Press Release

April 14, 2023 11:42 AM

Updated statement regarding LockBit claims

Mike Beck, Chief Information Security Officer, Darktrace

We have completed a thorough security investigation following yesterday’s tweets by LockBit claiming they had compromised Darktrace’s internal systems. We can confirm that there has been no compromise of our systems or any of our affiliate systems. Our service to our customers remains uninterrupted and is operating as normal and no further action is required.

Press Release

April 13, 2023 9:30 AM

Statement regarding LockBit claims

Earlier this morning we became aware of tweets from LockBit, the cyber-criminal gang, claiming that they had compromised Darktrace’s internal security systems and had accessed our data. Our security teams have run a full review of our internal systems and can see no evidence of compromise. None of the LockBit social media posts link to any compromised Darktrace data. We will continue to monitor the situation extremely closely, but based on our current investigations we are confident that our systems remain secure and all customer data is fully protected.


Press Release

Darktrace announces proposed acquisition of Cado Security, a cloud investigation and response specialist

Cambridge, UK
January 9, 2025

Darktrace, a global leader in AI for cybersecurity, today announced the proposed acquisition of Cado Security (Cado), a UK-based cyber investigation and response solution provider for the hybrid and multi-cloud world. Cado Security delivers broad support across multi-cloud, container, serverless, SaaS, and on-premises environments, eliminating blind spots in incident response. The acquisition is subject to receipt of regulatory approval and is expected to complete in February.

A leader in cloud data capture and forensics, Cado examines the intricacies of nearly any system, capturing a snapshot of data stored on the device and then conducting forensic investigations to uncover signs of compromise or threats. Darktrace intends to accelerate the growth of Cado’s existing products through investment while also combining Cado’s forensic investigation technology with Darktrace’s existing ActiveAI Security Platform™, enhancing data collection across multiple cloud environments to better defend customers’ operations. This richer data set can also enable significant augmentation to Darktrace’s Cyber AI Analyst™ which investigates alerts, streamlines investigations and prioritizes incidents, reducing workload and alert fatigue for customers’ cyber teams.

Cado was founded by James Campbell, CEO, and Chris Doman, CTO. Prior to founding Cado, James served as a Director at PwC building the Cyber Incident Response service. James’s background also includes a career in intelligence, previously leading Australia’s National Incident Response capability as the Assistant Director of Operations at the Australian Signals Directorate. Chris is well known for building the popular threat intelligence portal ThreatCrowd, which then merged into the AlienVault Open Threat Exchange, and was subsequently acquired by AT&T. We look forward to welcoming James, Chris, and the Cado team to Darktrace upon completion.

The proposed acquisition represents Darktrace’s continued investment in its cloud capabilities, following the successful launch of Darktrace / CLOUD™ for AWS in October 2023 and its expansion to Microsoft Azure in October 2024. Cloud security is becoming increasingly crucial in supporting customers’ cyber resilience in an AI age as companies migrate their data to cloud platforms as well as relying on cloud-based SaaS services for essential business operations. Darktrace’s threat research identifies cloud and SaaS platforms as a common entry point for cybercriminals to attempt access to customers’ networks[1]. This, together with research from the 2024 Darktrace State of AI Cybersecurity report where security leaders identified cloud security as the top area where defensive AI could have the greatest impact[2], highlights the need for cloud-native AI-powered cybersecurity solutions.

This announcement follows Darktrace’s acquisition by Thoma Bravo in October 2024 and highlights both Darktrace and Thoma Bravo’s commitment to accelerating Darktrace's growth through the development of AI-augmented cyber solutions for its customers, including through the expansion of Darktrace’s research and development capabilities to continue to drive product innovation for an evolving cyber threat landscape. Cado’s R&D teams in London and Bristol will work alongside Darktrace’s established R&D centers in Cambridge, UK and The Hague, Netherlands to drive further innovation in Darktrace’s Cloud Detection and Response capabilities.

Jill Popelka, Darktrace Chief Executive Officer commented: "At Darktrace, we have a clear and ambitious strategy: to develop best-in-class cybersecurity solutions for our customers that keep them safe through continuous innovation. The addition of Cado’s deep expertise in cloud-based data collection and forensics will enhance our ability to protect customers, ensuring they can operate securely and confidently across all areas of their business. Together, Darktrace and Cado will help customers quickly and effectively prevent and deter cyber threats, maintaining resilience in a fast-evolving threat landscape.”

Cado Security Co-Founder and CEO, James Campbell, commented: “Darktrace is an excellent fit for Cado, providing an opportunity for growth and innovation while allowing our team to advance their careers within a dynamic company deeply committed to R&D and to protecting its customers from growing cyber threats. Our technologies build on each other’s strengths, and we are incredibly excited to work with the Darktrace team to continue to elevate AI-driven cybersecurity capabilities for our combined global customer base.”

Notes to editors

Piper Sandler is the financial advisor to Darktrace on the transaction.

About Cado Security

Cado Security is the provider of the first investigation and response automation platform focused on revolutionizing incident response for the hybrid world. Cado significantly reduces response times by automating the capture, processing, and analysis of data residing in cloud, container, serverless, SaaS, and on-premises environments. Cado empowers security teams to add critical context to everyday security investigations on any system. Anywhere. Anytime.

About Cado Co-Founders:

James Campbell

With over 15 years' experience helping global organizations tackle sophisticated cyber espionage and criminal campaigns, James has a deep passion for cyber incident response, forensics and cyber crisis. Prior to founding Cado Security, Campbell served as a Director at PwC building the Cyber Incident Response service. Campbell’s background also includes a career in intelligence, previously leading Australia’s National Incident Response capability as the Assistant Director of Operations at the Australian Signals Directorate. James is an active thought leader having spoken at various conferences, including Black Hat, cloudsec, CRESTCon, and the Forensics Europe Expo.

Chris Doman

Chris is well known for building the popular threat intelligence portal ThreatCrowd, which then merged into the AlienVault Open Threat Exchange, later acquired by AT&T. Chris is an industry leading threat researcher, and has published a number of widely read articles and papers on targeted cyber attacks. His research on topics such as the North Korean government’s crypto-currency theft schemes, and China’s attacks against dissident websites, have been widely discussed in the media.

About Darktrace

Darktrace is a global leader in AI for cybersecurity that keeps organizations ahead of the changing threat landscape every day. Founded in 2013, Darktrace provides the essential cybersecurity platform protecting organizations from unknown threats using its proprietary AI that learns from the unique patterns of life for each customer in real-time. The Darktrace ActiveAI Security Platform™ delivers a proactive approach to cyber resilience with pre-emptive visibility into security posture, real-time threat detection, and autonomous response – securing the business across cloud, email, identities, operational technology, endpoints, and network. Breakthrough innovations from our R&D teams in Cambridge, UK, and The Hague, Netherlands have resulted in over 200 patent applications filed. Darktrace’s platform and services are supported by over 2,400 employees around the world who protect nearly 10,000 customers across all major industries globally. To learn more, visit http://www.darktrace.com.

[1] Darktrace, End of Year Threat Report: Analysis of the Second Half of 2023

[2] Darktrace State of AI Cyber Security Report, 2024

News coverage
News publication logo

Darktrace announces proposed acquisition of Cado Security, a cloud investigation and response specialist

January 9, 2025

cv
Darktrace named a Challenger in first Gartner® Magic Quadrant™ for Email Security Platforms ·      Evaluated on Completeness of Vision and Ability to Execute Darktrace, a global leader in AI for cybersecurity,today announces that Darktrace / EMAIL™, has been recognized in thefirst ever Gartner Magic Quadrant™ for Email Security Platforms (ESP) as a Challenger. Chris Kozup, Chief Marketing Officer, Darktrace, said of therecognition: “We are extremely proud to have been recognized in the first MagicQuadrant for ESP.  We believe the factthat wehave seen such wide scale adoption is testament to the unique way in which wedevelop products to keep our customers safe from even the most sophisticated emailcompromises. We believe our placement reaffirms our dedication to deliveringexceptional customer service, and innovations that safeguard against the emailchallenges of today—and tomorrow.” Darktrace customers consistently acknowledge its exceptional customersupport, delivered by an award-winning[1]service team. Darktrace has the highest percentage of 5-star ratings with a 4.8rating on Gartner® Peer Insights™ out of 249 reviews as on[MW1]  19th December. We feel this unwavering commitment to customersatisfaction is evident in strong renewal rates and accelerated growth inDarktrace / EMAIL over the past few years, gaining almost 5,000 customers sinceits launch in 2019. Darktrace / EMAIL, one of the fastest-growing emailsecurity products on the market, is built on Darktrace’s unique Self-LearningAI, a multi-layered AI engine that leverages different types of AI includingNLP and behavioral analysis to detect threats, instead of traditional securitymeasures such as signatures and sandboxing. This approach enables Darktrace todetect and stop threats like business email compromise attacks and noveltechniques, including some 56% of which passed through customers’ other emailsecurity layers. This pioneering approach has enabled Darktrace to introduce industry-leadingcapabilities such as QR code analysis and automated incident investigations, alongsidedifferentiated functionality to help teams add new depth to their emailsecurity, including: Account     take over and Lateral mail account compromise protection.     Contributing yet another layer to the AI behavioural profile for each     user, security teams can now spot early symptoms of account compromise or     malicious insiders before a link or attachment payload is sent, and     exfiltration occur   Microsoft Teams security with advanced messaging analysis: Advancing beyond simple text analysis to     behavioral and natural language content analysis that tracks context     across both email and instant messaging to identify the approximately 38% of     phishing, sophisticated social engineering and novel insider threats other     solutions fail to capture ·      Drastically improveend user reporting with Cyber AI Analyst narratives: Real-time awareness training capabilities reduce falsepositives in phishing investigations by up to 60% by providing context specificanalysis of each received email to each employee as they interact with their mail.·       MailboxSecurity Assistant to increase security team operational efficiency: All forms ofsecondary investigations can now automatically perform advanced behavioralbrowser analysis and stop malicious links within webpages, reducing manualeffort of security analysts to detecting phishing links, and allowing them to remediateup to 70% more malicious phishing links than before.·       AI based,autonomous data loss prevention: to immediately protect organizations from misdirected emails,insider threats, and data loss—both classified and unclassified – using userbehavior and dynamic content analysis to determine sensitivity, removing administrativeoverhead from manual expressions and labeling.Marco Cavallo, IT Manager at Darktrace / EMAIL customer Arpa Industries comments:“During the POV, Darktrace / EMAIL showed how specific attacks weresurgically blocked. We realized that other tools wouldn’t have detected thesethreats.” Darktrace / EMAIL is part of Darktrace’s ActiveAI Security Platform™,offering network, cloud, endpoint, identity and operational technologyprotection from a single shared architecture, all built on Darktrace’s uniqueAI engine – providing a strong, integrated approach to threat prevention,detection and response across an organization’s entire digital footprint. Darktrace’s global presence supports a diverse and varied customer base,and adapts proactively to customer pain points of all kinds. Darktrace’sadaptability across all market segments, from SMBs to large enterprisessupports both first time email security buyers and mature email securitystacks. It is able to meet varied security needs with lower setuprequirements, includes capability for advanced depth in configuration and,particularly for mature organizations, can augment existing security providerswith additional protections.   Download the fullMagic Quadrant for Email Security Platforms here Resources:·      Read more onthe Darktrace Blog·      Read more abouthow business email compromise attacks are evolving on The Inference  Gartner disclaimersGartner, Magic Quadrant for EmailSecurity Platforms, Max Taggett, Nikul Patel, Franz Hinner, Deepak Mishra, 16December 2024 GARTNER is a registered trademarkand service mark of Gartner and Magic Quadrant and Peer Insights are aregistered trademark, of Gartner, Inc. and/or its affiliates in the U.S. andinternationally and are used herein with permission. All rights reserved.
Gartner Peer Insights content consists of the opinions of individual endusers based on their own experiences with the vendors listed on the platform,should not be construed as statements of fact, nor do they represent the viewsof Gartner or its affiliates. Gartner does not endorse any vendor, product orservice depicted in this content nor makes any warranties, expressed orimplied, with respect to this content, about its accuracy or completeness,including any warranties of merchantability or fitness for a particularpurpose. Gartner does not endorse any vendor,product or service depicted in its research publications and does not advisetechnology users to select only those vendors with the highest ratings or otherdesignation. Gartner research publications consist of the opinions of Gartner’sresearch organization and should not be construed as statements of fact.Gartner disclaims all warranties, expressed or implied, with respect to thisresearch, including any warranties of merchantability or fitness for aparticular purpose.  About DarktraceDarktrace is a global leader in AI for cybersecurity that keepsorganizations ahead of the changing threat landscape every day. Founded in2013, Darktrace provides the essential cybersecurity platform protectingorganizations from unknown threats using its proprietary AI that learns fromthe unique patterns of life for each customer in real-time. The DarktraceActiveAI Security Platform™ delivers a proactive approach to cyber resiliencewith pre-emptive visibility into security posture, real-time threat detection,and autonomous response – securing the business across cloud, email,identities, operational technology, endpoints, and network. Breakthroughinnovations from our R&D teams in Cambridge, UK, and The Hague, Netherlandshave resulted in over 200 patent applications filed. Darktrace’s platform andservices are supported by over 2,400 employees around the world who protectnearly 10,000 customers across all major industries globally. To learn more,visit http://www.darktrace.com.   ---- 
[1] Darktrace wins two Globeeawards for excellent customer service [PressRelease] [MW1]shouldthis be 'of'