frequently asked
Answers, in one place.
Everything we are asked most often about ransomware, Shadow AI, how Anti Data Exfiltration works, and getting BlackFog running in your environment.

- All
- AI Security
- Anti Data Exfiltration
- Compare
- Gangs
- General
- macOS
- Ransomware
- Ransomware Report
- Respond
- Threats
- Vision
- Vision General
- Vision Governance
- Vision Operation
ADX Vision maintains visibility of AI tools in use, tracks the data-handling terms behind each model, and blocks transfers that would breach policy, producing the evidence and control the Act expects, enforced on the endpoint rather than in a document.
No. Blanket bans push usage onto personal devices where there is even less visibility. The durable approach is to allow sanctioned AI while blocking the specific transfers that put data at risk, judged by what is being sent rather than which site it goes to.
Traditional DLP matches known patterns against known channels like email and USB. AI usage breaks those assumptions: data leaves inside encrypted browser sessions to destinations DLP has no reason to distrust. Effective AI security watches data movement on the endpoint, by behavior, before it is sent.
Shadow AI is the use of AI tools and assistants that an organization has not approved or does not monitor, such as employees pasting sensitive data into consumer chatbots. Because the data leaves as encrypted conversational text, traditional DLP and network tools rarely see it.
BlackFog focuses on the exfiltration step. ADX runs on the endpoint and blocks the unauthorized outbound transfer of data in real-time, by behavior rather than signatures. Stopping the theft removes the leverage behind double extortion before encryption or an extortion demand can follow.
Healthcare was the most-targeted sector in Q2 2026 at 26% of disclosed attacks (81 incidents), followed by services (15%) and government (10%). The United States absorbed 55% of disclosed incidents and Australia 18%, with organizations across 98 countries hit in total, underscoring ransomware’s global reach.
Only about 1 in 8 attacks ever becomes public. In Q2 2026 alone we identified 2,027 undisclosed attacks against 306 disclosed — 2,333 in total, of which 87% never surfaced publicly. We identify the undisclosed volume through continuous monitoring of ransomware leak sites.
In our Q2 2026 research, 97% of publicly disclosed ransomware attacks involved data exfiltration, the highest rate we have ever recorded. Data theft, not encryption, is now the primary source of leverage in an attack.
Double extortion is the now-dominant model in which attackers first exfiltrate sensitive data, then encrypt systems, and finally threaten to publish or sell the stolen data. Because the information is already gone, restoring from backup no longer removes the threat, which is why 97% of attacks now involve data theft.
Yes. Additional analytics, policy controls, and classification insights are in development.
Yes. Ongoing updates will increase coverage as the AI landscape evolves. No agent updates are required as new LLM platforms are added.
Yes. Pricing scales with deployment size.
ADX Vision is offered as a standalone or an add-on to the ADX platform.
Protections remain active even without network connectivity. It will not protect against locally run LLM’s because data is not actually leaving the device.
No. It is engineered for lightweight, efficient, on-device analysis.
Yes. To non approved LLM’s.
Yes. It monitors AI activity even when embedded within familiar applications.
Yes. By blocking all but licensed LLM’s you can prevent sensitive data being sent to systems that automatically train against your data.
Yes. Administrators can review AI interaction history and trends within events.
Yes. Administrators can receive immediate event alerts when unauthorized AI interaction occurs.
Yes. Its on-device model inherently supports privacy-first requirements.
No. Only device activity is recorded and aggregated in the cloud to provide the size and scope of organizational AI use. No prompts are recorded.
Minimal operational data required for security alerts and reporting. No sensitive data is sent to the cloud.
Yes. By preventing sensitive data from leaving the environment, ADX Vision supports AI governance, privacy, and regulatory controls.
Yes. Policies can be applied at granular levels across departments, roles, or devices.
Yes. Administrators can define approved and unapproved AI tools.
Yes. ADX Vision is an extension of the ADX platform and has been designed to work both independently and as part of the wider ADX platform which prevents additional cybersecurity threats such as ransomware.
At time of launch, ADX Vision is available for Windows. macOS and Linux will follow in early 2026.
No. The analysis and prevention occur directly on the device.
ADX Vision is deployed at the endpoint level using BlackFog’s standard lightweight agent. It is quick and easy to deploy and has been designed to work seamlessly with other cybersecurity products.
The user is prevented from accessing the LLM and sending the data, IT administrators will be able to see the blocked action in the BlackFog console.
No. Organizations can allow approved AI tools while blocking unauthorized or risky ones.
Popular large language models (LLMs), AI-powered productivity tools, browser-based AI interfaces, and embedded AI features within enterprise applications.
ADX Vision monitors real-time endpoint activity to identify data flowing to AI applications, models, and interfaces.
With AI tools becoming mainstream, most organizations experience Shadow AI activity, even if they are unaware. Employees often use AI tools to increase productivity without understanding the risk.
Many AI models store and learn from user inputs. When sensitive data is shared, it can be retained outside organizational control, leading to IP exposure and compliance violations.
Shadow AI refers to the use of unapproved or unmonitored AI tools by employees, often without IT or security oversight.
Any organization using or evaluating AI tools, particularly those with strict regulatory, compliance, privacy, or IP protection requirements.
The rapid rise of AI tools created an urgent need for visibility and controls around how enterprise data is shared. ADX Vision extends BlackFog’s award-winning ADX platform to protect against this new category of data exfiltration.
As organizations increasingly adopt AI tools, Shadow AI has emerged as a significant risk. ADX Vision prevents sensitive data from being shared with unapproved or ungoverned AI systems.
ADX Vision is BlackFog’s next-generation solution designed to detect and prevent unauthorized data sharing with AI tools. It provides real-time visibility and control over AI interactions on every endpoint.
Yes. BlackFog 5.0.1 or later supports Chromes QUIC network protocol. This is a low level protocol that uses UDP instead of TCP for web browsing. While BlackFog operates across the entire operating system using UDP and TCP, special handling is required for Chrome.
If you are using the Privacy relay feature under System Settings > iCloud > Private Relay you will notice less blockings than normal. This is because your system is redirecting traffic through iCloud and effectively hiding the destination of requests by some applications. While BlackFog will still pickup nefarious bad actors on other levels of the operating system it will not see general browser activity through Safari.
Yes. The macOS edition can operate with any other software, including VPNs, and runs seamlessly in the background.
Yes. BlackFog operates natively on both Intel and M1 based macs as long as they use macOS 13 or later.
No. To get the best protection BlackFog has designed each agent to work natively on each operating system. It is highly optimized to leverage the hardware using low level API’s. A specific version that operates on iPads will be available soon.
Apple takes security and privacy very serious. As a result they demand full disclosure when a product requires elevated permissions or installs system extensions like BlackFog requires. When you manually deploy the mac edition you will be asked to approve 3 things.
- Installation of a system extension
- Activate the network extension, and finally
- Allow the BlackFog filter
There is no way to bypass these dialogs, as they are mandated by Apple to ensure the user is aware of what it is happening. If you are system administrator and using a management solution you can bypass these dialogs by installing the package remotely.
Yes. We price our macOS edition the same as our Windows edition. The goal is to ensure you can cover your entire enterprise at the same cost, no matter what platform or mix of platforms you use.
The macOS platform has undergone many changes over the last few years that has now made it possible to provide similar functionality to our Windows platform without reverting to raw kernel drivers. Apple has introduced system extensions that can be managed and deployed more seamlessly within the enterprise. We also took the opportunity to rewrite our entire architecture in Swift to future proof the product on macOS and provide rapid updates. This will ensure better support and ultimately make macOS safe and secure from escalating threats.
BlackFog has closely aligned the macOS edition with its Windows counterpart. It has 95% feature parity and uses the same AI based algorithms. It shares the same rulesets and additionally includes macOS specific threats.
BlackFog supports macOS 13 (Ventura) and above, this includes macOS 14 (Sonoma) and macOS 15 (Sequoia). It natively supports both Apple M Series and Intel processors running 64 bits.
While financial gain is usually the primary motivation driving large cybercrime groups, some may also have political or ideological motives beyond just monetary profits. However, most large, sustained cybercrime operations still require substantial funding to cover operational costs. So even for groups with additional non-financial goals, the financial aspect of their activities remains very important to the continued survival and growth of the organization.
More sophisticated, well-funded cybercrime groups do dedicate some resources towards research and development activities. This could include developing new exploits, evasion techniques, malware variants and updating toolkits based on emerging threats and weaknesses that get detected.
Some groups are able to become bigger due to their success and profits. Groups that are particularly successful at compromising systems, stealing data or funds are likely to reinvest those profits into expanding their operations. This enables them to take on more projects and recruit/pay more members. Large groups may also be able to dedicate resources to specialized tasks like development, operations security, and money laundering.
Having a clear, comprehensive ransomware response plan is essential for any business. This should include details on what everyone’s responsibilities are, how to make and recover backups and what reporting steps are required.
Law enforcement agencies in the US and UK advise against paying ransomware demands, as this provides further encouragement to cybercriminal gangs. Businesses that do are more likely to come under further attack than those that refuse.
Costs for ransomware include direct lost business, ransomware payments, recovery expenses, investigation and future mitigation, fines from regulators and class action lawsuits. In 2023, this added up to an average total of $5.13 million, compared with $4.45 million for data breaches as a whole.
Traditional antivirus software may have difficulty detecting the latest advanced attacks. Monitoring tools that analyze behavior within the network are therefore essential in spotting ransomware attacks.
Every business is at risk of ransomware, regardless of size or industry. However, the most common targets include firms in the healthcare, education or public services sectors.
The majority of ransomware attacks enter networks via email. Phishing attacks and human error are also among the main causes of ransomware.
Traditional forms of ransomware include locker and crypto malware. However, the most common form today is double extortion ransomware, which leverages data exfiltration.
Ransomware refers to any malicious software (malware) that aims to disrupt operations by deleting, encrypting or otherwise compromising key files and demanding payment for the restoration of access.
BlackFog is often described as ‘set it and forget it’ by our customers. It offers 24/7 automated protection, so you don’t need to deploy extra resources to manage it. In addition, BlackFog offers a vCISO productfor those companies who would prefer to have it managed for them.
We would suggest an audit of the tools you are currently using. If you are currently spending a portion of your budget on a traditional solution such as AV for example, it’s worth noting that AV is now embedded into every modern operating system, so it’s a very easy decision to cut this expenditure and focus on newer technologies like Anti Data Exfiltration.
This is exactly why you need to invest in cybersecurity. Cybercriminals are most often looking for low hanging fruit like smaller under-resourced organizations.
Every organization regardless of size, vertical or location has data worth protecting. Cybercriminals don’t discriminate and they often look for low hanging fruit, which is in many cases those businesses who don’t feel they are worthy of being a target.
Many organizations are using 20+ cybersecurity tools to prevent attacks, yet many of them still make front page ransomware and data breach news. The goal of any cybercriminal is data theft and with 89% of ransomware attacks exfiltrating data in 2022, ADX has become an essential technology.
BlackFog’s Breach Monitoring module allows an organization to monitor its exposure over the Dark Web with regular domain scanning. With more than 10 billion accounts exposed over the Dark Web, BlackFog ensures you are notified in real time when a breach has occurred. The module also enables benchmarking against industry peers and easy report generation.
BlackFog’s unique Threat Hunting module provides threat intelligence for all organizations, where previously only organizations with large technology budgets and teams of experts were able to benefit from this type of threat intelligence. This module takes threat intelligence to a new level by providing detailed insights into each identified threat, enabling organizations to stay ahead of cybercriminals as the threat landscape evolves. With insights such as crowdsourced impact, confidence level and MITRE classification, BlackFog’s Threat Hunting capabilities are able to identify false positives, investigate threat origins and provide peer-based risk analysis.
With 89% of ransomware attacks now exfiltrating data, you need to ensure you have a tool that prevents data exfiltration and ransomware. When you look at the many global corporations making ransomware headlines on a regular basis, it’s clear that many of these tools aren’t successfully blocking attacks. Preventing data exfiltration offers an additional layer of protection which has become a ‘must have’ technology.
We know that any cybercriminal intent on infiltrating a device or network will eventually find a way in, regardless of the perimeter defense solutions that are in place. ADX looks at the problem in a new way. By making the assumption that bad actors will get into the network, it focuses on preventing them from leaving with an organizations data. No data exfiltration means no successful cyberattack.
The goal of any cyberattack is data theft. Adding an ADX solution to a security strategy ensures that there is nothing for an attacker to gain. Without data exfiltration there is no breach, no ransom and no extortion. When cybercriminals can’t steal data, they move on to the next target.
ADX works by investigating outgoing data on endpoint devices. This gives it a markedly smaller footprint than other solutions, such as firewalls or DLP, which examines incoming and outgoing traffic at the edge of the network. ADX solutions are lightweight enough to run on mobile devices and do not need to work on the corporate network. Instead of comparing traffic to a dictionary of attack signatures, ADX solutions use behavioral analytics to identify unusual behaviors on a user-centric basis. ADX limits the ability for users – including privileged users and administrators – to send sensitive data outside the network.
Pioneered by BlackFog, ADX is a technique used to prevent unauthorized data from leaving a device. By targeting multiple parts of the kill chain, ADX effectively blocks the activation and spread of cyberattacks. Since cyberattacks, especially ransomware focuses on data theft for extortion this has become an important technique to thwart modern polymorphic attacks that cannot be stopped by traditional anti-virus or EDR solutions.
BlackFog has been around since 2015 and is the leader in ADX, a new category for anti data exfiltration technology. BlackFog has been endorsed by leading analysts and received several industry awards, so you can trust ADX technology. Hundreds of global customers across all industry verticals trust BlackFog to secure their data and prevent cyberattacks.
Defensive based technologies aren’t effective at preventing the types of attacks we see today. If a cybercriminal really wants to infiltrate a device or network, they will be successful. Preventing cybercriminals leaving with your data is critical in preventing a cyberattack.
While cyber insurance has become a ‘need to have’ for many organizations, it is only part of a cybersecurity strategy. Cyber insurance may help with the cost of remediation from an attack, but it doesn’t offer any protection. Cyber insurers are also suffering from an exponential rise in claims and the industry is changing quickly to adapt. Policies are harder to get, more expensive, and may not pay out on ransomware attacks. It’s also worth noting that many insurers are mandating certain technologies such as ADX in order to qualify for coverage.
EDR / XDR solutions provide necessary endpoint protection as well as threat detection, investigation, and response by using threat intelligence and data analytics. BlackFog works well alongside these solutions but also offers some advantages over these technologies. Here are some main points to consider.
- AI powered EDRs can’t always provide persistent, protectable solutions for 100% threat detection whereas BlackFog uses behavioral analysis to identify and block suspicious activity before the attack begins.
- With EDR /XDR not all responses are automated, so human input and response is required. BlackFog is a fully automated on-device technology, meaning the action is taken immediately by the agent on the device. No human intervention required.
- Some EDR / XDR solutions do not provide cross platform protection and reporting. They also require “a push” to install updates, whereas BlackFog can work across most platforms with integrated reporting available from our Enterprise Console. Our updates are all done automatically via the on device agent.
- Traditional EDR / XDR requires specialized and dedicated staff. BlackFog does not require specialized staff to monitor or react to threats or attacks, eliminating the need for dedicated resources. Our Enterprise Console provides a centralized, easy to use view of what is happening across all devices in the organization.
- Most EDRs / XDRs are cloud based whereas BlackFog provides on device protection that does not require any cloud access to provide protection.
- EDR / XDR is not designed to prevent data exfiltration. Insider threats such as employee mistakes, credential theft and rogue employees require constant monitoring and intervention. BlackFog’s core function is preventing data exfiltration through outbound traffic analysis, restricting data leaving the device under specific, suspicious circumstances.
ADX has been specifically designed to be a zero trust solution as it prevents any code from unauthorized data exfiltration. BlackFog effectively validates a zero trust architecture by ensuring every application is doing exactly what it says it should. In an ideal world this would not be necessary, but latent code can activate at anytime as we have seen time and time again.
Data Loss Prevention (DLP) is one of the most popular legacy approaches to keeping sensitive data secure for organizations. A traditional network approach developed in the 1990’s, it struggles to accommodate the needs of the modern remote workforce. ADX builds on the technology behind DLP while making it more relevant to today’s workforce and security threats. BlackFog sits on the endpoint, so it doesn’t matter where employees are based. Unlike DLP which requires a strict set of policies which are difficult to implement and change, BlackFog is easy to deploy, and fully automated.
The short answer is NO. BlackFog is very conscious about privacy and we do not collect information about you. In fact, BlackFog makes you aware of what information other applications are collecting and where all your information is going (whether you have consented or not).
The only information that is sent to our servers is the IP address of the destination request so that we may geo-locate it for you and send back the result. We do not keep log files about this activity and the results are only consumed by BlackFog and cached locally for later use.
BlackFog utilizes different rule sets to protect your device. Updating BlackFog is managed within the application automatically. BlackFog periodically checks BlackFog servers for updated rules and downloads new ones as necessary. BlackFog uses SSL for all connections to its update servers. Please ensure you have all the relevant ports open to ensure it is working correctly in your environment.
In addition, BlackFog periodically provides application updates to providing additional features and bug fixes. The application checks for updates every few days and allows you to install the update if desired. Our enterprise console allows updates to happen automatically in the background with no user intervention.
BlackFog has been specifically designed to have little to no impact on your machine in terms of performance. If anything you should notice your machine is noticeably faster because it is preventing the transfer of vast amounts of information from your machine over the network.
From a CPU perspective BlackFog uses around 1-5% (depending on Operating System and processor) during normal network operation and 0% on idle. Your browser typically uses 20% or more depending upon the site you are visiting. BlackFog also uses only small amounts of other system resources such as memory and drive space.
From a system resource perspective BlackFog was designed to be very lightweight. In fact, the BlackFog executable occupies approximately 2MB of drive space and the whole package around 20MB. It has been developed in the same language as the underlying operating system and has no dependency on other runtime frameworks, so it is very fast.
BlackFog has a small memory footprint of around 25MB and uses less that 5% CPU at its peak. Routinely you will see it around 1-2% on a very active machine.
Anti-Virus products focus on what to do AFTER you have been infected. BlackFog focuses specifically on real-time network threat detection and preventing spyware and ransomware from infecting your machine in the first place. BlackFog works in conjunction with your existing AV solution. Just like you would go to the Dr. when you are sick, an AV solution will help you get better. BlackFog operates by preventing the sickness by decreasing your exposure to pathogens and boosting your immunity overall.
By proactively blocking threats and distribution networks using BlackFog’s pioneering anti data exfiltration we can eliminate over 99% of threats.
For an in depth look at our technology we highly recommend you look at our technology page.
FRee assessment
See the Shadow AI on your endpoints.
Run a free 14-day AI Discovery & Data Exposure
Assessment in your own environment.
