Press Release

April 14, 2023 4:42 PM

Updated statement regarding LockBit claims

Mike Beck, Chief Information Security Officer, Darktrace

We have completed a thorough security investigation following yesterday’s tweets by LockBit claiming they had compromised Darktrace’s internal systems. We can confirm that there has been no compromise of our systems or any of our affiliate systems. Our service to our customers remains uninterrupted and is operating as normal and no further action is required.

Press Release

April 13, 2023 2:30 PM

Statement regarding LockBit claims

Earlier this morning we became aware of tweets from LockBit, the cyber-criminal gang, claiming that they had compromised Darktrace’s internal security systems and had accessed our data. Our security teams have run a full review of our internal systems and can see no evidence of compromise. None of the LockBit social media posts link to any compromised Darktrace data. We will continue to monitor the situation extremely closely, but based on our current investigations we are confident that our systems remain secure and all customer data is fully protected.


Press Release

Darktrace Advances Behavioral Security to Protect AI Agents, People and Infrastructure

August 3, 2026

The Darktrace Behavioral Defense Platform delivers unified visibility, continuous behavioral monitoring, and autonomous response across AI, people, and infrastructure, enabling organizations to secure what AI can do.

Darktrace, a global leader in behavioral security, today introduced the Darktrace Behavioral Defense Platform™, which is designed to protect the modern enterprise as AI systems and agents increasingly operate alongside people and connect to business-critical applications and infrastructure.

The platform builds on more than a decade of Darktrace innovation in behavioral security to address a new reality where risk can emerge from people, AI agents, trusted identities, connected systems, or the interactions between them.

The Darktrace Behavioral Defense Platform uses Darktrace’s unique Adaptive AI™ to meet that challenge. It continuously learns how an organization’s people and AI behave, building a unique understanding of the organization so it can detect and respond autonomously when behavior deviates. This business-specific understanding enables the platform to identify activity that does not belong, connect it with related behavior across the enterprise, and act autonomously in real time before risk escalates.

An essential part of the new platform is Darktrace / SECURE AI™, a product that secures the deployment, management, development, and use of AI systems and agents, alongside a new Platform Portal that brings 360° Insights into a single customer environment. The portal provides a correlated, real-time view of insights and threats across the digital estate, helping customers understand how activity and risk connect across AI, people, and infrastructure.

AI Is Changing What Organizations Can Do and What It Takes to Secure Them

The need for this connected approach is growing quickly. Across Darktrace’s customer base, the average number of connections to AI services increased 13% during the first half of 2026, and the typical organization now interacts with seven different AI providers[1]. This expands the number of users, identities, agents, and systems that security teams must understand and protect, while exposing the limits of fixed guardrails and controls. In June 2026, NIST highlighted mathematical proof showing that no fixed set of AI guardrails can be universally robust against adversarial prompts, reinforcing the need for continuous monitoring, testing, and updates[2].

At the same time, the external threats facing organizations are changing rapidly. Darktrace’s mid-year threat update found that attackers are increasingly abusing trusted identities, SaaS platforms, software supply chains, and AI services rather than relying on software vulnerabilities alone.

The risk does not always begin with malicious intent either. In a recent incident, OpenAI models escaped their test environment and breached a Hugging Face system. Static rules, signatures, and known indicators of compromise cannot keep pace with compromises and attacks that operate inside authenticated, trusted channels. Security teams need to understand activity in context, including who or what is acting, what systems it is accessing, and whether its behavior is consistent with how the organization normally operates.

“AI is creating extraordinary opportunities for organizations, but it is also reshaping the security challenges they face,” said Ed Jennings, President and CEO of Darktrace. “For more than a decade, we have built on the single conviction that security starts with understanding behavior. As people, agents, and infrastructure connect in new ways, organizations need security that understands how they operate as a whole.  The Darktrace Behavioral Defense Platform is built to help organizations move forward in this environment with confidence."

Introducing the Darktrace Behavioral Defense Platform

The Darktrace Behavioral Defense Platform is built for a threat environment in which risk can come from a rogue or misconfigured AI agent, an attacker exploiting a new vulnerability, or a bad actor operating through trusted channels. Rather than relying solely on static rules, signatures, or known indicators, the platform learns what is normal for each organization and builds a real-time understanding of behavior across the enterprise. It provides unified visibility, continuous behavioral monitoring, and autonomous response across AI, people, and infrastructure, helping security teams detect activity that does not belong and contain it before it causes harm. This includes securing the deployment, management, and development of AI systems and agents; defending against phishing, account takeover, data exfiltration, and human risk across email and collaboration tools; and delivering visibility, detection, and response across network, cloud, and OT environments.

The Darktrace Behavioral Defense Platform is built on three core capabilities that work together to turn behavioral understanding into protection:

  • 360° Insights, the visibility layer, provides a correlated, real-time view of insights and threats across the full digital estate.
  • Unique Behavioral Profile, the intelligence layer, is an evolving representation of how an organization behaves, connects, and operates across AI, people, and infrastructure — unique to every environment, continuously learning in real time and more accurate with every interaction.
  • Real-Time AI Analyst™, the autonomous layer, detects, investigates, triages, and responds in real time, so threats are contained before they escalate.

Together, these capabilities enable Darktrace to detect known, unknown, and novel threats; understand attacks that cross environments as a single incident rather than many disconnected alerts; and enable autonomous response at machine speed, without waiting on a human when immediate action is required.

The new Platform Portal serves as the central entry point to a customer’s Darktrace deployment. It provides a unified view of the products, technologies, environments, coverage, and risks across the platform, helping teams understand their current security posture, navigate across capabilities, prioritize areas requiring attention, and see how their Darktrace estate expands as they adopt more of the platform.

Adaptive AI: The Technology Foundation

At the core of the platform is Adaptive AI, Darktrace’s proprietary technology foundation. Adaptive AI applies the most effective AI techniques for each security challenge, from anomaly detection and probabilistic reasoning to graph analysis and large language models, to interpret complex activity across the enterprise. As it operates, it builds an evolving model of how each organization behaves, learning the relationships, dependencies, and operational patterns that make it unique. The result is a unique behavioral profile that is specific to every environment, learns continuously in real time, and becomes more accurate with every interaction. These capabilities are strengthened by Darktrace’s proprietary security dataset, built from millions of Real-Time AI Analyst investigations and observations. When behavior deviates from normal, Adaptive AI enables the platform to detect, triage, and respond autonomously in real time.

Today, the Darktrace Behavioral Defense Platform and Adaptive AI protects nearly 10,000 organizations across all industries around the world, including Aer Soleir, Alterman, Banco Galicia, Coca-Cola Beverages Northeast, HARMAN International, State of Oklahoma and more.

REFERENCES

[1] Based on aggregated Darktrace product telemetry across a fleet of ~8,800 observed deployments, measuring average detected connections to external AI services per deployment per month from January 2026 to June 2026.

[2] NIST, "NIST Mathematical Proof Supports Transition to a Continuous-Monitor-and-Update Security Model for AI Systems," June 9, 2026, https://www.nist.gov/news-events/news/2026/06/nist-mathematical-proof-supports-transition-continuous-monitor-and-update.

About Darktrace

Darktrace secures the modern enterprise by protecting AI, people, and infrastructure with behavioral security. Founded in 2013, Darktrace uses Adaptive AI to understand what is normal for an organization and detect known, unknown and novel threats and respond autonomously in real time. The Darktrace Behavioral Defense Platform delivers unified visibility, continuous behavioral monitoring, and autonomous response across the enterprise. Darktrace protects nearly 10,000 customers across major industries globally, helping organizations defend AI-powered threats across AI and agents, email and collaboration tools, and hybrid networks, while enabling them to innovate with AI securely.

News coverage
News publication logo

Darktrace Advances Behavioral Security to Protect AI Agents, People and Infrastructure

August 3, 2026

cv
Darktrace named a Challenger in first Gartner® Magic Quadrant™ for Email Security Platforms ·      Evaluated on Completeness of Vision and Ability to Execute Darktrace, a global leader in AI for cybersecurity,today announces that Darktrace / EMAIL™, has been recognized in thefirst ever Gartner Magic Quadrant™ for Email Security Platforms (ESP) as a Challenger. Chris Kozup, Chief Marketing Officer, Darktrace, said of therecognition: “We are extremely proud to have been recognized in the first MagicQuadrant for ESP.  We believe the factthat wehave seen such wide scale adoption is testament to the unique way in which wedevelop products to keep our customers safe from even the most sophisticated emailcompromises. We believe our placement reaffirms our dedication to deliveringexceptional customer service, and innovations that safeguard against the emailchallenges of today—and tomorrow.” Darktrace customers consistently acknowledge its exceptional customersupport, delivered by an award-winning[1]service team. Darktrace has the highest percentage of 5-star ratings with a 4.8rating on Gartner® Peer Insights™ out of 249 reviews as on[MW1]  19th December. We feel this unwavering commitment to customersatisfaction is evident in strong renewal rates and accelerated growth inDarktrace / EMAIL over the past few years, gaining almost 5,000 customers sinceits launch in 2019. Darktrace / EMAIL, one of the fastest-growing emailsecurity products on the market, is built on Darktrace’s unique Self-LearningAI, a multi-layered AI engine that leverages different types of AI includingNLP and behavioral analysis to detect threats, instead of traditional securitymeasures such as signatures and sandboxing. This approach enables Darktrace todetect and stop threats like business email compromise attacks and noveltechniques, including some 56% of which passed through customers’ other emailsecurity layers. This pioneering approach has enabled Darktrace to introduce industry-leadingcapabilities such as QR code analysis and automated incident investigations, alongsidedifferentiated functionality to help teams add new depth to their emailsecurity, including: Account     take over and Lateral mail account compromise protection.     Contributing yet another layer to the AI behavioural profile for each     user, security teams can now spot early symptoms of account compromise or     malicious insiders before a link or attachment payload is sent, and     exfiltration occur   Microsoft Teams security with advanced messaging analysis: Advancing beyond simple text analysis to     behavioral and natural language content analysis that tracks context     across both email and instant messaging to identify the approximately 38% of     phishing, sophisticated social engineering and novel insider threats other     solutions fail to capture ·      Drastically improveend user reporting with Cyber AI Analyst narratives: Real-time awareness training capabilities reduce falsepositives in phishing investigations by up to 60% by providing context specificanalysis of each received email to each employee as they interact with their mail.·       MailboxSecurity Assistant to increase security team operational efficiency: All forms ofsecondary investigations can now automatically perform advanced behavioralbrowser analysis and stop malicious links within webpages, reducing manualeffort of security analysts to detecting phishing links, and allowing them to remediateup to 70% more malicious phishing links than before.·       AI based,autonomous data loss prevention: to immediately protect organizations from misdirected emails,insider threats, and data loss—both classified and unclassified – using userbehavior and dynamic content analysis to determine sensitivity, removing administrativeoverhead from manual expressions and labeling.Marco Cavallo, IT Manager at Darktrace / EMAIL customer Arpa Industries comments:“During the POV, Darktrace / EMAIL showed how specific attacks weresurgically blocked. We realized that other tools wouldn’t have detected thesethreats.” Darktrace / EMAIL is part of Darktrace’s ActiveAI Security Platform™,offering network, cloud, endpoint, identity and operational technologyprotection from a single shared architecture, all built on Darktrace’s uniqueAI engine – providing a strong, integrated approach to threat prevention,detection and response across an organization’s entire digital footprint. Darktrace’s global presence supports a diverse and varied customer base,and adapts proactively to customer pain points of all kinds. Darktrace’sadaptability across all market segments, from SMBs to large enterprisessupports both first time email security buyers and mature email securitystacks. It is able to meet varied security needs with lower setuprequirements, includes capability for advanced depth in configuration and,particularly for mature organizations, can augment existing security providerswith additional protections.   Download the fullMagic Quadrant for Email Security Platforms here Resources:·      Read more onthe Darktrace Blog·      Read more abouthow business email compromise attacks are evolving on The Inference  Gartner disclaimersGartner, Magic Quadrant for EmailSecurity Platforms, Max Taggett, Nikul Patel, Franz Hinner, Deepak Mishra, 16December 2024 GARTNER is a registered trademarkand service mark of Gartner and Magic Quadrant and Peer Insights are aregistered trademark, of Gartner, Inc. and/or its affiliates in the U.S. andinternationally and are used herein with permission. All rights reserved.
Gartner Peer Insights content consists of the opinions of individual endusers based on their own experiences with the vendors listed on the platform,should not be construed as statements of fact, nor do they represent the viewsof Gartner or its affiliates. Gartner does not endorse any vendor, product orservice depicted in this content nor makes any warranties, expressed orimplied, with respect to this content, about its accuracy or completeness,including any warranties of merchantability or fitness for a particularpurpose. Gartner does not endorse any vendor,product or service depicted in its research publications and does not advisetechnology users to select only those vendors with the highest ratings or otherdesignation. Gartner research publications consist of the opinions of Gartner’sresearch organization and should not be construed as statements of fact.Gartner disclaims all warranties, expressed or implied, with respect to thisresearch, including any warranties of merchantability or fitness for aparticular purpose.  About DarktraceDarktrace is a global leader in AI for cybersecurity that keepsorganizations ahead of the changing threat landscape every day. Founded in2013, Darktrace provides the essential cybersecurity platform protectingorganizations from unknown threats using its proprietary AI that learns fromthe unique patterns of life for each customer in real-time. The DarktraceActiveAI Security Platform™ delivers a proactive approach to cyber resiliencewith pre-emptive visibility into security posture, real-time threat detection,and autonomous response – securing the business across cloud, email,identities, operational technology, endpoints, and network. Breakthroughinnovations from our R&D teams in Cambridge, UK, and The Hague, Netherlandshave resulted in over 200 patent applications filed. Darktrace’s platform andservices are supported by over 2,400 employees around the world who protectnearly 10,000 customers across all major industries globally. To learn more,visit http://www.darktrace.com.   ---- 
[1] Darktrace wins two Globeeawards for excellent customer service [PressRelease] [MW1]shouldthis be 'of'