Rebuilding the Brand Catalog

/brands is our public record of brand impersonation: one page per brand, listing the hosts where that brand's name turned up on a page we scanned. It has been rebuilt this week, and the changes are mostly about being honest rather than being bigger.
As of 10 September 2026 it monitors 651 brands, of which 89 have published detections, covering 3,479 sightings.
Listing a host is an accusation, so both engines have to agree
Every scan gets two independent verdicts: a rule engine and an AI analysis. The catalog now withholds a (brand, host) pair when both call the page harmless. That currently holds back 413 pairs.
What it deliberately is not is a "hide anything low-risk" filter. 260 published pairs are rated low risk by the rule engine while the AI analysis calls them high risk or an outright scam — which is usually the rule engine underrating a real phishing kit. A simple risk-band filter would have deleted exactly those, which are the ones most worth publishing.
Withheld pairs are counted and disclosed, never quietly dropped. Each brand page says how many and why, in those words:
4 further hosts are not listed: the MetaMask name appeared on them, but both our rule engine and our AI analysis rated the page harmless, so we do not publish them as impersonation.
Every row shows its evidence
A brand name appearing on a page is not all one thing. metamask-ai-agent.vercel.app, titled
"MetaMask Assist AI", is a different claim from a blog post that mentions MetaMask in passing.
So each row now states where the match came from — the brand in the hostname, in the page title,
or only in the page and screenshot text — alongside the verdict and the scan it came from.
Weak provenance is labelled as weak rather than hidden. And every row carries a Report as wrong link, prefilled with the host, the brand and the scan, because a public accusation should come with a way to contest it.
It is actually browsable now
The gallery used to return all 651 brands on every load, most of which had nothing to show. It now defaults to brands with detections and does filtering, sorting and paging on the server — the page dropped from 244 KB to about 100 KB.
Brand pages paginate properly too. Facebook has 927 hosts; the old page capped at 100 and 89% of them were simply unreachable. Each brand also gets a detection timeline and a CSV or JSON export, so you can take the data rather than scrape it.
The logos are ours
The gallery used to fall back to a third-party favicon service for brand logos. That meant 59 requests per page load to another company, each one carrying the name of the brand you were looking at. On a site whose product is finding trackers, that is not a defensible default.
Logos are now harvested once from each brand's own domain and served from our origin — 62 so far, with a plain monogram for the rest. Nothing on the page reaches off-site.
A few to look at
- MetaMask — 132 hosts, mostly free-hosting subdomains naming the wallet outright
- Facebook — the largest set by a wide margin, at 927 hosts
- Social Security Administration — government-benefit lures, a steady and under-reported category
- Trust Wallet and Roblox — crypto and gaming, the two audiences targeted hardest
- DocuSign — the document-lure pattern behind a lot of corporate credential theft
If your brand is listed somewhere it should not be, use the report link on the row. It reaches us with the scan attached.
Figures measured 2026-09-10 and they move daily; the live counts are on /brands.