fide offering of goods or services, constitutes evidence of bad faith registration and use under the UDRP.
What role did the registrar’s data play in uncovering potential identity theft?
During the registrar verification process, discrepancies between the initial filing data and the actual registrant information emerged, leading the Panel to conclude that a third party had likely engaged in identity theft to conceal their involvement in registering the disputed domain.
What procedural challenges did Carrefour SA face during this UDRP proceeding?
The Complainant had to navigate a registration agreement written in German while seeking to conduct the proceedings in English, which was ultimately granted after the Respondent failed to object.
Is someone blocking a brand domain?
Passive holding is a common precursor to more complex threats like identity theft and phishing. Our UDRP assessment helps you proactively reclaim your digital assets and stop bad actors before they escalate their tactics.
This case note is for informational purposes only and is not legal advice.



