The dark web often gets portrayed as a lawless digital bazaar where you can buy anything — from stolen identities to malware, services, how-to-guides, hit men and even human organs – as long as you know where to look. The assumption is that all illegal things are available to purchase on the dark web.
But how much of that reputation is true? Especially during the holiday season when sensational headlines tend to resurface and most are looking for a few stocking fillers! So, as we approach the holiday shopping season, we wanted to explore the myths and realities of dark web “holiday shopping,” what is truly available to criminals, how do they find it, and what can we do to combat this through dark web monitoring.
The Myth: “You Can Buy Absolutely Anything If You Know Where to Look”
This is the biggest misconception. Movies and tabloids love to exaggerate the dark web’s capabilities and the activities that take place there.
The Reality:
The dark web is messy, unreliable, and full of scams. Many “products” that criminal forums advertise are fake, recycled, or outright frauds designed to steal from other criminals. Law-enforcement stings, exit scams, and disappearing marketplaces happen constantly. And most things are not readily available. The criminals still require access to these goods – meaning they need a supply chain, and they have to have the means of sending these goods or services to their customers.
That is not to say that you can’t buy nefarious goods on the dark web – it is well known for its booming drug markets, and hacking and tools are readily available lowering the barrier to conducting some attacks. Furthermore, the sale of stolen data only continues to grow as we move into 2026.
The Myth: “Dark-Web Marketplaces Are Just Like Amazon”
Some people imagine a slick interface full of products and reviews.
The Reality:
This isn’t false. A lot of dark web marketplaces do model themselves after more mainstream commercial retail sites. Most marketplaces have listings, reviews, shipping time frames, and images of their listings. There is even a marketplace called Awazon!
That being said, most dark web markets are also unstable and can be confusing, slow, and filled with phishing mirrors. A lot of listings can also be scams, with vendors offering goods and accepting payments for goods they never intend to ship. Even the markets that try to mimic legitimate platforms collapse frequently — sometimes due to law enforcement, sometimes because operators run off with users’ funds. But this is not always the case – some markets are more mature and stable than others.
The Myth: “Holiday Specials Make It a Busy Time for Buyers”
You’ll occasionally see rumors about festive deals on illicit services or stolen data. Some markets will provide advertisements offering deals for things such as “Black Friday.”
The Reality:
Seasonal themes are mostly cosmetic. Some forums change banners or run small, informal “events,” but the idea of “Cybercriminal Black Friday Sales” is largely sensationalized. What does rise is scam activity — low-effort attempts to take advantage of distracted users. Usually “serious” vendors do not care what time of year it is – the price they set is based on the product they have and what they think people will pay for it. We have seen huge demands for stolen data in this last year – some of which have been paid either as a ransom or by other criminals hoping to use the data for their own gain.
The Myth: “Data Sold on the Dark Web Is Always New and Dangerous”
Headlines often imply a constant flow of fresh, highly sensitive data which is easily accessible to anyone who wants to access it.
The Reality:
Much of what circulates on dark web forums is outdated breach material, repackaged, and resold repeatedly. Combolists are known to pull data from multiple leaks which can be years old. Other threat actors may attempt to make more money by repackaging leaks which have already been sold.
Real, recent data is harder to obtain, tightly controlled, and often monitored by law-enforcement agencies. Ethically, this data should not be purchased; which makes it more difficult to access for those monitoring the leaks of these data sets for protection purposes. What’s more, just because there is a report of a data leak in the media does not mean that the data will be available on the dark web. Some threat actors steal data for their own personal use or negotiate within closed groups.
The Myth: “Everyone Accessing the Dark Web Is Up to Something Criminal”
Dark web content is frequently portrayed as exclusively illegal.
The Reality:
Not all dark web browsing is illicit. Whistleblowers, journalists, and privacy researchers use Tor for legitimate reasons. There are many legitimate sites on the dark web that help share true information and combat censorship. The technology is neutral — it’s the illegal marketplaces that create risk. Therefore, it is important to remember that whenever accessing dark markets to make sure you are doing so in a legal and ethical manner and never purchasing goods without legal authorization. This is why using DarkOwl to track the sale of these goods can be the safest way forward.
Why the Dark Web Can be Especially Dangerous During the Holidays
Phishing mirrors multiply as scammers impersonate well-known markets.
Pop-up marketplaces appear, then disappear with users’ money.
An increase in account-takeover attempts occurs as criminals hunt for holiday shopping creds to resell.
Cybercriminals know people are stressed, rushed, and spending more. It’s prime scamming season. This does not just apply to the dark web. All consumers should be hyper vigilant to scams during the festive time of year.
Final Thoughts
The festive season brings out the creativity — and opportunism — of cybercriminals. But most dark web holiday myths crumble under scrutiny. Understanding the reality helps prevent people from falling for exaggerated stories… and from stumbling into dangerous territory.
A Deep Dive into Shipping Choices on Illicit Marketplaces
December 11, 2025
When we think of darknet marketplaces, the focus is usually on the products: drugs, counterfeit goods, stolen data, and more (linked are just a few of the blogs where DarkOwl has covered these examples). But behind every transaction lies a critical question: how does it get delivered? Shipping choices aren’t just logistical; they reflect trust, risk, and strategy in the underground economy. In this blog, we explore which carriers dominate the darknet, how preferences differ across marketplaces, locations, and product categories, and what these patterns reveal about the hidden infrastructure supporting illicit trade.
Shipping Options
Shipping is the final connection between vendor and buyer, and on darknet markets the choice of carrier shapes how a transaction is carried out. Vendors consider factors such as reliability, delivery speed, risk of scrutiny, and whether the shipment is domestic or international.
Not all listings specify shipping information. In DarkOwl’s enhanced market dataset within its DarkMart data store, a little over half (55%) of listings collected between January 2025 and November 2025 include any shipping details at all. This suggests that many vendors either keep logistics flexible or negotiate them directly with buyers. Among those listings that do include shipping information, the level of detail varies widely. Some specify a particular carrier, while others use general terms like standard or express without naming a particular service. Listings may include multiple carrier options or alternative delivery methods such as dead drops or digital delivery (see Figure 1). In some cases, only shipping price or estimated delivery time is provided, with no carrier identified.
Figures 1 and 2: Example listings with varied shipping options
For consistency, our analysis focuses on the four major global shipping companies most frequently mentioned:
USPS – The United States Postal Service (USPS) is the primary postal operator in the U.S., handling nationwide mail and package delivery. Its widespread domestic network makes it a frequent option for shipments within the country. Because USPS handles so much daily mail volume, some vendors may view it as the safest way to blend in.
DHL – An international courier service headquartered in Germany. DHL maintains a strong global presence, particularly in Europe, and provides express and cross-border shipping to more than 220 countries and territories. DHL has a strong footprint in Europe and is known for smooth cross-border shipping, which makes it appealing for vendors sending goods overseas.
FedEx – A major U.S.-based courier service offering express, ground, and international delivery. FedEx operates an extensive global logistics network and is well known for its fast turnaround times. Its tight tracking and security can make some vendors hesitant, though others prefer it for speed of delivery.
UPS – Another large U.S.-based courier and logistics company with a broad ground and air network. UPS provides domestic and international parcel delivery, along with a wide range of supply-chain services. Vendors who want consistent delivery but don’t need overnight speed may lean toward UPS.
In addition to these major carriers, we also tracked references to regional postal services such as Deutsche Post, Royal Mail, and GLS, as well as nontraditional delivery methods like digital delivery and dead drops. While these alternative methods were less common than standard shipping, they illustrate the variety of strategies vendors use to move goods. Below, figure 3 shows the distribution of all delivery types.
Overall, USPS was the most frequently mentioned carrier mentioned in 34% of listings naming a shipping vendor, followed by DHL (24%), FedEx (14%), and UPS (7%). Royal Mail, dead drop, Deutsche post, and GLS appeared in a smaller subset of listings with a combined total of 8%. While we considered all these shipping methods in our analysis, the rest of this blog will focus specifically on the top four main carriers: USPS, DHL, FedEx, and UPS.
Figure 3: shipping type distribution, based on number of listings within DarkOwl’s DarkMart data store
Market Breakdown
Shipping patterns vary noticeably across darknet marketplaces. Some sites show clear loyalty to certain carriers, while others provide a mix of options. For example, MGM Grand, Dark Matter, Mars Market, and Velox Market are dominated by USPS listings, suggesting a preference for this domestic carrier. On the other hand, Crown Market, TorZon Market, and DrugHub display a more balanced mix, with FedEx and DHL appearing frequently. Certain markets, such as Courier Market, Halfbreed, and King Market, lean more heavily toward DHL, particularly for international shipments. Meanwhile, Revolution Market and Ares offer a fairly even spread across at least three of the four major carriers. Notably, UPS does not dominate in any marketplace, appearing more sporadically across listings. Figure 4 illustrates the distribution of shipping options across these top markets.
Figure 4: Distribution of shipping types across the top markets
Location Breakdown
Beyond marketplace-level trends, we also examined the origins and destinations of shipments for each major carrier. For this analysis, we focused on listings specifying country-to-country routes, rather than broader “country-to-worldwide” entries. Each country was mapped to its corresponding region or continent to simplify the view. Figure 5 presents these flows using Sankey diagrams, which visually show the volume of shipments between source and destination regions.
USPS listings show a heavy concentration of domestic deliveries within North America, along with a notable stream of transatlantic shipments to Europe. DHL’s activity is also centered around Europe, but it distinguishes itself as the primary carrier facilitating large volumes of shipments moving from Europe to Asia and Oceania. FedEx, by contrast, is dominated by routes from North America to Africa and Europe, with comparatively fewer packages staying within North America. UPS displays yet another pattern: most of its activity remains within Europe, with a smaller, though visible, share of shipments originating in North America and heading primarily to African destinations.
These patterns highlight the distinct regional footprints of each carrier. North American vendors rely heavily on USPS and FedEx for both domestic and transatlantic shipments, while European markets are served mainly by UPS and DHL. DHL’s broader international reach underscores its role in longer-distance trade, particularly to Asia and Oceania. Overall, the flow patterns reveal how vendors align carrier choice with both origin and destination regions, reflecting practical considerations like geographic coverage, shipping speed, and the global nature of darknet commerce.
Figure 5: Shipping to/from for (a) USPS ,(b) DHL, (c) Fedex, (b), and (d) UPS
Category Breakdown
We also reviewed which types of products were being shipped by each carrier. To do this, we looked at the product categories listed in each shipment and normalized them for consistency, focusing only on listings that included both a category and one of the major carriers. Figure 6 shows how each carrier is distributed across the top three categories.
Unsurprisingly, Drugs and Chemicals made up the largest share of shipments, followed by Fraud and Counterfeit items. Drugs and Chemicals include illicit narcotics, prescription medications, and psychoactive substances, as well as, precursor chemicals. Fraud includes items such as stolen credit card data, phishing kits, and fake IDs. While counterfeit items include counterfeit currency, fake branded goods (ie, watches, bags, etc..), and forged documents. USPS clearly dominates the drugs and chemicals category, with DHL and FedEx appearing less frequently. DHL stands out as the primary carrier for fraud and counterfeit goods.
Figure 6: Category shipping by type
These patterns hint at how vendors match products to carriers based on shipping needs. USPS’s prominence in drugs and chemicals suggests a focus on domestic or shorter-range shipments, whereas DHL’s role in fraud and counterfeit items highlights its reach for international deliveries. FedEx’s presence across multiple categories may indicate its flexibility for both speed and cross-border logistics. Overall, the distribution of products across carriers gives a window into the practical considerations shaping darknet shipping—showing how the type of product can influence both the choice of carrier and the geographic scope of the shipment.
Conclusion
Shipping on the darknet is far from random, it’s a carefully chosen part of the trade. Different carriers dominate specific markets, regions, and product types. USPS dominates deliveries within the U.S., especially for drugs and chemicals, while DHL and FedEx handle more international shipments and fraud-related goods. UPS shows up but rarely takes the lead. Across marketplaces, countries, and product types, clear patterns emerge: vendors align their carriers with the practical demands of each shipment, from speed and reliability to geographic reach. These trends reveal that even in illegal markets, logistics and strategy matter. By looking at how goods move, we gain a window into the hidden infrastructure that keeps darknet commerce running smoothly, an underground network that’s as much about moving packages as it is about managing risk and trust.
Curious to learn how darknet data is relevant to you? Contact us
Hackers are always looking to gain access to sensitive information to ransom or sell. In recent years, there has been a surge in universities being attacked due to their large databases and typically more vulnerable systems. The most common attacks that compromise universities’ systems are phishing, ransomware, and denial of service (DDoS) attacks. Phishing involves tricking users into revealing login credentials, ransomware locks critical data until a payment is made, and DDoS attacks overwhelm systems to disrupt services.
Why Should Universities Take Precautions?
Universities can face major disruptions if their network is compromised by threat actors. There have been multiple cases where universities have had to shut down their networks to solve the problem, causing huge disruption to their staff and students. If a university deems it necessary to shut down their network, the immediate effects are an annoyed student body, frustrated staff, and long term can cost the school millions. Students expect their university to stay on schedule throughout the year, which is why a network shutdown can reflect poorly on the university.
Ransomware groups especially put pressure on universities because attackers assume they will receive a payment shortly after ransoming data due to a universities’ low tolerance of leaked information being made public and possible long periods of downtime. Furthermore, the school can face lawsuits from students if information is not handled correctly. This is why often when a ransomware group successfully attacks a university, the ransom appears to be paid within a few days.
Universities are required by law to keep any sensitive information like social security numbers, banking accounts, and health records secure. One example of laws that govern universities and how they handle information is FERPA (Family Educational Rights and Privacy Act). Since this is in the context of students who are above the age of 18, this law ensures that schools do not release any information without a student’s consent. This is why when breaches occur, universities tend to face lawsuits for not properly securing their students’ and or alumni’s data. Even when the ransom is paid and not leaked, students, alumni, or faculty can still pursue legal action on the grounds of negligence.
Recent Cyberattacks on Universities
University of Michigan
In August 2023, a major data breach occurred at the University of Michigan. Around 230,000 students, alumni, and employees were affected by the breach. The threat actors stole financial accounts, social security numbers, driver’s license details, and health information.
While the vulnerability that the attackers exploited was never released to the public, the University found the attackers stole the information from the University’s Health Service and School of Dentistry. Once the attack was detected by the University, they immediately shut down their network. The internet shutdown across all three of their campuses ultimately lasted four days during the first week of classes and stopped University operations during that period. The University of Michigan faced two lawsuits after the attack. Both claim that the University was negligent with the security of information. It is unknown if this information was released or who was behind the attack.
Stanford University
Another 2023 cyberattack, coming only a month after The University of Michigan breach was the cyberattack on Stanford University. Unlike Michigan, this attack on Stanford University was claimed by a ransomware group called Akira.
The data Akira gathered was from Stanford’s Department of Public Safety. They claimed to have 430GB of data that would be released unless a ransom was paid. The group later released a link in order for others to download this data. The data they claimed to have was “private information and confidential documents”. Stanford never released the information stolen or if they paid Akira. What we do know is that the FBI has advised companies and universities not to pay ransoms and instead immediately report it to law enforcement.
The below image shows Akira announcing information about the leak on their leak site, as well as the download link which is not shown in the image below.
Ransomware groups will make data available if victims do not pay, this can lead to further attacks against the victims or organizations in their supply chain as information found in this data can be used for further phishing or social engineering attacks.
Figure 1: Akira announcing information about the leak on their leak site; Source: DarkOwl Vision
Multi University Attack
The ransomware group Cl0p was responsible for a series of attacks on universities in May of 2023. They were able to exploit the software called MOVEit which is a file transferring tool. MOVEit at the time was known to have a high level of security, especially because many of the files moved within the software contained sensitive information. MOVEit handled file transferring of many other organizations, meaning this attack was not limited to just universities.
Some of the universities that reported the attack included UCLA, Rutgers, and Missouri. These universities reported student and faculty Social Security numbers and financial account information being posted online.
Some analysts believe this attack should not be considered a ransomware attack since the compromised data was never encrypted. However, Cl0p still demanded payments from some universities for the return of data. Recently, some ransomware groups like Cl0p have not been encrypting stolen data and instead pressure people or organizations into paying purely on the threat of releasing the data online.
Have These Attacks Increased?
A company called Netwrix, surveyed 1,309 IT and security professionals globally during 2024, finding that 77% of organizations in the education sector reported an attack on their systems within the past 12 months. This number was up 8% from 2023, which suggests a trend upwards of cyberattacks on schools and universities.
In 2025, the education sector has been the number 1 target for cyber-criminals and ransom groups. Specifically, DeepStrike reported that the two main threats are phishing and ransomware, while explaining that schools and universities typically have high vulnerability in their systems and have large amounts of data, two characteristics that make them top targets.
Protection Against These Attacks
The easiest way for universities to protect against an attack is to have strong authentication requirements. When trying to access the network, the university should require a login via student ID/faculty ID – a second layer to this is multi-factor authentication. This method can also make it easier to track malicious activity by linking activity on the network to an ID.
Another measure that can be overlooked is security software on school computers. These computers are often directly connected to the network, therefore exploiting one can give an attacker access to all of them. The main problem with updating all the software is that it takes a lot of time and most of the time this can’t be done all at once. A good time to update systems would be over Fall, Thanksgiving, Winter, or Spring break when these computers are not being used.
Finally, make sure faculty and students are aware of phishing emails. Humans can be just as vulnerable as a computer – make sure to always keep your passwords secure and do not download suspicious looking files.
To read more about security best practices, check out this blog.
Have you ever wondered how threat actors end up with names like Cozy Bear, Lazarus Group, Conti, ShinyHunters, or Lapsus? They sound dramatic, almost cinematic, but the real story behind them is far more practical. In the cybersecurity world, these names serve as anchor points that help researchers follow long running patterns of behavior without getting buried in technical descriptions.
Most threat groups don’t identify themselves or leave any sort of signature. Analysts make those connections by looking for shared tools, similar infrastructure, recurring techniques, and familiar mistakes. When the same elements appear across multiple incidents, known as Tools, Techniques, and Procedures (TTPs), researchers often assess that they’re dealing with a single group or a tightly connected team. Giving a group a name makes it possible to track them across years, industries, and geopolitical shifts as well as compare them with other professionals.
How Naming Conventions Take Shape
Different cybersecurity companies and intelligence teams have their own naming styles. CrowdStrike is well known for animal themed names, which is where Cozy Bear and Fancy Bear came from, with “bear” being the code for Russian activity. Other organizations use minerals, weather patterns (Microsoft), codes, or even something pulled from the first case they studied – like a server alias or a fragment of code. Sometimes the naming process is almost accidental. A small detail in a malware sample might stand out and eventually evolve into the label everyone uses. What begins as shorthand inside a research team can turn into the name recognized globally.
However, some threat actors have also been known to choose their own names, especially the ones who care about visibility on the Darknet, such as ShinyHunters and Lapsus who built brands intentionally. Their names help them attract attention, buyers, or recruits. State aligned actors tend to avoid that entirely, attempting to obfuscate their activities as much as possible. Their operations rely on staying quiet; however, there can be overlap with criminal or hacktivist groups which makes it difficult for security researchers to assign a name to activities.
What Happens Once a Group Is Named
When a threat actor has a name, investigators can organize everything known about them into a structured profile. As new attacks occur, every shared pattern strengthens the understanding of that group’s behavior – sometimes leading to the identification of new groups. Analysts track the malware the group uses, how often it reuses infrastructure, the hours that match its activity, and the types of organizations it targets. Over time, this can form a reliable behavioral fingerprint. When a new intrusion resembles a known group, the name brings an entire history of techniques and motives with it.
This shared language is one of the reasons naming matters. It lets analysts talk about complex activities in a way others can quickly understand.
How Threat Actors Navigate the Darknet
The darknet often gets portrayed as chaotic, but most real activity happens inside structured, closed off communities. These spaces act like ecosystems where reputation, connections, and trust shape everything. They include invite-only forums, encrypted marketplaces, long running chat groups, and networks that link buyers and sellers. Threat actors maintain long term aliases and build trust through proven deals, technical skill, and vouches from known members. Even criminals fear scams and infiltration, so new participants usually need some form of verification before gaining access.
Each community has its own culture. Some focus on selling stolen data or credentials. Others exist for trading access to compromised networks. Some offer malware and related tools as a service. A few give actors a platform for leaking data to build notoriety. Every one of these spaces has its own rules, moderators, and internal politics.
Darknet ecosystems change constantly. Markets shut down without warning. Administrators disappear. Forums break apart and reappear under new names. Actors move with them, carrying their habits and relationships across these spaces. Those recurring habits become valuable clues for investigators.
How Investigators Connect Attacks to Groups
Attribution can look mysterious, but it relies on patterns, not guesses. Analysts gather small details across multiple incidents and compare them to what’s known about existing groups. They look at coding styles, compile choices, command structures, and mistakes that show up repeatedly. They watch for reused infrastructure, similarities in target selection, and operational timing that matches specific regions. One group might favor certain hosting providers, while another consistently makes the same configuration errors. No single clue reveals the truth. Attribution is a cautious process that builds confidence over time. That’s why researchers use phrases like “consistent with” or “aligned with known activity.” They’re acknowledging the direction the evidence points without claiming absolute certainty.
DarkOwl’s Role in Understanding Threat Actors
To understand threat actors fully, you need visibility into the places where they operate, communicate, and adapt. That’s where DarkOwl plays a central role. The darknet is intentionally fragmented and difficult to navigate, built on temporary platforms, closed doors, and hidden communities. DarkOwl collects intelligence from these hard-to-reach areas and provides the broader context needed to make sense of threat activity. DarkOwl monitors closed forums, high turnover marketplaces, encrypted groups, leaked datasets, and messaging boards that appear and disappear quickly. This depth of coverage helps analysts spot new trends early, identify resurfacing aliases, follow market shifts, and track the growth of emerging communities.
While DarkOwl doesn’t reveal identities on its own, the intelligence it provides forms the environment around each clue. It helps investigators see how threat actors move, when their chatter increases, how their tools circulate, and when a group seems to be preparing for something new. That broader view is essential for understanding the full lifecycle of threat activity.
Why This Matters
Threat actor names might sound theatrical, but they serve a practical purpose in organizing complex information. They help analysts talk about long running patterns, understand motives, and communicate findings across the industry. Once you see how these names emerge and how threat actors operate on the darknet, the landscape becomes easier to understand. DarkOwl’s intelligence adds critical visibility into the hidden corners of that landscape. Combined with naming conventions, behavioral profiling, and attribution techniques, the insight DarkOwl provides gives organizations a clearer view of the threats they’re facing and how those threats evolve.
With increasing regularity, the media is filled with reports of mass shootings, assassinations, political violence, and other forms of targeted violence. While targeted violence is nothing new, our fractured society does appear to be experiencing these events more frequently as time goes on.
One of the ways in which law enforcement, security professionals, and healthcare professionals have sought to combat and prevent these acts of violence is through the practice of threat assessment. A systematic process, built over decades, which seeks to identify and prevent targeted violence through assessment of behavior and managing risk.
However, in an increasingly digital age the sheer volume of data that is available to these professionals is ever growing. Whether monitoring social media for any mentions of credible threats or reviewing large volumes of emails in response to a triggering event or reviewing messaging apps it can be impossible to identify which individuals actually pose a threat and the best way to assist them. This does not even take into consideration the issue of identifying who the real person is behind sometimes anonymous online personas.
This study focuses on high-volume threatening communication within far-right Telegram channels. The far-right is understood here as an umbrella term encompassing a diverse range of ideologies, movements, and political actors situated at the extreme end of the right-wing spectrum. While diverse, these groups usually share some characteristics: nationalism, racism, xenophobia, anti-democratic tendencies, or strong state advocacy (Mudde, 2000). All far-right ideologies, view human inequality as natural and even desirable (Mudde, 2019). Translating definitions of ideology to the online sphere is challenging, since information about individuals or groups is often limited to their digital expressions. As Conway (Conway, 2020) observes, the contemporary online far-right is best understood as a decentralized “scene,” “milieu,” or “ecology” — a fluid and rapidly shifting network of individuals, groups, movements, political parties, and media outlets that overlap and interact in complex ways.
Many of the far-right channels identified by DarkOwl remain active on the platform, which has allowed us to collect a substantial amount of data from the communications within the channels selected for this analysis.
Using a dataset collected from active far-right Telegram channels, DarkOwl and Mind Intelligence Labs sought to examine whether combining AI tools with manual analysis of text-based content from far-right Telegram channels could enhance the identification of threats and deepen understanding of their nature to support threat assessors.
The far-right Telegram channels analyzed in this study contain a high volume of threatening communication, making it challenging to determine which threats are more credible than others. Our analysis shows that most threats are explicit and directed at specific targets. Operationally detailed threats are also common, indicating a normalization of violent rhetoric and a potential for mobilization within these online communities.
What is Threat Assessment
Threat assessment is the process of identifying if individuals may be at risk for engaging in targeted violence and managing that risk to prevent violence from occurring. Assessments are conducted based on an individual’s observable behavior and therefore require a review of how an individual is acting, what they are saying both online and in the “real world,” as well as communications of intent and contextual stressors.
Both the FBI and the Secret Service provide guidance for how to conduct threat assessment, highlighting that it is not just about identifying an initial risk, but ongoing management to prevent any risk that may be posed over time as an individual’s situation changes.
Key components of threat assessment include:
Identify – Detect behaviors or statements that a person may be moving towards violence. This can include direct threats, planning behaviors, or having a grievance. Bystanders such as friends or family members are often those that report concerning behaviors, but it can also be detectable through online communications that can be tracked.
Assess – Collect and assess information about the person, what motivates them, what accesses do they have, and what opportunities for violence do they have. Have they shared a specific threat and is this credible and or viable? This can include a review of their online communications as well as interviews with colleagues or family members, and even the subject themselves.
Manage – A very important aspect of threat assessment is the ongoing management of the risk. This requires developing tailored strategies to reduce the threat. Options can include mental health support, social services, law enforcement involvement, safety planning, and ongoing monitoring and follow up on the subject.
Threats made online differ from those expressed in person since digital platforms provide anonymity, lower inhibitions, and offer wide reach. As noted in the FBI’s Making Prevention a Reality guide (2019), perceived anonymity can reduce typical social restraints, allowing individuals to voice hostility or intimidation they might not display in face-to-face settings. Yet, detecting and evaluating threats that are posted online is important to prevent violence.
Assessing threats in a high-volume environment poses substantial challenges. The sheer number of online communications makes it difficult to distinguish which threats are credible and require further analysis. The FBI emphasizes that not every threatening message indicates a genuine intent to harm. The goal of assessing concerning communications is to determine whether a message is an expression of anger or frustration or a behavioral indicator of movement toward violence. An assessment helps decide which communications warrant deeper investigation or management intervention.
When assessing threats online, several factors must be considered — particularly the specificity, credibility, and intent behind the communication.
A threat is considered specific if it contains concrete information such as who will carry out the act, the intended target, when and where it will occur, and how it is supposed to happen. Specific details — such as the mention of weapons, timing, or location — increase the level of concern because they demonstrate planning or forethought.
Credibility relates to the source of the threat and its feasibility. Analysts evaluate whether the source is reliable or directly connected to the individual of concern, whether similar threats have been made before, and whether there is a consistent pattern of behavior. The assessment also considers how viable the threat is: does the individual have the means, access, or capability to act on their words?
Determining intent involves examining signs of motivation, planning, or commitment to carry out an attack. Indicators may include expressions of grievance, fixation on a target, or evidence of preparation. Establishing intent can be particularly challenging in online environments, where individuals may exaggerate or use violent rhetoric without a genuine plan to act.
Telegram
The messaging app Telegram was founded in 2013 by Pavel Durov who previously founded the popular Russian social media app VK. Telegram has approximately 950 million registered users worldwide. Although a messaging app, Telegram operates more like a social media platform. Users register using a telephone number but can use any display name they want. Users can message each other directly, but the platform also has the concept of channels and groups where mass communication can occur.
In a channel, multiple users can communicate with each other, acting as a chat function you are able to see the username and their comments. Other channels operate more of a broadcast system where only the admins can share messages. Users are able to join channels and are notified of any comments. As well as operating as a communications platform, some of these channels are also used as markets, buying and selling goods such as drugs, counterfeit items and personally identifiable information (PII).
Over the years, Telegram has been used by a wide range of criminal communities. This includes terrorist activity, hacktivism, ransomware, hacking, CSAM, drugs, and the distribution of stolen data. In recent years, it has also become a hub for extremist rhetoric, with groups such as Terrorgram using the platform to promote their views and incite violence among followers. As Telegram’s role in criminal and extremist ecosystems has expanded, Telegram threat intelligence has become increasingly important for analysts and investigators seeking to monitor channels, identify threat actors, and connect Telegram-linked activity to broader online threat environments. At the same time, many other groups – often right-wing – have emerged on the platform, each with different ideological angles and audiences.
Telegram has long been criticized by law enforcement and security analysts for hosting extremist content, CSAM material, and other illicit content. It is renowned for not cooperating with law enforcement. In August 2024 Durov was arrested in Paris for not taking steps to curb the criminal use of Telegram. Since that time, the platform has taken some steps to remove channels reportedly conducting criminal activity, but there does not appear to have been any consistency to this activity.
Methodology
Using DarkOwl’s collection of Telegram channels, analysts identified and reviewed a variety of far-right channels and selected those that had some of the most concerning content from a variety of right-wing movements. Concerning content was defined as those that included mentions of extremist views, violence or appeared to be attacking groups or individuals. Although we classified the channels as far-right, they had a range of ideologies within that belief system, some were explicitly pro-Trump, some were composed almost exclusively of J6 rioters, some were conspiracy theory heavy, others were racist and xenophobic, etc.
Since our focus was on analyzing threatening language, we selected channels that were not overly image based. However, we acknowledge that images and memes constitute an important component of threat analysis. We also prioritized channels that were highly active and had a substantial number of members.
Below is a list of the channels selected and dates for which we had collected data that was analyzed as part of this project.
About the Data
A total of 190,535 messages written by 11,068 individuals was collected from the listed channels. To identify threatening and violent communication within this dataset, we used a set of threat detection tools developed by Mind Intelligence Lab. The tools are based on a machine learning model designed to automatically detect violent threats (Lundmark et al, 2024). Of the 190,535 messages collected, 5% (9,442) contained threatening or violent content. Nearly 4% of the users had posted at least one violent threat. These figures illustrate the exceptionally high volume of threatening communication, which poses significant challenges for threat assessors and law enforcement in determining the severity and credibility of individual threats.
Assessing Threatening and Violent Communication
To better understand the nature of threatening and violent communication, we conducted a qualitative content analysis of a random sample of 749 threatful messages that were automatically identifed using Mind Intelligence Labs tools. Each threat was annotated according to five analytical categories:
Explicit Target – The message clearly identifies a specific person, group, institution, or location as the target of harm. Example: “I’m going to make sure Senator James pays for this.”
Operational Details – The author provides information on how violence should be executed (e.g., weapon type, method). Example: “I’m getting my AR-15 to shut them up.”
Explicit Date or Time – A concrete date or timeframe is given for when the act will occur. Example: “You’ll all see what happens on July 4th.”
Research on the Target – The writer indicates surveillance, investigation, or personal knowledge about the target. Example: “I know her schedule — she always leaves work at 6 p.m.”
General Threatening or Hateful Language – Non-specific expressions of hostility, hate, or implied violence. Example: “People like them deserve to suffer.”
Findings
The purpose of our analysis was to examine the extent to which the identified threats contained identifiable targets, operational details, or explicit temporal markers—features that are often indicative of intent, planning, and potential capability. Our findings revealed that 93% of the threats (697 cases) explicitly mentioned a specific target, indicating a strong focus on particular individuals, groups, or institutions. More than 41% of the threats (308 cases) included operational details or descriptions of how the act should be carried out, suggesting a degree of planning and tactical consideration. Only a small fraction, 0.3% (2 cases), contained an explicit date or time for the intended act, indicating that while detailed, most threats did not include a defined timeline for execution. When a timeframe was given, it was vague — for example, “next week” or “by tomorrow.” None of the threats contained information about research conducted on the target.
Nearly 40% of the analyzed threats contained general threatening or hateful language, reflecting a broad spectrum of hostility rather than concrete plans for violence. This category included dehumanizing expressions, where individuals or groups were referred to as “monkeys”, “cockroaches”, or other derogatory terms that strip them of human qualities. Such language serves to justify or normalize aggression by framing the target as less than human — a well-documented precursor to acceptance of violence in both extremist and hate-based contexts.
In addition to dehumanization, many threats expressed violent fantasies or wishes, such as hoping that harm, punishment, or death would befall a specific person or group.
These findings indicate that even when no actionable plans are present, generalized hate and dehumanizing rhetoric can reflect underlying attitudes relevant to risk assessment. Such expressions may foster or normalize an environment in which violence is encouraged, justified, or perceived as acceptable, making this form of language an important factor to consider in both threat assessment and ongoing monitoring of threats.
Explicit Targets
Almost all threats (93%) had a explicit target. More than half of the threats (58%) were directed toward unspecified groups or individuals (they/them, he/she or you). These general expressions of aggression often use dehumanizing language and reflect a diffuse sense of grievance rather than a specific intent to harm. However, even non-specific threats serve an important function since they normalize violent discourse and reinforce group identity.
Explicitly racialized threats are highly prevalent. Black people (12%), immigrants (7%), Jews (4%), and Muslims/Arabs (3%) together constitute over one-quarter of all the analyzed threats. This pattern is consistent with far-right narratives centered on nationalism, racism, xenophobia, antisemitism, and anti-Muslim sentiment.
Threats against women (5%) and LGBTQ+ individuals (3%) reflect the intersection of misogyny and anti-LGBTQ+ within far-right telegram channels. Although less frequent, government officials (3%), politicians (1%), law enforcement (2%), and political opponents (2%) represent an important category of threats directed toward institutions of authority. These messages often frame violence as legitimate resistance against a disfunctional or corrupt state. Even though these threats form a smaller proportion of the total, they are of particular concern due to their potential to inspire real-world attacks on public officials or infrastructure.
A small part of the threats targets pedophiles (1%) and “race traitors” (1%). Threats against alleged pedophiles are often framed as a defense of children or morality, providing a pseudo-legitimizing rationale for violence. In contrast, attacks on so-called “race traitors” reflect that a perceived ideological disloyalty within the in-group is punished rhetorically or violently.
Operational Details
More than 41% of the threats included details on how the act should be carried out. References to specific methods offer valuable insight into how far-right actors imagine and express violence. The threats ranged from fantasies of large-scale attacks to symbolic punishments. While many of them may not reflect an immediate ability to act, the repeated calls for violence help to incite and encourage further violent behavior.
Shooting (31%) is the most frequently mentioned method, underscoring the centrality of firearms in far-right violent imagination. Guns are often presented as tools of justice or resistance, reflecting a broader cultural fascination with militarization and armed self-defense. References to specific weapons (e.g., “AR-15,” “rifle,” “sniper”) are common, and their frequency indicates potential access or aspiration toward weapon use.
Hanging (18%) and execution (10%) threats are notable for their symbolic weight. These methods are often framed as public punishment for perceived “traitors,” political opponents, or minority groups. Such imagery mirrors historical lynching narratives and functioning both as intimidation and as a performative assertion of dominance.
Beating (13%) and torture or inflicting pain (8%) represent more personal and intimate forms of violence. These threats often emphasize suffering and humiliation rather than efficiency, indicating a sadistic dimension.
Threats involving burning (5%) and explosives (4%) are less common. Burning is often directed toward symbolic targets such as religious buildings or refugee centers, while explosive threats are associated with aspirations toward large-scale attacks. Although these references are relatively rare, they reflect higher levels of operational imagination and thus represent elevated threat potential.
A smaller part of threats involves stabbing (3%), poisoning (2%), or other forms of methods (2%) such as being hit by vehicles, attacked by animals, drowned, or starved. These methods indicate creative variability in violent expression and sometimes suggest opportunistic or improvised violence.
Mentions of prison or arrest (3%) and deportation (1%) demonstrate how far-right actors also employ state-like punitive language. Such threats often frame violence as an extension of “justice” or legitimate punishment, blurring the line between vigilante violence and imagined authority.
Conclusion
Overall, the threat landscape on far-right Telegram channels is dominated by broadly directed, racially motivated, and ideologically charged hostility. The combination of generalized incitement and specific identity-based targeting suggests a dual function of such communication: maintaining a shared sense of grievance and providing moral justification for violence. Although explicit threats against named individuals are relatively rare, the pervasive use of dehumanizing and violent language toward entire social groups constitutes a persistent incitement environment.
The dominance of operational methods such as shooting, hanging, and beating in the threats shows two key aspects of far-right violent language: it is both militarized and ritualized. Firearms represent strength and control, while hanging and execution reflect ideas of punishment and revenge. Together, they express a worldview that portrays violence as justified and even necessary.
Although many threats lack clear plans for action, their impact should not be overlooked. They normalize violent attitudes, define who is seen as a legitimate target, and create a shared language that can encourage real-world violence.
The mix of modern weapons and old forms of punishment shows how far-right communities combine past and present ideas of violence into a single story of resistance, revenge, and exclusion.
Recommendations
Monitor high-threat environments: Continuous monitoring of far-right online spaces is essential to detect emerging risks and shifts in rhetoric.
Identify targeted groups and trends: Mapping which individuals or groups are being targeted, and how these patterns evolve over time, helps in understanding broader threat dynamics.
Assess credibility carefully: Determining whether a threat is credible is challenging when analysis is limited to digital communication. Online expressions may range from symbolic aggression to genuine intent.
Address incitement and inspiration: Even when individuals do not act directly, exposure to violent rhetoric and extremist narratives can inspire others to commit acts of violence. Efforts should therefore focus not only on explicit threats but also on messages that glorify or encourage violence.
Lundmark, L., Kaati, L. & Shrestha, A. (2024). Visions of Violence: Threatful Communication in Incel Communities. In: 2024 IEEE International Conference on Big Data (BigData): pp. 2772-2778.
Mudde, C. (2000). ‘The Ideology of the Extreme Right’, Oxford University Press.
Mudde, C. (2019). ‘The Far Right Today’, John Wiley & Sons.
During this webinar experts Jane van Tienen (OSINT Combine) and Erin Brown (DarkOwl) explore the evolving role of artificial intelligence in investigations and how it is transforming investigative workflows, the ethical challenges it presents, and how threat actors are exploiting AI for phishing, deepfakes, fraud, and propaganda. Learn why keeping the human in the loop is essential and how to build resilient, AI-aware intelligence practices.
NOTE: Some content has been edited for length and clarity.
Kathy: And now I’d like to turn it over to Jane, Chief Intelligence Officer with OSINT Combine, and Erin Brown, the Director of Intelligence and Collections with DarkOwl, to introduce themselves and start our discussion.
Erin: Thanks, Kathy. So yeah, we’re going to jump right in because as Kathy mentioned, we’ve got a lot of content to go over, but we’re just going to start with a brief introduction to who DarkOwl are, and OSINT Combine.
I’m just going to give the brief background on DarkOwl. As Kathy mentioned, my name’s Erin, I’m the Director of Collections and Intelligence at DarkOwl, so responsible for the data that we collect and also the investigations that we conduct. DarkOwl has been around since early, well, Vision since 2014, I think we’ve been around since 2012, and we primarily collect data from the dark web, from forums, from marketplaces, from Telegram, from Discord, and other sources where we’re seeing kind of what threat actors are talking about, what they’re selling, and some of the trends out there and making that data available to our customers. And if anyone has any further questions on DarkOwl, I’m sure Kathy can share some more information, but with that, I’m going to hand over to Jane.
Jane: Thanks very much, Erin, and thanks, Kathy, as well. I’m really pleased to join you here on the webinar today, so thank you for inviting me to come along. So, good afternoon, everyone. My name’s Jane van Tienen, and I’m the Chief Intelligence Officer for a company called OSINT Combine. I’ve spent a career in intelligence, predominantly national security and international intelligence diplomacy, before more recently moving into open-source intelligence.
I’m assuming that most people on the call would probably know what open-source intelligence or OSINT is, but just to ground truth it, it’s intelligence derived from publicly available or commercially available information, rather than classified sources.
Today, Erin and I are going to be talking all about artificial intelligence, of course, but not just because of the way it enhances our capabilities of investigators and intelligence professionals, but also because of the capabilities of the bad guys that we investigate. But before we delve into that interesting topic, just a little bit more to touch on this slide here about OSINT Combine. We are a proud partner of DarkOwl. OSINT Combine is a global company, we’re US-owned, but Aussie-founded so, Australian-founded and veteran-operated. And we’re all about helping build enduring OSINT capability, which we do through our AI-enabled OSINT collection platform that’s called Nexus Explorer, our foundational and advanced open-source intelligence training, as well as thought leadership.
And so, our focus on building enduring OSINT capability means that our company is more than just about giving people great tooling, although, of course, great tooling is important, but we feel really passionately about making sure that people are able to use the tools, understand the tradecraft to operate effectively, safely, and ethically in their work. We work with clients similar to DarkOwl, actually, ranging from national security agencies through to global banks. And that means that we’re seeing OSINT practices, as well as increasing AI adoption up close in different kinds of workplaces.
And we’re sort of getting insights, therefore, into what’s working, what’s kind of breaking or tricky, and where practitioners and leaders are struggling in relation to these issues.
Before we get into the actual thick of the webinar today, I wondered if there might be an opportunity for us to do just a quick poll in the chat there, just to give us a sense about how many of you are already using AI in some form as a part of your workflow. I was going to see if I can have a peep in the chat while we do that. If there’s anyone there already using AI as a part of the workflow. And let’s go on to the next slide while people might consider that there, Erin. Thank you.
So, my point in asking that is really to observe that for many of us, AI isn’t really a future concept anymore, is it? It’s already embedded into a lot of our investigation’s workflows, whether we’re working law enforcement or intelligence investigations or even corporate due diligence. And really, it’s the necessity that’s driving that adoption. Every day, practitioners are using AI really to expand the human capacity for things, for all sorts of things, actually, like language translation, rapid entity resolution, network mapping, pattern recognition, even brainstorming alternative scenarios, which I really enjoy using AI for these days, as well as summarizing vast volumes of content and doing all of that within minutes.
In that context, particularly at, say, a government level here in the US, but also across allied governments, so think Five Eyes, as well as NATO member states, we’ve already seen some pretty strident language and strategic choices about how AI should be embedded into intelligence workflows. And that’s probably most prominent when we’re thinking about open-source intelligence workflows. A great example is here in the US in defense strategy, where we’ve heard, OSINT being referred to as the INT of first resort.
And of course, we know that when it comes to private industry, OSINT really is the INT of only resort. And so, I think that’s important to observe, because oftentimes, you know, the increased utilization of OSINT also means hand in glove, the increased utilization and exploration of AI and AI augmented workflows. So, the point being that regardless of sector regional budget, really, our debate now has moved far beyond should we use AI to more about how do we use it wisely?
So, for investigations and intelligence work, we’ve always needed to ask critical questions, haven’t we? And those critical questions and those fundamental skills of tradecraft really haven’t gone away. But in an AI augmented workflow, regardless of purpose, the scope of those questions has absolutely expanded. And so, in understanding how to use AI to greatest effect, analysts and investigators must now not just interrogate the content or the information that they derive, but also the machines that help produce it.
And so, these areas on the slide, Brainstorming Partner, Research Support, Analytical Partner, Writing and Communication support, these are areas where OSINT combined through our work, we’re most commonly seeing AI being utilized as a part of OSINT workflows in various workplaces today. And indeed, the role of AI will continue to expand as technology evolves, no doubt.
I think the key issue is, though, that when deciding when to use AI in your work, the consideration really is about, you know, the accountability in decision making, and who owns the accountability in the decision making, because that is you, because it is always a human issue. It’s not to be, you know, for the machine. So, it doesn’t really matter at the end of the day how advanced our tools become. We cannot, in fact, must not remove the human from the investigative workflow. And so that’s what we mean when we say the phrase, keep the human in the loop, which we’ll be speaking to a little bit further in the presentation.
We have to remember that, as good as AI might be in any given moment, there are always going to be things that it cannot or should not do. And sometimes those boundaries are determined by governance frameworks that might exist in your organization or even your community of interest. We know that investigations and intelligence work, it lives and dies by its credibility. And so, no matter how the advanced tools we use, how great they are, our assessments are only really going to be value if they’re trusted by those who rely on them. And so, the challenge is really one where rather AI can overwhelm with lots of different plausible outputs that can actually bypass some of the analytical tradecraft or critical thinking that we might apply otherwise. And so, when we receive an AI output response, the trouble is that it can look right, but it doesn’t always mean that it is. And so, within OSINT combined, we’ve been investing a lot of thought, time and effort into how to most soundly incorporate AI into OSINT workflows, understanding what it can and cannot do, and know when to trust AI and when to challenge it. And it’s important that you do so as a part of your own investigative and intelligence products and to maintain your operational security online. And I’ve got an example of one of those resources that is freely available to download there on the slide, more to come on that.
If we look at the pros and cons of AI as it stands at the moment, I think these are fairly accepted in our industry and our collective work. And so there should be no surprises there, and I’m not going to go through every one of them. Some of these we will absolutely be showcasing in various means throughout the webinar.
But to pull the thread on one of these things in the Cons column there, which is a bit of a passion project of mine, if you like, and it pertains to role clarity, which is something that we don’t talk about as often as I think we should in this regard. And so, what I mean by that is that analysts, team leaders, decision makers, even boards, you know, each role in the decision-making chain or in the chain of command, if you like, really interacts with AI differently. Using AI to best effect isn’t really about only a practitioner level AI literacy or fluency, but it’s about the capacity of others as well as the organization and organizational system to understand it.
I think one of the most dangerous assumptions that we see in investigative work is this issue of mirror imaging, which is both believing that adversaries think and act like we do, as well as the fact that they don’t have the access to the same technology as we do. Unfortunately, not only do they have access to technology, the same as we do, but they also have a willingness to operate outside our own ethical and moral compass.
This is something not to be underestimated when we need to consider AI. The same generative models that we use to draft reports to identify patterns or detect anomalies are going to be used by criminal and extremist actors to fabricate personas or automate deception and manipulate narratives at scale. I think the real trouble is that AI makes generating some of these artifacts pretty trivial in some cases. And so, our tradecraft is really evolving beyond how do I find that needle in the haystack or how do I find the truth to now also include how do I recognize what’s been machine shaped to look like the truth. And that’s a really hard nut to crack.
Erin, I wonder if we might hear from you now about some of the examples that you and your team are seeing sort of in the wilds out there, just to illustrate some of these points.
Erin: Yeah, thanks very much, Jane. As Jane has mentioned, we hopefully are all using AI as part of our workflows and investigations. But you know, the criminals, the terrorists, extremists are definitely using AI as well.
I’m going to run through kind of a couple of examples that we’re seeing of those using that technology.
But I think one of the key things that I want to start with is so far, at least I think in what we’re seeing of threat actors using AI, is they’re using it in the same way that we all are too, in that they’re using it to increase productivity, improve the output of what they’re working on. But it still requires that human intervention, right? And they still need to do things as a threat actor and have some experience.
You know, even if we’re talking about them using, vibe coding to create malware, they need to have a basic understanding of coding and how they do that to be able to do that effectively. So at least thus far, we’re just seeing them using it to enhance the types of attacks and operations that they were already doing. With I guess the one caveat to that being, deep fakes and the way that they’re developing and how good generative AI is at producing images and speech now is definitely becoming more and more of a problem.
But let’s dive into some examples of how exactly they are using AI. And I stole this from a Trend Micro report, but I think it nicely maps out kind of the different attack vectors and vulnerabilities that criminals are going after in terms of deep fakes but also using their own LLMs. And we’ll talk about that in a little bit more detail.
And we’ll go through some of these examples in more detail too. But, you know, things like business email compromise and creating more sophisticated and believable phishing emails is something that we’ve seen go on the rise, but also, you know, business compromise in terms of spoofing CEOs or executives through their voice, through their images, through Zoom calls, things like that is definitely on the rise. We’re also seeing, you know, more targeting of foreign victims. I think, gone are the days of the Nigerian prince with language that you don’t really understand, and you can tell quite quickly that it’s fraudulent just because of the fact that a native English speaker hasn’t written it. That’s not really happening anymore because they’re using AI to translate their messages and to create those images for them. We’re also seeing an increase in things like romance scams, sextortion, CSAM, unfortunately, and virtual kidnappings and things like this. So, using AI and what we would maybe traditionally think as the cyber realm for more real-world effects. And some of those are having really awful consequences on a lot of people. And so, something that we all need to be kind of aware of and how to deal with.
I mentioned there are criminal versions of LLMs. These are based usually on the, you know, open source or other LLMs that we’re using out there, things like ChatGPT that have been made freely available. But they’re basically getting rid of the guardrails that these companies have put in place around this AI to try and combat the technology being used for nefarious purposes.
WormGPT is one of the models that came out fairly early. I think it’s been around for a year or two now. And this is taken from a darknet web page where they’re advertising it. And one of the interesting things and one of the reasons I wanted to raise this is you’ll see that they’re advertising it very much in the same way that, you know, OpenAI or PerplexC or those other, you know, ethical companies, I hope, are kind of putting this out there. So, they’re telling you it’s a game-changer, you know, what it does, how it can help you.
It has pricing plans. You can get different plans depending on your expertise and kind of what information you want to use it for. And then you can see that they’ve got it on the command line as well. So, they’re able to see it. They call it the biggest enemy of well-known ChatGPT. And it allows you to kind of do all of those malicious things without the guardrails that you will get in those more legitimate services. So WormGPT is one.
Another one is FraudGPT. And this kind of does what it says on the tin. It’s really helping threat actors to conduct fraud. And it’s, you can see at the bottom, it’s not just the LLM. They’ve also got testing, cracking, access tools. So, they’re trying to build a whole ecosystem around offering this, to be honest, as a criminal enterprise.
And again, you can see that they’re advertising it on their site. This is another dark website where they’re talking about the different ways that you can use it. So, you can create phishing pages. You can create hacking tools. You can write scam pages. You can find leaks. And some of these things in here are things that we as investigators might want to do, you know, finding leaks or finding, you know, vulnerabilities from a red team perspective. And AI can help you do that. But I think the thing to think of, and to Jane’s point about, you know, is that threat actors have access to this technology too. And they are using versions of these tools in some cases that make it easier to find some of those things than maybe we have as investigators.
And again, this is just the FraudGPT pricing. So, you can see they have a breakdown of a lot of different tools and accesses that you can get.
They really are selling this as a service, as a way to give other threat actors that maybe aren’t up to tax.
And this was also taken from the FraudGPT site. You can see this is a kind of a chatbot telling them kind of how to put the prompts in to be able to get some of this information back. So, the top one is, “write me a short but professional SMS spam text I can send to victims who bank with Bank of America, convincing them to click on my malicious short link”. This really feeds into that kind of phishing kind of attacks, where this is one area where we’re seeing AI really kind of increase the sophistication, for want of a better word, of those types of attacks, just in terms of it’s making it a lot harder for victims to identify when they’re receiving these malicious emails, or SMS messages, based on the way that they are written. And you can see it’s fairly simple for them to kind of put in these prompts and get that kind of information back that’s going to assist them with that.
And these are just some shots of kind of threat actors actually talking about this technology on various forums that we collect on the dark web. So, you can see there’s threads talking, you know, about FraudGPT and what it can do for you and how it can help you. We can see things on Russian hacking forums as well, and that’s been used. So, they’re talking about useful AI, which ones are the best. So, we’re seeing them talking about different methodologies and how they can use this as part of their workflows as criminals. And then you can see them talking as well about kind of the different services that are out there. So, the bottom one’s very hard to see, but they’re talking about Grok. It’s not just ChatGPT, they’re talking about a lot of the other kind of AI services that are out there as well. This is just to show that, you know, the same way we’re, you know, having this webinar and talking about uses of AI and how AI can help us in our workflows and our investigations, the threat actors are talking about that too. And we are seeing that kind of pop up on forums.
We have also seen AI being used as part of attacks. I’m not going to delve into this hugely because it’s not really kind of on the dark web side of things, but this is just kind of an article highlighting how Grok AI was used to bypass app protections and spread malware to millions. We are seeing more and more of this. We are seeing, you know, ransomware strains being developed using AI or having kind of some AI implementation as part of them. And I think this is something that we expect to rise as, you know, the technology becomes more widely used and I assume continues to increase in sophistication. We are going to see a lot more of these types of attacks and it is going to become an attack vector in cyber as we kind of move on with that. I just kind of wanted to mention that as a side.
I’m going to dive in now into some specific examples of how this is being used. Starting off with criminals, I’ve kind of already touched on this, but we’re seeing it very much in phishing, social engineering attacks, romance scams, and also for defeating KYC to get into kind of financial fraud.
We’ll go through those in a little bit more detail. This is an example of an advertisement on Telegram. This is a service where they are offering an AI face builder. It will create a unique face and then you can use that for whatever you need. So, this is being used, we’ve seen this being used for defeating KYC.
You can see you’re swapping faces on photos and videos so that you can look like you’ve got your ID card. For those organizations where they ask you to take a picture of yourself with your ID, this is kind of helping them to kind of combat those checks and balances that are put in place. But we’re also seeing these kind of face builders and generators being used in sextortion as well, and I’ll kind of touch on that in a bit. But you can see kind of how this is part of the business that they’re offering. You can get a tutorial; they give you kind of free services to start off with to test it. You can do bulk processing and purchasing credits. So, it is kind of interesting how they’re using this going forward.
This is another discussion on a dark web forum talking about fraud GPT, but I highlighted it here because it’s saying this is what it’s going to help you do. It’s going to help you write phishing emails, develop malware, forge credit cards. These are the types of activities and crimes that are being posted as AI will be able to help you to conduct these types of crimes.
This is also another news article that I came across in terms of them using deep fakes to spoof a celebrity. The individual that was spoofed is an actor in a US soap opera.
His videos were generated and being sent to a woman based in California, and he was able to scam several thousand dollars out of that individual by asking for money and kind of creating a relationship with this victim by pretending to be this famous soap actor.
This one I don’t think did have a romance angle, but this is very much how romance scams can be operating with the use of AI as well in terms of them generating fake videos of fake individuals or pretending to be a celebrity, impersonating their voice, but obviously getting them to say things that they would never say and targeting individuals to get them to send them money, usually via cryptocurrency. And there has been a huge increase in this, and a lot of celebrities are being targeted in terms of their likenesses being used via social media to target victim to get that financial fraud out of it. And I don’t actually have the video to play here. This is a screenshot. But if you see any of these videos and to Jane’s point about like how do you identify this information, they’re very realistic. It’s very difficult for people to identify that this might not be real, especially I think for some of those victims that might be more vulnerable and not as savvy to be open to this technology, but also these kinds of attacks.
These are some more advertisements from Telegram, but this is more related to social engineering services that they’re providing. So Purple on the right, you can see that they’re doing call protection, but they’re generating ultra realistic voices via AI. They’re offering different tones, male, female, neutral. And they’re using these voices to spam people basically to have these calls to try and get people to hand over their money. They’re providing this as a service to people so they can use these different voices to scam unsuspecting individuals. So, you know, it isn’t, I think when we think of phishing, we tend to think of emails or maybe SMS messages, but I think more and more phone or video messages are going to become more of an issue with the advent of AI.
On the left-hand side as well, this is kind of more of the business email compromise where they’re kind of talking about all the different ways that they can make sure that an email campaign would be successful, including AI powered optimization. And I think to go back to, you know, it’s the same way, you know, that we’re using this in our everyday life, the criminals are using it. I mean, you could have an SEO marketing company that’s kind of saying the same thing to businesses that want to kind of advertise their services. But from the threat actor side, if you put the different slant on it, they are using AI and customizing email addresses to make sure that you can spam people more successfully and conduct those financial crimes. It’s interesting how it’s being used in a similar way, but, you know, with a lot more malicious intent than the rest of us would be using it.
Moving onto sex related crimes, I think this is a really important one and one that people don’t always necessarily think of or sometimes think that there isn’t a victim if it’s AI generated, but that’s definitely not the case. I think the main areas where we are seeing AI being used is child sexual abuse material, CSAM, and generation images relating to that, Human Trafficking and Sextortion and Romance Scams.
To highlight the AI generated child sexual abuse material, you know, Europol have made arrests quite recently related to this and put out information about it.
But a lot of people are using AI to generate fairly real looking videos depicting CSAM. And there are still victims in this because the individuals that are watching this material may go on to also target children in the real world, but also, they need to train these models and create these images based on something. And so, there are children that are still being victimized by this kind of activity, and it is making it more prevalent.
It’s something that I think is really important that we are able to stop. And it is becoming, you know, more and more sophisticated. And I think this quote from the IWF, Internet Watch Foundation, is probably a little bit out of time now, but saying that, it has progressed at such an accelerated rate that they’re very realistic examples of videos depicting this. And I think we are seeing those very realistic videos and images being distributed across the dark web and other sources at this time. It’s definitely something that obviously we need to stop.
Human trafficking, I think people might not necessarily equate AI with human trafficking and see exactly how it’s working. This map actually just shows human trafficking victims across the world. It isn’t specific to AI, but I think I wanted to highlight kind of how much of an issue human trafficking still is. This is from Interpol.
But also, in terms of how we’re seeing AI, it’s being used to generate fake job advertisements. So, kind of as part of that initial phase of the human trafficking of enticing victims in and generating material that’s going to make them think there’s a believable job or there’s kind of a believable activity that they want to be involved in and kind of suckering them into that whole industry. It’s also being used to bribe people in terms of generating false sexually explicit images for victims of human trafficking and using that to really kind of enforce the activity that’s going on.
And that brings us in the same vein to sextortion. In a lot of cases, AI is being used to generate images of individuals and then extort money from them. So basically, creating nudes or sexually explicit images of individuals, it’s not them, it’s AI generated, their face has been put on it, but threatening to share those images and say that they are real with their friends, with their family, with their colleagues. It’s really prevalent against young people using social media vectors, so things like Snapchat, Instagram, things where images are shared quite a lot but it is targeting people of all ages and it is targeting both females and males and it’s really you know an awful kind of practice there have been noted suicides of people that have been targeted by these types of sex distortion attacks. So again, it’s going back to how can people identify that these images aren’t real you know the victims feel that they look so real even though that they know that they’re not because they haven’t shared that material with them, that they’re so worried about this, that they are paying these people. And there are, unfortunately, fairly well-organized criminal groups that are kind of doing this on a rotation basis, trying to kind of build up these relationships with these individuals generating these images and getting this money from them. It is becoming a real huge issue, as I said, particularly among the younger generation.
We’re also seeing AI being used by terrorist organization and extremist groups. It’s primarily being used, I would say, for Propaganda, but also Disinformation as part of those propaganda campaigns and campaigns and putting a lot of that information out there. We’re also seeing them using it for Translation a lot to make sure that they can reach individuals in multiple countries to bring them into their extremist beliefs and also generating images, again, with propaganda and disinformation in mind. But some examples of that, this is taken from an ISIS chat group. You can kind of blurred out in the back of the ISIS flag, but it’s an AI-generated image on an article about building bombs. So, part of their propaganda, part of their education of individuals, they’re using AI to make this look kind of more believable and kind of draw in individuals. So that’s kind of one aspect we’ve seen.
This is another one that kind of looks you know, if you don’t know what to look for, but it’s Iranian terrorists claiming that they crashed a plane into Disney World in Anaheim. You can see the Disney castle in the background and the crash plane. I would argue the plane isn’t that realistic because planes don’t tend to crash backwards. But it’s highlighting that propaganda. It’s well kind of incentivizing people to go after these kind of targets. They’re putting ideas and people’s minds using AI of ways in which you could, you know, go about conducting attacks. And that’s something we need to be very mindful of.
This is a video that was put out with Hamas. So, Hamas talking, again, this was not a real video, but it looked like a news conference of Hamas leadership talking about the Israeli army and how they wear diapers because they’re stationed for so long and that led to generated images of you know Israeli forces wearing diapers which in some cases look quite authentic.
I mean I think most people would see this as a joke but obviously there you know there can be more concerning ways in which people about providing these kind of generated images. But to the point where they even had a TikTok video that was going around that went viral where an Israeli commander was talking about the nappy. So again, they were impersonating him and getting him to speak as if it was him to kind of try and back up the story that was put out there. And this is obviously all put out there to undermine Israeli from Hamas terrorist group. So, you know, it’s that disinformation. This one, obviously, I think most people would not believe, but they are putting things out there that are much more believable and it’s making it very difficult for people to understand what is real, especially in these times of kind of conflict.
And with that, I’m going to stop talking and hand it back to Jane.
Jane: Thanks, Erin. What you’ve demonstrated there in that kind of collection of examples is just the fact that, you know, AI, unfortunately, can increase the sophistication of a lot of bad actors really quickly. And so that can make our jobs, of course, really challenging.
So, we won’t necessarily do the poll now in the interests of time, but I’ll still talk through it because I think it’s interesting in the fact that, you know, when you reflect on these kinds of questions yourself, thinking about your own environment, whether, you know, your biggest challenges relate to some of the synthetic media that Erin sort of spoke about or perhaps it’s the scale of all of the things that you’re challenged with and in some cases even organizational readiness and maturity can pop up to being a big challenge for some practitioners and workplaces. But I think what is really interesting just to kind of emphasize your point there, Erin, is that this question really is one where the risks are kind of symmetrical in the sense that the same capability that helps us as practitioners, investigators, analysts, whatever in terms of automation and language generation, pattern recognition, it’s exactly what the threat actors are going to be using against us. And so, there’s an absolute need that we ensure that we have high levels of literacy when we’re kind of engaging in our work today. Because, AI itself, it’s not inherently malicious or benevolent, really. It’s what determines that is the outcome of its use and how well we govern it and verify and all of those kinds of things.
I think a lot of these are making things extremely difficult for practitioners and we can see a world where sometimes we might not we might simply not be able to verify whether something is true or not and that’s sort of the future that we’re looking at but at the moment we’re not quite there and so there are certainly some techniques that we kind of encourage you to consider Let’s have a look at the next slide, Erin.
I think one of the key things when at least OSINT combined when we’re talking about this challenge is that, you know, we really are talking about the analyst requiring stronger discernment, which references the fact that we acknowledge that AI gives velocity and capability in a way that perhaps, threat productors didn’t before have. But also, analysts must maintain this skill for validation and be the purveyors of veracity in as much as possible.
We think the most effective lens to kind of look at this is a multi-kind of modality kind of approach, if you like, that blends both traditional verification and analytical tradecraft with AI aware cues. And so, we acknowledge that this can be a difficult task, of course. Certainly, in some of those disinformation examples, Erin, that you provided, where analysts are going to be requiring to perform validation and verification, as well as potentially some really detailed content and metadata analysis. So, you’re adding on to your traditional analytical tradecraft tool sets around critical thinking and some of your analytical practices, you’re adding onto that some quite technical skills when it comes to sort of unpicking content and metadata analysis. But we think that it’s doable at this stage if you break it down. And so, we favor kind of practical steps and some guides for that process such as inauthentic content analysis maps which we’ve written blogs about that you can check it out on our website. And so, I’ve put some key examples there around anatomical artifacts and reverse retrieval and those kinds of things which of course are always going to be helpful. Providence Chain also super interesting for us when we’re kind of considering whether how something has proliferated online and where it was created and so forth.
But for me, I can’t get my head out of this space of the meta questions, and I think that’s got to do with largely my traditional intelligence training. And so, the questions that I always come back to in addition to some of these AI-aware cues are things like, “What would I expect to see if this were true?” And so that has me going to actually, look at some of the context, which is still super important to us. And the other question I like to ask when I’m considering the adversary is, “Well, what would my adversary need AI to achieve here – Would it be scale, speed or story?” And that really speaks to intent capability and, you know, the motivation factor, of course, which we always need they always need to maintain an eye on. But having the AI helping us out, as well as applying some of that human validation and verification activity is a real emphasis, I think, to ensure that the human remains in the loop. Really, we want our analysts to think critically, act ethically, and adapt intelligently alongside the machine that they’re working with.
There’s some available resources, all available to you, to download from the OSINT Combined website, and there are certainly more available. Let’s look at some key takeaways.
I think what we’ve been able to demonstrate today as a base of sort of numerous examples across different kinds of crime types and actor groups that absolutely adversaries have access to AI and they’re not afraid to use it. And they’re certainly, experimenting with it just as we are at the moment too. Human in the loop remains essential. We’ve discussed that. And there’s an importance there for layered verification. So not just trust in one modality over the other, but kind of really thinking quite deeply about, well, what are the different kinds of ways that I can speak to reliability, relevance, credibility, and consistency when I’m looking to verify information. And as a bonus tip, always thinking about, hey, some of these deep fakes, particularly the voice synthetic media that you identified, Erin, are becoming pretty sophisticated. And so, there is an element here to prepare for the inevitable in terms of preparing your organization to harden against impersonation and to prepare a playbook if you like about what happens if. And so, I think we can’t really avoid that.
I can see we’re at time. Kathy, I wonder if we pass to you and more than happy to take questions offline and respond to people if there are any, but over to you for final words.
Kathy: Sure, we do have a couple of questions that have come in. If you two want to go ahead and address them now, we can address the two that have come in and if any others come in, we can address those offline later if that would work.
Jane: Yes, I think that’s fine for us. I can see Erin nodding. So please, please fire away. And of course, if people need to drop off, they can, and they’ll received the recording.
Kathy: Sure. So, the first question is, how do you brief leadership when you suspect synthetic media but can’t prove it?
Jane: Yeah, we get asked that one quite a bit, Kathy and Erin, you might have thoughts on this too, but I think I still go back to this factor about you need to sort of explain confidence, not just certainty, to the leadership group and so that means about being really transparent about what you do know and what you suspect and what’s unverified and being open to being contested about that too. So, you know you have to sort of be professionally honest here. So, we want people to sort of show you know their reasoning how they came to a particular conclusion, could be you know to identify the anomalies and maybe even network behavior or some kind of thing that was flagged during the analysis. But I think it’s also really useful for leadership to sort of say, hey, if this is genuine, then here’s the impact, because that’s essentially what the leaders need to know is the impact so that they can act accordingly. And then vice versa, well, if it’s fabricated, here’s what, you know, we know that the adversary is trying to achieve against us. And so, both of those things are actually really important, I think, for all leaders to know about.
Erin: Yeah, I just add to that. I think I agree with what you’re saying, Jane, but I think just transparency, I think, you know, outside of AI, when we’re talking about intelligence and the things that we find, just because something is low confidence, or, you know, we haven’t been able to verify it with a lot of other sources, doesn’t mean it’s not something that should be shared and should be part of the intelligence package. So, I think it’s just making sure that we’re using those traditional kind of ways of how we do assessment and not doing anything different just because it’s AI.
Kathy: Great, thank you both. And kind of piggybacking on that a little bit. What’s your protocol for documenting AI’s role in your findings?
Jane: Yeah, I mean, I think it’s really important, Erin, and you were just sort of touching on it then, weren’t you? Like, just because we have AI now in the mix doesn’t mean that we’re going to be throwing the baby out with the bathwater when it comes to analytical and assessment tradecraft. All of that still applies, but we need to be professionally honest and transparent about when and how AI is being utilized throughout the process. And so actually, you know, in the US, there’s some strong guidance around this point for the US intelligence community, but OSINT Combine has actually, produced a best practice guide for citing AI to just for anyone. So, don’t have to be intelligence community, could be private sector, but really it’s about accountability through transparency is essentially it. And so, you want to be pretty transparent about how AI was utilized as a part of your assessment, what tasks it supported, where the output was validated, and where the human analyst made the final judgement. So typically, I see almost like a short provenance note or some kind of disclaimer in the methods section of analytical reporting now, that’s not uncommon. But we really need to be transparent to your point, Erin, earlier.
Kathy: Great. Thank you. That is all the questions that have come in to us right now, but we do have up on the screen contact information for both Jane and Erin, if anybody has further questions, or they’d like to reach out to us.
And I’d like to thank Jane and Aaron for an insightful discussion today. As a reminder to all of the attendees, we will be following up via email with a link to the recording and other resources. And we thank you all for joining us for this webinar and we hope to see you all again at another webinar in the future. Thank you.
DarkOwl is excited to announce substantial updates to its darknet marketplace data capabilities, available in both Vision UI and Vision API. These enhancements are designed to empower investigators, analysts, and researchers to navigate the complexities of darknet marketplaces with deeper insights and more precise control over darknet product listings.
Darknet marketplaces are hubs for illicit activity—ranging from the sale of drugs and weapons to stolen data and counterfeit goods. Monitoring these marketplaces is vital for law enforcement agencies working to dismantle criminal networks, to provide actionable insights into illegal operations, help track and apprehend perpetrators, recover stolen assets, and disrupt illicit supply chains.
DarkOwl’s new Markets feature introduces a tailored experience for darknet marketplace investigations, including:
Rich Data Extraction and Display: Access unique data elements including Vendor and Product Details, Payments, Shipment Information, Reviews,and more—all structured for investigative workflows.
Specialized Search Operators and Filters: Search listings by Keyword, Vendor, Market, Category, Price, and other market-specific options for targeted results.
Advanced Date Options: Sort or filter listings by when they were First Seen or Last Changed on the market, enabling time-sensitive analysis.
Result Set Summaries: Visualize your findings with a timeline of new listings, a map of shipping sources by volume, and metrics on top markets and vendors.
“With these new capabilities in Vision, we’re delivering a purpose-built experience for researching darknet marketplaces that is intuitive, powerful, and grounded in the most comprehensive data available,” said Sarah Prime, Director of Product Technology. “By offering enhanced data extraction, advanced filtering, and powerful visualizations, we’re enabling our clients to uncover insights faster and more effectively than ever before.”
These updates reflect DarkOwl’s commitment to delivering tools that evolve with the threat landscape, trusted by Fortune 500 companies, government agencies, and security researchers around the world.
About DarkOwl
DarkOwl is the industry’s leading provider of darknet data. We offer the world’s largest commercially available database of information collected from the darknet. Using machine learning and human analysts, we automatically, continuously, and anonymously collect and index darknet, deep web, and high-risk surface net data. Our platform collects and stores data in near real-time, allowing darknet sites that frequently change location and availability to be queried in a safe and secure manner without having to access the darknet itself. Customers are able to turn this data into a powerful tool to identify risk at scale and drive better decision making. For more information, contact us.
This fireside chat, “New Regulations and What They Mean for Your Supply Chain,” features legal expert Rich Hanstock and DarkOwl’s Lindsay Whyte as they unpack the evolving cybersecurity regulatory landscape across the UK and EU. The discussion explores the shift toward mandatory, continuous, and ecosystem-based compliance, highlighting key regulations such as the EU Cyber Resilience Act, NIS2 Directive, and the UK’s Cyber Security and Resilience Bill. With increasing supply chain complexity and heightened accountability, the speakers examine how organizations can proactively manage risk, leverage threat intelligence, and prepare for upcoming compliance deadlines—all while navigating the broader implications for cybersecurity professionals and industry resilience.
NOTE: Some content has been edited for length and clarity.
Kathy: And now I’d like to turn it over to Lindsay, a Regional Director for DarkOwl and Rich Handstock, Barrister and founder of pwn.legal to introduce themselves and start our discussion.
Lindsay: Thanks very much, Kathy. The aim of today’s session is to shed some light on the regulatory landscape as it relates to cybersecurity practices in the UK and Europe. And obviously from DarkOwl’s perspective, we’re always keen to share how our technology and ever-evolving collection approach meets these regulations. But today, it’s important to spend a bit of time setting the scene, I think, and stepping back a little, because there’s a few things at play here which affect many more professionals than just those involved in DarkInt collection and threat intelligence.
So perhaps, Rich, I can start by asking you as a specialist, legal professional in the world of cybersecurity and data privacy. What is the regulatory landscape right now with regards to cyber resilience?
Rich: Thanks, Lindsay. I think it’s quite an exciting time to be talking about this. Jurisdictions around the world, it seems to me, are converging around this idea of the challenges and risks of cybersecurity being shared, rather than seeing responsibility concentrated in states or in a few larger kind of critical infrastructure type organizations. Take CrowdStrike, for example, events like that surface into the popular imagination, the kind of sheer extent of hidden dependency on technology, many of which are not readily understood by or foreseeable to the average person and the systems we’re seeing vulnerabilities in ways that are not necessarily well understood either. But what is understood is that when it goes wrong, even for one company, even if that company isn’t currently a household name, that incident can have ramifications for a vast number of people outside that one organization. And so, if that keeps happening, and I think we have to assume that it will, that has the potential to erode the sense of security that many of us at least are fortunate to depend upon. Some of us maybe take for granted. And when that happens at scale, it can become a national security issue. But the challenge is just so huge. And fundamentally, I think governments are realizing that the cybersecurity challenge is too big, too great, too rapidly evolving for states alone to solve.
So, for the last few years in the kind of cyber policy space there’s been a discussion around what’s been termed a ‘whole-of-society’ approach to cyber security and this idea that partnerships not just between states and those key kind of private sector organizations that are deeply embedded in kind of infrastructure of the internet and so on, but critically between cooperation within the private sector, between and across markets and sectors and jurisdictions, with the focus really being now on assuring business continuity, data security and integrity, so as to project confidence to end users and to other businesses that everyone’s working together to help to keep the lights on globally.
So, to answer your question, I think it’s the recognition in policy of a need for that whole of society, everyone working together in partnership approach to cybersecurity that is driving this kind of shift in the regulations towards focus on the supply chain, ensuring private sector organizations of all shapes and sizes are taking the threat seriously, not just to their own backyard, but looking outward to their dependencies in their supply chain as well. There’s a sense, I think, that regulators need to have the power to ensure that more organizations are thinking about business continuity and security with ever broader responsibilities and so on. But it’s all about enhancing our collective security.
Lindsay: Yes, I see what you mean. And what are you saying then is the sort of general direction of travel on that basis then?
Rich: Again, it’s broadly the same idea, right? More accountability for cybersecurity throughout what are life cycles and throughout the supply chain. Whilst there is alignment around that central idea, national implementation is creating complexity for multinationals. And I think that there are effectively three kinds of big handful, big three, three big key shifts that I want to talk about.
First of all, we’ve got the shift from voluntary standards to kind of mandatory standards, at least for those who are in scope. Historically, cybersecurity standards have been kind of largely self-regulated. You can get ISO certified, adopt various frameworks, get your cyber essentials and so on. All of its really good practice. Sometimes you see those kinds of certifications as being conditional upon kind of eligibility for a contract. It’s kind of a compliance requirement. But fundamentally, they’re voluntary. And what we’re seeing now is regulators kind of saying, well, if you’re in scope of our regulatory powers, that’s not going to be enough. You need to have these as kind of a minimum baseline. And that’s why we’re seeing kind of legal duties of care being put on kind of manufacturers and operators, as well as just the critical infrastructure providers. That’s shift one, voluntary to mandatory.
The second shift is a move from point in time security and assurance, to more continuous monitoring and assurance, which is kind of linked to the first point. It’s not performative, or supposedly, it’s not just performative. You need to be taking this kind of focus on effectiveness and outcomes rather than just ticking boxes. So, for example, under the CRA, the EU’s Cyber Resilience Act, you don’t just certify a product is secure when you launch it, you’ve got ongoing obligations throughout its life cycle. So, if three years after release of vulnerability emerges, and it’s being exported, and you become aware of that, you’ve got specific notification timelines that are pretty sporty, actually, to the relevant authorities. And that fundamentally changes what compliance looks and feels like inside an organization. It’s not just okay, we’ve got a stiff cut on the wall, big tick. It’s a continuous operational responsibility. That means that you have to understand the threat environment as it evolves. So, voluntary to mandatory, point in time to continuous.
Thirdly, from perimeter thinking to more ecosystem thinking. It’s this idea that traditionally compliance is focused on your backyard, within your fence, your organization’s security. These new regulations effectively make you responsible to an extent for understanding your own supplier’s security. And in some cases, your supplier’s suppliers, this kind of idea of nth-party security, where does it stop, you’re now accountable for risks that you might not even have visibility into at the moment. There’s kind of a question about underwiring your ability to discharge your own responsibility by getting insight into what your suppliers are doing. That’s part of the challenge in effect. And critically, the penalties of getting bigger and sharper teeth, you know, like 15 million euros, two and a half percent of turnover for CRA, that really changes the conversation in the boardroom. And we’ll hopefully empower CISOs and certain people who are responsible for compliance in this space to be stepped up and listened to and maybe have more budget than typically they’ve had previously.
Lindsay: That’s such a good point because there are now just these endless strings of supply chains in this day and age. Why do you think these changes are happening then?
Rich: Well, I think primarily it’s the instance that I mentioned. We can list them off all day, SolarWinds, CrowdStrike, JLR, MLS, these weren’t necessarily isolated attacks on single companies in terms of the way that they were, that the impacts were felt, these were supply chain compromises that kind of cascaded across many people, many different organizations and I think we have seen regulators watching companies with quite sophisticated security programs getting breached because of vulnerabilities in third party software that they maybe didn’t have any or enough visibility into. That goes back to the point I made a moment ago about perimeter-based security, just not really working when the threat enters through your supply chain. We’ve also got because of that kind of cascading effect, the kind of sense of market failure, where cybersecurity incidents are what economists might term a negative externality, right? When a product is insecure, that it’s not the manufacturer alone that bears all the cost, customers suffer the impacts of breaches, critical infrastructure is disrupted, but the manufacturer’s liability might not necessarily capture what is regarded by the sort of person on the street as kind of being fair. The idea is that if markets aren’t naturally optimizing for security because of the externalization of some of the cost, regulation; there’s a case for regulation stepping in to correct that market failure. I think regulators are trying to use the law to internalize those costs to kind of make manufacturers and operators bare the true cost of insecurity.
Which actually leads me onto another important point, which I think is often overlooked in this space, which is the insurance market. This has been a lot of conversation about this, around the JLR incident. Insurers, I think, have historically struggled to price risk effectively to understand the risk because there’s no kind of standardized way to assess security practices across supply chains and I think without that without baseline security standards there’s a risk that the risk transfer mechanism it kind of breaks down. So, look at the discussion around insurance up to JLR, would it even, would the insurance that JLR was criticized for not having picked up even have been sufficient? Maybe not, right? And to the extent that that reflects a gap in the market, I think we’re going to see the insurance market mature, partly as a consequence of these regulations, partly as a result of the incident and the discussion that is now going on about it.
It’s not just about preventing breaches is my point. I think these regulations are also about creating more predictable risk environments so that insurance markets, ultimately capital markets, can function more effectively. So, without that predictability or that ability to understand what’s going on in the supply chain, where the dependencies are, where the vulnerabilities are, there’s a risk that the digital economy is more unstable than we would like it to be.
Lindsay: And on that question of the new regulations, could you talk a little bit more about what they are saying?
Rich: Sure. I mean, there’s a lot of them. I know you’ve– I think we’ve got a slide. If you could call that up, that’d be great. I’m not going to try and cover all the detail now, but I think there are kind of two or three main tracks.
We’ve got the EU Cyber Resilience Act, which came into force in December last year. The reporting obligations kick in in September 26th, full compliance by the end of ’27. NIS2 alongside that came into effect in 2023, which that was really about expanding critical infrastructure obligations. And a lot of the conversation in the UK now around the Cyber Security Resilience Bill is about extending original NIS regulations to managed service providers, bringing a big chunk of the supply chain into the scope for the first time. We’ve talked at the beginning about the big handful shifts, and we’re drilling down now into some more of the regulations and what it is that they actually say.
I think Question Zero the clients always ask is, am I in scope? I know scope is expanding, there’s a lot of talk about the fact that scope is expanding and the greater burden that therefore imposes on people. That’s obviously an interesting and important feature of these regulations, but it tends to drive the conversation around, while there are some new regulations coming, how do I avoid them or minimize my exposure to them? Obviously, that’s important to understand it, but I always advise clients that the conversation doesn’t stop there. So, kind of my prediction is that the requirements that each of these frameworks bring will over time become market norms, to the extent that we could see those requirements invoked by analogy, like in private litigation, even those who are outside the scope of regulatory jurisdiction. So, if you have an obligation, say in a contract, to take reasonable steps or perform due diligence, I think we’re going to see a failure to take steps that in some sectors are required by regulators, potentially being deployed against people who are otherwise out of scope in litigation or at least in negotiation around a commercial contract or following an incident. I think it makes sense that whether you’re in scope or not to understand what more you can do to understand your exposure to risk.
Big handfuls, if in the EU manufactured importers, you’re looking at the Cyber Resilience Act, so if you’re making or importing products with digital elements into the EU, so that could be software, IoT devices, anything connected, you’re going to have obligations at sort of three main stages. Before the market, you’re looking at being able to demonstrate security by design in software and hardware, risk assessments, documentation, so on. At market, the things like CE marking, conformity assessments, kind of build on the pre-market stuff. You’re looking at creating what’s called software builds of materials, or SBOMs, in a particular, format that need to be given to regulators on request to goagain, to show that you understand where the dependencies are in your software.
Then the big shift is throughout the lifecycle of the product, right? You’ve got a monitor for vulnerabilities in your product throughout a support period, usually five years. And if you become aware of a vulnerability that’s actively exploited, maybe through responsible disclosure or otherwise. You’ve got to notify National Authorities and ENISA within 24 hours, a detailed report within 72 hours, final report 14 days. This is pretty quick in the context of an incident, right? And critically becoming aware can include constructive knowledge. So, if it’s publicly available, you could be deemed to know. So, you need to be monitoring what’s going on, have a vulnerability disclosure policy and be engaging responsibly with those who make those responsible exposures, that’s a bit of a bugbear of mine.
NIS2 then, if you’re kind of an essential or important operator in say energy, transport, banking, health, infrastructure, those kinds of sectors, in the UK this is expanding to MSSPs, you’re going to have similar kind of key obligations around risk management, including understanding your supply chain and your exposure to risk there. Again, incident reporting, early warning within 24 hours, 72 hours, detailed notification, final report within a month. And so, you can see like an integration point here where if you’re an operator within this too, you’ve probably got to verify your supply is compliant to the CRA.
So effectively, what we’re seeing is a cascading accountability. So, you can’t just take your vendors at their word, you know, you just get a warranty that says, “Oh yeah, we comply with all of this stuff “and it’s all fine.” You actually need ongoing visibility into their security posture as well as your own. And it makes sense as well to make sure that you have the contractual levers, but critically the relationships in which those levers might be pulled to ensure that you’ve got the right information available to you and to demonstrate that you have the right information if a regulator comes knocking, as well as the competence to interpret that information. So, this is about investing in relationships, contracts, people, so that you can ensure that you’re able to assure a regulator or a supplier that you have the visibility that you need into your organization, but also those on which you depend. It’s really, really quite broad.
Lindsay: Yeah, and I guess, bringing these two subjects together, you know, taking that spider’s web of supply chain now, can companies in your opinion rely on, you know, the government for all matters relating to threat intelligence, you know, is it sufficient to rely on the government and, you know, government punishments and that sort of thing to prevent threats in future?
Rich: No, so I think the short answer is no. Why threat intelligence with government on its own isn’t enough and I think that is by design, going back to my point earlier about kind of reducing perceived dependence on government to mitigate these risks. And I think effectively the regulations are structured to make sure that you are taking responsibility for your own security, your own company’s security, as well as that of your supply chain, and to make that make commercial sense. That’s the point about regulation to correct perceived market failure. From a big broad policy perspective, I think that reflects a broader global shift in thinking about commercial resilience as a component of national security, in which we all play a part, right?
So again, come back to JLR. People are asking now, what is the proper role of the state when an incident hits, right? Kind of like the conversation we were having a few years ago, about banks and fraud, right? Who should bear the cost of a hostile act? and what protective measures need to be in place to then fail and how severe do the impacts need to be before somebody other than the victim, typically in that dynamic, a consumer, intervenes or maybe even the state intervenes to kind of swaddle or mitigate the loss.
And my sense is that these regulations are kind of the beginning of a clarification of what the role of the state is in a cyber-attack, a cyber incident, like it’s more about the state setting standards and enforcing them, but giving advice about how to meet those standards without providing the kind of operational security service at scale for individual companies or people in the supply chain. That’s everyone’s responsibility, not just the state. It’s that whole of society approach again, right? And again, so states can help with things like quality assurance to a credit, cyber security solution providers. They can help with setting what cyber essential should be, but that sort of thing. But the day-to-day security, your backyard and your competitors, that’s on you, that’s the clear message. And you can kind of see that as and when a critical mass kind of adopt that mindset to the extent that that hasn’t already happened whether compelled through regulation or voluntarily, the idea is we should be more secure because there is this natural surveillance within the market around threats, but that doesn’t mean you can out source it, you need to be looking at our own and those on who your continuity depends.
Specifically on threat intelligence, I think government threat intelligence is clearly invaluable. The NCSC in the UK, CISA in the US, ENISA in the EU, it tends to provide the quite strategic contextual information about kind of nation-state level threats, because that’s naturally where the focus is, kind of big vulnerability disclosures, maybe some sector-specific guidance. But because it’s operating at that macro level, it’s not enough on its own, that’s why I say it is not enough, because you look at the what the CRA and NIS2 require you to be looking for; they are requiring you to monitor for threats that are really quite specific to your products and your supply chain and that means effectively if your components have got vulnerabilities, if your credentials are circulating on criminal forums, if your employees or contractors or suppliers are vulnerable or being targeted that kind of granular operational intelligence is on you to collect and understand and interpret and assess. Government just can’t provide that kind of granularity as a service to all industries all of the time. They don’t know your specific bit of material, your supplier relationships, your attack surface. And there’s always a bit of a lag, right between the filtering down of government intelligence to, to public advisories, right, by which time the pace at which the threat is evolving, especially with AI and so on, its attackers have probably moved on a little bit. I think that’s always part of the challenge with public advisories. And I think governments accept this, right.
We’re seeing regulatory guidance that explicitly encourages companies to use commercial threat intelligence, right? Look at the British lawyer, look at the NCSC, for example. The NCSC’s guidance on supply chain security recommends continuous monitoring using multiple intelligence sources and seeks to equip companies to kind of understand what the market is offering in the threat intelligence space and the continuous monitoring space in order to make an informed choice for their organization as between what could be quite expensive, in some cases, and quite technical, different products. So yeah, that I think is the role of government. It’s helping you to make choices, but it’s the making of those choices that you still need to do in order to get the information that you need. So, if you’re relying solely on government threat intelligence, you’re probably not going to satisfy the appropriate procedures standard in the regulations. You need to be demonstrating proactive continuous monitoring, tailored to your risk profile. Loads of vendors do that, some are better than others.
I think fundamentally these regulations are trying to align compliance incentives with actual security outcomes. The idea is that we move away from this box ticking compliance much more towards actually improving your resilience to cyber attack, which is kind of in your commercially interest anyway, right? But it’s also about making sure that you can demonstrate if you’re audited or if a supplier comes knocking that you are doing all the right things, as well as actually using the intelligence in the right way.
Anyway, I’m conscious I’ve been talking for quite a long time, and I’ve got a few questions for you, Lindsay, if I may, about your experience at DarkOwl. So, reflecting on your experience with your clients, people who use your products, what kind of common challenges are they facing? Why is supply chain security important to them?
Lindsay: There’s a few reasons. I think one is best explained by the way that cloud technology is creating what could be described as a logarithmic network effect, the sort of spider’s web that I described earlier, where the ease of integrations between technology, which is a brilliant thing, causes an enormous reliance on external parties and risks from the supply chain. I mean, as you mentioned earlier, and I think it’s worth repeating. We know that last month that the CEO of Sophos, an enormous European cybersecurity company, Joe Levy, he summed it up nicely by saying that third party risk management is now “Nth Party Risk Management” that deserves being repeated, given the endless string of supplies involved in the provision of a product or a service.
And it’s not just B2C end products. Most B2B products on the infrastructure level now can’t escape a world of interdependence and over reliance on suppliers. We all thought data centers were that sort of the end of the supply chain thread where risks are more controllable from a sort of compliance perspective, etc. But you just have to look at the recent events with underwater sea cables in the Red Sea to realize that no one is safe.
And I think another big issue is the diversity of regulations as they relate to supply risk. If your supply chain is getting longer, so too is the certainty that some of those supplies are based in a different jurisdiction to your companies, and they’re probably more focused on that jurisdiction too from a compliance perspective. So, one of the regulations that you mentioned, the UK Cybersecurity and Resilience Bill, you know, that extends the current network and information security systems regulations to cover more ground, like you mentioned, managed service providers. And that is an enormous chunk of the cybersecurity supply chain for almost any sized company. So, not only are you contending with different suppliers, more supplies, but also, different countries and approaches to regulations in which those supplies operate.
Rich: Yeah, so thinking about those security professionals’ jobs, how are they impacted day-to-day by these regulations?
Lindsay: Yeah, I think that’s probably why we talk about people specifically working in the roles within threat intelligence and allied professions. If you take a look at the micro level, there are so many things to talk about even just within that category.
There’s a lot of things to consider. There’s the onboarding of third parties and all the checks that that entails. For example, you have within the lifetime of a third-party contract, the ongoing maintenance and technical debt, there’s the offboarding, the decommissioning phase, often done so often with less sort of support from cross functional teams who just want to get rid of the contract they have with this supplier.
There’s the ever-evolving world of application security too. But then, what about the consultants, in a world of outsourced services and staffing? You know, the people who have been working on this technology or so, have they got key cards on them? Then there’s that added issue of maybe areas that are blended with corporate security responsibilities. You need to account for those and stepping back even further. This is all in a world in which an information security professional probably doesn’t actually own the supplier relationship or even project manage the deployment. So, looking at all of these variables on both the job level for people working in security through to this macro level of nation state threats as you mentioned quite rightly in the complex and independent supplier applications and networks. It’s no surprise that some of the prevailing guidance is about how to take matters into your own hands as you ended with, because we can’t readily rely on the government to sort it out for us.
Rich: Yeah, I mean, there’s the inflection point right between what we’ve been talking about. New technologies and sort of big data, there’s more data out there swimming around, there’s got to be an opportunity there, right, to better understand these threats?
Lindsay: Yeah. We should probably talk about something positive, I think in all of this, because no doubt we’re all affected by the speed with which data can be crawled and fused in the threat intelligence sector. And yes, the explosion in supply chains means that there’s more ways for threat actors to get lucky, you know, business email compromise, service desk social engineering and beyond, you know, there’s a broader attack surface, meaning there’s need for more threat intelligence. And I think thankfully, there’s now a renewed attention you’re starting to see on threat intelligence and open-source intelligence that encapsulates everything from APT group reconnaissance to Twitter feeds and ways that we confuse this normalized data to give warning signals to information security pros. Alert fatigue is a problem especially, you know the moment you introduce responsibilities to monitor the supply chain and the wider regulatory sort of consequences for doing so the answer will inevitably lie in looking over the horizon, looking over the IT network and strategically addressing the issue rather than tactically. And technology can certainly help us do that.
Rich: What a neat segue into DarkOwl. So how has DarkOwl helped to equip information security professionals and others to navigate that increasingly complex environment and think differently about how it and get ahead of those risks?
Lindsay: Yeah, when we were sort of thinking about this, we developed something called DarkSonar. So, DarkSonar is a risk score. So that when there’s been more activity surrounding a company’s domain and staff credentials on the darknet, essentially it would let you know when there has been more exposed than you’d normally expect. Breaking this apart a little bit, it gives a relative risk rating to an email domain that considers the nature, the extent and severity of credential leakage on the darknet to provide a company with a signal that acts as a measurement for a company’s exposure in advance of an attack. Because we know that one of the biggest threat vectors to this day is still compromised credentials for entry to a system. And we tested this metric against 237 cyber-attacks occurring between 2021 and 2022 and found our signal was elevated within the last four months as it says there, a prior to an attack for 74% of the attacks on organizations. And I suppose there’s three things going on here.
So, number one, it’s data-driven future warnings as opposed to alerts after the fact. Number two, it’s scalable to all domains and supplies included. In fact, Security Scorecard have endorsed this for us publicly for this reason. And then finally, it offers companies the ability to measure market benchmarks because their supplier may not know where their exposure lies in relation to other companies, especially in relation to government departments and local councils, for example, that sit side by side, but are actually not always sure as to what exposure level they should come to expect, especially if you can benchmark it against predicting breaches and ransomware attacks.
So, this is the way for you and your supplier to do just that. It’s one contribution we’re making to at scale help organizations look over the horizon at risks to their suppliers and by extension themselves.
Rich: That predictive model sounds really critical for businesses that are trying to get ahead of a threat, right? And/or if you want to criticize someone else in your supply chain who didn’t get ahead of it. I was just going to say, did you have some slides that kind of demonstrated that?
Lindsay: Yeah, so if we look at a couple of examples that we threw together of sort of brand names just to make the data pop a little bit, you can sort of just visually sort of evaluate the success of using this sort of metric to predict an oncoming attack, just looking at Fujifilm and Robin Hood and their ransomware and data breaches that they experienced, respectively.
So yeah, I mean, this is something that we’re working on, we’re always looking for people to try it, to test it out. We like to be very transparent and understand where people are in their journey. This industry only works, threat intelligence only works if, you know, information flows both ways and we can certainly benefit from that. So, I mean, talking of that, I mean, perhaps we can turn to some questions from the floor because we’ve both been talking enough now.
So, Kathy, I don’t know if any questions have come in, but we can maybe answer any in case.
Kathy: Yes, thanks, Lindsay. We have one question that came in. It is, your webinar is looking at future trends, but from existing commercial customers, is DarkOwl seeing any trends today and how to leverage the darknet?
Lindsay: Good question. It’s funny because I was reading the UK government’s chronic risk report that was brought out last month and inside it, it details the ways in which so many risks are converging. So, I mean, the report itself was consistently emphasizing the interdependence of cyber risks, geopolitical risk, economic risk, even ecological risks. And one of the long-term uncertainties they officially were outlining is that the internet is going to become fragmented into sort of splinter nets, which basically means that, you know, the internet will fragment, thanks to regional policies, which will sort of isolate digital interactions and data access, creating sort of digital islands. And when you add that sort of thought to, okay, at the same time in the UK, we’ve got a, you know, explosion of VPN adoption since the online safety act and the sort of the risk we’re re-anonymizing the internet. Really, what that all means is a big trend we’re hearing from customers and partners is that they’re finally treating the darknet as an online space, just like the rest of the internet, which is needed for brand protection, situational awareness, just as importantly as they’re using the surface net for those same purposes.
Kathy: Okay. Thank you, Lindsay. We have another question that has come in: We are a mid-sized manufacturer, December 2026 feels close for CRA reporting obligations. What should we be doing now?
Rich: Yeah, it is close. I tend to advise my clients to kind of phase their preparation over the next 12 to 18 months if they haven’t started already. Their objectives really need to be to getting and making sure they’ve got the right people on it, first of all, sort of the right consultants, lawyers, to help to ensure preparedness. And the first thing to do, I suggest, really is to map the supply chain, get visibility into what components you’re using, who your critical suppliers are, what your relationships look like, what contractual and commercial levers you’ve got to get information about their exposure to risk. Where you have a gap? How do you fill it? Do you need to buy threat intelligence? Do you need to buy access to data? That kind of thing, then you assess your vulnerability monitoring. Can you at the moment detect when your components have actively exploited vulnerabilities? Are you researching vulnerabilities entering software yourself. If not, I suggest certainly the former is quite a serious gap. Start looking at continuous monitoring solutions, get some quotes, start integrating. Then if you’re not already generating SBOMs, the builds and materials start building or procuring that capability, because that’s again foundational to compliance.
And then once all that’s in place, we need to look at incident notification planning. So, running tabletops, what does it look like in practice to meet that kind of 24-hour notification timeline as the case may be, who needs to be involved, who calls whom, at what point, who makes the decisions. And these could be quite big decisions, right? Like, do we pay a ransom? Like, whose job is it to decide and what’s recorded. Where is it recorded? Probably not on a compromised system, right? Whose job is it to record everything? And then test them, test the response procedures, document them, improve them, test them again. And it’s kind of acontinuous cycle.
What else? Reviewing supplier contracts, you probably need or will be asked to give kind of CRA specific warranties and indemnities, Make sure they’re fair and that there isn’t this kind of knee jerk, complete and utter transfer of risk onto you. Think as well about on the topic of risk transfer, think about insurance. Whilst I think I’ve said that the market is still maturing, if you’re not insuring, make sure the risk is at least surfaced and noted at the correct level. I think the companies that struggle in 2026, 2027 will be those who kind of see this as a bit of a last-minute compliance exercise trying to buy their way into like a performative compliance at the last second. Like not acting now I suggest is also a decision and you should think about where the accountability for that decision might lie and if you don’t know where that is, it’s probably you. The companies that are succeeding in in 2027 will be those who have embedded security monitoring, continuity planning, and so on into their operations. Now, easier said than done, right? It needs investment and time and money and people, but that’s the way of the world.
Kathy: Great. Thank you, Rich. Both Lindsay and Rich, that looks like that’s the last of our questions, and I just want to thank the both of you for an insightful discussion today.
And as a reminder to all of our attendees, we will be following up via email with a link to the recording and other resources. If you’d like to contact either Lindsay or Rich, their contact information is presented on this slide. And we thank you again, and we look forward to seeing you at another webinar in the future.
Ticura has partnered with DarkOwl, the industry’s leading provider of darknet data, to revolutionize how organizations monitor for data breaches and dark web threats. This partnership will deliver a streamlined, solution to empower security teams to gain instant visibility into leaked credentials, financial data, and underground chatter. By combining DarkOwl’s vast darknet intelligence database with Ticura’s activation and attribution framework, organizations will be able to monitor and achieve optimal protection to quickly respond to threats.
Monitoring the dark web and clear web to proactively identify leaked credentials, credit card information, and underground chatter is a critical part of cyber defense. For many organizations, and especially security service providers managing dozens or even hundreds of clients, this can be a labor-intensive and complex task. Traditional licensing/selling models often do not align with the needs or economics of smaller organizations.
To address this challenge, Ticura partnered with DarkOwl, to deliver an effortless way to operationalize breach and dark web monitoring. With DarkOwl’s unparalleled dark web intelligence repository—covering millions of darknet sites, forums, and marketplaces—combined with Ticura’s simplified activation and attribution framework, security teams can set up monitoring in minutes instead of weeks.
“Our partnership with Ticura represents a significant step forward in operationalizing darknet intelligence at scale,” said Mark Turnage, DarkOwl CEO. The DarkOwl platform continuously collects and indexes millions of darknet pages, forums, and marketplaces in near real-time. By integrating our data with Ticura’s AI-driven enrichment and attribution engine, we’re enabling security teams to not only detect leaked credentials and sensitive data faster, but also to understand the context—who’s behind it, where it’s spreading, and how it connects to broader threat actor activity. This level of automation and precision is critical for MSSPs and enterprises looking to stay ahead of emerging threats without adding operational overhead.
Our collaboration enables customers to:
Gain immediate visibility into leaked credentials, credit cards, and underground chatter.
Simplify breach and dark web monitoring with easy, automated setup.
Attribute findings with clear context and relevant threat actor connections.
Scale monitoring cost-effectively with transparent, pay-per-asset pricing.
By uniting high-fidelity dark web data with Ticura’s enrichment and explainability, organizations can close intelligence gaps, reduce complexity, and respond decisively to threats before they escalate.
About Ticura
Optimized Cyber Threat Intelligence
ticura is the first AI-powered Threat Intelligence Analytics Service that evaluates the value and efficiency of over 1,100 cyber threat intelligence sources, then optimizes and configures them individually according to customer needs with just a few clicks.
With one of the industry’s most comprehensive real-time threat intelligence repositories, ticura delivers curated threat intelligence, summarized into a single feed at the push of a button, thereby always providing the latest information from all available threat intelligence sources. All sources are continuously measured for quality, enhanced through hundreds of correlations and enrichments, and made actionable and frictionlessly integrated. Learn more at ticura.io.
About DarkOwl
DarkOwl is the industry’s leading provider of darknet data. We offer the world’s largest commercially available database of information collected from the darknet. Using machine learning and human analysts, we automatically, continuously, and anonymously collect and index darknet, deep web, and high-risk surface net data. Our platform collects and stores data in near real-time, allowing darknet sites that frequently change location and availability to be queried in a safe and secure manner without having to access the darknet itself. Customers are able to turn this data into a powerful tool to identify risk at scale and drive better decision making. For more information, contact us.
DarkOwl is a Denver-based company that provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data. We shorten the timeframe to detection of compromised data on the darknet, empowering organizations to swiftly detect security gaps and mitigate damage prior to misuse of their data.