Press Release

April 14, 2023 11:42 AM

Updated statement regarding LockBit claims

Mike Beck, Chief Information Security Officer, Darktrace

We have completed a thorough security investigation following yesterday’s tweets by LockBit claiming they had compromised Darktrace’s internal systems. We can confirm that there has been no compromise of our systems or any of our affiliate systems. Our service to our customers remains uninterrupted and is operating as normal and no further action is required.

Press Release

April 13, 2023 9:30 AM

Statement regarding LockBit claims

Earlier this morning we became aware of tweets from LockBit, the cyber-criminal gang, claiming that they had compromised Darktrace’s internal security systems and had accessed our data. Our security teams have run a full review of our internal systems and can see no evidence of compromise. None of the LockBit social media posts link to any compromised Darktrace data. We will continue to monitor the situation extremely closely, but based on our current investigations we are confident that our systems remain secure and all customer data is fully protected.


Press Release

Darktrace Brings Industry First Endpoint Visibility And Enhanced Agentic AI To ActiveAI Security Platform™, Closing The Gaps In Cyber Defenses

Cambridge, UK
October 23, 2025
  • Darktrace introduces NEXT™, the first mixed network traffic and endpoint process telemetry agent to use Self-Learning AI, bringing native visibility of endpoint processes to network detection & response (NDR).
  • Unrivalled native visibility of endpoint processes enables analysts to trace incidents to their root cause in seconds, without pivoting between NDR, EDR and XDR tools.
  • Industry first use of Self-Learning AI on network telemetry and process data enables Darktrace / ENDPOINT™ to work alongside EDR to detect and prioritize early threats EDRs alone miss, like legitimate app misuse and living off the land techniques.
  • Cyber AI Analyst™ becomes the first automated security operations platform to use agentic AI to connect insights and detect novel threats natively across endpoint processes, network, cloud, SaaS, identity, and email in detection, investigation and response
  • Upgrades to Darktrace / OT™ expand visibility to new protocols and highlight operational anomalies, while closing critical vulnerability gaps. Darktrace / Attack Surface Management™ extends innovation in attack-path modeling, exploit prediction, leaked-credential monitoring, and business-aware patching.

Darktrace, a global leader in AI for cybersecurity, today announced a wave of innovations across its ActiveAI Security PlatformTM to protect organizations from increasingly complex, multi-vector and novel attacks. The innovations extend novel threat detection and autonomous investigations across email, network, OT, cloud and SaaS, and deliver deeper endpoint visibility than ever before. Together, these innovations provide a new level of understanding across an organization’s digital footprint, enabling security teams to close the seams attackers exploit as they cross IT domain boundaries, stop emerging threats and act with the speed, context, and confidence needed to stay ahead of attackers.

Most organizations still rely on fragmented security tools that each see only part of the picture. Endpoint products often miss what’s happening on the network, while network tools lack context about processes running on devices. Analysts are left pivoting between dashboards, stitching together evidence, and wasting time chasing down root causes. Meanwhile, novel threats now outpace known ones[1], and attackers are increasingly exploiting the seams between disconnected email, network, endpoint, cloud, distributed identity, and OT environments.

Darktrace is closing these seams with the introduction of the industry’s first Network Endpoint eXtended Telemetry (NEXT) agent which natively combines full network packet data with endpoint process data using Self-Learning AI. By unifying insights from network to endpoint, Darktrace is the first Network Detection and Response leader to natively provide security teams with the ability to trace network threats directly to their endpoint root cause. For analysts, this means investigations that once took hours and multiple pivots between NDR, EDR and XDR tools can now be resolved in seconds. Instead of seeing only an unusual network connection, Darktrace immediately shows which process on which device initiated the connection and unearths threats that would otherwise be missed such as the misuse of legitimate software, living off the land techniques or unapproved software usage.

With this new level of visibility, Cyber AI Analyst™, Darktrace’s sophisticated agentic AI system, becomes the first of its kind to have full native context across endpoint processes, network, cloud, SaaS, identity, and email — giving it a complete view of incidents as they unfold. This unified understanding allows it to spot and stop unknown and undetected threats that move between these domains — all without relying on external integrations, central data lakes, or manual correlation. By cutting out harmless noise, improving detection accuracy, and providing clearer incident summaries, Cyber AI Analyst augments human teams and helps them focus on what truly needs attention.

By extending Self-Learning AI across all of these environments, Darktrace amplifies its ability to deliver AI-native, real-time threat detection, investigation, and response for activity that moves across domains, strengthening defenders’ ability to stay ahead of emerging attacks.

Pip Robbins, IT Manager at M&S Logistics, a global leader in bulk liquid logistics, and an early adopter of Darktrace’s new endpoint capabilities, commented

“The complete network to endpoint process understanding provided by the NEXT agent, combined with Cyber AI Analyst’s investigative capabilities, have had a huge impact on our ability to investigate potential incidents. Our investigations now happen faster, we’re not jumping between tools, and we have more context than we’ve ever had before.”

Darktrace / NETWORK has also introduced enhancements to support autonomous response in highly complex and segmented networks, plus increased response efficacy with additional firewall integrations. This enables security teams to respond to network threats faster and more effectively with a solution proven to contain zero-day threats up to 8 days before public disclosure.

Real-Time Understanding In Operational Environments

For organizations running operational technologies, the dangers of bad actors targeting their networks at the seams are even greater as OT and IT environments continue to converge, and teams look to bridge the gap. As operational technology becomes increasingly interconnected with traditional IT infrastructure, defenders face new challenges in maintaining visibility, modeling risk, and responding to threats across converged ecosystems. Many alternative OT security tools narrowly focus on asset discovery or rule-based detection, leaving critical gaps in understanding how attackers can move between IT and OT, exploit exposed vulnerabilities, or disrupt operations through misconfigured segmentation. These blind spots matter not just to security teams but to OT engineers responsible for keeping systems running. Both groups need shared context to collaborate effectively — securing the environment while maintaining uptime.

New updates to Darktrace / OT, Darktrace’s purpose-built platform for securing operational technologies, provide a step forward in defenders’ ability to address these challenges with operationally relevant insights, real-time attack path modeling, and unified governance across their entire ecosystem:

  • Dashboards tailored for OT engineers enable them to track operational anomalies without navigating ill-fitting systems and workflows designed around IT systems, boosting their productivity and device adoption.
  • Expanded firewall rule analysis for Fortinet FortiGate, provides a clear view of how attackers could reach critical devices, identifies new segmentation opportunities, and helps teams focus patching on genuinely exposed assets rather than those already protected by existing controls.
  • Configuration Management integration with ServiceNow, automatically syncs asset intelligence to improve governance and reduce manual maintenance.
  • Expanded protocol support for GE-SRTP and MELSOFT, increases visibility across GE and Mitsubishi environments without requiring manual rules or configuration.

New Tools Help Security Teams Focus on The Most Critical Internal and External Risks

Traditional vulnerability and attack surface management tools often operate in silos, producing long lists of issues without context or prioritization. Security teams are left trying to determine which vulnerabilities pose real risk, which are exploitable, and which should be patched first — wasting valuable time and effort.

Darktrace’s latest updates integrate external attack surface and internal exposure management to give defenders a complete, continuous view of their risk, based on the unique context of their environment. By validating exposures against live network data, mapping vulnerabilities to specific devices, and understanding how attackers could exploit them, Darktrace helps security teams focus on what’s truly critical and take pre-emptive action before attackers can act. Darktrace is making continuous threat exposure management (CTEM) workflows easier for security teams, no matter where threats lie.

  • Darktrace / Attack Surface Management now conducts surgical and scheduled penetration assessments of exposed systems for the most common CVEs, helping defenders see which weaknesses are likely to be exploited in practice, continually test against them, and fill a gap between annual penetration tests. It also includes continuous monitoring of leaked credentials, the number 2 initial attack vector, across millions of sites, forums, and marketplaces on the deep and dark web. This continuous monitoring greatly expands the visibility and reach teams have of their attack surface, giving defenders time to mitigate and change credentials before they can be taken advantage of.
  • Darktrace / Proactive Exposure Management now identifies and prioritizes vulnerabilities without relying on third-party vulnerability management scanners. It uses internal context — such as network layout, existing controls, and real-world accessibility — to show which issues matter most and includes cost-benefit analysis to help teams weigh the effort of patching against the potential business impact of leaving a vulnerability unaddressed.

Managing Security at Scale

The newly introduced ActiveAI Security Portal™, designed for large enterprises, partners and MSSPs, unifies control, configuration, and visibility across all Darktrace deployments. It provides one login across products and deployments, centralized and granular permissions management, and unified API setup, bringing all the intelligence Darktrace provides, from identity, to network, to cloud, and email, into one place making it easier to scale and manage in the most complex environments.

As security teams work to protect their organizations from increasingly complex, multi-vector attacks, Darktrace’s latest innovations help put them on the front foot — uniting visibility across their digital footprint, closing the seams attackers exploit, and giving defenders the speed, context, and confidence to act before threats take hold.

“Security teams are under pressure to move faster, but most tools still leave them piecing together fragments of information,” said Connie Stride, SVP of Product, Darktrace. “With Darktrace’s latest innovations, we’re giving them the full picture: from tracing a network threat straight to its root cause on a device, to easily understanding attack paths across IT and OT. By closing the seams between systems and uniting visibility across domains, Darktrace is helping organizations stay ahead of evolving threats with greater speed, context, and confidence.”

Availability

All enhancements to Darktrace/ NETWORK, Darktrace / ENDPOINT, Darktrace / OT, Darktrace / Attack Surface Management, and Darktrace / Proactive Exposure Management are available immediately along with our recent enhancements to Darktrace / CLOUD and introduction of the new product, Darktrace / Forensic Acquisition & Investigation.

Additional Resources

About Darktrace 

Darktrace is a global leader in AI for cybersecurity that keeps organizations ahead of the changing threat landscape every day. Founded in 2013, Darktrace provides the essential cybersecurity platform protecting organizations from unknown threats using its proprietary AI that learns from the unique patterns of life for each customer in real-time. The Darktrace ActiveAI Security Platform™ delivers a proactive approach to cyber resilience to secure the business across the entire digital estate – from network to cloud to email. It provides pre-emptive visibility into the customer’s security posture, transforms operations with a Cyber AI Analyst™, and detects and autonomously responds to threats in real-time. Breakthrough innovations from our R&D teams in Cambridge, UK, and The Hague, Netherlands have resulted in over 200 patent applications filed. Darktrace’s platform and services are supported by over 2,300 employees around the world who protect nearly 10,000 customers across all major industries globally. To learn more, visit  http://www.darktrace.com.

[1] Mandiant Time-to-Exploit Report September 2025 https://www.virustotal.com/gui/collection/report--25-10045948

News coverage
News publication logo

Darktrace Brings Industry First Endpoint Visibility And Enhanced Agentic AI To ActiveAI Security Platform™, Closing The Gaps In Cyber Defenses

October 23, 2025

cv
Darktrace named a Challenger in first Gartner® Magic Quadrant™ for Email Security Platforms ·      Evaluated on Completeness of Vision and Ability to Execute Darktrace, a global leader in AI for cybersecurity,today announces that Darktrace / EMAIL™, has been recognized in thefirst ever Gartner Magic Quadrant™ for Email Security Platforms (ESP) as a Challenger. Chris Kozup, Chief Marketing Officer, Darktrace, said of therecognition: “We are extremely proud to have been recognized in the first MagicQuadrant for ESP.  We believe the factthat wehave seen such wide scale adoption is testament to the unique way in which wedevelop products to keep our customers safe from even the most sophisticated emailcompromises. We believe our placement reaffirms our dedication to deliveringexceptional customer service, and innovations that safeguard against the emailchallenges of today—and tomorrow.” Darktrace customers consistently acknowledge its exceptional customersupport, delivered by an award-winning[1]service team. Darktrace has the highest percentage of 5-star ratings with a 4.8rating on Gartner® Peer Insights™ out of 249 reviews as on[MW1]  19th December. We feel this unwavering commitment to customersatisfaction is evident in strong renewal rates and accelerated growth inDarktrace / EMAIL over the past few years, gaining almost 5,000 customers sinceits launch in 2019. Darktrace / EMAIL, one of the fastest-growing emailsecurity products on the market, is built on Darktrace’s unique Self-LearningAI, a multi-layered AI engine that leverages different types of AI includingNLP and behavioral analysis to detect threats, instead of traditional securitymeasures such as signatures and sandboxing. This approach enables Darktrace todetect and stop threats like business email compromise attacks and noveltechniques, including some 56% of which passed through customers’ other emailsecurity layers. This pioneering approach has enabled Darktrace to introduce industry-leadingcapabilities such as QR code analysis and automated incident investigations, alongsidedifferentiated functionality to help teams add new depth to their emailsecurity, including: Account     take over and Lateral mail account compromise protection.     Contributing yet another layer to the AI behavioural profile for each     user, security teams can now spot early symptoms of account compromise or     malicious insiders before a link or attachment payload is sent, and     exfiltration occur   Microsoft Teams security with advanced messaging analysis: Advancing beyond simple text analysis to     behavioral and natural language content analysis that tracks context     across both email and instant messaging to identify the approximately 38% of     phishing, sophisticated social engineering and novel insider threats other     solutions fail to capture ·      Drastically improveend user reporting with Cyber AI Analyst narratives: Real-time awareness training capabilities reduce falsepositives in phishing investigations by up to 60% by providing context specificanalysis of each received email to each employee as they interact with their mail.·       MailboxSecurity Assistant to increase security team operational efficiency: All forms ofsecondary investigations can now automatically perform advanced behavioralbrowser analysis and stop malicious links within webpages, reducing manualeffort of security analysts to detecting phishing links, and allowing them to remediateup to 70% more malicious phishing links than before.·       AI based,autonomous data loss prevention: to immediately protect organizations from misdirected emails,insider threats, and data loss—both classified and unclassified – using userbehavior and dynamic content analysis to determine sensitivity, removing administrativeoverhead from manual expressions and labeling.Marco Cavallo, IT Manager at Darktrace / EMAIL customer Arpa Industries comments:“During the POV, Darktrace / EMAIL showed how specific attacks weresurgically blocked. We realized that other tools wouldn’t have detected thesethreats.” Darktrace / EMAIL is part of Darktrace’s ActiveAI Security Platform™,offering network, cloud, endpoint, identity and operational technologyprotection from a single shared architecture, all built on Darktrace’s uniqueAI engine – providing a strong, integrated approach to threat prevention,detection and response across an organization’s entire digital footprint. Darktrace’s global presence supports a diverse and varied customer base,and adapts proactively to customer pain points of all kinds. Darktrace’sadaptability across all market segments, from SMBs to large enterprisessupports both first time email security buyers and mature email securitystacks. It is able to meet varied security needs with lower setuprequirements, includes capability for advanced depth in configuration and,particularly for mature organizations, can augment existing security providerswith additional protections.   Download the fullMagic Quadrant for Email Security Platforms here Resources:·      Read more onthe Darktrace Blog·      Read more abouthow business email compromise attacks are evolving on The Inference  Gartner disclaimersGartner, Magic Quadrant for EmailSecurity Platforms, Max Taggett, Nikul Patel, Franz Hinner, Deepak Mishra, 16December 2024 GARTNER is a registered trademarkand service mark of Gartner and Magic Quadrant and Peer Insights are aregistered trademark, of Gartner, Inc. and/or its affiliates in the U.S. andinternationally and are used herein with permission. All rights reserved.
Gartner Peer Insights content consists of the opinions of individual endusers based on their own experiences with the vendors listed on the platform,should not be construed as statements of fact, nor do they represent the viewsof Gartner or its affiliates. Gartner does not endorse any vendor, product orservice depicted in this content nor makes any warranties, expressed orimplied, with respect to this content, about its accuracy or completeness,including any warranties of merchantability or fitness for a particularpurpose. Gartner does not endorse any vendor,product or service depicted in its research publications and does not advisetechnology users to select only those vendors with the highest ratings or otherdesignation. Gartner research publications consist of the opinions of Gartner’sresearch organization and should not be construed as statements of fact.Gartner disclaims all warranties, expressed or implied, with respect to thisresearch, including any warranties of merchantability or fitness for aparticular purpose.  About DarktraceDarktrace is a global leader in AI for cybersecurity that keepsorganizations ahead of the changing threat landscape every day. Founded in2013, Darktrace provides the essential cybersecurity platform protectingorganizations from unknown threats using its proprietary AI that learns fromthe unique patterns of life for each customer in real-time. The DarktraceActiveAI Security Platform™ delivers a proactive approach to cyber resiliencewith pre-emptive visibility into security posture, real-time threat detection,and autonomous response – securing the business across cloud, email,identities, operational technology, endpoints, and network. Breakthroughinnovations from our R&D teams in Cambridge, UK, and The Hague, Netherlandshave resulted in over 200 patent applications filed. Darktrace’s platform andservices are supported by over 2,400 employees around the world who protectnearly 10,000 customers across all major industries globally. To learn more,visit http://www.darktrace.com.   ---- 
[1] Darktrace wins two Globeeawards for excellent customer service [PressRelease] [MW1]shouldthis be 'of'