Famous Typosquatting Cases: The Landmark Domain-Name Disputes, Their Outcomes, and the Lesson for a Domain Buyer
Typosquatting is the practice of registering a domain name that is a deliberate misspelling of a famous brand, such as gooogle.com for Google or faacebook.com for Facebook, to catch traffic from people who mistype the real address. The famous cases are the ones that ended in a courtroom or an arbitration panel, and they set the rules everyone else now lives by.
Typical write-ups treat these cases as a curiosity, a list of funny domains with no dates and no dollar figures. This guide does the opposite. It tells each landmark case in full, with the court, the year, the remedy, and the money, from Facebook’s 2.8 million US dollar judgment over 105 domains to the first criminal sentence ever handed down for a typo domain.
It also draws the line the listicles skip. A typosquatting case is decided on bad-faith intent toward a trademark, not on the age of the domain. That distinction matters to the domain buyer, because a trademark-loaded typo name is a liability a re-purchaser can inherit. SEO Domains operates the curated marketplace where aged and expired domains are screened before they are listed, which is where avoiding that liability begins.
What is typosquatting, and why the famous cases matter
Typosquatting is registering a domain name that is a deliberate misspelling or near-variant of an established trademark, in order to capture traffic from people who mistype the genuine address. The famous cases are the disputes that reached a court or an arbitration panel, and their published outcomes set the precedents that define what is unlawful and what a panel will order.
The term is also written as URL hijacking or brand impersonation in security writing. Cornell’s Legal Information Institute defines typosquatting as a form of cybersquatting that relies on the typographical errors users make when entering a website address, and that is the read this guide follows.
Why a list of cases is the most useful map of the law
Typosquatting has no single statute that lists every banned domain. The boundary is drawn case by case, by panels and judges applying trademark law to specific facts. A roster of decided cases is therefore the clearest map of where the line falls in practice, because each ruling shows a real domain, a real intent finding, and a real remedy.
The cases also reveal the three forums that resolve these disputes: the Uniform Domain-Name Dispute-Resolution Policy, the United States Anticybersquatting Consumer Protection Act, and, in one landmark, a federal criminal statute. Each forum produced a different kind of outcome, and the famous cases are the cleanest way to see why.
The scale behind the headline cases
The famous rulings sit on top of a large and growing dispute volume. The World Intellectual Property Organization recorded 6,192 domain-name dispute cases in 2023, a record and a rise of over 7 percent on 2022, lifting its cumulative total to 67,625 cases since the system began in 1999, with .com names making up 80 percent of the filings. Typosquatting is one of the recurring fact patterns inside that caseload, which is why the same legal tests reappear across the famous decisions.
Typosquatting versus cybersquatting: the line the cases turn on
Cybersquatting is the broad practice of registering a domain that matches a trademark to profit from it. Typosquatting is a subcategory that registers a deliberate misspelling of the mark instead of the exact name. The legal test is identical: both turn on bad-faith intent to profit from another party’s trademark, which is the element every famous case had to prove.
The three related practices the cases separate
The Jackson Walker analysis “Cybersquatting, Typosquatting, and Domaining” draws the distinctions cleanly, and the lines still hold across the decided cases.
Cybersquatting
Registering a domain identical or confusingly similar to a trademark, then ransoming it to the brand or trading on confused traffic. The parent category of the famous cases.
Typosquatting
A subcategory that registers a deliberate misspelling of a mark, such as a dropped or doubled letter, to catch visitors who mistype the real address. The focus of this guide.
Domaining
The lawful business of registering, holding, and dealing in domain names. It crosses the line into a dispute only when a specific name targets a mark in bad faith.
The clean acquisition
Buying an aged or expired domain that carries no targeted trademark, for a real site or backlink use. The earned authority is a genuine asset and sits outside the cases entirely.
The practical takeaway from the case law is that the misspelling itself is not the violation. A doubled letter in a domain breaks no rule on its own. The violation is the doubled letter aimed at a protected brand to profit from the confusion, and that is the fact a complainant had to establish in every dispute on this page.
The anatomy of a typosquat: the six patterns the famous cases used
The famous typo domains fall into six recurring patterns: a simple misspelling, a transposition of two letters, a character substituted for a look-alike, an omitted character, an added or removed hyphen, and a switched top-level domain. Recognising the six patterns explains how nearly every famous case domain was constructed, and which kinds of typo a buyer is likely to inherit.
UpGuard and Kaspersky, two security references that rank for this topic, classify typo domains along the same axes. The six patterns below map every famous case domain in this guide to its construction method.
| Pattern | How the typo is built | Famous-case example |
|---|---|---|
| Simple misspelling | A doubled, dropped, or wrong letter in the brand | gooogle.com for Google; faacebook.com for Facebook |
| Transposition | Two adjacent letters reversed | arifrance.com for Air France |
| Character substitution | A letter swapped for a look-alike letter or digit | weiisfarg0.com for Wells Fargo (ll to ii, o to zero) |
| Character omission | A letter left out of the brand | gacebook.com and faacebok.com for Facebook |
| Hyphenation or spacing | A hyphen added to or removed from the brand | added-hyphen variants used to dodge exact-match filters |
| Wrong top-level domain | The brand kept, the ending changed | .org or .net variants of celebrity names |
The landmark typosquatting cases, told in full
The defining typosquatting cases span a corporate ACPA judgment worth 2.8 million US dollars, a first-of-its-kind criminal prosecution, a UDRP panel ruling that typosquatting is bad faith on its face, a brand that ran 309 arbitration cases, and a string of celebrity and parody disputes that shaped the doctrine. Each one fixed a different point of the law.
Panavision and the early celebrity-domain disputes establish that registering a trademark-laden name to sell it back is actionable. Source: Jackson Walker case survey.
A WIPO panel orders the transfer of madonna.com, ruling the pornographic site was registered in bad faith. Source: searchenginepeople case roundup.
John Zuccarini is sentenced to 30 months, the first prison term for typosquatting, under the Truth in Domain Names Act. Source: US Department of Justice.
McAfee features goggle.com, a typo of Google, in a web-safety campaign after the site is found loading malware. Source: Wikipedia typosquatting record.
A US court awards Facebook 2.8 million US dollars over 105 typo domains, the first ACPA statutory-damages formula. Source: TechCrunch, Cozen O’Connor.
John Oliver’s Last Week Tonight registers equifacks.com, experianne.com, and tramsonion.com to satirise the credit bureaus, a public illustration of how trivially typo domains are built. Source: Wikipedia.
Facebook v. typosquatters (2013): the 2.8 million dollar formula
Facebook v. Banana Ads and others
gacebook.com · gfacebook.com · faacebok.com (105 domains in total)
On 30 April 2013, a magistrate judge in the US District Court for the Northern District of California recommended that Facebook be awarded 2.8 million US dollars in statutory damages under the Anticybersquatting Consumer Protection Act, and that 105 confusingly similar domains be transferred to the company. The court built a formula to set damages per domain, weighing the number of names a defendant registered, whether the registrant was a serial squatter, whether traffic was funnelled to deceptive landing pages, and whether the registrant concealed its identity. Individual defendant awards ran from 20,000 to 1,340,000 US dollars. Source: TechCrunch, 1 May 2013; Cozen O’Connor IP alert; Lexology.
Outcome: 105 domains transferred, 2.8 million US dollars in damages, the first per-domain ACPA statutory-damages formula.
This decision is the high-water mark for typosquatting damages because it converted a vague harm into a per-domain dollar figure a court can replicate. The Anticybersquatting Consumer Protection Act, codified at 15 U.S.C. section 1125(d), authorises statutory damages of 1,000 to 100,000 US dollars per offending domain under 15 U.S.C. section 1117(d), and the Facebook ruling showed a court applying that range across a whole portfolio. The deeper mechanics of that statute are covered in the cybersquatting-law hub’s ACPA explainer.
John Zuccarini: the first criminal typosquatting sentence
United States v. John Zuccarini
thousands of misspellings of brands such as Cartoon Network and Hot Wheels
Zuccarini registered thousands of typo domains that redirected children and other users to pornographic and ad-laden pages. In 2003 Congress passed the Truth in Domain Names Act in direct response to his conduct, and Zuccarini became the first person prosecuted under it. He pleaded guilty to 49 counts on 10 December 2003 and was sentenced to 30 months in federal prison on 26 February 2004. Source: US Department of Justice press release, 26 February 2004; Wikipedia.
Outcome: 30 months in prison, the first criminal sentence for typosquatting in the United States.
The Zuccarini case is the one famous dispute that left civil law entirely and became a crime. It marks the outer edge of the doctrine: typosquatting that targets minors and deception can draw a prison term, not a transfer order. For every domain investor reading the roster, it is the clearest signal that intent and conduct, not the act of owning a misspelled name, drive the severity of the outcome.
Wells Fargo v. weiisfarg0.com: typosquatting as bad faith on its face
Wells Fargo & Company UDRP complaint
weiisfarg0.com (ll to ii, o to zero)
Wells Fargo brought a UDRP complaint over weiisfarg0.com, a domain that swapped the two letter L characters for two letter I characters and the final o for a zero. The panel found the name was registered and used in bad faith and ordered its transfer. The decision is widely cited for the panel’s statement that typosquatting in itself indicates bad faith under the UDRP. Source: GigaLaw, Doug Isenberg.
Outcome: domain transferred; precedent that the typo pattern alone evidences bad faith.
The Wells Fargo decision matters because it lowered the proof burden for complainants. Where a domain is a transparent misspelling of a famous mark, a panel can treat the typo construction itself as evidence of the registrant’s bad-faith intent, instead of requiring separate proof of a scheme. That reasoning runs through the celebrity and parody cases below.
Lego: the brand that ran 309 arbitration cases
Lego Juris A/S domain-enforcement program
hundreds of misspellings and variants of the Lego mark
Lego built one of the heaviest domain-enforcement records on file, spending roughly 500,000 US dollars to take 309 cases through UDRP proceedings against typo and variant domains of its brand. Verizon and Lufthansa are documented alongside Lego as brands that chase typosquatted names at scale. Source: Wikipedia typosquatting record.
Outcome: 309 UDRP filings; an illustration that enforcement at scale is a budget line, not a one-off.
Lego is the case study in volume. It shows that for a heavily targeted brand the response is industrial: a standing program of arbitration filings instead of a single landmark suit. It also explains why the secondary market for any name resembling a major brand is treated as radioactive by careful buyers, a point industry trade outlets such as Domain Name Wire return to whenever a brand-enforcement sweep hits the aftermarket, because the brand owner is already filing.
The celebrity, parody, and malware cases that shaped the doctrine
A cluster of earlier disputes drew the doctrinal edges that the big-money cases later applied. The searchenginepeople case roundup and the Wikipedia record document the following, each cited to a reported outcome.
- MikeRoweSoft.com. A teenager named Mike Rowe registered a phonetic play on Microsoft. WIPO and a cease-and-desist process resolved it, and the dispute became a cautionary tale about a brand overreaching against a non-commercial name.
- madonna.com. A WIPO panel in 2000 ordered transfer of the pornographic site to the performer, finding bad-faith registration of the trademark name.
- PETA and peta.org. A “People Eating Tasty Animals” parody site was ordered transferred, with courts weighing the parody defence against trademark confusion.
- goggle.com. A misspelling of Google flagged by McAfee in 2006 for loading malware, and tracked through later adware and redirect phases, a fixture of the security literature.
- arifrance.com and yuube.com. A transposition of Air France and a misspelling of YouTube, both documented as diverting users to discount-travel pages or malware prompts.
The parody cases are the instructive ones for the doctrine, because they show the limit. Where a name was non-commercial and made a genuine point, courts hesitated to find bad faith. Where a name merely mirrored a mark to harvest traffic or credentials, the finding was routine. The dividing question, again, was intent toward the mark.
How the famous cases were won: UDRP, ACPA, and a criminal statute
The famous cases were resolved through three distinct forums. The UDRP delivers a fast, low-cost transfer of the domain but no money. The Anticybersquatting Consumer Protection Act delivers statutory damages of 1,000 to 100,000 US dollars per domain through a federal court. The Truth in Domain Names Act, used once in the Zuccarini case, makes deceptive typo domains a crime. The forum a brand chose decided what remedy it would win.
The three tracks, side by side
| Forum | What it delivers | Speed and cost | The case that defines it |
|---|---|---|---|
| UDRP (arbitration) | Transfer or cancellation of the domain; no money damages | Weeks to a few months; filing fees, no litigation | Wells Fargo v. weiisfarg0.com; Lego’s 309 filings |
| ACPA (US federal court) | Domain transfer plus 1,000 to 100,000 US dollars per domain in statutory damages | Months to years; full litigation cost | Facebook v. typosquatters, 2.8 million US dollars |
| Truth in Domain Names Act (criminal) | Criminal conviction and a prison sentence | A federal prosecution; reserved for egregious deception | United States v. Zuccarini, 30 months |
Why most brands choose arbitration first
The UDRP is the default because it is fast and the remedy a brand usually wants is the name itself, not money. Lego’s 309 filings show the model: a brand that only needs the domains removed runs a standing arbitration program instead of 309 lawsuits. The deeper comparison of the two civil routes, what each costs and what each can win, is set out in the UDRP versus ACPA guide in this hub.
When the stakes justify a lawsuit
A brand reaches for the ACPA when it wants to punish and deter, not merely recover the name. Facebook faced 105 domains run by serial registrants funnelling traffic to deceptive pages, and a transfer alone would not have changed the economics for those operators. The 2.8 million dollar award, built on a per-domain formula, made the conduct unprofitable, which is the deterrent a transfer order cannot deliver.
What every famous case has in common: the bad-faith pattern
Across every forum and every decade, the famous cases share one finding: bad-faith intent to profit from a trademark. The typo construction, the redirect to a deceptive or monetised page, the concealed registrant, and the absence of any legitimate use recur as the evidence of that intent. The cases a registrant lost were the cases where this pattern was visible; the cases a registrant survived were where a genuine, non-commercial purpose broke it.
The recurring evidence of bad faith
Reading the roster from Madonna in 2000 to Facebook in 2013, the same facts appear in the losing cases.
- A domain built as a transparent misspelling or variant of a distinctive mark.
- A landing page that redirected, monetised, or phished instead of informing.
- A concealed or serial registrant identity, weighed directly in the Facebook damages formula.
- No legitimate, non-commercial, or fair use that would explain the name.
The Wells Fargo panel compressed this into a single move: where the domain showed typosquatting on its face, bad faith was inferred. The Facebook court did the reverse, treating concealment and serial registration as aggravating factors that raised the per-domain figure.
The line the survivors stayed behind
The cases registrants did not lose outright are as instructive as the ones they did. A parody site making a real point, a phonetic play registered without a scheme to ransom it, or a non-commercial use repeatedly gave courts pause. The pattern that drew a loss was never the misspelling alone. It was the misspelling joined to a profit motive aimed at the mark. That distinction is the entire doctrine in one sentence, and it is the part a domain buyer needs to internalise.
The case roster and the buyer lesson, in one table
The consolidated roster sets each famous case against its typo domain, the targeted brand, the forum that resolved it, the documented outcome, and the lesson for a domain buyer. Read top to bottom, the buyer-lesson column converges on one point: the risk lives in the targeted mark, not in the domain’s age, so the name has to be cleared before money changes hands.
| Case | Typo domain | Forum and outcome | The buyer lesson |
|---|---|---|---|
| Facebook v. typosquatters (2013) | gacebook.com, faacebok.com, 105 total | ACPA: 2.8M USD, all domains transferred | A typo of a major brand is uninsurable. The earned authority is worthless against the inherited claim. |
| United States v. Zuccarini (2004) | thousands of brand misspellings | Criminal: 30 months in prison | Deceptive intent escalates the outcome from a transfer to a conviction. Conduct, not ownership, drives severity. |
| Wells Fargo (UDRP) | weiisfarg0.com | UDRP: transferred; typo equals bad faith | A transparent misspelling is presumed bad faith. There is no clean re-sale of such a name. |
| Lego enforcement program | 309 brand variants | UDRP: 309 filings, about 500K USD spent | Heavily targeted brands file at scale. Any near-brand name is already on an enforcement list. |
| goggle.com (2006) | goggle.com for Google | Security flag: malware host | A typo name often carries a toxic security history on top of the trademark claim. |
| madonna.com (2000) | the exact celebrity mark | WIPO: transferred for bad faith | Personal-name marks are protected too. Fame, not registration order, decides the claim. |
| PETA parody (peta.org) | the exact org acronym | Court: transferred; parody weighed | A genuine non-commercial use can survive, but the margin is narrow and litigated. |
The pattern in the final column is the practical core of this guide. A domain’s age, traffic history, and backlink profile are genuine assets, and acquiring an aged or expired domain for a real site is a legitimate, common strategy. A typo of a live trademark is the exception that poisons all of those assets, because the inherited trademark claim can take the name regardless of what authority it carries. Sourcing from screened inventory instead of an unvetted drop list is how a buyer keeps the assets and avoids the exception, which is the subject of the closing section and the wider expired domain fundamentals hub.
Typosquatting frequently asked questions
The questions buyers, brand owners, and SEOs raise when they search for famous typosquatting cases, answered against the decided record and the bad-faith test the cases share.
Q1Is typosquatting illegal?
Typosquatting that targets a trademark in bad faith is unlawful, and the famous cases prove it across three forums. A UDRP panel can transfer the name, a US court can award 1,000 to 100,000 US dollars per domain under the Anticybersquatting Consumer Protection Act, and in the Zuccarini case a deceptive operator drew a 30-month prison sentence under the Truth in Domain Names Act.
Registering a misspelled domain with no targeted mark and a genuine purpose is not itself illegal. The violation is the bad-faith intent toward a brand, not the misspelling.
Q2Is typosquatting a form of phishing?
Typosquatting is a delivery method that phishing campaigns frequently use, but the two are not the same. Typosquatting is the domain tactic of registering a look-alike misspelling. Phishing is the fraud of harvesting credentials or data. The goggle.com and arifrance.com cases show typo domains used to host malware or divert traffic, which is where the two overlap.
Q3What is the biggest typosquatting case ever?
By money, the landmark is Facebook v. its typosquatters in 2013, where a US court awarded 2.8 million US dollars over 105 domains and built the first per-domain ACPA statutory-damages formula. By legal weight, the Zuccarini criminal sentence of 30 months stands apart as the only famous case that crossed from civil dispute into a federal crime.
Q4How is a typosquatting case detected and proven?
A complainant shows three things under the UDRP: the domain is identical or confusingly similar to its mark, the registrant has no legitimate interest, and the name was registered and used in bad faith. The Wells Fargo decision held that a transparent typo can satisfy the bad-faith element on its face. Registration history through RDAP, which replaced WHOIS as the standard lookup on 28 January 2025, supplies the ownership evidence.
Q5Can an aged or expired domain be a typosquatting risk?
An aged or expired domain is a typosquatting risk only when the name itself is a misspelling or variant of a live trademark. The age and backlink profile are not the problem and are a genuine asset for a real site. The problem is a name that targets a mark, because the trademark claim travels with the domain to its next owner. Screening the name against trademark databases before purchase removes the exposure.
The buyer takeaway: screen the name before acquiring a domain
The famous cases all point a domain buyer to the same defensive move. Clear the name against trademark records before acquiring it, because a typo or variant of a live mark carries a claim that outweighs any inherited authority. A clean aged or expired domain with no targeted mark is an asset; a trademark-loaded typo name is a liability the buyer inherits. Sourcing from screened inventory is how the two are kept apart. SEO Domains operates that curated marketplace.
Why the case roster is a buyer’s checklist in disguise
Every losing registrant in the roster owned a name that targeted a mark. None of them lost because the domain was old or carried backlinks. The lesson for a buyer is precise: the danger is the string of characters and the brand it imitates, not the registration date or the link profile. A pre-purchase trademark clearance answers the one question the cases truly test.
The asset versus the liability
An aged or expired domain that carries real, earned authority and targets no live trademark is a legitimate acquisition for a brand site, a 301 redirect, or white-hat link building. A name that misspells a famous mark is the opposite, a liability that arrives with a built-in claim. Treating every aged domain as risky is the error the fear-first coverage makes; the precise risk is the targeted mark, and it is screenable.
How to source a domain that carries no hidden claim
A name that holds up clears a trademark check before money changes hands. The signals that matter sit across the cybersquatting-law and authority-metrics hubs:
- The name is not a misspelling, transposition, or variant of a distinctive or famous mark.
- A search of trademark databases returns no live registration the name resembles or imitates.
- The registration history, read through RDAP, shows no prior dispute or abusive use.
- The backlink and authority profile, read in the Domain Authority and Metrics hub, is clean and editorially earned.
A typo name fails the first two checks no matter how strong its metrics look, and a clean aged domain passes them and stays an asset. The screen is the entire difference between the names in the case roster and the names worth acquiring.
Browse clean aged and expired domains with no targeted-mark exposure
The legitimate demand behind a search for famous typosquatting cases is to acquire real domain authority without inheriting a trademark fight. That is the product: a clean, screened aged or expired domain, not a brand-protection service and not a monitoring tool. SEO Domains operates the curated marketplace where aged and expired domains are screened across their registration history and authority metrics before they are listed and priced.
