Anyone filing an international patent application (PCT) today is soon pushed to register in WIPO’s system – and finds their inbox filling up with dubious payment demands. Neither is a coincidence; both are the result of a policy that consistently shifts burdens and risks onto applicants. A critical assessment.
Anyone who files an international patent application under the Patent Cooperation Treaty (PCT) – for example through the European Patent Office (EPO) as receiving Office – regularly experiences two things. Shortly after filing, messages arrive from the World Intellectual Property Organization (WIPO) urging registration in its electronic ePCT system. And the e-mail address provided at filing fills up within weeks with deceptively authentic-looking “invoices” and “registration offers”. Both phenomena deserve a critical look.
From Optional Convenience to De Facto Compulsion
As recently as 2008, electronic communication was a mere add-on service: by ticking a box on the PCT request form, the applicant could authorise an “advance copy” of notifications by e-mail. The legally decisive channel remained delivery on paper. WIPO put it unmistakably at the time: the e-mail communications did not replace the “paper notifications sent by mail as usual, which will remain the legal copy”.
This coexistence ended abruptly. On 30 March 2020, in the course of its COVID-19 business-continuity protocol, WIPO’s International Bureau stopped sending paper documents and announced that it would henceforth transmit PCT documents “exclusively via email”. What began as a temporary pandemic measure has to this day – in 2026 – never been reversed. Electronic delivery has thus shifted from a convenience to the de facto standard; the traditional paper mail that many applicants prefer for good reason has practically ceased to exist. A voluntary add-on option has become – without any formal change in the law, solely through a never-ended “emergency measure” – a largely alternative-less channel.
The Pressure to Register: Account, App and “eHandshake”
In parallel, WIPO pushes its users into the ePCT system. Anyone who wants to view an application online, actively manage it or make submissions needs a “WIPO account” with “strong authentication” – in practice a smartphone app or a security token. Shared access to a file is additionally controlled via so-called “eHandshakes”, that is, the mutual linking of authenticated WIPO accounts before any access rights (eOwner, eEditor, eViewer) can even be assigned.
For large firms with a steady PCT practice this may be manageable. For occasional applicants, small and medium-sized enterprises or individual inventors, however, it means that in order merely to receive official communications they are expected to familiarise themselves with an account, app and rights-management system. Many – understandably – do not want to. Particularly unfortunate here is an inherent contradiction: the very organisation that sends unsolicited prompts to register and confirm an account warns elsewhere, in the strongest terms, against precisely such “official-looking” e-mails. For the recipient, the line between a legitimate prompt and phishing becomes blurred – a home-made problem.
The Open Data Source: How a Filing Turns Into Spam
The second point of criticism weighs more heavily. The International Bureau publishes every PCT application 18 months after the priority date in the freely accessible PATENTSCOPE database – with the names and addresses of applicants and representatives, application and publication numbers, title, IPC symbols and priority details. This data is systematically harvested and used to fuel a decades-old industry of misleading requests for payment: deceptively authentic-looking “invoices” for supposed registrations or publications that have nothing to do with WIPO.
The scale is remarkable. WIPO itself maintains a warning list of fraudulent senders covering the period from 2002 to 2024 – a documented problem spanning more than twenty years. Recently the attack vector has shifted: alongside the classic paper “invoices”, e-mail phishing is on the rise. In a warning dated 10 April 2026, WIPO reports fake e-mails impersonating WIPO, the EPO and the EUIPO – for instance via spoofed addresses such as admin@wipo-office.com – demanding payment for the supposed securing of IP rights. WIPO’s key statement reads: “None of these organizations – WIPO, EPO or EUIPO – will solicit payments through unsolicited emails”. Anyone filing a PCT application therefore feeds their contact data into an environment whose misuse the organisation has long been aware of.
In Fairness: The Spam Does Not Come From WIPO – But WIPO Enables It
At this point, fairness is called for. The dubious invoices and phishing e-mails do not come from WIPO. They are third-party fraud, against which WIPO expressly warns and which it occasionally even helps to pursue – as in the case stopped by the Florida Attorney General in 2009. Anyone who blames the flood of spam directly on WIPO misreads the facts.
And yet the criticism remains justified. For WIPO is not a neutral bystander but the operator of the infrastructure that makes the abuse possible in the first place. It obliges applicants to disclose their contact data, keeps the data source fully open year after year, and shifts the entire burden of vigilance onto those affected by way of a warning notice. At the same time, by abolishing paper delivery it has removed precisely that low-threshold, hard-to-scale channel that many applicants valued as a robust fallback. The result is a structure in which applicants must either enter WIPO’s ecosystem or risk missing official communications – and in which their data flows, in any event, into a fraud market known since 2002. An organisation that has documented the problem for so long could do more than warn: it could refrain from publicly exposing e-mail addresses, offer a genuine opt-out or paper option, and act more decisively against the senders.
What Applicants Can Do
Until the practice changes, a structured approach is advisable:
- Consolidate the address for service: Where possible, route official communications through the professional representative (as “common representative”) rather than exposing your own company or private address to direct delivery.
- Use a dedicated e-mail address: For IP matters, use a separate address or alias that can easily be replaced if abused.
- Do not pay unsolicited invoices: Check the sender address and the payment channel. Genuine WIPO communications end in
@wipo.int, and neither WIPO nor the EPO demands payment by unsolicited e-mail. Only the International Bureau charges fees for international publication – there is no separate third-party “publication fee”. - Establish internal approvals: Clearly define who in the organisation is authorised to approve payments for IP rights.
- Monitor deadlines independently: Do not rely on WIPO e-mails arriving reliably; note and monitor deadlines yourself.
Conclusion
WIPO’s communication practice is convenient for the organisation and inconvenient for applicants. The quietly perpetuated farewell to paper, the pressure to register and the unrestricted publication of contact data together paint a picture that is hard to reconcile with the claim of being a reliable, applicant-friendly authority. Until WIPO improves matters here, the rule is: every “official-looking” message following a PCT filing deserves a healthy dose of scepticism – and a firm processing protocol within the firm.