Jonathan Matkowsky

Jonathan Matkowsky

Threat-intel-backed investigation and domain takeover proceedings

Decades of experience spanning internationally recognized law firms, in-house legal teams, and elite cyber threat-intelligence teams.

I bring that experience together to investigate and disrupt malicious infrastructure, use legal process to pursue attribution, and where appropriate, make criminal referrals aimed at stopping threat actors from targeting or retargeting your organization.

Let’s explore together what makes practical sense for your organization.

How do you investigate and disrupt phishing or spear-phishing infrastructure?

A phishing response can begin with the lure domain, URL, sender, or landing page, but a stronger investigation looks for the infrastructure behind it: related domains, DNS history, hosting, mail configuration, redirects, certificates, page resources, registration patterns, and other recurring fingerprints.

The goal is to identify the scope of the operation before choosing a disruption path. Depending on the evidence and circumstances, options may include registrar or host escalation, abuse reporting, administrative domain proceedings, other provider action, technical blocking, or legal escalation. Removing one domain without understanding the surrounding infrastructure can leave the operator free to retarget the organization quickly.

In a 2021 dispute brought by Blackhawk Network, Inc. (WIPO D2021-1611), historical IP data, redirects, Google Analytics identifiers, site content, and registrant details helped link 27 domains, all of which were transferred. The published decision identified three active phishing pages; the remaining domains had other states or uses.

Sources: MITRE ATT&CK — Acquire Infrastructure: Domains

AI can make mistakes. By using this site, you hereby agree to the Terms and Privacy Notice.