• JADEPUFFER: the first agentic ransomware

  • JADEPUFFER: the first agentic ransomware

  • External Attack Surface Management: reducing your external exposure

  • External Attack Surface Management: reducing your external exposure

  • Stay ahead of threats to your industry with real-time intelligence.

  • Stay ahead of threats to your industry with real-time intelligence.

  • Your executives are targets. Monitor your leadership's digital exposure.

  • Your executives are targets. Monitor your leadership's digital exposure.

REAL CASES

Alone it seemed like a routine. Correlated it became a case

Work we delivered, told the way it happened: the signal that looked isolated, the correlation that changed the reading and what it prevented in practice.

All 28

Brand 6

Fraud 8

Leak 7

Exposure 5

People 4

Third parties 4

A leaked credential, five open doors

ISOLATED SIGNAL

A credential in a stealer log tied to the URL of an authentication portal — on its own it would look like a one-off password reset.

CORRELATION

Cross-referenced with External Attack Surface Management, we identified four other company portals reachable with the same credential.

OUTCOME

Instead of closing one door we closed five — access revoked across every portal at once, with MFA reinforced at the entry points.

All sectors

External Attack Surface Management

The executive's personal account nobody reports

ISOLATED SIGNAL

An executive's personal credential found in a leak — the kind of finding a traditional CTI does not report, because it is not corporate.

CORRELATION

We validated that the credential gave access to the executive's Instagram and LinkedIn.

OUTCOME

An open door for social engineering and impersonation, closed before it could be used against the company and its contacts.

All sectors

VIP Monitoring

Phishing with the customer data already for sale

ISOLATED SIGNAL

A spoofed domain imitating the brand — on its own it would look like just another opportunistic phishing page.

CORRELATION

Cross-referenced with Deep & Dark Leak: the same customer data from that domain was already circulating on a fraud marketplace.

OUTCOME

It reveals a coordinated campaign, not an isolated incident — and the response gets prioritised by the real scale.

All sectors

Brand Protection · Deep e Dark Leak

Stolen session: access with no password and no MFA

ISOLATED SIGNAL

A valid session cookie in a stealer log — with it, the attacker walks straight into the authenticated session, no password and no second factor triggered.

CORRELATION

Cross-referenced with the mapped assets, we confirmed the session belonged to an active corporate system and was still valid.

OUTCOME

Session killed and credentials rotated immediately — changing the password alone would not have worked: the cookie would still be valid.

All sectors

Infostealer Monitoring · External Attack Surface Management

The compromised supplier holding the key to the environment

ISOLATED SIGNAL

An incident at a provider, spotted by the Intel Hub — it would look like something that did not affect the client directly.

CORRELATION

Cross-referenced with Third Party Risk Manager, we confirmed that provider had direct access to one of the client's environments.

OUTCOME

Access isolated before the supplier's incident became the client's incident — cutting the chain before it propagates.

All sectors

Intelligence · Third Party Risk Manager

The credential that was worth a code repository

ISOLATED SIGNAL

An employee's credential and cookie in a stealer log — at first glance, just another routine alert.

CORRELATION

We cross-referenced it with the public professional profile and saw it was a developer: the access could reach code repositories and development environments.

OUTCOME

Treated as top priority because of the blast radius — sessions revoked and a sweep for secrets exposed in the code.

All sectors

Infostealer Monitoring · Investigation

The 4pm insider

ISOLATED SIGNAL

On a closed forum, a seller was offering access and internal information about a client. It could be a bluff — sellers commonly inflate what they have to attract buyers.

CORRELATION

Working undercover, one pattern stood out: he only replied after 4pm. We mapped the employees whose shift ended at that hour and, with camera footage, caught the suspect photographing the screen.

OUTCOME

Suspect identified and the case documented with evidence — legal response and dismissal before the access was sold.

All sectors

Deep e Dark Leak · Investigation

The issuer's cards for sale on the dark web

ISOLATED SIGNAL

A criminal marketplace advertising a batch of cards — with no confirmation they belonged to the client's base.

CORRELATION

We collected the partial data available (BIN, first six and intermediate validating digits) and cross-referenced it with the issuer's base, confirming authenticity and scoping the batch.

OUTCOME

An actionable report handed to the security team, which validated and blocked the compromised cards before use.

Banking & Finance

Deep e Dark Leak · Fraud Exposure

The fraud that starts before the login

ISOLATED SIGNAL

A spike in internet banking access attempts with no apparent failure — it looked like nothing more than anomalous traffic.

CORRELATION

The combinations being tested matched customer credentials already leaked on other services: it was credential stuffing, not brute force.

OUTCOME

At-risk accounts identified by name and protected before the first fraudulent transfer, without locking down the entire base.

Banking & Finance

Infostealer Monitoring · Fraud Exposure

The corporate access advertised on the forum

ISOLATED SIGNAL

An ad offering VPN access to a financial institution, without naming it — only the sector, the size and the region.

CORRELATION

ASM identified the exposed VPN concentrator that matched the description, and Deep & Dark tied the offer to a known access broker.

OUTCOME

Access closed and credentials rotated before the sale — cutting ransomware at the stage where it is still a negotiation.

Banking & Finance

External Attack Surface Management · Deep e Dark Leak

The fake app that asks for the second factor

ISOLATED SIGNAL

An application carrying the bank's name published on an unofficial store, with few installs and inflated ratings.

CORRELATION

The app replicated the login screen and captured the MFA token — and the server it used matched an already active phishing campaign.

OUTCOME

App removed and infrastructure taken down before mass distribution — the scam dies before it scales.

Banking & Finance

Brand Protection · Takedown

Insiders selling SIM swaps

ISOLATED SIGNAL

While monitoring fraud channels, an individual was offering SIM swap services claiming access to real carrier employees — it could have been a bluff.

CORRELATION

We interacted directly with the fraudster inside the monitored environment, progressively enriching the data: full names, phone numbers, staff IDs, corporate emails and photographs.

OUTCOME

More than 50 unique records of compromised employees identified — the basis for an internal and legal response before exploitation.

Telecom

Deep e Dark Leak · Investigation

The SIM card that became a bank account

ISOLATED SIGNAL

A partner store attendant's credential in a stealer log — one more third-party access among thousands.

CORRELATION

Cross-referenced with ASM, the credential opened the SIM activation portal — and on Deep & Dark that same access was already being advertised for ownership transfers.

OUTCOME

Access revoked ahead of the SIM swap wave — the scam that intercepts the confirmation SMS and empties the subscriber's account.

Telecom

External Attack Surface Management · Deep e Dark Leak

The subscriber lookup sold by subscription

ISOLATED SIGNAL

A Telegram bot offering personal-data lookups by tax ID, answering in seconds for a monthly price.

CORRELATION

The format of the fields returned matched the layout of an internal service system — this was not an old database, it was a live query.

OUTCOME

The improper access account identified and cut off — the subscriber base stops feeding activation fraud and social engineering.

Telecom

Deep e Dark Leak · Investigation

The antenna nobody knew was answering

ISOLATED SIGNAL

A network element management panel exposed on the internet, with factory default credentials and outside the inventory.

CORRELATION

ASM tied the IP to a carrier block and the Threat Feed showed active scanning against that equipment model in the same week.

OUTCOME

Panel taken offline before exploitation — avoiding network downtime and the regulatory risk of a service interruption.

Telecom

External Attack Surface Management · Feed Signal

The shell company network behind the clones

ISOLATED SIGNAL

Different phishing pages, apparently unrelated, were using the same instant-transfer key to collect payments from victims.

CORRELATION

We correlated dozens of fraudulent ads through that same key and analysed the company registration naming pattern, which exposed dozens of other similar registrations.

OUTCOME

An organised network of roughly 20 shell companies mapped — it becomes a report on an entire operation, not a takedown that reappears the following week.

Retail & E-commerce

Brand Protection · Investigation

The internal domain nobody knew existed

ISOLATED SIGNAL

Called in under war room conditions, with no indication of a vector — only the brand as a starting point.

CORRELATION

The attack surface analysis starting from the brand revealed an internal domain unknown to the client's own security team, with a remote access service publicly exposed.

OUTCOME

Entry point closed — that was exactly where the attacker was trying to authenticate, and the access was available to anyone on the internet.

Retail & E-commerce

External Attack Surface Management

The critical flaw in the customer service platform

ISOLATED SIGNAL

Routine monitoring at a retailer that already had a CTI solution — one more collection cycle, no standout alert.

CORRELATION

The analysis identified a critical remote access vulnerability in the customer service platform, with sensitive data reachable.

OUTCOME

Mitigated before it was exploited — and the operation went on to generate more accurate events, with a drop in false positive volume.

Retail & E-commerce

External Attack Surface Management · Third Party Risk Manager

The clone already selling with your customers' data

ISOLATED SIGNAL

A fake store carrying the brand's visual identity advertising a sale — at first glance, another routine takedown.

CORRELATION

The e-tracker showed the page was a literal copy of the official site — and on Deep & Dark the customer data was already circulating for sale.

OUTCOME

Campaign blocked and customers warned ahead of the chargebacks — protecting revenue, reputation and the cost of support.

Retail & E-commerce

Brand Protection · Deep e Dark Leak

The coupon that became a loss at scale

ISOLATED SIGNAL

A Telegram group circulating discount coupons that nobody in marketing created, with usage climbing by the hour.

CORRELATION

The generation pattern pointed to access to the promotional panel — and an analyst's credential appeared in a stealer log from the same week.

OUTCOME

Panel locked and coupons invalidated before the weekend — cutting the margin loss before it became meaningful volume.

Retail & E-commerce

Deep e Dark Leak · Infostealer Monitoring

The fake job ad that harvested ID and selfie

ISOLATED SIGNAL

A job posting using the brand's name on a social network, asking candidates for an ID document and a selfie.

CORRELATION

The profile publishing the vacancy was linked to other cloned pages from the same operation, already mapped by Brand Protection.

OUTCOME

Profile removed and a notice issued — preventing the candidate's data from becoming a fraudulent account opened in their name.

Retail & E-commerce

Brand Protection · Takedown

The hospital access for sale in the underground

ISOLATED SIGNAL

An offer of corporate access naming a hospital on an access broker forum — one among dozens of generic offers.

CORRELATION

The most active buyer was a ransomware group with a track record in healthcare — a halted patient system forces a fast payment.

OUTCOME

Access isolated and backups reinforced before the purchase — instead of finding out through a hijacked medical record and a halt in care.

Healthcare

Deep e Dark Leak · Intelligence

The medical record that leaked through the supplier's door

ISOLATED SIGNAL

An incident at a remote diagnostics company, reported as the supplier's problem, with no mention of the hospital.

CORRELATION

TPRM confirmed that this supplier maintained an active API integration with the client's medical record system.

OUTCOME

Integration suspended and credentials rotated before it spread — sensitive patient data stays out of the breach.

Healthcare

Third Party Risk Manager

The on-call credential that never expires

ISOLATED SIGNAL

A shared on-call login turned up in a stealer log, with the session cookie still valid.

CORRELATION

The session belonged to the scheduling and medical record system, reachable from outside — changing the password would not kill the cookie.

OUTCOME

Session killed and access individualised — closing the door that bypasses MFA and leaves no audit trail.

Healthcare

Infostealer Monitoring · External Attack Surface Management

When miles are the most liquid currency

ISOLATED SIGNAL

Improper access to the loyalty programme exposed names, contact details, mileage balances and partial card data.

CORRELATION

The pattern pointed to checkers testing en masse credentials already circulating in leaks and stealer logs — it was not a new intrusion, it was reuse of an old credential.

OUTCOME

Highest-balance accounts protected before fraudulent redemption — miles are currency, and the loss is financial, not merely reputational.

Aviation Services

Infostealer Monitoring · Fraud Exposure

The fake agency selling tickets that do not exist

ISOLATED SIGNAL

A ticket sales site priced well below market, using the airline's brand and identity.

CORRELATION

The same registration pattern appeared across other travel domains — Investigation mapped the shell network behind the pages.

OUTCOME

It becomes a report on an entire operation, not a takedown that reappears under another domain the following week.

Aviation Services

Brand Protection · Investigation

The executive who shows up on the radar before the trip

ISOLATED SIGNAL

A mention of one of the airline's executives on a closed forum, alongside the itinerary and agenda of a public event.

CORRELATION

Cross-referenced with VIP Monitoring, his personal data was already exposed — material ready for impersonation and deepfakes.

OUTCOME

Exposure reduced and the team alerted before the event — cutting off the payment authorisation scam run in the board's name.

Aviation Services

VIP Monitoring · Deep e Dark Leak

The exam leak before the test date

ISOLATED SIGNAL

Profiles on a social network offering access to exam content ahead of the official date — at first, a promise with nothing behind it.

CORRELATION

Analysis of the partial images published as samples visually confirmed a genuine leak; tracing the payment key and cross-referencing through OSINT identified one of the sellers as a teacher in a specific state.

OUTCOME

Origin located at a school in that state, with time to spare — containment before the material circulated widely.

Education

Investigation · Brand Protection