Press Release
Updated statement regarding LockBit claims
We have completed a thorough security investigation following yesterday’s tweets by LockBit claiming they had compromised Darktrace’s internal systems. We can confirm that there has been no compromise of our systems or any of our affiliate systems. Our service to our customers remains uninterrupted and is operating as normal and no further action is required.
Press Release
Statement regarding LockBit claims
Earlier this morning we became aware of tweets from LockBit, the cyber-criminal gang, claiming that they had compromised Darktrace’s internal security systems and had accessed our data. Our security teams have run a full review of our internal systems and can see no evidence of compromise. None of the LockBit social media posts link to any compromised Darktrace data. We will continue to monitor the situation extremely closely, but based on our current investigations we are confident that our systems remain secure and all customer data is fully protected.
Press Release
Darktrace Expands Network Detection and Response Capabilities to Protect Modern Enterprises including Remote Workforces
- New innovations and integrations bolster visibility, enhance autonomous response, and introduce additional proactive risk management capabilities for evolving perimeter-less and distributed network architectures.
CAMBRIDGE, UK, April 22, 2025 — Darktrace, a global leader in AI for cybersecurity, today announced enhancements to its Network Detection and Response (NDR) solution to address the complex demands of modern enterprise networks. These latest innovations and integrations continue to extend beyond traditional NDR solutions to offer deeper visibility, more precise autonomous response, new proactive risk management capabilities, and integrations to augment novel threat detection for Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA) technologies.
The news comes on the heels of enhancements to Darktrace Cyber AI Analyst™, which pushes the boundaries of NDR by conducting AI-led investigations of all relevant alerts, including alerts from third party solutions, to reduce triage time and allow analysts to spend more time on validation, response and proactive tasks.
As organizations increasingly rely on hybrid work and distributed cloud applications, the network perimeter has dissolved, creating new blind spots and response challenges for security teams. With adversaries using cloud services to move undetected throughout the network, it’s critical that security teams use AI-powered solutions to accurately detect and contain known and novel attacks at machine speed anywhere in the enterprise. AI can also use its knowledge of how an organization works to guide security teams on how to proactively prevent threats and reduce risks across their people, process, and technology. According to Darktrace’s 2025 State of AI Cybersecurity report, 55% of security professionals expect defensive AI to have the biggest impact on network security.
“At Darktrace, we’re not just enhancing NDR, we’re redefining it. Unlike traditional NDR solutions that rely on signature-based approaches to catch known threats, Darktrace uses Self-Learning AI to find unknown threats that these systems miss," said Connie Stride, SVP of Produce, Darktrace. "We’re providing the visibility, real-time detection and autonomous response capabilities that customers need to defend against fast-moving and changing threats—whether they originate from a remote worker device, a misconfigured SaaS app, or a compromised internal server. These new features and integrations are designed to help organizations rebuild their security operations around AI and create proactive cyber resilience to protect their complex digital environments.”
Highlights of the new capabilities include:
- Increased Visibility of Threats to Remote Workers with Netskope Cloud TAP: A new integration with Netskope enables Darktrace to ingest raw, decrypted network traffic to detect unknown, novel and active threats targeting remote workers using SASE environments. The Netskope NewEdge Network enables fast performance for traffic packet capture between users and offices and the Netskope One platform across the globe with the ready-to-use Darktrace integration. This visibility reduces blind spots for customers even as network traffic flows shift further away from traditional network perimeters.
- Enhanced Autonomous Response for Zscaler Private Access: Darktrace can now deliver response actions at machine speed for remote user devices by integrating with Zscaler’s Zero Trust Network Access service. After Darktrace detects an active threat allowed within existing policies, this new capability enables security teams to autonomously shut down access using ZPA and stop suspicious activity on remote devices at machine speed, buying valuable containment time for analysts to confirm investigation results and remediate.
- Support for Decrypted Traffic via Mira: The new integration with Mira ETO allows organizations that choose to decrypt for compliance to analyze network traffic in its plaintext form. This integration maintains the encrypted traffic’s context while enabling more in-depth anomaly detection, adding to Darktrace’s leading Self-Learning AI, which can already detect novel threats without the need to decrypt traffic.
- Custom Routes for Autonomous Response in Complex Networks: A new module allows organizations to define custom pathways for Autonomous Response actions that stop the malicious action while maintaining production activity, allowing for more precise threat containment even in highly segmented network environments.
- Attack Path Finder and New Risk Management Reports: Darktrace is introducing a searchable risk visualization dashboard that maps out all attack paths between assets and vulnerable users, not just the critical paths, helping teams prioritize and proactively build resilience. The solution includes three new automatically generated reports that are designed to highlight the impact and success of risk management activity and demonstrate ROI to stakeholders.
- Expanded Protocol Analysis: With new support for WebSocket, Darktrace extends detection coverage into real-time communication channels often used in live chat and streaming applications, which can be targeted by attackers.
These advancements build on Darktrace’s leadership in the NDR space. The company was recently recognized as a Leader in the 2024 IDC MarketScape for Worldwide Network Detection and Response and an overall leader in KuppingerCole’s 2024 Leadership Compass for NDR. Darktrace’s unique approach to NDR helps organizations of all sizes free up their teams to build and maintain a state of proactive cyber resilience. For example, HARMAN International uses Darktrace to automatically detect and respond to the majority of potential threats, elevating their security analysts to analyze critical threats raised by Darktrace Cyber AI Analyst as requiring immediate attention. Currently, analysts receive 15-20 such alerts daily and can investigate and respond to potential threats much faster using actionable insights from Darktrace / NETWORK.
Darktrace’s Self-Learning AI is the backbone of its NDR solution, uniquely learning the normal ‘pattern of life’ for every network entity and user. Unlike traditional approaches that rely on threat signatures or manual rule-setting, Darktrace uses its knowledge of the organization to identify and contain known and unknown threats in real-time, utilizing that data to not only investigate all relevant alerts with Cyber AI Analyst™, but also provide recommendations for security improvements ensuring organizations stay ahead even as adversaries evolve. The Darktrace ActiveAI Security Platform™ extends beyond the capabilities of traditional NDR solutions and helps organizations transform existing security operations with AI, while maintaining a state of network resilience with AI-led risk prioritization, proactive incident readiness and bespoke recovery playbooks.
Additional Resources
- Customers can read more about the new NDR integrations and features, along with other new updates, by visiting the Darktrace Customer Portal.
- Learn more about how NDR and ZTNA work together to achieve network security outcomes on the Darktrace blog.
- Visit Darktrace at RSA Booth S-2227 or meet with one of our subject matter experts on site.
About Darktrace
Darktrace is a global leader in AI for cybersecurity that keeps organizations ahead of the changing threat landscape every day. Founded in 2013, Darktrace provides the essential cybersecurity platform protecting organizations from unknown threats using its proprietary AI that learns from the unique patterns of life for each customer in real-time. The Darktrace ActiveAI Security Platform™ delivers a proactive approach to cyber resilience to secure the business across the entire digital estate – from network to cloud to email. It provides pre-emptive visibility into the customer’s security posture, transforms operations with a Cyber AI Analyst™, and detects and autonomously responds to threats in real-time. Breakthrough innovations from our R&D teams in Cambridge, UK, and The Hague, Netherlands have resulted in over 200 patent applications filed. Darktrace’s platform and services are supported by over 2,400 employees around the world who protect nearly 10,000 customers across all major industries globally. To learn more, visit http://www.darktrace.com.
Darktrace Expands Network Detection and Response Capabilities to Protect Modern Enterprises including Remote Workforces
cv
Darktrace named a Challenger in first Gartner® Magic Quadrant™ for Email Security Platforms · Evaluated on Completeness of Vision and Ability to Execute Darktrace, a global leader in AI for cybersecurity,today announces that Darktrace / EMAIL™, has been recognized in thefirst ever Gartner Magic Quadrant™ for Email Security Platforms (ESP) as a Challenger. Chris Kozup, Chief Marketing Officer, Darktrace, said of therecognition: “We are extremely proud to have been recognized in the first MagicQuadrant for ESP. We believe the factthat wehave seen such wide scale adoption is testament to the unique way in which wedevelop products to keep our customers safe from even the most sophisticated emailcompromises. We believe our placement reaffirms our dedication to deliveringexceptional customer service, and innovations that safeguard against the emailchallenges of today—and tomorrow.” Darktrace customers consistently acknowledge its exceptional customersupport, delivered by an award-winning[1]service team. Darktrace has the highest percentage of 5-star ratings with a 4.8rating on Gartner® Peer Insights™ out of 249 reviews as on[MW1] 19th December. We feel this unwavering commitment to customersatisfaction is evident in strong renewal rates and accelerated growth inDarktrace / EMAIL over the past few years, gaining almost 5,000 customers sinceits launch in 2019. Darktrace / EMAIL, one of the fastest-growing emailsecurity products on the market, is built on Darktrace’s unique Self-LearningAI, a multi-layered AI engine that leverages different types of AI includingNLP and behavioral analysis to detect threats, instead of traditional securitymeasures such as signatures and sandboxing. This approach enables Darktrace todetect and stop threats like business email compromise attacks and noveltechniques, including some 56% of which passed through customers’ other emailsecurity layers. This pioneering approach has enabled Darktrace to introduce industry-leadingcapabilities such as QR code analysis and automated incident investigations, alongsidedifferentiated functionality to help teams add new depth to their emailsecurity, including: Account take over and Lateral mail account compromise protection. Contributing yet another layer to the AI behavioural profile for each user, security teams can now spot early symptoms of account compromise or malicious insiders before a link or attachment payload is sent, and exfiltration occur Microsoft Teams security with advanced messaging analysis: Advancing beyond simple text analysis to behavioral and natural language content analysis that tracks context across both email and instant messaging to identify the approximately 38% of phishing, sophisticated social engineering and novel insider threats other solutions fail to capture · Drastically improveend user reporting with Cyber AI Analyst narratives: Real-time awareness training capabilities reduce falsepositives in phishing investigations by up to 60% by providing context specificanalysis of each received email to each employee as they interact with their mail.· MailboxSecurity Assistant to increase security team operational efficiency: All forms ofsecondary investigations can now automatically perform advanced behavioralbrowser analysis and stop malicious links within webpages, reducing manualeffort of security analysts to detecting phishing links, and allowing them to remediateup to 70% more malicious phishing links than before.· AI based,autonomous data loss prevention: to immediately protect organizations from misdirected emails,insider threats, and data loss—both classified and unclassified – using userbehavior and dynamic content analysis to determine sensitivity, removing administrativeoverhead from manual expressions and labeling.Marco Cavallo, IT Manager at Darktrace / EMAIL customer Arpa Industries comments:“During the POV, Darktrace / EMAIL showed how specific attacks weresurgically blocked. We realized that other tools wouldn’t have detected thesethreats.” Darktrace / EMAIL is part of Darktrace’s ActiveAI Security Platform™,offering network, cloud, endpoint, identity and operational technologyprotection from a single shared architecture, all built on Darktrace’s uniqueAI engine – providing a strong, integrated approach to threat prevention,detection and response across an organization’s entire digital footprint. Darktrace’s global presence supports a diverse and varied customer base,and adapts proactively to customer pain points of all kinds. Darktrace’sadaptability across all market segments, from SMBs to large enterprisessupports both first time email security buyers and mature email securitystacks. It is able to meet varied security needs with lower setuprequirements, includes capability for advanced depth in configuration and,particularly for mature organizations, can augment existing security providerswith additional protections. Download the fullMagic Quadrant for Email Security Platforms here Resources:· Read more onthe Darktrace Blog· Read more abouthow business email compromise attacks are evolving on The Inference Gartner disclaimersGartner, Magic Quadrant for EmailSecurity Platforms, Max Taggett, Nikul Patel, Franz Hinner, Deepak Mishra, 16December 2024 GARTNER is a registered trademarkand service mark of Gartner and Magic Quadrant and Peer Insights are aregistered trademark, of Gartner, Inc. and/or its affiliates in the U.S. andinternationally and are used herein with permission. All rights reserved.
Gartner Peer Insights content consists of the opinions of individual endusers based on their own experiences with the vendors listed on the platform,should not be construed as statements of fact, nor do they represent the viewsof Gartner or its affiliates. Gartner does not endorse any vendor, product orservice depicted in this content nor makes any warranties, expressed orimplied, with respect to this content, about its accuracy or completeness,including any warranties of merchantability or fitness for a particularpurpose. Gartner does not endorse any vendor,product or service depicted in its research publications and does not advisetechnology users to select only those vendors with the highest ratings or otherdesignation. Gartner research publications consist of the opinions of Gartner’sresearch organization and should not be construed as statements of fact.Gartner disclaims all warranties, expressed or implied, with respect to thisresearch, including any warranties of merchantability or fitness for aparticular purpose. About DarktraceDarktrace is a global leader in AI for cybersecurity that keepsorganizations ahead of the changing threat landscape every day. Founded in2013, Darktrace provides the essential cybersecurity platform protectingorganizations from unknown threats using its proprietary AI that learns fromthe unique patterns of life for each customer in real-time. The DarktraceActiveAI Security Platform™ delivers a proactive approach to cyber resiliencewith pre-emptive visibility into security posture, real-time threat detection,and autonomous response – securing the business across cloud, email,identities, operational technology, endpoints, and network. Breakthroughinnovations from our R&D teams in Cambridge, UK, and The Hague, Netherlandshave resulted in over 200 patent applications filed. Darktrace’s platform andservices are supported by over 2,400 employees around the world who protectnearly 10,000 customers across all major industries globally. To learn more,visit http://www.darktrace.com. ----
[1] Darktrace wins two Globeeawards for excellent customer service [PressRelease] [MW1]shouldthis be 'of'