Brand impersonation intelligence
See the fake site before your customers do.
OctopuShield watches suspicious domain activity to surface brand impersonation early — with source, time and evidence attached to every finding.
What the score is made of
- sector word present
- call-to-action word
- sector + action combined
- deep subdomain chain
| What was found | First seen (UTC) | Score |
|---|---|---|
| sector word present •••[.]•••[.]portal[.]•••[.]exchange[.]•••[.]•••[.]net | Oct 03, 09:50 AM | 60/100 |
How it works
From suspicious address to evidence.
Every finding travels the same path, and every step leaves something you can inspect afterwards.
Continuous monitoring
New addresses resembling your brand are seen as soon as they appear. If monitoring stops, it does not stop quietly — the panel says so.
Filtering
Look-alike impersonations are reduced to a comparable form; names that look similar but are spelled differently are caught, not dropped.
Prioritisation
Each candidate is ranked by how strong the impersonation is. The order you see starts with what you should look at first.
Visit evidence
Optional, off by default. If enabled, an anonymous report is made when a fake page is actually opened. No identity is involved.
Evidence
Source, timestamp, record reference and the reasoning behind the ranking are kept together, so a finding stays reviewable, contestable and forwardable.
Current status
What the engine is seeing right now
Measured on the open early signal stream. Every number below was counted, not estimated — where something was not measured it says so.
Three things you get to know.
What appeared.
Newly observed domains tied to the names you monitor, each with the source that produced it and the time it was first seen.
Why it matters.
The reasoning behind each candidate is written out — why it is considered suspicious, when it was seen and which facts support it — so a human can judge.
What you can prove.
Findings carry their source, timestamp and raw record reference, so a takedown request is not built on a screenshot.
Operational console
The same discipline inside the product.
The console shows what the system currently holds. When a number is zero, it stays zero — no placeholder rows, no invented activity.
Sentinel
When your page is copied, the copy can say so.
Sentinel is a small script you place on your own site. If the page is copied and republished under another domain, it shows the visitor a notice and points them back to your real address. It runs before any network call, so the notice appears even if the request never completes.
- No identity is collected — no email, no username, no account identifier.
- The optional observation channel is anonymous and unverified by design.
- It does not block, redirect silently, or make an enforcement decision.
Our commitment
Security without invented certainty.
- We do not say blocked when we only observed.The product surfaces and documents. It does not block traffic, and it does not claim to.
- We do not show 100% coverage when coverage has not been measured.Coverage is not currently measured, so we do not publish a coverage figure.
- We do not turn anonymous observations into identity decisions.Observations are anonymous and classed as unverified. They never become a verdict about a person.
- Every operational number has a date.A figure without a timestamp is not evidence, so we do not present one.
Evidence & validation
Evidence you can inspect.
References
References available on request.
No approved public references are listed at the moment. Internal and test properties are not customers and are never presented as such.
- 瑞湖银行CN
- 长风证券CN
- 明州信托CN
- 云岭商业银行CN
- Северный Кредит БанкRU
- Банк «Ладога-Инвест»RU
- Банк «Дніпро-Степ»UA
- Банка Моравска УнијаRS
- Harmattan Trust BankNG
- Ashanti Delta BankGH
- Benki ya Ziwa KuuKE
- Benki ya Serengeti MasharikiTZ
- Cascadia Union BankUS
- Beacon Harbor FinancialUS
- Sierra Vista TrustUS
- Granite Ledger BankUS
- Banco Serra DouradaBR
- Financeira Amazônia VerdeBR
- Banco Pampa UniãoBR
- Banco del Plata AustralAR
- Coral Sea Mutual BankAU
- Outback Pastoral BankAU
- Southern Cross SavingsAU
- Aoraki Community BankNZ
These 112 institutions are invented. None of them is a customer, a partner, or a real organisation. They are shown only to illustrate how the product looks once brands are being monitored. Names are written in their original scripts because impersonation detection works across scripts.
Frequently asked questions
How early will I see addresses impersonating my brand?
Most impersonating addresses become visible before anyone has visited them. Each finding arrives with its first-seen time, public registration facts and an evidence digest; the decision is yours.
Do you catch every impersonation?
No, and we say so plainly. No monitoring sees everything. Where something cannot be observed the product writes "not measured" — never "no threat". The reason behind a zero is always distinguishable.
What do I do with a finding?
You pick the right recipient (registrar, host, blocklist or national CERT) and the application package is prepared in your language. Sending is your decision and your action; the system sends nothing on your behalf.
How long does a phishing site typically stay alive?
Industry measurements put the median lifetime in the range of hours, with the large majority closing on their own without anyone intervening. The practical consequence: a takedown vendor saying 'we removed it in X minutes' is not by itself evidence of impact. Measuring impact requires comparing domains that were acted on against domains that were not.
How does a CAA record prevent brand impersonation?
CAA limits which certificate authorities may issue for your domain. Without CAA, every authority in the world can issue in your name. But an incomplete CAA also hurts you: an authority missing from the list cannot renew, and your site goes down when the certificate expires. That is why CAA must be derived from the authorities the domain actually uses, not guessed.
How long does a takedown take, and what can be done meanwhile?
Registrars and hosts can take days, sometimes weeks. Throughout that window the site is live and victims reach it. What can be done without waiting is turning findings into a blocklist enforceable on your own network (DNS resolver, firewall, browser blocker). That is independent of what the registrar does and takes effect in seconds.
See what is already out there under your name.
A demo runs against real data for the names you choose. Nothing is published, and nothing is sent to your customers.
As of September 3, 2026