Constella Intelligence

Information Pollution Significantly Impacts Online Debates on COVID-19 in Latin America and the Caribbean, UNDP and Constella study warns

PANAMA and NEW YORK, March 24, 2022 /PRNewswire/ — Today, the United Nations Development Programme (UNDP) and Constella Intelligence released a first-of-its-kind joint publication that details some of the key debates that have been unfolding in the online public sphere of Latin America and the Caribbean around COVID-19 and reveals the risks that information pollution poses not only for the effectiveness of the pandemic responses but also for social cohesion and the functioning of governance systems.

The research publication titled, “Exploring COVID-19 online debates and information pollution in Latin America and the Caribbean” found that a significant amount of information pollution is created by repackaging, reframing, and reproducing content produced by mainstream media and that approximately 1.4% of the reviewed content in the region could be classified as information pollution. While the proportion may seem small, it corresponds to half a million items over four months, which has an outsized impact on vulnerable audiences. As part of the analysis, UNDP and Constella Intelligence took a deep dive into the significant volume of conversations related to COVID-19, revealing the true nature of online discussions during the pandemic to help identify vulnerabilities and inform strategies to counter the most harmful effects of information pollution.

The analysis explores the public digital sphere in Spanish and English languages from October 2020 to February 2021, capturing 37 million results from 4.4 million profiles across all public platforms including Twitter, Facebook, YouTube, Instagram, media domains, blogs, and other online communities. The report concludes that most of the information pollution originates outside the Latin American and the Caribbean region.

“UNDP has identified information pollution as a key issue that can affect multiple governance and development issues. In Latin America and the Caribbean, the battle against misinformation was already taking shape before COVID-19 and will likely continue to be a matter of significant concern for a long time to come. This report offers relevant insights based on new methods of research and analysis and provides actionable recommendations on how to promote information integrity in the short and long term,” said Luis Felipe López-Calva, UN Assistant Secretary-General and UNDP Regional Director for Latin America and the Caribbean.

The document recommends that all short and long-term responses to tackle information pollution should be carried out with human rights at the forefront. It is important that any solutions do not unfairly stigmatize users for legitimate use of the internet or unduly interfere with users’ human rights. To this effect, UNDP is supporting national partners to promote information integrity by strengthening the capacity of public institutions to promote access to reliable and accurate information sources; improving media capacity to effectively manage information pollution; increasing public resilience to information pollution; and developing evidence-based, proportionate and rights-based information integrity policies.

“The research conducted by Constella and the UNDP is a great example of the importance of public-private collaborations delivering insights into global and local trends emerging from the digital public sphere. That joint work is essential to halting the spread of multi-language information pollution. COVID-19 is just the tip of the iceberg,” said Alex Romero, Chief Operating Officer at Constella Intelligence.

The report also urges political leaders, government agencies, media, social media companies, civil society, religious and community leaders, influencers, and personalities to work together to counter information pollution regarding COVID-19, vaccines, and beyond in the region.

“This research is part of a global initiative to improve understanding on disinformation and how it impacts inclusive governance and peacebuilding in the contexts where UNDP operates. The knowledge we get from the report will be used not only in our regional responses but also to inform global policy discussions on the role of disinformation in the global south, which remains poorly understood”, says Arvind Gadgil, Director of UNDP’s Oslo Governance Center.

This initiative was supported and made possible by funding from the Government of Norway. Download the report here to gain insights into key social media trends such as where information pollution originates geographically, how it spreads within and across borders, and which narratives have been propagated most effectively.

ABOUT UNDP:
UNDP is the leading United Nations organization fighting to end the injustice of poverty, inequality, and climate change. Working with our broad network of experts and partners in 170 countries, we help nations to build integrated, lasting solutions for people and the planet. Learn more at www.undp.org or follow at @UNDP. 

Press Release

Constella Intelligence Launches Phishing and Botnet Protection With Real-Time Breach Alerting

LOS ALTOS, Calif., March 16, 2022 /PRNewswire/ — Constella Intelligence (“Constella”), a leading global Digital Risk Protection and Identity Threat Intelligence company, today announced the release of Phishing and Botnet Protection, a new service allowing for the real-time notification of personal data and credential harvesting. 

Constella Phishing and Botnet Protection is a unique service that allows partners the opportunity to alert their customers in real-time when their account credentials or personal data is being harvested, and before their stolen information is being used on the Deep and Dark Web. Phishing and Botnet Protection is an enhancement to Constella’s Intelligence API product. Until this release, no vendor has offered a real-time service around identifying credentials and personal information that have just been harvested by Phishing campaigns. 

“We are thrilled to be able to offer our partners this new service that will further ensure they are able to protect themselves and their customers from being victims of phishing and botnet attacks,” said Kailash Ambwani, CEO of Constella. “Phishing and Botnet Protection will be an essential addition to the array of products and services we offer for digital risk protection.” 

The two components, Phishing and Botnet, will work side-by-side through monitoring technology that detects and provides alerts when Constella’s end-user’s data has been stolen by phishing campaigns or botnet malware.   

With Phishing and Botnet Protection, partners and customers can immediately take protective measures to thwart a breach or abuse of the stolen information—minimizing the potential for financial loss and personal disruption. Customers of Phishing and Botnet Protection will also be prompted to reset passwords for compromised accounts before damage occurs and will have unique and immediate visibility into when they have been victims of an attack. This premium monitoring service will be immediately accessible for existing customers and can be effortlessly combined with other Constella Intelligence products to provide comprehensive monitoring and defense to further protect customers’ data and brands.   

“When consumers’ credentials, such as logins and passwords, are compromised in a breach, they often are not even aware that they’ve been compromised until after their credentials are spotted on the dark web, or after fraud occurs,” said Tracy Kitten, the Director of Fraud & Security at Javelin Strategy & Research. “Providing consumers with real-time, proactive notification of credential compromise, alerting them to change their passwords before their information appears on the dark web, will be essential in the coming years as phishing and botnet campaigns become more prevalent.” 

Press Release

Telco Sector Exposures Press Announce

Constella Intelligence Research Detects Significant Exposed Data Records Rampant Cyber Breaches for Top Fortune Global 500 Telecommunications Companies

PRESS RELEASE
LOS ALTOS, Calif., March 1, 2022 — Today, Constella Intelligence (“Constella”), a leader in Digital Risk Protection and Identity Threat Intelligence, announced the release of its Mobile World Congress 2022 Exclusive Report: Telcos & Digital Identity Cyber Risks. The report expands upon Constella’s 2021 Identity Breach Report, outlining new findings regarding exposures, breaches, and leakages within the telecommunications (“Telco”) sector. The analysis specifically reviewed the credentials of employees and executives from the top twenty Telco companies on the Fortune Global 500 list. Constella’s threat intelligence team analyzed data from January 2018 through September 2021, working to understand the digital vulnerabilities that Telco companies face due to exposed records through leakages and data breaches. Among the surface, deep and dark web, Constella’s team identified 4,873 breaches and leakages and 5,561,409 exposed records among Telco industry companies. These exposed records include attributes such as email addresses, passwords, phone numbers, addresses, and usernames connected to employee corporate credentials.“Our new findings highlight the prevalence of data breaches and leakages facing today’s remote workforce,” said Kailash Ambwani, the CEO of Constella Intelligence. “Unaddressed, this exposed data spells serious digital risk for global Telco companies undergoing increasing digitization and transitioning to remote, virtual workforces and operations.”The circulation of sensitive employee data grants threat actors access to execute a wide variety of cyberattacks, including impersonation, phishing, account takeover, and several others that can lead to more sophisticated attacks such as ransomware or coordinated disinformation campaigns.“The Telco sector is in a unique position due to its broad customer base and the desire for ubiquitous data access. As the world’s primary connector between people and information, Telco companies touch nearly everyone’s personal and account information at some point,” said John Masserini, a senior research analyst with TAG-Cyber. “A breach of just one Telco employee’s corporate credentials creates a vulnerability that can lead to a massive data breach affecting millions of customers worldwide.”

 

This report uncovers the widespread prevalence of breaches and exposures related to the corporate credentials of employees and executives in the Telco sector, detailing the serious risks emerging from exposed sensitive data that negatively impact customers, employees, executives, and brands.

Key Findings:

  • Constella detected over 5.6M exposed records from almost 5K breaches and data leakages pertaining to corporate credentials since 2018 across the world’s largest Telco companies. The number of exposed records skyrocketed in 2021, accounting for 57% of the 5.6M exposed records.
  • Exposure of Telco executives and their personal information is widespread – 43% of Telco executives have had their corporate credentials exposed in a breach or leakage since 2018.

Telco employees are likely incurring risk by using corporate credentials on non-essential sites like gaming, social media, and others. 13% of breaches occurred on third-party domains classified as “gaming.” Over two-thirds (67%) of the breaches and leakages identified include personally identifiable information (PII), and diverse attributes. Constella continuously monitors social media as well as the surface, deep and dark web for exposed corporate credentials and other PII with automatic alerts once a threat is detected to protect employees, executives, and companies from a targeted attack.

Download Mobile World Congress 2022 Exclusive Report: Telcos & Digital Identity Cyber Risks.

ABOUT CONSTELLA INTELLIGENCE

Constella Intelligence is a global leader in Digital Risk Protection, safeguarding millions of global users at some of the world’s largest organizations, including many of the largest global Telco companies. Our solutions are a unique combination of proprietary data, technology, and human expertise to anticipate, identify, and remediate targeted threats to your people, your brand and your assets at scale—powered by the most extensive breach and social data collection on the planet, from the surface, deep and dark web, with over 100B attributes and 66 billion curated identity records spanning 125 countries and 53 languages.

Executives and key employees like privileged IT personnel and HR are the new attack vector for cybercriminals as they have top-tier access to sensitive information which can lead to credential theft, account takeover, and a ransomware attack.

Try our Exposure Risk Tool to understand your level of risk and find out if you, your company, or your employees have been exposed – FREE.

Digital Exposure Report Finds Widespread Cyber Vulnerabilities for Pharma Companies & Executives on Fortune Global 500 List

LOS ALTOS, Calif., Jan. 26, 2022 /PRNewswire/ — Today, Constella Intelligence (“Constella”), a leader in Digital Risk Protection and Identity Threat Intelligence, released their Pharma Sector Exposures Report: 2018-2021 Digital Risk Findings and Trends. This report builds on insights from Constella’s 2021 Identity Breach Report, and includes new and additional findings pertaining to exposures, breaches, and leakages within the Pharmaceutical (Pharma) sector, specifically focusing on employees and executives from the top twenty Pharma companies on the Fortune Global 500 list.

This industry-specific report examines data from January 2018 through September 2021. By analyzing identity records from data breaches and leakages found in open sources and on the surface, deep, and dark web, Constella’s threat intelligence team identified 9,030 breaches/leakages and 4,549,871 exposed records—including attributes like email addresses, passwords, phone numbers, addresses, and even credit card and banking information—related to employee corporate credentials from the companies analyzed. The proliferation and circulation of this sensitive employee data endows threat actors with the necessary resources to execute a wide range of cyberattacks, including impersonation, phishing, account takeover and several others that can lead to more sophisticated attacks such as ransomware or coordinated disinformation campaigns.

Report Finds Widespread Cyber Vulnerabilities for Pharma Companies & Executives on Fortune Global 500 ListPost this

“The Pharma sector’s role within the healthcare ecosystem, especially with today’s public health needs, only emphasizes how critically important it is that these companies protect themselves from cyber threat actors,” said Constella Intelligence CEO, Kailash Ambwani. “As we have seen before, only one exposed employee credential can lead to a company having their systems or supply chain shut down by a data breach leading to a ransomware attack, resulting in a shortage of life-saving supplies.”

Pharma companies are high-value targets for threat actors because of their intellectual property and proprietary information as well as their vital role in developing life-saving treatments. The transition towards remote workforces, driven by the pandemic, amid accelerating operational digitization has increased the overall digital footprint of companies in this sector, leading to greater digital vulnerabilities and risk.

This report uncovers the widespread prevalence of breaches and exposures related to the corporate credentials of employees and executives in the Pharma sector, detailing the serious risks emerging from exposed sensitive data that negatively impact customers, employees, executives, brands, public health, and the healthcare system.

Key Findings:

  • Constella identified over 4.5M exposed records from nearly 10K breaches and leakages exposing the corporate credentials of employees from the top twenty Global Fortune 500 Pharma companies between 2018 and 2021.
  • Nearly two-thirds of breaches and leakages in the Pharma sector since 2018 include personally identifiable information (PII), with the most common attributes being email, password, name, username, phone number, address, date of birth, and credit card information.
  • A sample of 78 executives (C-suite profiles) from top Pharma companies found that 58% of executives have had their corporate credentials exposed in a third-party breach or leakage since 2018.
  • Approximately 59% of total breaches and 76% of total exposed records identified in the report occurred since 2020, signaling both are escalating in the Pharma sector at an alarming rate.   

Constella continuously monitors social media and the surface, deep, and dark web for exposed corporate credentials and other PII with automatic alerts once a threat is detected to protect employees, executives, and companies from a targeted attack.

Download Pharma Sector Exposures Report here.

Press Release

Constella Partners with Anti-Human Trafficking Intelligence Initiative (ATII) in First Annual Darkwebathon

The Anti-Human Trafficking Intelligence Initiative (ATII) will host their first annual Darkwebathon from December 6-10, a 5-day virtual hackathon event with the goal of investigating data from the Darkweb and uncovering actionable intelligence that can be used to effectively handle real-world cases involving crimes on the Darkweb. This program will bring industry data experts together to equip law enforcement and federal officials with fact-based content to address the highly challenging and dynamic nature of cybercrimes in human trafficking, modern slavery, and child sex abuse material.

The Darkwebathon will utilize ATII’s licensed dark web platform, Hades, by having over 300 registered event participants competing to identify and profile potential traffickers. “In 2021, ATII has had tremendous success in mapping out organized criminal networks on the darkweb in addition to attributing cryptocurrency data in blockchain forensics applications and allowing cryptocurrency companies to map out their exposure to these darkweb entities.” said Larry Cameron, CISO of ATII. “We have uncovered and triaged a significant amount of data within the application and are now for a limited time allowing the public to assist with the investigations.” Outside of the event, ATII uses Hades in a much larger capacity as a way to detect child exploitation, CSAM, drugs, weapons, fraud, mixers/washers, money laundering or other illicit activity – in addition to human trafficking.

“This hackathon is critical in helping law enforcement agencies navigate the Darkweb for cybercrime,” said Aaron Kahler, Founder & CEO of ATII. “Our event allows participants to identify and profile potential traffickers, providing law enforcement agencies with real and actionable intelligence.

Those participating are from crypto exchanges, NGOs, BitATM, law enforcement, and members of academia. In addition to hundreds of participants, there are 14 sponsorship partners, many of which are industry leaders such as Constella Intelligence, a global leader in Digital Risk Protection, safeguarding 30M+ global users at some of the world’s largest organizations.

“We are proud to be an inaugural sponsor of the Darkwebathon,” said Constella Intelligence CEO, Kailash Ambwani. “This program provides Constella the opportunity to work with industry leaders and law enforcement, creating a united front in the fight against human trafficking issues on the dark web.”

Press Release

Digital Exposure Report Finds Widespread Cyber Vulnerabilities for Top 20 Fortune Global 500 Financial Services Companies

LOS ALTOS, Calif., Nov. 18, 2021 /PRNewswire/ — Today, Constella Intelligence (“Constella”), a leader in Digital Risk Protection and Identity Threat Intelligence, released their Financial Services Sector Exposure Report: 2018-2021 Findings and Trends. This report comes on the heels of Constella’s 2021 Identity Breach Report, and includes new and additional findings pertaining to exposures, breaches, and leakages within the financial services (Finserv) sector, specifically focusing on employees and executives from the top 20 Finserv companies on the Fortune Global 500 list.

This industry-specific report examines data from January 2018 through September 2021. By analyzing identity records from data breaches and leakages found in open sources, and on the surface, deep, and dark web, Constella Intelligence’s threat intelligence team identified 6,472 breaches or leakages and 3,367,059 exposed records related to employee corporate credentials from the companies analyzed. The proliferation and circulation of this sensitive employee data enables threat actors with the necessary resources to execute a wide range of cyberattacks, including ransomware, impersonation, phishing, account takeover, and several others.

Report Finds Widespread Cyber Vulnerabilities for Top 20 Fortune Global 500 Financial Services CompaniesPost this

“This report should be a wake-up call for every bank, insurance company, stock brokerage, credit card company, and financial institution that they are attractive and viable targets for cyber threat actors,” said Constella Intelligence CEO, Kailash Ambwani. “Companies and individuals must take new precautions to protect themselves from threats with high potential to target employees as a vector to inflict reputational and financial harm.”

Financial institutions are home to an individual’s most sensitive and personally identifiable information, and this report uncovers the widespread prevalence of breaches in the Finserv sector, detailing the serious damage than can be inflicted on customers, employees, executives, and brands.

Key Findings:

  • Constella identified over 3.3M exposed records from nearly 6.5K breaches and leakages between 2018 and 2021 from top 20 Global Fortune 500 Finserv companies analyzed.
     
  • Two-thirds of breaches and leakages in the Finserv sector since 2018 include PII, with the most common attributes being email (100%) and password (72%).
     
  • Finserv sector employees are incurring serious risk by using corporate accounts to register on entertainment, news, retail, gaming, and other technology and services sites.
     
  • 70% of C-suite executives profiled from Fortune Global 500 Finserv companies have had their corporate credentials exposed in a breach or leakage since 2018. Of those executives exposed, 98% have been exposed in breaches that include PII, and over 40% had their passwords exposed.

“Left unchecked, this exposed data spells serious digital risk for financial services companies of all sizes,” said Constella’s VP of Threat Intelligence, Sean Tierney, who has worked in various cyber threat roles for companies such as Morgan Stanley, JP Morgan Chase, and UBS. “It may seem that major institutions are too large to be seriously affected by cyber threats, but that is far from the case.”

Constella monitors social media and the surface, deep, and dark web for identity-related breaches and verifies the authenticity of those data sets. Click here to download the report.

Press Release

Partners with CDA for Cyber Crime Investigations in Banking

Cyber Defence Alliance partners with Constella Intelligence to Accelerate Cybercrime Investigations in the Banking Sector

PRESS RELEASE
LONDON, October, 27, 2021 — The UK’s Cyber Defence Alliance (CDA), has formed a partnership with Constella Intelligence to accelerate cyber-crime investigations in the banking sector and make use of cyber-crime fighting tools that leverage and champion OSINT data for the purposes of cyber investigations and threat attribution.

 

CDA is a not-for-profit organisation that works with member banks to jointly tackle cyber-crime and protect the public and financial sector from criminal activity.

Constella Intelligence is a global leader in Digital Risk Protection and has the most extensive breach and social data collection from the surface, deep and dark web on the planet, with over 100 billion attributes and 66 billion curated identity records spanning 125 countries and 53 languages.

The goal of the partnership is to help identify cybercriminals targeting global banks and disrupt fraud in the sector by maximizing the intelligence reach to protect bank staff, customers, and assets from cybercrime. This partnership will enable greater data sharing between key cyber intelligence stakeholders and streamline the processes and technology used to escalate criminal activity to law enforcement to protect the banking sector.“The partnership with Constella enables the CDA to accelerate cyber-crime investigations. Their services allow us to identify criminal activity with a breadth of investigative tools,” said Steven Wilson, CEO of the CDA. “Our mission is to continue to protect our members, disrupt criminal activity, and make customers safer.”

The partnership helps keep Constella and the CDA abreast of technological innovations and investigative approaches to anticipating and identifying cyber-crime in the financial sector. It will combine Constella’s agile product development approach with daily exposure to cyber-crime investigation approaches. Thus, the CDA is championing OSINT automation and Constella’s powerful investigative technology for the frontline.

“Partnering with CDA reinforces our commitment to fighting cyber-crime, specifically in the banking sector,” said Kailash Ambwani, CEO of Constella Intelligence. “We look forward to fostering a strong relationship with CDA and continuing to help in the global mission of defeating digital risk.”

ABOUT THE CYBER DEFENCE ALLIANCE (CDA)

— The Cyber Defence Alliance (CDA) is a non-profit public-private partnership that works collectively and collaboratively across the financial sector and with law enforcement to pro-actively share information to fight cybercrimes and threats. They analyse information turning it into actionable intelligence for the banking sector and law enforcement.

— The CDA is led by the industry for industry, with the rationale that an attack against one bank is an attack against all and that security is not a competitive advantage. The cornerstone of the CDA is trust and trusted relationships, which leads to the sharing of information and resources.

— Their mission is to support the sector to proactively detect, deter, disrupt, and stop emerging threats, to share resources/expertise and knowledge to increase maturity levels and resilience and to support law enforcement action against criminal networks threatening the industry and its customers.

ABOUT CONSTELLA INTELLIGENCE

Constella Intelligence is a global leader in Digital Risk Protection that works in partnership with some of the world´s largest organizations to safeguard what matters most and defeat digital risk. Our solutions are a unique combination of proprietary data, technology, and human expertise to anticipate, identify, and remediate targeted threats to your executives, your brand, and your assets at scale—powered by the most extensive breach and social data collection from the surface, deep and dark web on the planet, with over 100B attributes and 45 billion curated identity records spanning 125 countries and 53 languages.

Constella Intelligence Contact:
Lindsay Whyte
lindsay.whyte@constellaintelligence.com

CDA Contact:
Moustafa Fadel Ahmed
Moustafa.Fadel@cda.financial

Constella Intelligence Launches Dome Platform Introducing Employee & Executive Digital Protection

LOS ALTOS, Calif., Sept. 30, 2021 /PRNewswire/ — Constella Intelligence (“Constella”), a leading global Digital Risk Protection and Identity Threat Intelligence company, today announced the launch of Dome. Constella Dome is a modular platform designed to give enterprises a holistic view of the external risks to their people, brands, and assets. The first two modules are Dome Employee Protection and Dome Executive Protection. Constella plans to release additional modules under the Dome platform.

The Dome Employee and Executive Protection modules allow organizations to continuously monitor all employees and executives for external digital risks such as compromised corporate credentials and exposed PII data that can be used for account takeovers, supply chain attacks, ransomware, executive impersonation, and much more.

Only vendor offering a digital risk protection platform that can scale to continuously monitor thousands of employees.Post this

Current industry services are designed to monitor a select number of executives or high-profile individuals due to their reliance on manual processes and human oversight, forcing security teams to choose which few executives to monitor. To help customers address the rapid expansion of digital threats that target other employees as well as executives, Constella has brought to market, for the first time, an automated digital risk protection platform, augmented by human intelligence with our world-class analyst team, that can scale to continuously monitor thousands of employees in an organization. Dome can monitor employees in areas such as IT, HR, and finance who have access to critical systems and sensitive data.

Constella Dome Employee and Executive Protection enables organizations to identify and respond faster to digital risks, such as compromised credentials or leaked confidential data, because it continuously monitors thousands of proprietary and public data sources across the social, surface, deep, and dark web. Constella’s data lake contains over 100 billion attributes and 45 billion curated identity records, the largest in the industry, and the Dome platform provides external digital risk visibility across 53 languages and 125 countries.

With Dome, organizations can leverage real-time alerts to quickly identify and block the use of compromised credentials and initiate takedown of personal information before they can be weaponized and lead to account takeovers, impersonations, reputational attacks, and in extreme cases, cyber or physical threats that put an executive’s or employee’s family at risk.

Dome integrates with an organization’s existing IT and security infrastructure such as Active Directory, Security Information and Event Management (SIEM)/Security Orchestration, Automation, and Response (SOAR), and ticketing systems, enabling rapid provisioning and quick remediation. Dome’s automated monitoring, human curation, and customizable threat models that can address a company’s unique policies or requirements ensure that organizations get relevant, high-value insights on a constantly evolving external threat landscape.

“We are excited to take traditional executive protection a step forward by scaling it to protect thousands of employees,” said Kailash Ambwani, CEO of Constella Intelligence. “This platform will allow companies the opportunity to monitor a diversity of digital sources and no longer be forced to choose which executives or employees can be included in digital threat monitoring.”

Dome’s single pane of glass console delivers a holistic view of external risks across the entire enterprise. The Dome platform seamlessly integrates with existing provisioning systems, security tools, and response workflows to improve current systems and processes. Integration with Active Directory ensures fast onboarding and auto-provisioning of employees, executives, and VIPs to monitor. Integration with enterprise platforms, including SIEM and SOAR, will enrich the data in those tools to improve overall threat detection accuracy. ServiceNow integration will speed existing response workflows.

Press Release