Jonathan Matkowsky

Jonathan Matkowsky

Threat-intel-backed investigation and domain takeover proceedings

Decades of experience spanning internationally recognized law firms, in-house legal teams, and elite cyber threat-intelligence teams.

I bring that experience together to investigate and disrupt malicious infrastructure, use legal process to pursue attribution, and where appropriate, make criminal referrals aimed at stopping threat actors from targeting or retargeting your organization.

Let’s explore together what makes practical sense for your organization.

How should an organization choose among provider escalation, domain proceedings, litigation, and law-enforcement referral?

The choice should start with the objective, the evidence, the urgency, and the remedy each path can actually provide. Technical blocking may protect users immediately; a registrar, registry, host, or platform may be able to disable infrastructure; an administrative proceeding may support transfer or cancellation of a qualifying domain; litigation or legal process may provide different remedies or evidence; and law enforcement may have investigative authorities unavailable to a private organization.

Those paths are not necessarily a fixed ladder. Some can run in parallel, while in other matters acting too early can destroy evidence or alert the operator before the broader infrastructure is understood. Preserving the record and identifying who has authority to act are therefore part of the strategy, not merely preliminary tasks.

A useful enforcement decision connects threat intelligence to the legal and operational choices available. The goal is to select the path—or combination of paths—that fits the evidence and business objective without assuming that every malicious domain requires the same response.

AI can make mistakes.

By submitting a question to the AI, you thereby agree to the Terms and Privacy Notice.