July 22, 2026·28 min read·9 views·4 providers

Identity-First Dark Web CTI Landscape 2026

2026 map of identity-first dark-web CTI: vendor positioning on IEM, stealer logs, Telegram collection, pricing signals, and whitespace for mid-market adop�

Key Finding

Recorded Future monitors malware log dumps and dark web credential marketplaces to identify compromised accounts, and its 2025 Identity Threat Landscape Report found many credential records included active session cookies alongside stolen passwords.

high confidenceSupported by perplexity, openai
Justin Furniss
Justin Furniss

@Parallect.ai and @SecureCoders. Founder. Hacker. Father. Seeker of all things AI

gemini-litegrok-premiumperplexityopenai

Executive Summary

  • The market has consolidated rapidly: Mastercard acquired Recorded Future for ~$2.65 billion in September 2024 [1], and Bitsight acquired Cybersixgill for $115 million in November 2024 [2], fundamentally reshaping the competitive landscape and leaving meaningful whitespace for independent, identity-first specialists.
  • Identity exposure management (IEM) is now the central battleground: compromised credentials, session cookies, infostealer logs, and non-human identity (NHI) artifacts have displaced traditional IOC feeds as the primary currency of threat intelligence, with stolen credentials implicated in an estimated 86% of breaches [3].
  • Scale claims are staggering but differentiation is thin at the top: SpyCloud reports 65.7 billion distinct identity records (+23% YoY) and 8.6 billion stolen session cookies recaptured in 2025 alone [4]; Bitsight/Cybersixgill claims 70 billion+ credentials with 1 billion+ records added weekly [5] — yet most enterprise platforms still deliver alerts rather than automated remediation.
  • The mid-market is structurally underserved: Recorded Future and Flashpoint are widely regarded as too expensive and analyst-intensive for organizations below ~2,000 employees [3], creating a durable wedge for platforms that combine automated collection, contextual validation, and direct IdP write-back without requiring a dedicated threat intelligence team.
  • Flare.io's most defensible whitespace lies at the intersection of automated IEM remediation, non-human identity / API key exposure, and identity-centric supply chain risk — three dimensions where no incumbent has achieved dominant, productized coverage at mid-market price points [3, 6, 7].

1. Market Context: The Identity-First Inflection Point

By mid-2026, the center of gravity in cyber threat intelligence has moved decisively from network and endpoint indicators toward identity-centric signals [3, 8]. The proximate driver is the industrialization of infostealer malware: commodity stealers such as Redline, Raccoon, and their successors exfiltrate browser-stored credentials, session cookies, autofill data, and API tokens at scale, then distribute logs through Telegram channels and dedicated marketplaces within hours of infection [9]. Flashpoint's 2026 guide frames this shift explicitly — its infostealer e-book is titled "Identity Is the New Attack Surface" [10] — and Recorded Future's 2025 Identity Threat Landscape Report identified the co-presence of active session cookies alongside stolen passwords as one of the year's most consequential findings [3].

The quantitative picture is striking. In 2025 alone, Recorded Future observed nearly 1.95 billion credentials circulating in combo-list leaks [11]. SpyCloud recaptured 13.2 million infostealer malware logs, 642.4 million exposed credentials (approximately 50 per infection), and 8.6 billion stolen session cookies and related artifacts during the same period [4]. Telegram has become both exfiltration infrastructure and a primary trading venue for stolen logs [9]; one industry count documented 77 million posts containing Telegram links in 2024 alone [3].

Against this backdrop, Identity Exposure Management (IEM) — defined as the proactive detection, validation, and automated remediation of compromised credentials, session tokens, and non-human identities — has emerged as the organizing concept around which vendors are repositioning their entire product narratives [3]. The market is bifurcating into broad-spectrum enterprise platforms (Recorded Future, Flashpoint) and specialized identity-first vendors (SpyCloud, Flare.io), with a middle tier (KELA, Intel 471, ZeroFox) occupying focused niches between those poles.


2. Vendor-by-Vendor Analysis

2.1 Recorded Future — Global Intelligence Giant, Now a Mastercard Asset

Corporate trajectory. Recorded Future was majority-acquired by Insight Partners in 2019 for $780 million [12], then acquired by Mastercard in September 2024 for approximately $2.65 billion [1]. The Mastercard acquisition is the most consequential structural event in the CTI market in recent years: it embeds Recorded Future's intelligence capabilities into a global payments and fraud-prevention infrastructure, giving it distribution channels and use cases (payment fraud, account takeover at issuer scale) that pure-play CTI vendors cannot replicate. Prior to the acquisition, Recorded Future had pursued an active M&A strategy, acquiring Gemini Advisory in January 2021 [11] and the malware sandboxing firm Hatching in July 2022 [11].

Identity exposure management. Recorded Future launched a dedicated Identity Intelligence module in 2022 [11]. The module monitors infostealer log dumps, dark web credential marketplaces, and malware combo lists to detect compromised employee or customer accounts [3]. Critically, it provides contextual enrichment for each exposure: which infostealer malware stole the credential, the infected device hostname, file path, and password strength [11]. This context — moving beyond "credential X was found" to "credential X was stolen by Redline from device CORP-LAPTOP-447 on date Y" — is a meaningful differentiator against simpler breach-notification services.

Stealer-log and credential intelligence. In 2025, Recorded Future observed nearly 1.95 billion credentials in combo-list circulation [11]. Its Intelligence Graph correlates credential exposures with threat actor profiles, malware families, and campaign timelines, enabling analysts to understand not just that a credential leaked but which criminal ecosystem it entered.

Dark web and Telegram collection. Recorded Future maintains broad coverage of Tor-based forums, paste sites, and dark web marketplaces. Its Telegram coverage is present but less prominently featured than Flashpoint's or Flare's dedicated Telegram-first collection architectures.

Automated remediation. Recorded Future can trigger automated responses — password resets, MFA challenges, risk scoring adjustments, access restrictions — by integrating with IAM and SOAR systems [11]. However, this capability is delivered through integrations rather than native write-back, meaning it requires configuration effort and typically a dedicated security operations function to operationalize.

Pricing and packaging. Recorded Future operates a modular licensing model [13], with Identity Intelligence as an add-on to its core platform. Enterprise pricing is widely reported as starting in the six-figure annual range, with full-platform deployments reaching seven figures. This positions it firmly in the large-enterprise and government segment.

Differentiation and limitations. The Intelligence Graph's breadth — correlating identity signals with geopolitical, vulnerability, and threat actor intelligence — is unmatched. Post-Mastercard, the platform's fraud-prevention use cases at financial institution scale are a genuine moat. The limitation is structural: the platform's depth and cost make it inaccessible to organizations without dedicated threat intelligence analysts, and the Mastercard integration may gradually shift product roadmap priorities toward financial services use cases at the expense of general enterprise CTI.


2.2 Cybersixgill — Automated Dark Web Intel, Now Inside Bitsight

Corporate trajectory. Cybersixgill, an Israel-based vendor [2], raised a $35 million Series B in March 2022, bringing total funding to $56 million [2, 14]. Bitsight acquired Cybersixgill for $115 million in a deal announced November 14, 2024 and closed in December 2024 [2]. Bitsight subsequently launched an Identity Intelligence solution that combines Cybersixgill's dark web collection with Bitsight's existing third-party risk and security ratings infrastructure [15]. The combined entity reports 70 billion+ credentials in its database with 1 billion+ compromised records added weekly [5].

Identity exposure management. Post-acquisition, Bitsight's Identity Intelligence product is designed to help security teams detect compromised credentials and prevent unauthorized access, with a focus on proactive credential-based risk management [15]. The platform enables search across breach dumps and infostealer log dumps by email, username, or domain [2].

Stealer-log and credential intelligence. Cybersixgill's core architecture was built around automated, real-time collection from the cybercriminal underground — a design philosophy that made it attractive to Bitsight as a data layer. Its DarkFeed provides an automated stream of indicators of compromise derived from dark web sources [2].

Dark web and Telegram collection. Cybersixgill's original differentiation was the speed and automation of its underground collection — prioritizing "speed to signal" through automated ingestion from Telegram and dark web marketplaces [3]. Its API-first architecture made it a preferred data layer for MSSPs and security platforms building identity exposure features on top of third-party intelligence.

Automated remediation. Cybersixgill as a standalone entity did not offer automated remediation out-of-the-box [2]. Whether Bitsight's integration changes this is not yet fully documented in available sources, though the Identity Intelligence product announcement emphasizes detection and risk management rather than direct IdP write-back.

Pricing and packaging. As a standalone, Cybersixgill was positioned as a mid-to-enterprise tier product with API-first packaging suited to MSSP resale. Post-Bitsight, pricing is expected to be bundled into Bitsight's broader third-party risk platform, potentially making the dark web intelligence layer available to Bitsight's existing customer base as an upsell.

Differentiation and limitations. The Bitsight acquisition creates a unique positioning: dark web and identity intelligence embedded within a third-party risk rating platform. This is genuinely novel — no other vendor combines external attack surface ratings, vendor risk scores, and dark web credential exposure in a single workflow. The limitation is integration risk: Bitsight's core buyer (third-party risk and procurement teams) is different from the SOC analyst who traditionally consumed Cybersixgill's feeds, and the product-market fit for the combined offering is still being established.


2.3 KELA — Cybercrime Marketplace Specialist

Corporate trajectory. KELA is an Israeli threat intelligence vendor [16] that specializes in closed underground communities and cybercrime marketplace monitoring, with a core focus on financially driven threat actors [16]. In 2018, Vector Capital acquired approximately 25% of KELA at a $200 million valuation, injecting approximately $50 million to fuel growth [17]. No subsequent major funding rounds or acquisitions have been documented in available sources as of mid-2026.

Identity exposure management. KELA's identity exposure capabilities center on monitoring cybercrime marketplaces — particularly initial access broker (IAB) forums, ransomware leak sites, and credential markets — for data relevant to its customers' organizations and supply chains. Its KELA Cyber Intelligence Platform surfaces compromised credentials, corporate access listings, and data breach records with actor attribution [18].

Stealer-log and credential intelligence. KELA has invested in infostealer log collection and parsing, positioning its credential intelligence as actor-attributed rather than purely data-volume-driven. The emphasis is on understanding who is selling a credential and in which criminal ecosystem, rather than simply flagging that a credential appeared in a dump [19].

Dark web and Telegram collection. KELA's collection architecture covers Tor-based forums, ransomware leak sites, and Telegram channels, with particular depth in the financially motivated cybercrime ecosystem — carding forums, IAB markets, and ransomware affiliate programs [18, 20].

Automated remediation. KELA's platform emphasizes SOC integration and workflow automation for CTI-to-SOC handoff [19], but direct IdP write-back remediation is not a prominently documented capability. The platform is positioned more as an intelligence and alerting layer than a closed-loop remediation engine.

Pricing and packaging. KELA operates a subscription model with tiered access to its intelligence platform. Pricing signals suggest mid-enterprise positioning — above pure dark web monitoring tools but below Recorded Future's full-platform cost. No public pricing is available.

Differentiation and limitations. KELA's genuine differentiation is depth in financially motivated criminal ecosystems — particularly IAB markets and ransomware affiliate programs — with actor attribution that goes beyond credential dumps to include the criminal context around why and how data is being monetized. The limitation is breadth: KELA's coverage is narrower than Recorded Future's or Flashpoint's, and its remediation capabilities lag the identity-first vendors. The absence of recent funding activity raises questions about product investment velocity relative to better-capitalized competitors.


2.4 Flashpoint — Finished Intelligence and Dark Web Archives

Corporate trajectory. Flashpoint is one of the largest independent players in threat intelligence as of 2026, approaching $100 million ARR with 750+ customers [21]. The company executed an aggressive acquisition strategy: PhishLabs (late 2021), Risk Based Security (2022), and Echosec (2022) [21]. One source characterizes Flashpoint as likely PE-backed by Audax and others, though this is a single-source finding and should be treated as preliminary [21]. The Ignite platform is Flashpoint's unified intelligence delivery surface [22].

Identity exposure management. Flashpoint's 2026 infostealer guide — "Identity Is the New Attack Surface: A Guide to Infostealers and Proactive Response" [10] — signals a deliberate repositioning toward identity-centric intelligence. The platform collects and parses infostealer logs within one to two days of infection [10], surfacing exposed credentials and session artifacts with contextual enrichment from Flashpoint's deep archives of illicit community discussions.

Stealer-log and credential intelligence. Flashpoint maintains what is widely regarded as one of the largest historical archives of illicit community content — forums, marketplaces, paste sites, and chat logs accumulated over years of collection [3]. This archive is particularly valuable for long-term adversary tracking and understanding the provenance of credential dumps. The PhishLabs acquisition added phishing kit intelligence and brand abuse monitoring to the credential intelligence stack.

Dark web and Telegram collection. Flashpoint's Telegram coverage is a notable recent investment. In April 2025, the company announced a self-service workflow within Ignite that allows customers to submit up to five Telegram channel URLs for onboarding, with in-app notification within approximately five to ten minutes once a channel has been indexed [23]. The company also launched Automated Source Discovery (ASD) in 2023, which it used to track 5,472 Telegram posts by terrorist groups within 72 hours [21] — demonstrating the system's speed at scale.

Automated remediation. Flashpoint's remediation posture is oriented toward analyst-driven response rather than automated IdP write-back. The platform provides finished intelligence and alerting that feeds into SOC workflows, but closed-loop automation connecting a dark web detection directly to an Okta or Entra ID action is not a documented native capability.

Pricing and packaging. Flashpoint's Ignite platform is enterprise-priced, with modular add-ons for specific intelligence domains. At ~$100M ARR with 750+ customers, average contract values suggest mid-to-large enterprise positioning. The platform's depth and the analyst resources required to operationalize it effectively make it less accessible to organizations without dedicated threat intelligence functions.

Differentiation and limitations. Flashpoint's differentiation is the combination of historical archive depth, finished intelligence (analyst-written reports and assessments), and increasingly capable Telegram collection. The Risk Based Security acquisition added vulnerability intelligence, making Flashpoint one of the few vendors that can correlate identity exposure with CVE-level vulnerability context. The limitation is the same as Recorded Future's: the platform rewards organizations with dedicated analysts and penalizes those without them.


2.5 SpyCloud — Identity Risk Intelligence Leader

Corporate trajectory. SpyCloud is a US-based vendor [24] that secured a $30 million Series C in 2021 [24]. No subsequent major funding rounds have been documented in available sources as of mid-2026, though the company's database scale suggests continued organic investment. By 2026, SpyCloud's database includes hundreds of billions of assets [24], with the company reporting 65.7 billion distinct identity records (+23% YoY) and 8.6 billion stolen session cookies recaptured in 2025 [4].

Identity exposure management. SpyCloud is the most identity-focused vendor in the competitive set — identity exposure management is its core value proposition [24], not an add-on to a broader intelligence platform. The company's Annual Identity Exposure Report 2025 emphasizes the astronomical scale of risks posed by digital identity sprawl and the proliferation of credentials across services [24]. SpyCloud's data is cleaned, deduplicated, and enriched — a deliberate contrast to raw breach dump aggregators — covering passwords, session cookies, and API keys [3].

Stealer-log and credential intelligence. SpyCloud recaptured 13.2 million infostealer malware logs and 642.4 million exposed credentials in 2025, with approximately 50 exposed credentials per infection [4]. The company's emphasis on session cookie recapture — 8.6 billion artifacts in 2025 — reflects its recognition that session hijacking has become as dangerous as password theft, enabling attackers to bypass MFA entirely.

Non-human identity coverage. SpyCloud explicitly covers non-human identities (NHIs) — API keys, service account tokens, and machine credentials — a capability that distinguishes it from vendors focused solely on human credential exposure [3]. This is an increasingly important differentiator as organizations' attack surfaces expand through CI/CD pipelines, cloud service accounts, and third-party API integrations.

Dark web and Telegram collection. SpyCloud's collection architecture is oriented toward infostealer log markets and breach data sources rather than broad dark web forum monitoring. Its Telegram coverage exists but is less prominently featured than Flashpoint's or Flare's dedicated channel monitoring.

Automated remediation. SpyCloud offers remediation workflows that integrate with enterprise identity systems, enabling automated password resets and session invalidation triggered by credential exposure detections. This is more mature than most competitors' remediation capabilities, though the depth of native IdP integration varies by customer environment.

Pricing and packaging. SpyCloud packages its capabilities across several product lines: Employee ATO Prevention, Consumer ATO Prevention, and an API for embedding credential intelligence into third-party platforms. Pricing is enterprise-oriented but more accessible than Recorded Future or Flashpoint, reflecting SpyCloud's positioning as a specialized identity tool rather than a full-platform intelligence suite.

Differentiation and limitations. SpyCloud's differentiation is data quality and identity specificity: its cleaned, deduplicated, enriched identity data lake is the deepest purpose-built credential intelligence asset in the market. The NHI coverage and session cookie recapture capabilities are genuine technical moats. The limitation is breadth — SpyCloud does not offer the geopolitical, vulnerability, or adversary-TTP intelligence that Recorded Future or Flashpoint provide, making it a complement to rather than a replacement for broader CTI platforms in large enterprise environments.


2.6 ZeroFox — Unified Digital Risk Protection and Takedowns

Corporate trajectory. ZeroFox went public via a SPAC merger in August 2022, with the combined entity valued at approximately $1.3 billion [25]. The company merged with IDX in 2022 and acquired the assets of LookingGlass Cyber's Cyveillance unit in 2023 [25]. In 2024, ZeroFox transitioned back to private ownership under Haveli Investments [1]. This privatization removed the quarterly earnings pressure of public markets and may accelerate product investment, though it also reduces financial transparency.

Identity exposure management. ZeroFox's identity exposure capabilities are embedded within its broader Digital Risk Protection (DRP) platform. The platform identifies and remediates targeted phishing attacks, credential compromise, data exfiltration, brand hijacking, and executive threats [25, 26]. The IDX merger added identity theft protection and breach response capabilities, giving ZeroFox a consumer-facing identity protection layer that most pure-play CTI vendors lack.

Stealer-log and credential intelligence. ZeroFox monitors dark web sources for credential exposures relevant to its customers' domains and executive profiles. Its credential intelligence is integrated into a broader brand and executive protection workflow rather than delivered as a standalone identity data product.

Dark web and Telegram collection. ZeroFox maintains dark web monitoring capabilities covering Tor forums, paste sites, and Telegram channels [25]. Its collection is oriented toward brand abuse, executive threat, and phishing kit detection rather than the raw infostealer log volume that SpyCloud or Flare prioritize.

Automated remediation. ZeroFox is one of the more aggressive vendors on automated remediation, particularly for external-facing threats: automated takedowns of phishing sites, fraudulent social media profiles, and brand-impersonating domains are core platform capabilities [3]. For identity-specific remediation — triggering password resets or session revocations in enterprise IdPs — ZeroFox automates the link between dark web detection and identity provider action [3], though this capability is less prominently documented than SpyCloud's or Flare's.

Pricing and packaging. ZeroFox packages its platform as a unified DRP suite with modular add-ons for specific protection domains (executive protection, brand protection, dark web monitoring). Pricing is mid-to-enterprise, with the unified platform approach creating bundling opportunities that individual point solutions cannot match.

Differentiation and limitations. ZeroFox's differentiation is the combination of AI-driven brand protection, executive threat monitoring, and automated takedown services — a workflow that spans from dark web detection to external remediation (takedown) in a single platform [3]. The IDX acquisition adds consumer identity protection, creating cross-sell opportunities in financial services and healthcare. The limitation is that ZeroFox's identity intelligence depth — particularly for infostealer log volume and NHI coverage — lags SpyCloud and Flare, and its enterprise SOC integration story is less developed than Recorded Future's or Flashpoint's.


2.7 Intel 471 — Adversary-Centric Intelligence

Corporate trajectory. Intel 471 is a private cyber threat intelligence firm [8] that completed a Series C round of approximately $30 million in mid-2021 [8]. No subsequent major funding rounds or acquisitions have been documented in available sources as of mid-2026. The company is often characterized as an actor-centric intelligence provider [8], with a business model built around human-vetted intelligence on threat actor TTPs rather than automated data volume.

Identity exposure management. Intel 471 alerts customers as soon as leaked credentials relevant to their stakeholders are identified, covering employees, VIPs, customers, and third parties [27]. The platform's identity exposure capabilities are embedded within its broader adversary intelligence framework — credential exposures are contextualized against known threat actor profiles and campaigns rather than delivered as raw data alerts.

Stealer-log and credential intelligence. Intel 471's credential intelligence is distinguished by actor attribution: rather than simply flagging that a credential appeared in a dump, the platform contextualizes it within the criminal ecosystem — which actor or group is selling it, in which forum, and as part of which campaign [27]. This depth of attribution is valuable for organizations that need to understand threat actor intent, not just data exposure.

Dark web and Telegram collection. Intel 471 maintains coverage of closed underground communities, cybercrime forums, and Telegram channels, with particular depth in the financially motivated and nation-state-adjacent threat actor ecosystems [8]. Its collection is more selective and human-curated than the automated, high-volume approaches of Cybersixgill or Flare.

Automated remediation. Intel 471's platform is oriented toward intelligence delivery and analyst workflows rather than automated remediation. Direct IdP write-back or automated credential reset capabilities are not documented as native platform features.

Pricing and packaging. Intel 471 is positioned at the premium end of the market, with pricing reflecting the human intelligence (HUMINT) component of its collection methodology. Its customer base skews toward large enterprises, financial institutions, and government agencies that require high-fidelity, analyst-grade intelligence rather than automated alerting at scale.

Differentiation and limitations. Intel 471's differentiation is the quality and attribution depth of its threat actor intelligence — a capability that automated collection platforms cannot replicate. For organizations that need to understand who is targeting them and why, Intel 471's actor-centric approach provides context that data-volume leaders like SpyCloud or Bitsight/Cybersixgill do not. The limitation is scalability and accessibility: the human-curation model constrains data volume and speed relative to automated competitors, and the premium pricing excludes mid-market buyers.


3. Competitive Landscape Summary Table

VendorIdentity Exposure ManagementStealer-Log & Credential IntelDark Web & Telegram CollectionAutomated RemediationPrimary DifferentiationRecent M&A / FundingPricing Tier
Recorded FutureDedicated Identity Intelligence module (2022); contextual enrichment (malware family, device, file path)~1.95B credentials observed in combo lists (2025); Intelligence Graph correlationBroad Tor/dark web; Telegram present but not primary focusIAM/SOAR integration; requires configuration; not native write-backIntelligence Graph breadth; geopolitical + identity correlation; Mastercard distributionAcquired by Mastercard ~$2.65B (Sept 2024); acquired Gemini Advisory (2021), Hatching (2022)Enterprise / Government ($$$$$)
Cybersixgill / BitsightIdentity Intelligence product post-acquisition; 70B+ credentials, 1B+ added weeklyAutomated real-time collection; DarkFeed IoC streamAPI-first automated collection; strong Telegram ingestionDetection-focused; no documented native IdP write-backDark web data layer embedded in third-party risk platform; MSSP-friendly APIAcquired by Bitsight for $115M (Nov 2024); prior $35M Series B (2022)Mid-Enterprise / MSSP ($$-$$$)
KELACredential markets + IAB monitoring; actor-attributed exposuresActor-attributed credential intelligence; IAB and ransomware leak focusTor forums, ransomware sites, Telegram; depth in financially motivated ecosystemsSOC workflow integration; no documented IdP write-backFinancially motivated actor depth; IAB and ransomware affiliate ecosystem coverageVector Capital ~$50M / 25% stake (2018); no recent rounds documentedMid-Enterprise ($$-$$$)
FlashpointInfostealer logs parsed within 1–2 days; "Identity Is the New Attack Surface" positioningDeep historical archives; PhishLabs phishing kit intel; ~$100M ARRSelf-service Telegram onboarding (Apr 2025); ASD launched 2023; 5,472 Telegram posts tracked in 72 hrsAnalyst-driven; no documented native IdP write-backHistorical archive depth; finished intelligence; vulnerability + identity correlation (Risk Based Security)Acquired PhishLabs (2021), Risk Based Security + Echosec (2022); ~$100M ARR; likely PE-backedEnterprise ($$$$)
SpyCloudCore value proposition; 65.7B identity records (+23% YoY); NHI / API key coverage13.2M infostealer logs, 642.4M credentials, 8.6B session cookies recaptured (2025)Infostealer log markets primary; Telegram present; less forum-breadth focusAutomated password reset + session invalidation; IdP integrationDeepest purpose-built identity data lake; session cookie + NHI coverage; data quality/deduplication$30M Series C (2021); no recent rounds documentedMid-Enterprise / Enterprise ($$$)
ZeroFoxDRP-embedded credential monitoring; IDX merger adds consumer identity protectionDark web credential monitoring for brand/executive protection workflowsTor, paste sites, Telegram; brand-abuse and phishing-kit orientedAutomated takedowns (phishing, social, domains); IdP write-back documented but less prominentAI-driven brand protection + executive threat + automated external takedownsSPAC IPO Aug 2022 (~$1.3B); acquired IDX (2022), LookingGlass Cyveillance (2023); privatized under Haveli (2024)Mid-Enterprise ($$-$$$)
Intel 471Actor-attributed credential alerts; employees, VIPs, customers, third partiesHuman-curated actor-attributed credential intelligence; closed forum depthClosed underground communities; Telegram; human-curated, selectiveIntelligence delivery / analyst workflows; no documented native IdP write-backHUMINT-grade actor attribution; threat actor TTP depth; nation-state and financial crime coverage~$30M Series C (mid-2021); no recent rounds documentedEnterprise / Government ($$$$)
Flare.ioIdentity-first TEM platform; automated IEM workflows; 1M+ new stealer logs/week1M+ stealer logs/week; automated collection and contextual validation58,000+ Telegram channels monitored; Tor, I2P, infostealer marketsNative IdP write-back (Okta, Entra ID); password reset + session revocation automationMid-market automation; high signal-to-noise; direct IdP write-back without analyst overhead$30M growth capital ($15M Series B extension + $15M BMO debt); Inovia Capital ledMid-Market / Mid-Enterprise ($$)

4. Flare.io's Competitive Position and Whitespace Analysis

4.1 Current Positioning

Flare.io operates as an identity-first Threat Exposure Management (TEM) platform, continuously collecting and contextualizing data from cybercrime sources including Telegram channels, Tor forums, I2P sites, infostealer log markets, and leaked-credential combo lists [28]. The platform monitors 58,000+ Telegram channels and ingests more than 1 million new stealer logs weekly [3]. Its $30 million growth capital round — structured as a $15 million Series B extension led by Inovia Capital's Growth Fund (with Base10 Partners and White Star Capital participating) plus $15 million in debt financing from BMO — funds a Threat Exposure Management strategy and potential M&A activity [29]. The company now supports customers and partners in more than 50 countries [29].

Flare's core differentiation in the current landscape is the combination of:

  1. Automated, high-volume Telegram and dark web collection at a scale (58,000+ channels, 1M+ logs/week) that rivals enterprise platforms [3]
  2. Native IdP write-back — the ability to automatically trigger password resets and session revocations in Okta, Microsoft Entra ID, and similar platforms directly from a dark web detection, without requiring analyst intermediation [3]
  3. Mid-market accessibility — a platform designed to deliver value without a dedicated threat intelligence team, at price points that Recorded Future and Flashpoint cannot match [3]
  4. Contextual validation via AI — the "Threat Flow" AI layer that moves beyond raw alerting to confirm, for example, that a credential is linked to a high-risk session token or was found in a log alongside 500 other entries from the same infection [3]

4.2 Whitespace Gap 1: Automated Remediation as a Product, Not a Feature

The most structurally significant gap in the competitive landscape is the absence of a vendor that has made automated, closed-loop IEM remediation its primary product identity rather than a feature within a broader platform. SpyCloud offers remediation workflows, and Recorded Future integrates with SOAR systems, but neither has built its go-to-market narrative around "we detect a compromised credential and automatically fix it within minutes, without human intervention." ZeroFox automates external remediation (takedowns) but is less developed on internal IdP write-back [3].

Flare's native Okta/Entra ID write-back capability — triggering password resets and session revocations automatically from dark web detections [3] — is the foundation of a compelling "time-to-remediation" narrative. The market is shifting from "alerting" to "acting" [3], and buyers are increasingly valuing platforms with proven, automated, and measurable impact on security outcomes rather than intelligence volume [3]. A mid-size organization that can demonstrate "mean time to remediate a compromised credential: 4 minutes, automated, zero analyst hours" has a procurement story that no incumbent can match at comparable price points.

The opportunity: Productize the remediation workflow as a standalone metric — publish MTTR benchmarks, build case studies around automated remediation events, and position the IdP write-back as the primary value driver rather than a secondary feature. This creates a defensible narrative that is difficult for data-volume leaders (SpyCloud, Bitsight/Cybersixgill) to replicate without significant workflow engineering investment.

4.3 Whitespace Gap 2: Non-Human Identity and API Key Exposure at Mid-Market Scale

SpyCloud explicitly covers non-human identities (NHIs) — API keys, service account tokens, machine credentials [3] — but its pricing and packaging are oriented toward enterprise buyers. There is a massive, underserved segment of mid-market organizations — software companies, fintechs, SaaS vendors — that have extensive API key and service account exposure through developer tooling, CI/CD pipelines, and third-party integrations, but lack the budget or analyst capacity to operationalize enterprise-grade NHI monitoring [3].

The attack surface is real and growing: infostealer logs frequently contain browser-stored API tokens, OAuth credentials, and developer environment secrets alongside traditional passwords. A platform that can automatically identify when a developer's machine was infected by an infostealer, extract the API keys and service account tokens from the resulting log, and trigger automated rotation or revocation in the relevant platforms (GitHub, AWS IAM, GCP Service Accounts, Okta) would address a gap that no vendor has fully productized at mid-market price points [3].

The opportunity: Build a dedicated NHI exposure module that surfaces API key and service account exposures from stealer logs with automated remediation workflows into developer platforms and cloud IAM systems. This extends Flare's existing stealer-log collection and IdP write-back capabilities into an adjacent, underserved use case without requiring fundamentally new collection infrastructure.

4.4 Whitespace Gap 3: Identity-Centric Supply Chain Risk

Current supply chain security tools focus predominantly on vulnerabilities (CVEs) in third-party software components [3]. No vendor has built a productized, identity-centric supply chain risk capability that alerts organizations when their vendors' employees have leaked credentials or session tokens that could provide a backdoor into the customer's own systems [3].

The threat model is well-established: a managed service provider's employee credentials appear in an infostealer log; an attacker uses those credentials to access the MSP's management console; the attacker pivots to the MSP's customers. The SolarWinds and Kaseya incidents demonstrated this attack pattern at scale, yet the intelligence tooling to detect it proactively — monitoring for credential exposures among a customer's vendor ecosystem, not just the customer's own employees — remains largely unproductized [3].

Flare's existing collection infrastructure (58,000+ Telegram channels, 1M+ stealer logs/week) already captures the raw data needed to power this use case. The product gap is the workflow layer: mapping a customer's vendor ecosystem, monitoring for credential exposures among vendor employees, and surfacing alerts with enough context to enable a meaningful third-party risk response [3].

The opportunity: Launch an "Identity Supply Chain" module that allows customers to define a vendor watchlist and receive alerts when vendor employee credentials or session tokens appear in stealer logs or dark web markets. This creates a new buyer persona (third-party risk managers, procurement security teams) and a new competitive moat that neither SpyCloud nor Bitsight/Cybersixgill has explicitly targeted at mid-market price points.

4.5 Whitespace Gap 4: The Mid-Market Consolidation Play

The 2024 consolidation events — Mastercard/Recorded Future and Bitsight/Cybersixgill — have left the mid-market without a clear independent champion. KELA and Intel 471 are premium-priced and analyst-intensive. ZeroFox is privatized and refocusing. Flashpoint is approaching enterprise scale. SpyCloud is the closest competitor to Flare in the identity-first space but is US-centric and enterprise-priced [3].

Flare's $30 million growth capital round explicitly includes an M&A component [29]. The strategic logic for a tuck-in acquisition is compelling: a small, specialized vendor with complementary collection (e.g., a dark web forum specialist, a brand protection tool, or an NHI-focused startup) could be absorbed to accelerate the whitespace plays described above without requiring organic development timelines.

The opportunity: Use the M&A capital to acquire a complementary capability — NHI monitoring, supply chain identity risk, or a regional dark web collection specialist — that accelerates one of the whitespace plays while the market is still fragmented. The window for mid-market consolidation is narrowing as larger platforms extend downmarket.

4.6 Structural Advantages and Risks

Advantages:

  • The mid-market is structurally underserved by the current competitive set, and Flare's price-to-capability ratio is difficult for incumbents to replicate without cannibalizing their enterprise margins [3]
  • Native IdP write-back is a genuine technical differentiator that requires workflow engineering investment to replicate — it is not simply a data volume problem [3]
  • The Telegram collection scale (58,000+ channels) is competitive with enterprise platforms and provides a credible data story for enterprise prospects [3]
  • The growth capital structure (equity + debt) preserves optionality for both organic investment and M&A without requiring a near-term exit [29]

Risks:

  • SpyCloud's data lake scale (65.7 billion records, 8.6 billion session cookies) and NHI coverage represent a genuine capability gap that Flare must close or differentiate around [4]
  • Bitsight/Cybersixgill's combination of dark web data and third-party risk ratings creates a bundling threat for customers who already use Bitsight for vendor risk management [15]
  • The Mastercard/Recorded Future combination may eventually produce a mid-market offering leveraging Mastercard's distribution — a scenario that would compress Flare's addressable market from above [1]
  • Automated remediation creates legal and operational liability questions (what happens when an automated password reset locks out a legitimate user?) that require careful product design and customer education

5. Structural Market Dynamics and Forward Outlook

5.1 Consolidation Pressure

The 2024 acquisitions signal that large platform vendors — security ratings firms, payment networks, and enterprise software companies — view identity intelligence as a strategic layer worth acquiring rather than building. The Bitsight/Cybersixgill deal at $115 million [2] and the Mastercard/Recorded Future deal at ~$2.65 billion [1] bracket the valuation range for identity-first CTI assets. For Flare, this creates both an exit pathway and a competitive threat: the same dynamics that make the company an attractive acquisition target also attract better-capitalized entrants into its core market.

The broader M&A environment in cybersecurity has been active, with global M&A reaching $2.8 trillion in H1 2026 across sectors [30], and identity security remaining one of the most active sub-segments. Large players are aggressively acquiring identity security and threat intelligence assets to build closed-loop security ecosystems [3].

5.2 The Shift from Alerting to Acting

The most durable structural trend in the market is the buyer shift from paying for intelligence volume to paying for measurable security outcomes. Buyers are moving away from "AI narratives" and toward platforms with proven, automated, and measurable impact [3]. This trend favors vendors with native remediation capabilities (Flare, SpyCloud, ZeroFox) over pure intelligence platforms (Intel 471, KELA) and creates pricing pressure on vendors whose value proposition is data breadth without workflow integration.

The session cookie recapture story — SpyCloud's 8.6 billion stolen session artifacts in 2025 [4] — illustrates the stakes: if attackers can bypass MFA using stolen session tokens, the traditional "reset the password" remediation is insufficient. Vendors that can automate session revocation alongside password reset, and that can detect session token exposure in near-real-time from Telegram and infostealer markets, will capture the next wave of IEM budget.

5.3 Regulatory Tailwinds

NIST SP 800-63B (Digital Identity Guidelines: Authentication and Lifecycle Management) and the EU General Data Protection Regulation (Regulation (EU) 2016/679) both create compliance drivers for proactive credential monitoring and timely breach response [3]. As regulatory scrutiny of identity-related breaches intensifies — particularly in financial services and healthcare — the business case for automated IEM platforms strengthens. Vendors that can demonstrate compliance alignment (e.g., "our platform helps you meet NIST 800-63B's compromised credential detection requirements") will find receptive buyers in regulated industries.

5.4 The Non-Human Identity Frontier

The expansion of machine identities — API keys, service account tokens, OAuth credentials, CI/CD pipeline secrets — into infostealer log ecosystems is an emerging threat that the current competitive set has not fully addressed. SpyCloud's NHI coverage is the most developed, but it is enterprise-priced and not yet the centerpiece of a mid-market product motion. As organizations' developer toolchains and cloud infrastructure generate more machine credentials than human ones, the vendor that productizes NHI exposure management at mid-market price points will capture a structurally growing share of the IEM budget.


6. Synthesis: Where Flare.io Should Focus

The competitive analysis points to four actionable strategic priorities for a mid-size identity-first CTI vendor in Flare's position:

1. Own the automated remediation narrative. No incumbent has made closed-loop, automated IEM remediation its primary go-to-market identity. Flare's native IdP write-back is the foundation; the product motion is to build the MTTR benchmark story, publish it, and make "minutes to remediation, zero analyst hours" the primary sales metric.

2. Launch a productized NHI exposure module. The mid-market NHI gap is real, growing, and unaddressed at accessible price points. Flare's existing stealer-log collection already captures API keys and service account tokens; the product investment is in the workflow layer (automated rotation/revocation into GitHub, AWS IAM, GCP, Okta) and the go-to-market motion (developer security and DevSecOps buyers).

3. Build the Identity Supply Chain product. Vendor ecosystem credential monitoring is a whitespace that no incumbent has productized for mid-market buyers. The data infrastructure exists; the product gap is the vendor watchlist workflow and the third-party risk buyer persona.

4. Deploy M&A capital selectively. The $30 million growth capital round's M&A component [29] should target a tuck-in that accelerates one of the above three priorities — either a specialized NHI monitoring capability, a supply chain risk workflow, or a regional dark web collection asset that deepens Telegram/forum coverage in underserved geographies.

The window for these moves is finite. The Bitsight/Cybersixgill combination is still integrating [2]; Recorded Future is absorbing into Mastercard's product organization [1]; SpyCloud has not raised since 2021 [24]. The mid-market is, for the moment, genuinely open — but the consolidation dynamics that created this opening will eventually close it.

References

[1] Dark web monitoring platforms 2026 (huntress.com). huntress.com. https://huntress.com/cybersecurity-insights/dark-web-monitoring-platforms-2026

[2] Bitsight buys dark web security specialist cybersixgill for 115m (techcrunch.com). techcrunch.com. https://techcrunch.com/2024/11/14/bitsight-buys-dark-web-security-specialist-cybersixgill-for-115m

[3] 2025 lessons 2026 predictions (spycloud.com). spycloud.com. https://spycloud.com/resource/report/2025-lessons-2026-predictions

[4] Annual identity exposure report 2026 (spycloud.com). spycloud.com. https://spycloud.com/newsroom/annual-identity-exposure-report-2026

[5] msspalert.com. msspalert.com. https://msspalert.com

[6] Identity first threat intelligence platform expansions (flare.io). flare.io. https://flare.io/company/press/identity-first-threat-intelligence-platform-expansions

[7] Cyber threat intelligence platform (flare.io). flare.io. https://flare.io/cyber-threat-intelligence-platform

[8] Cyber threat intelligence (intel471.com). intel471.com. https://intel471.com/platform/cyber-threat-intelligence

[9] Stealer logs and telegram how cybercriminals industrialize data theft and what defenders must monitor (slcyber.io). slcyber.io. https://slcyber.io/blog/stealer-logs-and-telegram-how-cybercriminals-industrialize-data-theft-and-what-defenders-must-monitor

[10] 2026 guide to infostealers (flashpoint.io). flashpoint.io. https://flashpoint.io/resources/e-book/2026-guide-to-infostealers

[11] 7. recordedfuture.com. https://recordedfuture.com

[12] Recorded Future acquired for $780 million by venture firm - CyberScoop. cyberscoop.com. https://cyberscoop.com/recorded-future-acquistion-insights

[13] License options (recordedfuture.com). recordedfuture.com. https://recordedfuture.com/license-options

[14] Threat Intelligence Firm Cybersixgill Raises $35 Million - SecurityWeek. securityweek.com. https://securityweek.com/threat-intelligence-firm-cybersixgill-raises-35-million

[15] Bitsight unveils identity intelligence solution detect and stop credential based (bitsight.com). bitsight.com. https://bitsight.com/press-releases/bitsight-unveils-identity-intelligence-solution-detect-and-stop-credential-based

[16] Vector Capital | Investments | Kela. vectorcapital.com. https://vectorcapital.com/investments/case-study/kela

[17] Vector Capital Buys 25% Stake in Dark Web Monitoring Company KELA - CTech. calcalistech.com. https://calcalistech.com/ctech/articles/0,7340,L-3737038,00.html

[18] 9. kelacyber.com. https://kelacyber.com

[19] Work smarter in 2025 7 benefits of automating cti into soc activities (kelacyber.com). kelacyber.com. https://kelacyber.com/blog/work-smarter-in-2025-7-benefits-of-automating-cti-into-soc-activities

[20] Blog (kelacyber.com). kelacyber.com. https://kelacyber.com/blog

[21] Sk00u7j7gjx (calcalistech.com). calcalistech.com. https://calcalistech.com/ctechnews/article/sk00u7j7gjx

[22] Ignite (flashpoint.io). flashpoint.io. https://flashpoint.io/ignite

[23] Bring telegram sources into ignite in minutes (flashpoint.io). flashpoint.io. https://flashpoint.io/resources/product-updates/bring-telegram-sources-into-ignite-in-minutes

[24] Spycloud annual identity exposure report 2025 (spycloud.com). spycloud.com. https://spycloud.com/resource/report/spycloud-annual-identity-exposure-report-2025

[25] Dark web intelligence (zerofox.com). zerofox.com. https://zerofox.com/solutions/cyber-threat-intelligence/dark-web-intelligence

[26] Zerofox expands threat intelligence capabilities (zerofox.com). zerofox.com. https://zerofox.com/press-release/zerofox-expands-threat-intelligence-capabilities

[27] Compromised credential management (intel471.com). intel471.com. https://intel471.com/use-cases/compromised-credential-management

[28] Dark web monitoring (flare.io). flare.io. https://flare.io/dark-web-monitoring

[29] Flare secures 30 million growth capital tem ma strategy (flare.io). flare.io. https://flare.io/company/press/flare-secures-30-million-growth-capital-tem-ma-strategy

[30] Global ma hits 28 trillion in h1 2026 with mega deals and ai infrastructure pulling industrial manufacturing to a 28 surge (marketscale.com). marketscale.com. https://marketscale.com/industries/industrial-iot/global-ma-hits-28-trillion-in-h1-2026-with-mega-deals-and-ai-infrastructure-pulling-industrial-manufacturing-to-a-28-surge

Evidence Explorer

Select a citation or claim to explore evidence.

Cross-provider analysis

How 4 providers compared on 163 claims across 111 topic clusters

3
Consensus
0
Contested
91
Unique
23
Low-conf
standard

Consensus findings (3)

Multiple providers independently confirmed these. Treat as the most reliable evidence.

  • By 2026, cyber threat intelligence has shifted toward identity-centric intelligence, with dark web/stealer-log monitoring, credential theft, session hijacking, and machine/non-human identity abuse becoming central signals and attack vectors.

    79%
    gemini-litegrok-premiumperplexityopenai
  • SpyCloud focuses on identity exposure, compromised credential data, and account takeover risk prevention.

    77%
    gemini-liteperplexityopenai
  • Flare.io is an identity-first CTI/TEM provider that surfaces identity exposures, leaked secrets, and brand threats for each organization.

    69%
    gemini-liteopenaiperplexity

Single-source insights (91)

Reported by only one provider. Treat as preliminary unless independently verified.

  • Flare.io secured $30 million in growth capital for its Threat Exposure Management strategy.

    76%
    perplexity
  • In 2025 alone, Recorded Future observed nearly 1.95 billion credentials circulating in “combo list” leaks.

    76%
    openai
  • Cybersixgill’s last major funding was a $35 million Series B in March 2022.

    76%
    openai
  • In 2018, Vector Capital invested about $50 million in KELA, acquiring approximately 25% at a $200 million valuation.

    76%
    openai
  • SpyCloud secured a $30 million Series C in 2021.

    76%
    openai
  • Intel 471’s Series C round occurred in mid-2021 and was approximately $30 million.

    76%
    openai
  • + 85 more single-source insights

Low-confidence claims (23)

Weak signals the verifier flagged for hedged language in the report.

  • Flashpoint is now likely PE-backed by Audax and others.

    54%
    openai
  • Palo Alto Networks and ServiceNow are acquiring CyberArk and Veza to build closed-loop security ecosystems.

    56%
    gemini-lite
  • Recorded Future was expected to pursue an IPO when market conditions allow.

    58%
    openai
  • Flare supports customers and partners in more than 50 countries.

    58%
    perplexity
  • There is a massive, underserved segment of mid-market organizations struggling to secure API keys and service accounts.

    58%
    gemini-lite
  • + 18 more low-confidence claims

Go Deeper

Follow-up questions based on where providers disagreed or confidence was low.

Did Flashpoint complete a PE-backed transaction with Audax and others, and if so what changed in its 2026 product/market positioning around identity exposure management and automated remediation?

This is a direct contradiction-prone financing signal with downstream implications for competitive strategy, pricing, and packaging. If Flashpoint is PE-backed, it may explain investment in identity-first workflows, faster GTM, or bundling around dark web and Telegram collection versus pure intelligence delivery.

Low ConfidenceXS tier
Investigate this →

How strong is the evidence that large enterprise vendors are moving toward closed-loop identity security ecosystems by acquiring CyberArk and Veza, and what would that mean for demand in identity exposure management and automated remediation?

This claim is highly strategic but very uncertain. Verifying it would clarify whether the market is consolidating around identity/security control planes, which directly affects whitespace for a mid-size vendor like Flare.io and the credibility of the 'alerting to acting' shift.

Low ConfidenceS tier
Investigate this →

What exactly did Flare.io’s $30 million growth capital round finance, and does it support expansion into the 'identity supply chain' niche, automated Okta/Entra ID remediation, or broader mid-market API key and service account protection?

The funding signal is a strong single-source anchor, but the competitive implications are unexplored. Confirming how the capital is being deployed would test whether Flare can really execute on the alleged mid-market identity-first wedge and out-of-the-box remediation proposition.

ImplicationS tier
Investigate this →

What is the actual scale and differentiation of SpyCloud’s 2025 identity data corpus—13.2 million infostealer logs, 642.4 million exposed credentials, and 8.6 billion stolen session cookies/artifacts—and how does that compare to Recorded Future, KELA, Flashpoint, ZeroFox, and Intel 471 on stealer-log and credential intelligence?

These are unusually specific, high-signal figures that could materially reshape the competitive landscape, but they are currently single-source. A focused comparison would validate whether SpyCloud’s data advantage is large enough to anchor its identity exposure management positioning versus peers.

Low ConfidenceM tier
Investigate this →

Does the mid-market segment truly represent an underserved whitespace for identity exposure management focused on API keys, service accounts, and vendor employee credential leakage, and which vendors already address this use case end-to-end?

This clusters several weak signals into a concrete market-validation question. It is important because it tests the core whitespace thesis for Flare.io: whether simplified visibility plus automated remediation can win where large incumbents are considered too expensive or too analyst-heavy.

ImplicationM tier
Investigate this →

Key Claims

Cross-provider analysis with confidence ratings and agreement tracking.

111 claims · sorted by confidence
1

By 2026, cyber threat intelligence has shifted toward identity-centric intelligence, with dark web/stealer-log monitoring, credential theft, session hijacking, and machine/non-human identity abuse becoming central signals and attack vectors.

high·gemini-lite, grok-premium, perplexity, openai·flashpoint.ioslcyber.iobitsight.com+4·
2

SpyCloud focuses on identity exposure, compromised credential data, and account takeover risk prevention.

high·gemini-lite, perplexity, openai·flare.iospycloud.comspycloud.com·
3

Recorded Future was majority-acquired by Insight Partners in 2019 for $780 million.

high·grok-premium, openai·cyberscoop.comhuntress.comdealroom.co·
4

Intel 471 alerts customers when leaked credentials relevant to their stakeholders are identified, covering employees, VIPs, customers, and third parties.

high·gemini-lite, perplexity·intel471.comspycloud.com·
5

Recorded Future monitors malware log dumps and dark web credential marketplaces to identify compromised accounts, and its 2025 Identity Threat Landscape Report found many credential records included active session cookies alongside stolen passwords.

high·perplexity, openai·huntress.comstellarcyber.airecordedfuture.com·
6

Cybersixgill’s platform enables users to search for compromised emails, usernames, or domains across breach dumps and infostealer log dumps.

high·gemini-lite, openai·momentumcyber.comspycloud.com·
7

Recorded Future’s Identity Intelligence provides detailed context for credential exposures, including the infostealer involved, infected device hostname, file path, and password strength.

high·perplexity, openai·intel471.comg2.comzerofox.com+4·
8

Flare.io’s dark web monitoring platform collects and analyzes cybercrime data from sources such as Telegram channels, Tor forums, I2P sites, infostealer log markets, and leaked-credential combo lists.

high·grok-premium, perplexity·spycloud.comflare.io·
9

Intel 471 is a private cyber threat intelligence firm known for actor-centric, human-vetted intelligence on threat actor TTPs.

high·gemini-lite, openai·intel471.comspycloud.com·
10

Flare.io secured $30 million in growth capital for its Threat Exposure Management strategy.

high·perplexity·flare.io·
11

In 2025 alone, Recorded Future observed nearly 1.95 billion credentials circulating in “combo list” leaks.

high·openai·recordedfuture.com·
12

Cybersixgill’s last major funding was a $35 million Series B in March 2022.

high·openai·momentumcyber.commarketscale.com·
13

In 2018, Vector Capital invested about $50 million in KELA, acquiring approximately 25% at a $200 million valuation.

high·openai·apex-partners.comcalcalistech.com·
14

SpyCloud secured a $30 million Series C in 2021.

high·openai·flare.io·
15

Intel 471’s Series C round occurred in mid-2021 and was approximately $30 million.

high·openai·intel471.com·

Sources

40 unique sources cited across 111 claims.

Topics

identity exposure managementdark web threat intelligencestealer-log intelligencecredential intelligencetelegram threat collectionmid-market CTI gapsFlare.io whitespace

Share this research

Read by 9 researchers

Share:

Research synthesized by Parallect AI

Multi-provider deep research — every angle, synthesized.

Start your own research