Threat Center
A real-time window into what our sensor grid is catching right now. Every pulse, alert and takedown below reflects the same detection pipeline our analysts work, phishing, scams and malware, surfaced across the internet the moment they appear.
Global detections, streaming in real time
142 sensor nodes across six continents correlate billions of signals a day. The map shows where investigations are open; the feed shows individual detections as they land.
The numbers moving as you read
Tracking 318 active scam networks across 40+ threat feeds. Median takedown time this week: under 12 hours.
Recent takedowns
A sample of malicious assets our analysts confirmed and actioned. Domains are redacted only where an investigation is still open.
| Domain | Type | Origin | Status | Actioned |
|---|---|---|---|---|
| paypa1-secure-login.top | Phishing | 🇷🇺 Russia | Suspended | 2h ago |
| coinbase-wallet-verify.app | Phishing | 🇳🇱 Netherlands | Suspended | 3h ago |
| dhl-parcel-redelivery.info | Scam | 🇩🇪 Germany | Reported | 5h ago |
| ledgerlive-restore.net | Malware / C2 | 🇺🇸 United States | Sinkholed | 6h ago |
| irs-refund-2026.support | Scam | 🇺🇸 United States | Suspended | 8h ago |
| micros0ft-365-alert.co | Impersonation | 🇬🇧 United Kingdom | Reported | 11h ago |
| metamask-sync-wallet.io | Phishing | 🇸🇬 Singapore | Suspended | 14h ago |
| fedex-tracking-fee.click | Scam | 🇫🇷 France | Sinkholed | 18h ago |
Statuses: Suspended, asset disabled by the registrar or host · Reported, abuse notice filed, escalation in progress · Sinkholed, traffic redirected to a controlled server to neutralize command-and-control.
Top threat categories this week
Credential phishing continues to dominate the mix, but scam and impersonation campaigns are climbing as attackers chase parcel-delivery and financial-services lures. Percentages reflect verified detections across our sensor grid over the last seven days.
- Phishing leads at 38%Fake login pages targeting banks, wallets and SaaS accounts.
- Impersonation is risingLook-alike domains spoofing recognizable brands and government agencies.
Run the same checks our analysts do
Paste any domain you find suspicious. Our engine resolves DNS and WHOIS, cross-references 40+ threat feeds, inspects the TLS certificate and scores brand-impersonation signals, in seconds. Anything malicious goes straight into our takedown queue.
Seen a threat we haven't?
Report a suspicious domain in seconds, or talk to our SOC about continuous monitoring for your brand and customers.