It would be difficult for someone to sit on a domain and hold it for ransom, as unless you can show evidence that it is related to a business/site you run, you can get the domain registrar to take it back from the cybersquatter and return it to you - you also get a grace period if you forget to renew of about 12 days, so unless Halfords are particularly stupid (insert comments), they should be fine.
Ian