JADEPUFFER: the first agentic ransomware
JADEPUFFER: the first agentic ransomware
External Attack Surface Management: reducing your external exposure
External Attack Surface Management: reducing your external exposure
Stay ahead of threats to your industry with real-time intelligence.
Stay ahead of threats to your industry with real-time intelligence.
Your executives are targets. Monitor your leadership's digital exposure.
Your executives are targets. Monitor your leadership's digital exposure.
REAL CASES
Alone it seemed like a routine. Correlated it became a case
Work we delivered, told the way it happened: the signal that looked isolated, the correlation that changed the reading and what it prevented in practice.
All 28
Brand 6
Fraud 8
Leak 7
Exposure 5
People 4
Third parties 4
A leaked credential, five open doors
ISOLATED SIGNAL
A credential in a stealer log tied to the URL of an authentication portal — on its own it would look like a one-off password reset.
CORRELATION
Cross-referenced with External Attack Surface Management, we identified four other company portals reachable with the same credential.
OUTCOME
Instead of closing one door we closed five — access revoked across every portal at once, with MFA reinforced at the entry points.
All sectors
External Attack Surface Management
The executive's personal account nobody reports
ISOLATED SIGNAL
An executive's personal credential found in a leak — the kind of finding a traditional CTI does not report, because it is not corporate.
CORRELATION
We validated that the credential gave access to the executive's Instagram and LinkedIn.
OUTCOME
An open door for social engineering and impersonation, closed before it could be used against the company and its contacts.
All sectors
VIP Monitoring
Phishing with the customer data already for sale
ISOLATED SIGNAL
A spoofed domain imitating the brand — on its own it would look like just another opportunistic phishing page.
CORRELATION
Cross-referenced with Deep & Dark Leak: the same customer data from that domain was already circulating on a fraud marketplace.
OUTCOME
It reveals a coordinated campaign, not an isolated incident — and the response gets prioritised by the real scale.
All sectors
Brand Protection · Deep e Dark Leak
Stolen session: access with no password and no MFA
ISOLATED SIGNAL
A valid session cookie in a stealer log — with it, the attacker walks straight into the authenticated session, no password and no second factor triggered.
CORRELATION
Cross-referenced with the mapped assets, we confirmed the session belonged to an active corporate system and was still valid.
OUTCOME
Session killed and credentials rotated immediately — changing the password alone would not have worked: the cookie would still be valid.
All sectors
Infostealer Monitoring · External Attack Surface Management
The compromised supplier holding the key to the environment
ISOLATED SIGNAL
An incident at a provider, spotted by the Intel Hub — it would look like something that did not affect the client directly.
CORRELATION
Cross-referenced with Third Party Risk Manager, we confirmed that provider had direct access to one of the client's environments.
OUTCOME
Access isolated before the supplier's incident became the client's incident — cutting the chain before it propagates.
All sectors
Intelligence · Third Party Risk Manager
The credential that was worth a code repository
ISOLATED SIGNAL
An employee's credential and cookie in a stealer log — at first glance, just another routine alert.
CORRELATION
We cross-referenced it with the public professional profile and saw it was a developer: the access could reach code repositories and development environments.
OUTCOME
Treated as top priority because of the blast radius — sessions revoked and a sweep for secrets exposed in the code.
All sectors
Infostealer Monitoring · Investigation
The 4pm insider
ISOLATED SIGNAL
On a closed forum, a seller was offering access and internal information about a client. It could be a bluff — sellers commonly inflate what they have to attract buyers.
CORRELATION
Working undercover, one pattern stood out: he only replied after 4pm. We mapped the employees whose shift ended at that hour and, with camera footage, caught the suspect photographing the screen.
OUTCOME
Suspect identified and the case documented with evidence — legal response and dismissal before the access was sold.
All sectors
Deep e Dark Leak · Investigation
The issuer's cards for sale on the dark web
ISOLATED SIGNAL
A criminal marketplace advertising a batch of cards — with no confirmation they belonged to the client's base.
CORRELATION
We collected the partial data available (BIN, first six and intermediate validating digits) and cross-referenced it with the issuer's base, confirming authenticity and scoping the batch.
OUTCOME
An actionable report handed to the security team, which validated and blocked the compromised cards before use.
Banking & Finance
Deep e Dark Leak · Fraud Exposure
The fraud that starts before the login
ISOLATED SIGNAL
A spike in internet banking access attempts with no apparent failure — it looked like nothing more than anomalous traffic.
CORRELATION
The combinations being tested matched customer credentials already leaked on other services: it was credential stuffing, not brute force.
OUTCOME
At-risk accounts identified by name and protected before the first fraudulent transfer, without locking down the entire base.
Banking & Finance
Infostealer Monitoring · Fraud Exposure
The corporate access advertised on the forum
ISOLATED SIGNAL
An ad offering VPN access to a financial institution, without naming it — only the sector, the size and the region.
CORRELATION
ASM identified the exposed VPN concentrator that matched the description, and Deep & Dark tied the offer to a known access broker.
OUTCOME
Access closed and credentials rotated before the sale — cutting ransomware at the stage where it is still a negotiation.
Banking & Finance
External Attack Surface Management · Deep e Dark Leak
The fake app that asks for the second factor
ISOLATED SIGNAL
An application carrying the bank's name published on an unofficial store, with few installs and inflated ratings.
CORRELATION
The app replicated the login screen and captured the MFA token — and the server it used matched an already active phishing campaign.
OUTCOME
App removed and infrastructure taken down before mass distribution — the scam dies before it scales.
Banking & Finance
Brand Protection · Takedown
Insiders selling SIM swaps
ISOLATED SIGNAL
While monitoring fraud channels, an individual was offering SIM swap services claiming access to real carrier employees — it could have been a bluff.
CORRELATION
We interacted directly with the fraudster inside the monitored environment, progressively enriching the data: full names, phone numbers, staff IDs, corporate emails and photographs.
OUTCOME
More than 50 unique records of compromised employees identified — the basis for an internal and legal response before exploitation.
Telecom
Deep e Dark Leak · Investigation
The SIM card that became a bank account
ISOLATED SIGNAL
A partner store attendant's credential in a stealer log — one more third-party access among thousands.
CORRELATION
Cross-referenced with ASM, the credential opened the SIM activation portal — and on Deep & Dark that same access was already being advertised for ownership transfers.
OUTCOME
Access revoked ahead of the SIM swap wave — the scam that intercepts the confirmation SMS and empties the subscriber's account.
Telecom
External Attack Surface Management · Deep e Dark Leak
The subscriber lookup sold by subscription
ISOLATED SIGNAL
A Telegram bot offering personal-data lookups by tax ID, answering in seconds for a monthly price.
CORRELATION
The format of the fields returned matched the layout of an internal service system — this was not an old database, it was a live query.
OUTCOME
The improper access account identified and cut off — the subscriber base stops feeding activation fraud and social engineering.
Telecom
Deep e Dark Leak · Investigation
The antenna nobody knew was answering
ISOLATED SIGNAL
A network element management panel exposed on the internet, with factory default credentials and outside the inventory.
CORRELATION
ASM tied the IP to a carrier block and the Threat Feed showed active scanning against that equipment model in the same week.
OUTCOME
Panel taken offline before exploitation — avoiding network downtime and the regulatory risk of a service interruption.
Telecom
External Attack Surface Management · Feed Signal
The shell company network behind the clones
ISOLATED SIGNAL
Different phishing pages, apparently unrelated, were using the same instant-transfer key to collect payments from victims.
CORRELATION
We correlated dozens of fraudulent ads through that same key and analysed the company registration naming pattern, which exposed dozens of other similar registrations.
OUTCOME
An organised network of roughly 20 shell companies mapped — it becomes a report on an entire operation, not a takedown that reappears the following week.
Retail & E-commerce
Brand Protection · Investigation
The internal domain nobody knew existed
ISOLATED SIGNAL
Called in under war room conditions, with no indication of a vector — only the brand as a starting point.
CORRELATION
The attack surface analysis starting from the brand revealed an internal domain unknown to the client's own security team, with a remote access service publicly exposed.
OUTCOME
Entry point closed — that was exactly where the attacker was trying to authenticate, and the access was available to anyone on the internet.
Retail & E-commerce
External Attack Surface Management
The critical flaw in the customer service platform
ISOLATED SIGNAL
Routine monitoring at a retailer that already had a CTI solution — one more collection cycle, no standout alert.
CORRELATION
The analysis identified a critical remote access vulnerability in the customer service platform, with sensitive data reachable.
OUTCOME
Mitigated before it was exploited — and the operation went on to generate more accurate events, with a drop in false positive volume.
Retail & E-commerce
External Attack Surface Management · Third Party Risk Manager
The clone already selling with your customers' data
ISOLATED SIGNAL
A fake store carrying the brand's visual identity advertising a sale — at first glance, another routine takedown.
CORRELATION
The e-tracker showed the page was a literal copy of the official site — and on Deep & Dark the customer data was already circulating for sale.
OUTCOME
Campaign blocked and customers warned ahead of the chargebacks — protecting revenue, reputation and the cost of support.
Retail & E-commerce
Brand Protection · Deep e Dark Leak
The coupon that became a loss at scale
ISOLATED SIGNAL
A Telegram group circulating discount coupons that nobody in marketing created, with usage climbing by the hour.
CORRELATION
The generation pattern pointed to access to the promotional panel — and an analyst's credential appeared in a stealer log from the same week.
OUTCOME
Panel locked and coupons invalidated before the weekend — cutting the margin loss before it became meaningful volume.
Retail & E-commerce
Deep e Dark Leak · Infostealer Monitoring
The fake job ad that harvested ID and selfie
ISOLATED SIGNAL
A job posting using the brand's name on a social network, asking candidates for an ID document and a selfie.
CORRELATION
The profile publishing the vacancy was linked to other cloned pages from the same operation, already mapped by Brand Protection.
OUTCOME
Profile removed and a notice issued — preventing the candidate's data from becoming a fraudulent account opened in their name.
Retail & E-commerce
Brand Protection · Takedown
The hospital access for sale in the underground
ISOLATED SIGNAL
An offer of corporate access naming a hospital on an access broker forum — one among dozens of generic offers.
CORRELATION
The most active buyer was a ransomware group with a track record in healthcare — a halted patient system forces a fast payment.
OUTCOME
Access isolated and backups reinforced before the purchase — instead of finding out through a hijacked medical record and a halt in care.
Healthcare
Deep e Dark Leak · Intelligence
The medical record that leaked through the supplier's door
ISOLATED SIGNAL
An incident at a remote diagnostics company, reported as the supplier's problem, with no mention of the hospital.
CORRELATION
TPRM confirmed that this supplier maintained an active API integration with the client's medical record system.
OUTCOME
Integration suspended and credentials rotated before it spread — sensitive patient data stays out of the breach.
Healthcare
Third Party Risk Manager
The on-call credential that never expires
ISOLATED SIGNAL
A shared on-call login turned up in a stealer log, with the session cookie still valid.
CORRELATION
The session belonged to the scheduling and medical record system, reachable from outside — changing the password would not kill the cookie.
OUTCOME
Session killed and access individualised — closing the door that bypasses MFA and leaves no audit trail.
Healthcare
Infostealer Monitoring · External Attack Surface Management
When miles are the most liquid currency
ISOLATED SIGNAL
Improper access to the loyalty programme exposed names, contact details, mileage balances and partial card data.
CORRELATION
The pattern pointed to checkers testing en masse credentials already circulating in leaks and stealer logs — it was not a new intrusion, it was reuse of an old credential.
OUTCOME
Highest-balance accounts protected before fraudulent redemption — miles are currency, and the loss is financial, not merely reputational.
Aviation Services
Infostealer Monitoring · Fraud Exposure
The fake agency selling tickets that do not exist
ISOLATED SIGNAL
A ticket sales site priced well below market, using the airline's brand and identity.
CORRELATION
The same registration pattern appeared across other travel domains — Investigation mapped the shell network behind the pages.
OUTCOME
It becomes a report on an entire operation, not a takedown that reappears under another domain the following week.
Aviation Services
Brand Protection · Investigation
The executive who shows up on the radar before the trip
ISOLATED SIGNAL
A mention of one of the airline's executives on a closed forum, alongside the itinerary and agenda of a public event.
CORRELATION
Cross-referenced with VIP Monitoring, his personal data was already exposed — material ready for impersonation and deepfakes.
OUTCOME
Exposure reduced and the team alerted before the event — cutting off the payment authorisation scam run in the board's name.
Aviation Services
VIP Monitoring · Deep e Dark Leak
The exam leak before the test date
ISOLATED SIGNAL
Profiles on a social network offering access to exam content ahead of the official date — at first, a promise with nothing behind it.
CORRELATION
Analysis of the partial images published as samples visually confirmed a genuine leak; tracing the payment key and cross-referencing through OSINT identified one of the sellers as a teacher in a specific state.
OUTCOME
Origin located at a school in that state, with time to spare — containment before the material circulated widely.
Education
Investigation · Brand Protection