Jonathan Matkowsky

Jonathan Matkowsky

Threat-intel-backed investigation and domain takeover proceedings

Decades of experience spanning internationally recognized law firms, in-house legal teams, and elite cyber threat-intelligence teams.

I bring that experience together to investigate and disrupt malicious infrastructure, use legal process to pursue attribution, and where appropriate, make criminal referrals aimed at stopping threat actors from targeting or retargeting your organization.

Let’s explore together what makes practical sense for your organization.

What should a security team do when a domain is being used for phishing, fraud, a scam, or other abuse?

Preserve the evidence first. Capture the domain and URL, relevant pages or redirects, email artifacts, DNS and registration information, timestamps, and other indicators before the site, records, or hosting change.

Next, investigate scope. Determine whether the domain is isolated or connected to related domains, mail infrastructure, hosting, nameservers, redirects, analytics identifiers, templates, or registrant artifacts. That distinction affects whether the appropriate response is a single abuse report or a broader investigation and disruption effort.

The response can then be matched to the facts: defensive blocking, provider escalation, registrar or registry action, platform reporting, an administrative domain proceeding where the legal requirements are met, or other legal or law-enforcement escalation. The objective is to stop the immediate abuse while learning enough about the operator and infrastructure to reduce repeat targeting.

Sources: MITRE ATT&CK — Acquire Infrastructure: Domains

AI can make mistakes. By using this site, you hereby agree to the Terms and Privacy Notice.