Press Release
Updated statement regarding LockBit claims
We have completed a thorough security investigation following yesterday’s tweets by LockBit claiming they had compromised Darktrace’s internal systems. We can confirm that there has been no compromise of our systems or any of our affiliate systems. Our service to our customers remains uninterrupted and is operating as normal and no further action is required.
Press Release
Statement regarding LockBit claims
Earlier this morning we became aware of tweets from LockBit, the cyber-criminal gang, claiming that they had compromised Darktrace’s internal security systems and had accessed our data. Our security teams have run a full review of our internal systems and can see no evidence of compromise. None of the LockBit social media posts link to any compromised Darktrace data. We will continue to monitor the situation extremely closely, but based on our current investigations we are confident that our systems remain secure and all customer data is fully protected.
Press Release
Darktrace Releases New Innovations in Darktrace / EMAIL™ to Stop Emerging Cross-Domain Attacks and Protect Outbound Trust
- New research finds approximately 17% of email threats bypass Secure Email Gateways but are stopped by Darktrace’s AI[1]
- New enhancements strengthen protection against threats that move across channels, like email bombing campaigns, as the volume of these attacks surges 100x
- New brand verification capabilities introduced as phishing attacks targeting Black Friday shoppers surged 1,317% in November[2]
- Recognized across the industry for its AI-native approach, Darktrace / EMAIL™ was recently named a Leader in the 2025 Gartner® Magic Quadrant™ for Email Security Platforms (ESP)
Modern social engineering attacks no longer begin and end in the inbox. They move across identity platforms, SaaS tools, and collaboration apps, exploiting gaps between disconnected security products, and employing increasingly sophisticated techniques to evade traditional defenses and reach end users.
To address these challenges, Darktrace, a global leader in AI for cybersecurity, today announced a series of enhancements to Darktrace / EMAIL™ designed to detect and stop attacks spanning communications channels, strengthen outbound email protections and streamline SOC integrations. The new capabilities will help security teams catch sophisticated attacks that evade traditional email tools, protect sensitive data, and preserve trust in digital communications – all while reducing operational complexity in crowded security environments.
New Darktrace research shows that even with multiple layers of traditional email security in place, a significant share of dangerous messages still gets through. Across real-world deployments, Darktrace / EMAIL immediately identified the 17% of threats that bypassed SEGs, including highly targeted social engineering messages that appear routine or urgent, but contain no obvious payloads, such as impersonation attempts, fake payment or vendor change requests. Traditional methods miss these threats because they’re built to stop obvious spam and malware and, to avoid false positives, default to trusting emails that appear routine. Darktrace / EMAIL can stop these threats because its Self-Learning AI engine understands how each organization normally communicates and spots subtle changes in sender, tone, timing, and behavior that signal a threat, even when conventional tools see nothing unusual.
Enhanced Protection Against Cross-Channel Attacks
Attacks targeting users across their communications channels, like email bombing campaigns, are on the rise. Between April and July 2025, the volume of email bombing messages surged 100x, growing from 200,000 emails to more than 20 million observed across Darktrace’s email customer base. These campaigns flood inboxes with benign messages to create noise and confusion, then an attacker reaches out via other channels like Teams or a phone call, posing as IT support offering to resolve the issue, and uses that trust to gain access or carry out further malicious activity. Because these emails often originate from legitimate services and contain no malicious payloads, traditional email tools struggle to detect them until the attack is already well underway, leaving organizations exposed.
To tackle the rise of multi-channel campaigns, Darktrace today introduced a new integration between Darktrace / EMAIL and Darktrace / IDENTITY™ for stronger multi-domain detection and response. When Darktrace / EMAIL detects suspicious patterns like an email bombing campaign, it can now share that signal with Darktrace / IDENTITY™ to increase sensitivity around the targeted user and more quickly spot attempted account takeovers or impersonation to stop attacks from progressing. The same cross-domain understanding and correlation extends into business applications such as Salesforce, where Darktrace can assess and action potentially malicious tickets created from email, giving security teams faster and more coordinated response across the environments they rely on most.
Darktrace has also strengthened detection accuracy by layering its behavioral insights with traditional threat intelligence, using integrated antivirus verdicts and structured feeds to enrich alerts with deeper context and enable faster, more confident triage.
These enhancements build upon Darktrace / EMAIL’s existing ability to combine behavioral and content analysis across inbound, outbound, and lateral email, as well as Microsoft Teams messaging to identify threats across the entire attack chain. It learns the normal communication patterns of every user and organization, analyzing thousands of data points for each message including language, tone, links, sender profile, historical behavior of sender and recipient, and activity across other digital channels. As a result, Darktrace spots the subtle, context-driven deviations that define modern attacks and provides earlier, more precise detections. This unique approach has been recognized across the industry, with Darktrace / EMAIL™ being named a Leader in the 2025 Gartner® Magic Quadrant™ for ESP and a 2025 Gartner® Peer Insights™ Customers’ Choice for ESP.
Securing Outbound Communications and Data
Darktrace observed a 1,317% month-over-month rise in phishing attacks targeting Black Friday in November, as attackers used seasonal targeting to exploit customer trust[2]. This surge underscores how attackers are increasingly weaponizing impersonation and trusted channels, making securing outbound communications just as important as blocking inbound threats.
To help organizations tackle brand abuse and reinforce trust in their outbound messages, Darktrace / EMAIL–DMARC now includes full Brand Indicators for Message Identification (BIMI) support. BIMI enables organizations to display a verified brand logo directly in recipients’ inboxes, making legitimate communications easier to recognize. By pairing BIMI enforcement with Darktrace’s behavioral detection capabilities, organizations can authenticate outbound messages while identifying inbound emails that attempt impersonation, helping to protect both their brand and their users. Darktrace / EMAIL – DMARC is available at no additional cost for all Darktrace customers using Microsoft365.
At the same time, not all outbound risk comes from attackers. Human error remains a leading cause of data exposure, with mis-delivery accounting for 72% of all actions involving end users in internal breaches[3]. To address this, Darktrace created the industry’s first label-free behavioral data loss prevention (DLP) powered by a proprietary domain-specific language model within Darktrace / EMAIL. The solution can now automatically identify over 35 new categories of Personally Identifiable Information (PII) and Protected Health Information (PHI) across emails and attachments including personal, financial, and health data. By learning how each user typically handles sensitive information, and intervening when outbound behavior deviates from expected patterns, this behavioral approach adds a real-time, contextual safeguard against misaddressed messages and unintended data sharing.
Together, BIMI support and behavioral DLP help organizations secure both who appears to be sending an email and what is being sent, strengthening trust in outbound communications while reducing the risk of sensitive data exposure.
New Integrations Help Reduce Friction and Accelerate Investigations
To help SOC teams move faster without adding operational complexity, Darktrace / EMAIL now includes new integrations that streamline investigations and plug into existing workflows:
- Jira and ServiceNow Integrations: Darktrace can now automatically create a Jira or ServiceNow ticket, so every report is captured, tracked, and routed through the organization’s established processes.
- Sandbox Analysis Integration: Analysts can analyze payload behavior in isolated environments directly within the Darktrace UI to quickly validate threats and close cases with confidence.
These new capabilities build on Darktrace / EMAIL’s existing ecosystem integrations, including recent integration with Microsoft Defender for Office 365, that delivers unified quarantine management, so security teams can see and control emails actioned by both products in one place, with full Darktrace visibility in Microsoft 365, and the Darktrace Email Analysis Agent for Microsoft Security Copilot. The agent lets analysts ask questions in plain language and pulls Darktrace / EMAIL insights, including alerts, device details, Cyber AI Analyst™ incidents, and email-related threats, directly into their Copilot investigations. This helps teams quickly see what’s happening, where, and who is involved, all from a single conversational view.
Together, these integrations give security teams consolidated visibility and faster investigations, streamlining workflows for organizations managing complex, multi-tool environments.
“Email is the starting point for attacks that quickly expand into other parts of the digital ecosystem and can escalate into compromised identities, cloud access abuse, or manipulation of collaboration tools - well beyond what traditional email defenses are built to handle,” said Connie Stride, SVP of Product, Darktrace. “With our latest Darktrace / EMAIL™ innovations, we extend multi-domain detection by linking behavioral signals across email, identity, and SaaS to uncover advanced attacks that move across channels, while strengthening safeguards on outbound messages. These capabilities give security teams the visibility and precision to stop modern attacks before they progress and preserve trust in every interaction.”
Additional Resources
- Tune into Darktrace’s Innovation Launch on December 9th to learn more about our latest innovations.
- To learn more about Darktrace / EMAIL, check out the product page.
- Download a copy of 2025 Gartner® Magic Quadrant™ for Email Security Platforms report here.
- Learn more about Darktrace’s Black Friday phishing analysis and discover top tips to stay safe here.
- Download relevant images and logos here.
About Darktrace
Darktrace is a global leader in AI for cybersecurity that keeps organizations ahead of the changing threat landscape every day. Founded in 2013, Darktrace provides the essential cybersecurity platform protecting organizations from unknown threats using its proprietary AI that learns from the unique patterns of life for each customer in real-time. The Darktrace ActiveAI Security Platform™ delivers a proactive approach to cyber resilience to secure the business across the entire digital estate – from network to cloud to email. It provides pre-emptive visibility into the customer’s security posture, transforms operations with a Cyber AI Analyst™, and detects and autonomously responds to threats in real-time. Breakthrough innovations from our R&D teams in Cambridge, UK, and The Hague, Netherlands have resulted in over 200 patent applications filed. Darktrace’s platform and services are supported by over 2,300 employees around the world who protect nearly 10,000 customers across all major industries globally. To learn more, visit http://www.darktrace.com.
[1] According to internal Darktrace research. The figure is a volume-weighted average from real enterprise environments where Darktrace / EMAIL ran alongside native email security and a widely deployed leading SEG and represents the share of inbound threats that bypassed those controls but were detected by Darktrace.
[2] Based on live tracking of phishing emails mentioning ‘Black Friday’ [1 October – 30 November 2025].
[3] Verizon, 2025 Data Breach Investigations Report (DBIR), p. 22.
Darktrace Releases New Innovations in Darktrace / EMAIL™ to Stop Emerging Cross-Domain Attacks and Protect Outbound Trust
cv
Darktrace named a Challenger in first Gartner® Magic Quadrant™ for Email Security Platforms · Evaluated on Completeness of Vision and Ability to Execute Darktrace, a global leader in AI for cybersecurity,today announces that Darktrace / EMAIL™, has been recognized in thefirst ever Gartner Magic Quadrant™ for Email Security Platforms (ESP) as a Challenger. Chris Kozup, Chief Marketing Officer, Darktrace, said of therecognition: “We are extremely proud to have been recognized in the first MagicQuadrant for ESP. We believe the factthat wehave seen such wide scale adoption is testament to the unique way in which wedevelop products to keep our customers safe from even the most sophisticated emailcompromises. We believe our placement reaffirms our dedication to deliveringexceptional customer service, and innovations that safeguard against the emailchallenges of today—and tomorrow.” Darktrace customers consistently acknowledge its exceptional customersupport, delivered by an award-winning[1]service team. Darktrace has the highest percentage of 5-star ratings with a 4.8rating on Gartner® Peer Insights™ out of 249 reviews as on[MW1] 19th December. We feel this unwavering commitment to customersatisfaction is evident in strong renewal rates and accelerated growth inDarktrace / EMAIL over the past few years, gaining almost 5,000 customers sinceits launch in 2019. Darktrace / EMAIL, one of the fastest-growing emailsecurity products on the market, is built on Darktrace’s unique Self-LearningAI, a multi-layered AI engine that leverages different types of AI includingNLP and behavioral analysis to detect threats, instead of traditional securitymeasures such as signatures and sandboxing. This approach enables Darktrace todetect and stop threats like business email compromise attacks and noveltechniques, including some 56% of which passed through customers’ other emailsecurity layers. This pioneering approach has enabled Darktrace to introduce industry-leadingcapabilities such as QR code analysis and automated incident investigations, alongsidedifferentiated functionality to help teams add new depth to their emailsecurity, including: Account take over and Lateral mail account compromise protection. Contributing yet another layer to the AI behavioural profile for each user, security teams can now spot early symptoms of account compromise or malicious insiders before a link or attachment payload is sent, and exfiltration occur Microsoft Teams security with advanced messaging analysis: Advancing beyond simple text analysis to behavioral and natural language content analysis that tracks context across both email and instant messaging to identify the approximately 38% of phishing, sophisticated social engineering and novel insider threats other solutions fail to capture · Drastically improveend user reporting with Cyber AI Analyst narratives: Real-time awareness training capabilities reduce falsepositives in phishing investigations by up to 60% by providing context specificanalysis of each received email to each employee as they interact with their mail.· MailboxSecurity Assistant to increase security team operational efficiency: All forms ofsecondary investigations can now automatically perform advanced behavioralbrowser analysis and stop malicious links within webpages, reducing manualeffort of security analysts to detecting phishing links, and allowing them to remediateup to 70% more malicious phishing links than before.· AI based,autonomous data loss prevention: to immediately protect organizations from misdirected emails,insider threats, and data loss—both classified and unclassified – using userbehavior and dynamic content analysis to determine sensitivity, removing administrativeoverhead from manual expressions and labeling.Marco Cavallo, IT Manager at Darktrace / EMAIL customer Arpa Industries comments:“During the POV, Darktrace / EMAIL showed how specific attacks weresurgically blocked. We realized that other tools wouldn’t have detected thesethreats.” Darktrace / EMAIL is part of Darktrace’s ActiveAI Security Platform™,offering network, cloud, endpoint, identity and operational technologyprotection from a single shared architecture, all built on Darktrace’s uniqueAI engine – providing a strong, integrated approach to threat prevention,detection and response across an organization’s entire digital footprint. Darktrace’s global presence supports a diverse and varied customer base,and adapts proactively to customer pain points of all kinds. Darktrace’sadaptability across all market segments, from SMBs to large enterprisessupports both first time email security buyers and mature email securitystacks. It is able to meet varied security needs with lower setuprequirements, includes capability for advanced depth in configuration and,particularly for mature organizations, can augment existing security providerswith additional protections. Download the fullMagic Quadrant for Email Security Platforms here Resources:· Read more onthe Darktrace Blog· Read more abouthow business email compromise attacks are evolving on The Inference Gartner disclaimersGartner, Magic Quadrant for EmailSecurity Platforms, Max Taggett, Nikul Patel, Franz Hinner, Deepak Mishra, 16December 2024 GARTNER is a registered trademarkand service mark of Gartner and Magic Quadrant and Peer Insights are aregistered trademark, of Gartner, Inc. and/or its affiliates in the U.S. andinternationally and are used herein with permission. All rights reserved.
Gartner Peer Insights content consists of the opinions of individual endusers based on their own experiences with the vendors listed on the platform,should not be construed as statements of fact, nor do they represent the viewsof Gartner or its affiliates. Gartner does not endorse any vendor, product orservice depicted in this content nor makes any warranties, expressed orimplied, with respect to this content, about its accuracy or completeness,including any warranties of merchantability or fitness for a particularpurpose. Gartner does not endorse any vendor,product or service depicted in its research publications and does not advisetechnology users to select only those vendors with the highest ratings or otherdesignation. Gartner research publications consist of the opinions of Gartner’sresearch organization and should not be construed as statements of fact.Gartner disclaims all warranties, expressed or implied, with respect to thisresearch, including any warranties of merchantability or fitness for aparticular purpose. About DarktraceDarktrace is a global leader in AI for cybersecurity that keepsorganizations ahead of the changing threat landscape every day. Founded in2013, Darktrace provides the essential cybersecurity platform protectingorganizations from unknown threats using its proprietary AI that learns fromthe unique patterns of life for each customer in real-time. The DarktraceActiveAI Security Platform™ delivers a proactive approach to cyber resiliencewith pre-emptive visibility into security posture, real-time threat detection,and autonomous response – securing the business across cloud, email,identities, operational technology, endpoints, and network. Breakthroughinnovations from our R&D teams in Cambridge, UK, and The Hague, Netherlandshave resulted in over 200 patent applications filed. Darktrace’s platform andservices are supported by over 2,400 employees around the world who protectnearly 10,000 customers across all major industries globally. To learn more,visit http://www.darktrace.com. ----
[1] Darktrace wins two Globeeawards for excellent customer service [PressRelease] [MW1]shouldthis be 'of'






