@RobSalesforce The first one sounds illegal; you could just send a cease and desist.
For the second one, just talk to the admins. Admins are approachable on Fedi. (As such, this isn't actually a viable attack, and people don't do it.)
The only "cybersquatting" I've ever seen here is when somebody pretended to be Benjamin Netanyahu for a couple of weeks on one of the fascist instances; I think the motivation there was to prank people.