This is true [0]! But even more surprisingly clownstrike.com redirects to crowdstrike.com. I am surprised why they may have thought this is a good idea, but it means that we can actually use clownstrike.com instead to reference it in the web.
I worked at company_name when the .xxx top level domain became available, and my boss was sure that we should buy company_name.xxx. I talked them out of it. Luckily no one has maliciously registered company_name.xxx all these years later. I guess it could happen any day now.
CSCs whole deal is securing domain names for huge brands, they probably have people whose job involves thinking of derogatory domains like that so they can grab them pre-emptively. The people behind the .sucks TLD turned that into an incredible grift, they charge an exorbitant amount (about $300 a year) because they know every big brand will buy brand.sucks no matter what.
I worked for a company where MarkMonitor proactively registered domains for us which were likely typos of our brand (e.g. example.com -> examlpe.com, exmaple.com, etc), and would hunt down registrations of new domains which appeared likely to be phishing sites. They didn't catch everything, but they were pretty good.
[0] https://www.whois.com/whois/clownstrike.com