By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)
A fake website that copies a brand’s name, logo and look to sell counterfeits or steal credentials is trademark infringement under Section 29 of the Trade Marks Act, 1999 and, where it uses a deceptive domain, a domain-name dispute recoverable through INDRP (.in) or UDRP (gTLDs) — and the same act is also phishing punishable under Sections 66C and 66D of the IT Act, 2000. The removal route, since 20 February 2026, runs on a three-hour clock under Rule 3(1)(d) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended on 10 February 2026, triggered by a court order or an authorised government notification.
What counts as online trademark infringement under Section 29?
The elements of infringement under Section 29 Trade Marks Act translate directly to online conduct:
| Section 29 element | How it applies online |
|---|---|
| Registered mark | The plaintiff holds a registered trademark — word, device, shape, sound or combination — capable of distinguishing goods or services (Section 2(1)(zb)) |
| Identical or deceptively similar mark | The fake site uses the same mark or a mark likely to deceive or cause confusion (Section 2(1)(h)) — for example, hdfcbank-login.com, amaz0n-deals.in, or a cloned logo and colour scheme |
| In the course of trade, without authorisation | Operating a site, listing, advertisement, social handle or domain that offers goods or services or collects data under the mark, without the proprietor’s licence |
| For identical or similar goods or services, with likelihood of confusion or association | The classic case — counterfeits or lookalike services of the same type — but also Section 29(4): a well-known mark is protected even for dissimilar goods or services where use without due cause takes unfair advantage of or is detrimental to the distinctive character or repute of the mark |
| Modes that expressly include online use | Affixing to goods or packaging, offering for sale, advertising (Section 29(6), 29(8)), import/export, use as a trade or corporate name (Section 29(5)), and use on business papers and in advertising — all of which cover domain names, marketplace listings, sponsored ads and social commerce |
Two extensions courts routinely apply online:
- Domain name as trademark. Since Yahoo! Inc. v. Akash Arora ((1999) 19 PTC 201 (Del)) and Satyam Infoway Ltd v. Siffynet Solutions (2004) 6 SCC 145, a domain name that incorporates a mark functions as a trademark. A deceptively similar domain that diverts customers is not merely a technical address — it is trademark use.
- Keyword and sponsored-ad misuse. Bidding on a competitor’s mark as a keyword, or using it in sponsored listings in a manner that creates confusion, has been treated as trademark use in advertising under Section 29, with recent High Court jurisprudence examining marketplace and search-algorithm facilitation — now increasingly described as e-infringement through platform architecture.
Law vs interpretation: Section 29 sets the statutory test (registered mark, deceptive similarity, course of trade, likelihood of confusion). Whether a specific domain, listing or keyword bid creates that likelihood is interpretation by courts on the facts — including the Delhi High Court’s current reference to a Larger Bench (Hindustan Unilever v. Kwick Living, 2026) on territorial jurisdiction for online trademark disputes, which does not change the substantive infringement test but affects where suit can be filed.
How does a phishing domain combine trademark and cybercrime?
A phishing clone — for example, a fake KYC page for a Kerala cooperative bank — is rarely just a trademark case. The same page typically violates both regimes at once:
- Trade Marks Act — Section 29 infringement and Section 27(2) passing off for the brand misuse.
- IT Act — Section 66C (identity theft) for fraudulent use of the brand’s identity feature and Section 66D (cheating by personation using a computer resource) for pretending to be the brand through a computer resource. Each carries up to three years and fine up to one lakh rupees.
- BNS — Section 318(4) (cheating), Section 319(2) (cheating by personation), Section 308 (extortion) where payment is extracted under threat, and Section 336 (forgery of electronic record) where fake documents are generated.
A Kerala business that treats the phishing page as only an IT support ticket and not as an IP enforcement matter leaves the infringement remedy — injunction, damages, domain transfer and platform blocking — unused. Both tracks should be pursued together: a criminal complaint for investigation and a civil/domain action for removal and recovery.
What are the practical takedown and recovery routes?
Route 1 — INDRP for .in domains, UDRP for gTLDs
| Forum | Domains | What the complainant must prove | Remedy | Typical timeline |
|---|---|---|---|---|
| INDRP (NIXI, under the .IN Registry) | .in, .भारत, and Indian ccTLDs | (i) Domain identical or confusingly similar to a mark in which complainant has rights, (ii) registrant has no rights or legitimate interests, (iii) domain registered or used in bad faith, or for an illegal/unlawful purpose (clause 4(c)) | Transfer or cancellation of the domain | 2 to 3 months (practitioner estimate), decided on papers |
| UDRP (WIPO and other ICANN providers) | .com, .net, .org and other gTLDs | Same three-element structure as INDRP (ICANN UDRP para 4(a); in UDRP the bad-faith element is conjunctive — registered and used in bad faith) | Transfer or cancellation | 2 to 3 months |
INDRP is cheaper than UDRP and is the natural route for phishing domains targeting Indian consumers with .in lookalikes. Evidence should include the trademark registration certificate, screenshots of the infringing site showing the mark as used, WHOIS, and any customer complaints or credential-theft reports. Where WHOIS is privacy-masked, the INDRP provider can direct the registrar to disclose the underlying registrant.
Route 2 — Intermediary takedown under Rule 3(1)(d) — three hours on actual knowledge
Under Rule 3(1)(d) IT Rules as amended 10 February 2026 (in force 20 February 2026), an intermediary that receives actual knowledge through a court order or a notification from the appropriate government or its authorised agency must remove or disable access to unlawful information — which includes trademark-infringing and phishing content — within three hours (down from 36 hours). Sensitive complaints involving impersonation or non-consensual imagery go faster — within two hours.
For brand owners without a court order, the grievance mechanism under Rule 3(2) is the parallel channel: every intermediary must appoint a Resident Grievance Officer, acknowledge complaints within 24 hours, and resolve them within seven days (down from 15 days), with a 36-hour track for unlawful-content grievances and a two-hour track for nudity and morphed imagery. In practice, file both: a Rule 3(2) grievance with specific URLs and proof of registration, and — where the phishing is active — a police complaint that can generate the government notification that triggers the three-hour Rule 3(1)(d) clock. The Karnataka High Court’s 2025 decision in X Corp v. Union of India, upholding the Sahyog portal as a Section 79(3)(b) takedown route (Karnataka HC, 24 September 2025), is part of this ecosystem.
Route 3 — Civil injunction including Dynamic+ orders
Where phishing is not a single domain but a network of rotating mirrors — a pattern the Delhi High Court addressed in Dabur India Ltd v. Ashok Kumar (2025:DHC:11862, pronounced 24 December 2025) — the remedy that has matured since UTV Software v. 1337X (Delhi HC, 2019) and Universal City Studios v. Dotmovies.baby (Delhi HC, 2023) is the Dynamic+ and Dynamic++ injunction: an order that binds ISPs, DoT and MeitY to block not only named sites but their future mirrors and redirects in real time, without a fresh suit for each new domain. Deployed in the December 2025 Warner Bros. order and the 2026 JioStar IPL order for copyright, the same architecture is sought in trademark phishing where the defendant rotates domains to evade blocking. Courts also increasingly direct registrars to lock and suspend infringing domains within 72 hours and to disclose registrant data in sealed cover.
Route 4 — Criminal complaint
File at cybercrime.gov.in and at the district Cyber Police Station under Sections 66C and 66D IT Act read with Sections 318, 319 and 336 BNS. The complaint should annex the trademark certificate, the phishing URLs, screenshots with URLs and timestamps preserved for Section 63 BSA certification, and the INDRP or platform grievance reference where already filed. Under Section 78 IT Act, investigation of Sections 66C and 66D is by an officer of Inspector rank or above.
Can a Kerala business handle a cross-border infringer?
Often, but with planning. A large share of phishing infrastructure is hosted outside India, uses privacy-masked WHOIS, and accepts payment through foreign gateways. Three points matter:
- Jurisdiction for online infringement. The Delhi High Court’s 2026 reference to a Larger Bench in Hindustan Unilever v. Kwick Living (CS(COMM) 904/2026, reference order dated 25 August 2026) — whether IP suits are governed solely by Section 20 CPC or by Section 134 Trade Marks Act / Section 62 Copyright Act, and what purposeful-availment test applies for online accessibility — means forum choice should be pleaded carefully. For a Kerala plaintiff, the cause of action where the brand is used to target Kerala consumers and where confusion occurs in Kerala is part of the jurisdictional pleading, but the evolving Larger Bench guidance should be checked before filing.
- Cross-border takedown. Rule 3(1)(d) and grievance duties apply to intermediaries that provide services to users in India, even without a physical presence in India. Foreign-hosted phishing domains can still be addressed through INDRP (where the domain is .in), UDRP, and registrar and hosting-provider abuse channels, alongside the Indian injunction and criminal complaint.
- Evidence from outside India. Foreign server logs and registrar data that are electronic records will need to satisfy Section 63 BSA if tendered in an Indian court — which means planning for a certificate with device particulars, hash and dual signatures rather than relying on forwarded screenshots alone.
Primary sources
- Trade Marks Act, 1999 — India Code (Sections 2(1)(h), 2(1)(zb), 27(2), 29, 134)
- Information Technology Act, 2000 — India Code (Sections 66C, 66D, 78, 79)
- Bharatiya Nyaya Sanhita, 2023 — India Code (Sections 318, 319, 336)
- IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as amended 10 February 2026 — Gazette of India, G.S.R. 120(E) (Rules 3(1)(d), 3(2), 4)
- Yahoo! Inc. v. Akash Arora ((1999) 19 PTC 201 (Del)); Satyam Infoway Ltd v. Siffynet Solutions (2004) 6 SCC 145
- INDRP Policy and Rules of Procedure — NIXI (.IN Registry) and UDRP Rules — ICANN/WIPO
- Dabur India Ltd v. Ashok Kumar (2025:DHC:11862) on dynamic injunctions and registrar disclosure
FAQ
