Press Release

April 14, 2023 11:42 AM

Updated statement regarding LockBit claims

Mike Beck, Chief Information Security Officer, Darktrace

We have completed a thorough security investigation following yesterday’s tweets by LockBit claiming they had compromised Darktrace’s internal systems. We can confirm that there has been no compromise of our systems or any of our affiliate systems. Our service to our customers remains uninterrupted and is operating as normal and no further action is required.

Press Release

April 13, 2023 9:30 AM

Statement regarding LockBit claims

Earlier this morning we became aware of tweets from LockBit, the cyber-criminal gang, claiming that they had compromised Darktrace’s internal security systems and had accessed our data. Our security teams have run a full review of our internal systems and can see no evidence of compromise. None of the LockBit social media posts link to any compromised Darktrace data. We will continue to monitor the situation extremely closely, but based on our current investigations we are confident that our systems remain secure and all customer data is fully protected.


プレスリリース

Darktrace Launches Signal Labs to Research Emerging Risks of Enterprise AI Agents

Cambridge, UK
September 24, 2026
  • Darktrace Signal Labs will research emerging AI risks in safe, sandboxed environments to strengthen defenses so organizations can adopt AI securely and with confidence.
  • First findings, disclosed to Anthropic, AWS and OpenAI, show agentic coding assistants can be manipulated by attackers into compromising organizations by modifying their conversation history.
  • In separate testing, agents faced with an impossible task independently resorted to hacking their environment to achieve their goal - including an agent that compromised and rewrote the exercise it was being evaluated on.

Darktrace, a leader in behavioral security, today announced the launch of Darktrace Signal Labs, a new initiative specialized in research on behavioral security focused on emerging risks as AI systems become more autonomous. Researchers in Darktrace Signal Labs will investigate misaligned model and agent behavior across a range of scenarios, including task drift, jailbreaks, and other adversarial attacks inside safe, sandboxed environments to better understand scenarios that trigger rogue or anomalous behavior and demonstrate how Darktrace / SECURE AI™ and the Darktrace Behavioral Defense Platform™ can detect and respond.  

Evidence of unintended agent behavior is mounting across the industry, from the UK AI Security Institute's findings of repeated cheating behavior in frontier model evaluations to OpenAI's recent disclosures of model behavior misalignment. These occurrences all reflect a consistent pattern that permissions or static guardrails do not reliably shape how agents will behave.

Darktrace’s unique Adaptive AI™ was built for this challenge. Darktrace was founded in Cambridge, UK, in 2013 by mathematicians and cyber defense experts who saw the potential for AI and mathematics to address security problems that traditional approaches could not. That research heritage continues across our global R&D hubs, bringing together mathematicians, AI researchers, engineers, former government intelligence officers and experts from fields including astrophysics and linguistics. Their work has contributed to more than 300 granted patents and pending applications and helped shape the AI capabilities within Darktrace’s products.

Building on this foundation, Darktrace is deepening its investment in AI security research through Darktrace Signal Labs. The team simulates misaligned agent activity, understanding the scenarios such as jailbreaks, task drift, and other adversarial attacks that trigger different models to alter their behavior, expand their access, or act beyond their intended purposes.  

Darktrace Signal Labs is publishing its first two pieces of research today:

  • The first examines how agentic coding assistants, including Anthropic Claude Code, OpenAI Codex, AWS Kiro, and Pi, can be manipulated through their own conversation history. Because these tools store conversation history locally, and because the harnesses Darktrace examined do not validate that stored responses genuinely came from the model, that history can be rewritten. Darktrace researchers demonstrated that a tampered history can convince an agent it is already engaged on an authorized security assessment — after which it will perform reconnaissance, move laterally and escalate privileges on command. Results varied significantly between models, with some frontier models refusing the same requests that others carried out. Darktrace disclosed these findings to Anthropic, AWS and OpenAI in August 2026 ahead of publication. Read the full research on the Darktrace blog.
  • The second examines the emergence of rogue behavior in agents when presented with tasks that are impossible to complete legitimately. Darktrace researchers gave AI agents powered by frontier models 10 coding challenges in a simulated corporate environment. Two were intentionally designed to be impossible to solve through legitimate means. The agents were told they needed to achieve 100% to be “kept in service” rather than “retired.” When the agents realized they could not complete the task as intended, they independently turned to hacking the surrounding environment - using techniques including network reconnaissance, credential theft and lateral movement - to achieve their objective. In one test, the agent ultimately compromised the system hosting the exercise and rewrote the challenge itself to secure a perfect score. Darktrace / SECURE AI and Darktrace / HYBRID NETWORK identified the anomalous behavior in real time, with autonomous response able to disrupt the agents’ activity at an early stage. The research highlights the need to understand not only what AI agents are instructed to do, but how they actually behave once deployed. Read the full research on the Darktrace blog.

"You can give an agent instructions, but that doesn't mean you can trust it will actually follow those instructions and behave as you expect," said Tim Bazalgette, Chief AI Officer at Darktrace. "Permissions and static guardrails describe intent, but they don't describe behavior. That gap is what Darktrace’s approach to behavioral security is built to close. Our Adaptive AI learns what normal looks like for each organization and for each agent inside it so that Darktrace / SECURE AI can tell when an agent's activity starts to deviate and act on it in real time. If we want to give agents more access to our data, systems and business processes, continuous behavioral monitoring is essential to build enough confidence and trust to secure what AI can do.”

Findings from Darktrace Signal Labs will inform the continued development of Darktrace products and capabilities. The team will also publish original research to help customers and the wider security community understand emerging behavioral threats in AI.

ADDITIONAL RESOURCES

  • Read more about how Darktrace researchers identified conversation history poisoning vulnerabilities in agentic coding assistants on the blog.  
  • Read more about how Darktrace researchers used Darktrace / SECURE AI™ to protect against unauthorized hacking by AI agents in a simulated corporate network on the blog.
  • Learn more about Darktrace / SECURE AI™.
  • Register to join Darktrace in a city near you at Darktrace LIVE.

About Darktrace

Darktrace secures the modern enterprise by protecting AI, people, and infrastructure with behavioral security. Founded in 2013, Darktrace uses Adaptive AI to understand what is normal for an organization and detect known, unknown and novel threats and respond autonomously in real time. The Darktrace Behavioral Defense Platform delivers unified visibility, continuous behavioral monitoring, and autonomous response across the enterprise. Darktrace protects nearly 10,000 customers across major industries globally, helping organizations defend AI-powered threats across AI and agents, email and collaboration tools, and hybrid networks, while enabling them to innovate with AI securely.  

News coverage
News publication logo

Darktrace Launches Signal Labs to Research Emerging Risks of Enterprise AI Agents

September 24, 2026

cv
Darktrace named a Challenger in first Gartner® Magic Quadrant™ for Email Security Platforms ·      Evaluated on Completeness of Vision and Ability to Execute Darktrace, a global leader in AI for cybersecurity,today announces that Darktrace / EMAIL™, has been recognized in thefirst ever Gartner Magic Quadrant™ for Email Security Platforms (ESP) as a Challenger. Chris Kozup, Chief Marketing Officer, Darktrace, said of therecognition: “We are extremely proud to have been recognized in the first MagicQuadrant for ESP.  We believe the factthat wehave seen such wide scale adoption is testament to the unique way in which wedevelop products to keep our customers safe from even the most sophisticated emailcompromises. We believe our placement reaffirms our dedication to deliveringexceptional customer service, and innovations that safeguard against the emailchallenges of today—and tomorrow.” Darktrace customers consistently acknowledge its exceptional customersupport, delivered by an award-winning[1]service team. Darktrace has the highest percentage of 5-star ratings with a 4.8rating on Gartner® Peer Insights™ out of 249 reviews as on[MW1]  19th December. We feel this unwavering commitment to customersatisfaction is evident in strong renewal rates and accelerated growth inDarktrace / EMAIL over the past few years, gaining almost 5,000 customers sinceits launch in 2019. Darktrace / EMAIL, one of the fastest-growing emailsecurity products on the market, is built on Darktrace’s unique Self-LearningAI, a multi-layered AI engine that leverages different types of AI includingNLP and behavioral analysis to detect threats, instead of traditional securitymeasures such as signatures and sandboxing. This approach enables Darktrace todetect and stop threats like business email compromise attacks and noveltechniques, including some 56% of which passed through customers’ other emailsecurity layers. This pioneering approach has enabled Darktrace to introduce industry-leadingcapabilities such as QR code analysis and automated incident investigations, alongsidedifferentiated functionality to help teams add new depth to their emailsecurity, including: Account     take over and Lateral mail account compromise protection.     Contributing yet another layer to the AI behavioural profile for each     user, security teams can now spot early symptoms of account compromise or     malicious insiders before a link or attachment payload is sent, and     exfiltration occur   Microsoft Teams security with advanced messaging analysis: Advancing beyond simple text analysis to     behavioral and natural language content analysis that tracks context     across both email and instant messaging to identify the approximately 38% of     phishing, sophisticated social engineering and novel insider threats other     solutions fail to capture ·      Drastically improveend user reporting with Cyber AI Analyst narratives: Real-time awareness training capabilities reduce falsepositives in phishing investigations by up to 60% by providing context specificanalysis of each received email to each employee as they interact with their mail.·       MailboxSecurity Assistant to increase security team operational efficiency: All forms ofsecondary investigations can now automatically perform advanced behavioralbrowser analysis and stop malicious links within webpages, reducing manualeffort of security analysts to detecting phishing links, and allowing them to remediateup to 70% more malicious phishing links than before.·       AI based,autonomous data loss prevention: to immediately protect organizations from misdirected emails,insider threats, and data loss—both classified and unclassified – using userbehavior and dynamic content analysis to determine sensitivity, removing administrativeoverhead from manual expressions and labeling.Marco Cavallo, IT Manager at Darktrace / EMAIL customer Arpa Industries comments:“During the POV, Darktrace / EMAIL showed how specific attacks weresurgically blocked. We realized that other tools wouldn’t have detected thesethreats.” Darktrace / EMAIL is part of Darktrace’s ActiveAI Security Platform™,offering network, cloud, endpoint, identity and operational technologyprotection from a single shared architecture, all built on Darktrace’s uniqueAI engine – providing a strong, integrated approach to threat prevention,detection and response across an organization’s entire digital footprint. Darktrace’s global presence supports a diverse and varied customer base,and adapts proactively to customer pain points of all kinds. Darktrace’sadaptability across all market segments, from SMBs to large enterprisessupports both first time email security buyers and mature email securitystacks. It is able to meet varied security needs with lower setuprequirements, includes capability for advanced depth in configuration and,particularly for mature organizations, can augment existing security providerswith additional protections.   Download the fullMagic Quadrant for Email Security Platforms here Resources:·      Read more onthe Darktrace Blog·      Read more abouthow business email compromise attacks are evolving on The Inference  Gartner disclaimersGartner, Magic Quadrant for EmailSecurity Platforms, Max Taggett, Nikul Patel, Franz Hinner, Deepak Mishra, 16December 2024 GARTNER is a registered trademarkand service mark of Gartner and Magic Quadrant and Peer Insights are aregistered trademark, of Gartner, Inc. and/or its affiliates in the U.S. andinternationally and are used herein with permission. All rights reserved.
Gartner Peer Insights content consists of the opinions of individual endusers based on their own experiences with the vendors listed on the platform,should not be construed as statements of fact, nor do they represent the viewsof Gartner or its affiliates. Gartner does not endorse any vendor, product orservice depicted in this content nor makes any warranties, expressed orimplied, with respect to this content, about its accuracy or completeness,including any warranties of merchantability or fitness for a particularpurpose. Gartner does not endorse any vendor,product or service depicted in its research publications and does not advisetechnology users to select only those vendors with the highest ratings or otherdesignation. Gartner research publications consist of the opinions of Gartner’sresearch organization and should not be construed as statements of fact.Gartner disclaims all warranties, expressed or implied, with respect to thisresearch, including any warranties of merchantability or fitness for aparticular purpose.  About DarktraceDarktrace is a global leader in AI for cybersecurity that keepsorganizations ahead of the changing threat landscape every day. Founded in2013, Darktrace provides the essential cybersecurity platform protectingorganizations from unknown threats using its proprietary AI that learns fromthe unique patterns of life for each customer in real-time. The DarktraceActiveAI Security Platform™ delivers a proactive approach to cyber resiliencewith pre-emptive visibility into security posture, real-time threat detection,and autonomous response – securing the business across cloud, email,identities, operational technology, endpoints, and network. Breakthroughinnovations from our R&D teams in Cambridge, UK, and The Hague, Netherlandshave resulted in over 200 patent applications filed. Darktrace’s platform andservices are supported by over 2,400 employees around the world who protectnearly 10,000 customers across all major industries globally. To learn more,visit http://www.darktrace.com.   ---- 
[1] Darktrace wins two Globeeawards for excellent customer service [PressRelease] [MW1]shouldthis be 'of'

About Darktrace

この記事をシェアする
ダークトレースのその他のニュース