
Netcraft has introduced a new capability that targets cybercrime at its earliest stage. The company announced its AI-powered Preemptive Domain Disruption system, a method that identifies and removes malicious domains before attackers ever use them. This is a shift in how domain-based threats are handled. It moves action from reaction to prevention.
For years, phishing attacks and Business Email Compromise (BEC) schemes have relied on one simple step: registering domains that look legitimate. Those domains sit idle until the attacker is ready. Netcraft’s latest release focuses on that idle period. That timing is where the opportunity exists. And Netcraft is taking advantage of it.
A Shift From Cleanup to Prevention
Traditional cybersecurity workflows often start after damage begins. A phishing page goes live. Emails are sent. Victims click. Only then does detection and takedown begin. Netcraft is moving that timeline earlier.
The company’s system identifies suspicious domains during the registration phase. That means before content appears. Before emails are sent. Before a single victim is exposed.
This is not a small adjustment. It changes the economics of cybercrime. Attackers depend on time. They register domains in bulk. They prepare infrastructure. They wait. Netcraft’s approach removes that waiting period entirely.
How the Technology Works
The system uses AI (Artificial Intelligence) to analyze clusters of domain registrations and infrastructure signals. These signals include technical configurations, registration patterns, and known attack indicators. Instead of reviewing each domain in isolation, the platform groups related activity together.
This clustering approach increases confidence. It reduces false positives. It also speeds up response time. Security teams can act on patterns rather than individual alerts.
Netcraft then collects enforcement-grade evidence. That evidence is used to work directly with registrars, hosting providers, and infrastructure operators. Domains are disabled before they can be weaponized.
Real-World Results Already Stand Out
Early deployment numbers are hard to ignore. Netcraft reports that about 90 percent of malicious domains identified are taken down within 24 hours. That is before most attacks would even begin.
One enterprise customer saw more than 21,000 domains removed in a three-month period. That volume matters. It shows how much infrastructure attackers prepare in advance. It also shows how much risk can be removed early.
In plain terms, this closes the gap between domain registration and attack execution. That gap used to be a blind spot. Now it is a control point.
Why This Matters for Brands and Security Teams
Brand impersonation remains one of the most effective attack methods. A domain that looks like a legitimate business can trick customers, employees, and partners. The damage is financial and reputational.
Netcraft’s approach reduces that risk before it becomes visible. Domains that mimic brands can be flagged and removed before they host phishing pages or send fraudulent emails.
This also reduces workload for security teams. Instead of chasing live threats, teams can focus on prevention. That shift saves time. It also reduces incident response costs.
Integration With Existing Security Ecosystems
Once a threat is confirmed, Netcraft distributes high-risk signals across multiple systems. These include DNS (Domain Name System) providers, email filtering platforms, and fraud detection networks.
This creates a ripple effect. A domain flagged in one place becomes blocked in many places. Attackers lose reach. Campaigns fail before they start.
It is a coordinated defense. And coordination has been missing in many threat response models.
Industry Perspective Signals a Larger Trend
Peter Cassidy, Co-Founder of the Anti-Phishing Working Group (APWG), described the approach as a move into the future of cybercrime prevention. He pointed to the role of AI in scaling attacks. The same technology can now be used to stop them earlier.
Netcraft plans to contribute its findings to APWG’s eCrime eXchange. That data-sharing effort expands visibility across the industry. It also helps standardize how pre-deployed malicious domains are tracked.
This is not just a product launch. It reflects a broader change in strategy across cybersecurity. Prevention is gaining ground over response.
Netcraft’s Position in the Threat Disruption Space
Netcraft has spent more than two decades focused on domain abuse, phishing detection, and infrastructure takedowns. The company already operates one of the largest takedown networks globally.
This new capability builds on that foundation. It uses historical data, known attack patterns, and infrastructure relationships to predict behavior. That predictive layer is where the value sits.
Ryan Woodley, CEO of Netcraft, pointed out a key issue. Attackers now prepare infrastructure earlier and faster. That means defenders must act earlier as well. Waiting for an attack to go live is no longer acceptable.
His point is direct. Remove the infrastructure, and the attack never happens.
What This Means Going Forward
Cybercrime has always relied on scale. Register enough domains, launch enough campaigns, and some will succeed. Netcraft’s approach targets that scale at its source.
If domains are removed before use, the attacker’s cost increases. Their success rate drops. Their operations slow down.
This is a practical change. It is not theoretical. The numbers from early deployments support that claim.
Security teams should pay attention. This is a different way to think about domain threats. It focuses on timing, infrastructure, and behavior patterns.
And it raises a simple question. Why wait for an attack if you can stop it before it starts?
Netcraft’s latest release answers that question with action. The company is moving defense upstream. That is where the fight is now. And that is where it will stay.