
BlackFog Adds Advanced Insider Threat Protection to Anti Data Exfiltration Platform
SAN FRANCISCO – 30 April 2025 – BlackFog, today unveiled significant updates to its AI based ransomware prevention and anti data exfiltration (ADX) platform, introducing new baseline activity monitoring, to protect organizations from advanced persistent threats involving variable dwell time, living off the land (LotL) attacks and insider threats.
With bad actors continuing to remain latent for months – and sometimes years – before launching full-scale attacks, detecting these attacks is becoming crucial in the fight against ransomware. Similarly, new threats from insiders are becoming more routine, with a combination of disgruntled employees and ransomware groups adopting new tactics such as recruiting employees by force or inducement.
To combat these threats BlackFog automatically trains every device over seven to thirty days, searching for variations in baseline activity. If any event exceeds a predefined threshold, a flag is raised within the management console. BlackFog’s algorithms adapt continuously to each organization’s environment, accommodating differences in time zones and workdays (weekdays vs. weekends) to ensure accurate detection of suspicious activity.
“With the increasing costs of remediation, fines and loss of business now exceeding 1 million dollars it is becoming critical to protect not only customer data, but all your digital assets from the threat of extortion.” said Dr. Darren Williams, Founder and CEO of BlackFog. “With more than 95% of all ransomware attacks now involving data exfiltration it is more critical than ever to protect your data.”
BlackFog’s ADX technology represents a significant advancement in the fight against ransomware, delivering a vital layer of security beyond traditional defenses such as firewalls and EDR solutions. Offering comprehensive coverage across Windows, macOS, Chrome, Android and iOS, BlackFog ensures 24/7 defense without requiring human intervention. By proactively blocking emerging AI-driven threats, BlackFog strengthens organizational security with an essential new layer designed to address the evolving threat landscape.
About BlackFog
BlackFog is the category-defining vendor in anti data exfiltration (ADX). Founded in 2015, the company invented ADX on the thesis that the endpoint is the only control point capable of stopping data from leaving an organization, an architectural bet that has now been validated across three exfiltration vectors: ransomware, shadow AI, and autonomous AI agents. BlackFog’s endpoint-native platform protects more than 500 enterprises, government agencies, and critical infrastructure operators worldwide.
The company is the publisher of the annual State of Ransomware report and the BlackFog/Sapio Shadow AI Research, the most-cited primary research in the category. BlackFog’s recognition includes the teiss Awards 2026, the AI Excellence Award 2026, the Cybersecurity Excellence Awards 2026, and the Cybersecurity Breakthrough Award. Headquartered in San Francisco with international operations in London and Belfast. Learn more at blackfog.com.
Media Contact:
Share This Story, Choose Your Platform!
Related Posts
The State of Ransomware: April 2026
BlackFog's state of ransomware April 2026 measures publicly disclosed and non-disclosed attacks globally.
BlackFog Q1 2026 Ransomware Report: Only 1 in 9 Ransomware Attacks Made Public as Data Exfiltration Hits 96%
BlackFog Q1 2026 Ransomware Report reveals only 1 in 9 attacks are disclosed as data exfiltration hits 96% worldwide.
2026 Q1 Ransomware Report
BlackFog’s 2026 Q1 Ransomware Report - Ransomware Remains Relentless with Data Exfiltration Holding at 96%
Shadow AI and Governance: Why Traditional Control Is Failing CISOs
Shadow AI and Governance: Why traditional controls are failing CISOs as AI adoption accelerates, increasing risk and reducing visibility.
Ransomware in Energy and Utilities: The Real Story Behind the Attacks
Ransomware in energy and utilities is rising, combining disruption, data theft, and extortion across critical infrastructure.
Oracle Breach: What Happened and Why It Matters
The 2025 Oracle breach exposed millions of records across three separate incidents. Learn how attackers got in, which industries were hit, and how to protect your organization.






