Threat Center
A real-time window into what our sensor grid is catching right now. Every pulse, alert and takedown below reflects the same detection pipeline our analysts work — phishing, scams and malware, surfaced across the internet the moment they appear.
Global detections, streaming in real time
142 sensor nodes across six continents correlate billions of signals a day. The map shows where investigations are open; the feed shows individual detections as they land.
The numbers moving as you read
Tracking 318 active scam networks across 40+ threat feeds. Median takedown time this week: under 12 hours.
Recent takedowns
A sample of malicious assets our analysts confirmed and actioned. Domains are redacted only where an investigation is still open.
| Domain | Type | Origin | Status | Actioned |
|---|---|---|---|---|
| paypa1-secure-login.top | Phishing | 🇷🇺 Russia | Suspended | 2h ago |
| coinbase-wallet-verify.app | Phishing | 🇳🇱 Netherlands | Suspended | 3h ago |
| dhl-parcel-redelivery.info | Scam | 🇩🇪 Germany | Reported | 5h ago |
| ledgerlive-restore.net | Malware / C2 | 🇺🇸 United States | Sinkholed | 6h ago |
| irs-refund-2026.support | Scam | 🇺🇸 United States | Suspended | 8h ago |
| micros0ft-365-alert.co | Impersonation | 🇬🇧 United Kingdom | Reported | 11h ago |
| metamask-sync-wallet.io | Phishing | 🇸🇬 Singapore | Suspended | 14h ago |
| fedex-tracking-fee.click | Scam | 🇫🇷 France | Sinkholed | 18h ago |
Statuses: Suspended — asset disabled by the registrar or host · Reported — abuse notice filed, escalation in progress · Sinkholed — traffic redirected to a controlled server to neutralize command-and-control.
Top threat categories this week
Credential phishing continues to dominate the mix, but scam and impersonation campaigns are climbing as attackers chase parcel-delivery and financial-services lures. Percentages reflect verified detections across our sensor grid over the last seven days.
- Phishing leads at 38%Fake login pages targeting banks, wallets and SaaS accounts.
- Impersonation is risingLook-alike domains spoofing recognizable brands and government agencies.
Run the same checks our analysts do
Paste any domain you find suspicious. Our engine resolves DNS and WHOIS, cross-references 40+ threat feeds, inspects the TLS certificate and scores brand-impersonation signals — in seconds. Anything malicious goes straight into our takedown queue.
Seen a threat we haven't?
Report a suspicious domain in seconds, or talk to our SOC about continuous monitoring for your brand and customers.