Masterclass Instructor Gets a Lesson in Trademarks

The Curious Case of Help-Aetna.com: A UDRP Dispute Analyzed

Blue image with the letters UDRP

Attorney John Berryhill delves into a fascinating Uniform Domain Name Dispute Resolution Policy (UDRP) case, Help-Aetna(.)com, exploring the complexities and nuances that lie beneath the surface of what initially appears to be a straightforward domain name dispute. The intrigue of this case stems not only from the subject matter but also from the prominent figures involved, highlighting the evolving landscape of internet law and domain name governance.

A Seemingly Routine UDRP Dispute

At first glance, the Help-Aetna(.)com dispute seems like a textbook UDRP case, typical of the many that flood the system. Aetna, a well-established and recognized US insurance giant, filed the complaint. Representing Aetna was Attorney Doug Isenberg, a respected voice in internet law and the author of the acclaimed GigaLaw blog. Isenberg’s expertise in the UDRP is further demonstrated through his “Masterclass” YouTube series, dedicated to unraveling the intricacies of the policy. Given Aetna’s brand recognition and Isenberg’s expertise, one would naturally expect a swift transfer of the domain name to the complainant, Aetna.

A Distinguished Panel of Experts

The arbitration panel assembled to decide the case was comprised of highly respected individuals within the domain name dispute resolution community. Mr. Christopher Gibson, known for his extensive experience and having authored over 200 UDRP decisions, was one of the panelists. He was joined by Mr. Brian Winterfeldt, a prominent intellectual property attorney and a leading figure as president of the ICANN Intellectual Property Constituency. Rounding out the panel was Mr. Martin Schwimmer, a Harvard-educated legal scholar and the author of The Trademark Blog, a well-regarded resource for trademark law insights. The experience and reputation of these panelists suggested a well-reasoned and thorough examination of the case.

The Unexpected Twist: KnowBe4’s Involvement

The first indication that this UDRP case was not as straightforward as it seemed came with the identification of the respondent: “Whois Privacy Service / Manager Knowbe4.” KnowBe4, represented by Wilson Sonsini, a leading Silicon Valley IP law firm, added an unexpected layer of complexity. KnowBe4 is a NASDAQ-listed IT security company that provides cybersecurity training and awareness programs.

The Security Training Context

KnowBe4 uses a library of content for simulated phishing attacks as part of its services to corporate clients. This involves creating decoy domain names that mimic those used by legitimate businesses in various industries. These domains are used in controlled phishing simulations to train employees to identify and avoid falling victim to real-world phishing scams.

No Exploitation of the Aetna Mark

Crucially, the domain name Help-Aetna(.)com was not being used to capitalize on or exploit Aetna’s brand or to divert Aetna’s customers. While KnowBe4 used the domain name in connection with its commercial security testing services, it was not presented to the public as an Aetna-branded service. The controlled and targeted nature of these phishing simulations meant that the emails were not indiscriminately sent, minimizing the potential for real-world harm or confusion.

The Facebook v. Wombat Security Technologies Precedent

Despite these facts, Aetna pursued the case, filing a supplemental submission referencing a similar case: Facebook v. Wombat Security Technologies. In that case, domain names such as facbook-login(.)com were used for similar phishing simulation purposes by Wombat Security Technologies, now part of Proofpoint Inc. Facebook, represented by Hogan Lovells, argued against Wombat, which was represented by Pattishall, McAuliffe. The single panelist in the Wombat case, Mr. Robert Badgely, ruled in favor of Facebook, interpreting “bad faith” to include situations lacking malice.

The Wombat Case: A Contentious Decision

The decision in the Wombat case was met with considerable scrutiny and debate within the domain name legal community. Many considered it an expansive and questionable interpretation of “bad faith” under the UDRP, as it seemed to disregard the intent-based element traditionally associated with the term. This decision raised concerns about the potential for the UDRP to be applied in cases where there was no demonstrable intent to harm or exploit a trademark.

The Aftermath: Proofpoint v. Facebook in US District Court

The Wombat case did not end with the UDRP decision. Proofpoint, the parent company of Wombat, challenged the decision by filing a lawsuit against Facebook in the US District Court for the District of Arizona. The case, Proofpoint Incorporated v. Facebook Incorporated, ultimately ended with a voluntary dismissal, suggesting that the parties reached a settlement or agreement. The realization that a decoy name used for legitimate security testing does not infringe a trademark likely contributed to the resolution.

The Dynamics of a Three-Member Panel

Unlike single-member UDRP panels, a three-member panel involves deliberation and discussion among experienced experts. This collaborative process increases the likelihood that initial assumptions and unsupported conclusions will be challenged and refined. The multi-faceted perspectives provided by a panel of experts often lead to more nuanced and well-reasoned outcomes.

A Missed Precedent?

Remarkably, it appears that neither the complainant, respondent, nor the panel was aware of the Wombat case, despite its prior attention. The panel acknowledged that the case presented “an interesting question,” but there was no indication that they knew the question had been previously litigated. This highlights the challenges in effectively indexing and tracking UDRP decisions, which can lead to missed precedents and potentially inconsistent outcomes. The fact that UDRP disputes are often considered a niche area of IP law might also contribute to the limited awareness of past cases.

The Panel’s Decision in Help-Aetna(.)com

In the Help-Aetna(.)com case, the panel adopted a more circumspect view, finding that KnowBe4’s use of the domain name did not constitute the type of abusive domain registration that the UDRP was designed to address. The panel analogized the situation to a security company simulating a bank robbery to promote its services. While such an action might be in poor judgment or create some form of liability, it would not constitute a bank robbery if the company never actually robbed the bank.

Two Similar Cases, Two Different Outcomes

The Help-Aetna(.)com case underscores the inconsistencies that can arise within the UDRP system. Two virtually identical fact patterns resulted in diametrically opposed outcomes. The lack of readily accessible and comprehensive indices of UDRP decisions can contribute to this inconsistency, as parties and panelists may be unaware of relevant precedents. Although the *Wombat* case could have been cited and potentially contradicted, the dynamics of three-member UDRP panels and the strict requirements for establishing domain registration abuse led to the same outcome, but only after a detailed review process.

Conclusion

The Help-Aetna(.)com case serves as a reminder of the complexities involved in UDRP disputes, even when the underlying facts appear straightforward. It highlights the importance of carefully considering the context in which a domain name is used, as well as the need for greater transparency and accessibility within the UDRP system to ensure consistency and predictability in outcomes. The contrasting outcomes of the Help-Aetna(.)com and Wombat cases exemplify the subjective nature of the UDRP and the potential for divergent interpretations of key concepts such as “bad faith.” As the internet continues to evolve and new challenges emerge, it is essential that the UDRP remains adaptable and responsive to the needs of both trademark holders and domain name registrants. The decision to protect the rights of the registrant KnowBe4 shows that there is room for reasonable use of domain names.