The Shadowserver Foundation
- Company typePrivate
- Founded2004
- HeadquartersCalifornia City, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
The Shadowserver Foundation firmographics
Firmographics- Name
- The Shadowserver Foundation
- Legal name
- The Shadowserver Foundation, Inc.
- Website
- https://shadowserver.org
- Company type
- Private
- Founded year
- 2004
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
The Shadowserver Foundation industry classification
Industry- Product category
- Cybersecurity Threat Intelligence
- NAICS
- Investigation and Security Services (5616), Investigation and Personal Background Check Services (561611)
- SIC
- Services-Detective, Guard & Armored Car Services (7381), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Fraud, Cybercrime Investigations & Brand/Dark Web Monitoring (BPAKAHAO)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG)
Keywords
Where The Shadowserver Foundation is headquartered
LocationHeadquarters
- HQ city
- California City
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
The Shadowserver Foundation business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Technology or R&D, Personnel, Infrastructure, Operations
Revenue model
- Sponsorships: The Shadowserver Foundation receives funding from corporate sponsors who share their vision for a more secure Internet. They recently launched an Alliance Partnership program providing structured funding in exchange for additional benefits.
- Grants: Secured continued funding from the UK FCDO (Foreign, Commonwealth and Development Office) through March 2027 for Africa and Indo-Pacific capacity building projects. Additional grants from public sector partners.
- Charitable Donations: Receives charitable donations from individuals and organizations. Operating costs of approximately $5 million annually with less than 1% of subscribed entities currently providing financial support.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free Network Reports - All Subscribers |
Distribution channels4 records
Marketing channels7 records
The Shadowserver Foundation product offering
Product offeringCore offering
The Shadowserver Foundation is a nonprofit cybersecurity organization that collects vast amounts of threat data through internet-wide scanning, sinkhole operations, honeypots, sandboxes, and darknet monitoring, and delivers free daily remediation reports to vetted subscribers including network owners, National CSIRTs, and law enforcement. It maintains one of the world's largest malware repositories exceeding 1.9 billion samples and scans 3.7 billion IPv4 addresses daily across 148 ports.
Product overview
The Shadowserver Foundation operates as a nonprofit cybersecurity organization providing a suite of free threat intelligence services. The core offerings consist of Network Reporting (daily custom reports on cyber threats and vulnerabilities), Data Collection (maintaining one of the world's largest malware repositories with over 1.9 billion samples), and Investigation Support for law enforcement. Supporting capabilities include daily internet-wide scanning of IPv4/IPv6 addresses, sinkholing operations processing 145 million daily connections, and a Public Dashboard for visualizing aggregated threat data. Shadowserver also provides a RESTful Reports API for programmatic access and produces Special Reports during law enforcement operations. The organization serves over 6,900 vetted subscribers including network owners, National CSIRTs, and law enforcement agencies.
Differentiator
Problem solved
Functional benefit
Products and services
- Network Reporting Daily custom reports sent to vetted subscribers about cyber threats, malware infections, vulnerable services, and security exposures detected on their networks. Shadowserver sends tens of thousands of free daily remediation reports, with over 6,900 subscribers and 201 National CSIRTs covering 175 countries.
- Data Collection Shadowserver maintains one of the world's largest repositories of security information, storing trillions of historic malicious network connections and indexing many petabytes of threat data. Data sources include scans, sinkholes, honeypots, darknets, sandboxes, and blocklists. The malware repository contains over 1.9 billion samples.
- Investigation Support Provides CSIRTs and law enforcement agencies worldwide with technical and operational capabilities, investigative and attribution support, and relevant analysis for conducting effective local, regional, or international security investigations.
- Reports API RESTful API for programmatically accessing Shadowserver reports, using HMAC authentication. Enables automated report retrieval, listing available report types, downloading reports, and querying stored data.
- Public Dashboard A free public web-based dashboard for exploring aggregated country-level cyber threat intelligence data, including statistics on malware, DDoS attacks, botnets, IoT devices, and honeypot activity. Provides world maps, tree maps, time series, and visualization tools with shareable URLs.
Quantifiable outcome
- 146 million sinkhole connections processed daily
- +3 more outcomes
Companies that use The Shadowserver Foundation
Customer profileSegments4 records
Ideal customer profiles4 records
The Shadowserver Foundation technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
AI capability1 record
Feature6 records
The Shadowserver Foundation partnerships and signals
Strategic signalPartnerships
Twelve partnerships are on record, tiered core and minor.
- CrowdStrikecoreJoint takedown of the Glassworm botnet on May 26, 2026. Shadowserver worked with CrowdStrike and Google to simultaneously disrupt all four of Glassworm's command-and-control channels - Solana blockchain, BitTorrent DHT, Google Calendar, and VPS servers.
- GooglecoreJoint takedown of the Glassworm botnet on May 26, 2026. Coordinated disruption of all four C2 channels used by the botnet that targeted software developers.
- Europol/EC3coreShadowserver participated in the major international disruption of Tycoon 2FA phishing-as-a-service platform. Provided threat intelligence through Europol's Cyber Intelligence Extension Programme (CIEP) and supported domain seizure operations.
- MicrosoftcoreCollaborated on Tycoon 2FA disruption and Operation Endgame. Microsoft provided AI-assisted analysis to link malware families and legal action enabling unified takedowns.
- TrendAIcoreKey threat intelligence contributor to Tycoon 2FA disruption. Provided infrastructure mapping and actor attribution linking operation to threat actors using monikers 'SaaadFridi' and 'Mr_Xaad'.
- INTERPOLcoreShadowserver participated in INTERPOL's Operation Ramz across 13 MENA countries (October 2025-February 2026), resulting in 201 arrests and identification of 3,867 victims.
- ECOWAS CommissionminorShadowserver supported the Joint Platform for Advancing Cybersecurity (JPAC) in West Africa, a cyber capacity building project commissioned by German Federal Foreign Office and EU Commission.
- GIZ (Deutsche Gesellschaft für Internationale Zusammenarbeit)minorImplemented the JPAC West Africa project commissioned by Germany's G7 presidency and European Union Commission, with Shadowserver providing cybersecurity insights and recommendations.
- Global Cyber AlliancecorePart of the Common Good Cyber Fund secretariat along with CyberPeace Institute and Shadowserver Foundation, supporting nonprofits protecting the internet.
- CyberPeace InstitutecorePart of the Common Good Cyber Fund secretariat supporting nonprofits protecting the internet with coordinated efforts from G7 members.
- The Hague Humanity HubminorPartner in non-profit consortium launching national cyber resilience pilot for NGO sector in the Netherlands, along with CyberPeace Institute, Connect2 Trust Foundation, and Shadowserver.
- Connect2 Trust FoundationminorPartner in non-profit consortium for NGO sector cyber resilience pilot in the Netherlands.
Scale indicators9 records
Recent moves6 records
Expansion highlights5 records
The Shadowserver Foundation competitors and assessment
Company assessmentBroad incumbents
- Mandiant (Google Cloud): Mandiant, now part of Google Cloud, provides frontline incident response, threat intelligence, and cybercrime investigation services. It overlaps with Shadowserver's investigation support and botnet takedown capabilities but serves enterprise and government customers on commercial terms.
- Recorded Future (Insikt Group): Recorded Future operates a commercial threat intelligence platform that ingests data from across the internet to provide actionable intelligence to enterprises and governments. While commercial, it serves many of the same CSIRT and law enforcement use cases as Shadowserver, with greater analytics and paid SLAs.
- Kaspersky (GReAT / Threat Intelligence): Kaspersky's Global Research and Analysis Team publishes extensive threat intelligence and partners with law enforcement on major cybercrime operations, including Operation Ramz alongside Shadowserver. It offers overlapping malware research and cybercrime investigation capabilities as part of a broader cybersecurity portfolio.
Emerging players
- Group-IB: Group-IB is a private threat intelligence and cybercrime investigation vendor with strong presence in EMEA and APAC. It is explicitly named as a partner alongside Shadowserver in Operation Ramz and offers comparable botnet tracking and attribution services to commercial clients.
Direct peers
- AbuseIPDB: AbuseIPDB is a community-driven project that maintains a central database of malicious IP addresses reported by network operators. It overlaps with Shadowserver's network reporting and data collection functions, particularly around identifying abusive infrastructure for remediation.
- Team Cymru: Team Cymru is a threat intelligence company operating a global sensor network and offering botnet, DDoS, and cybercrime investigation data. It is explicitly named as a partner in Shadowserver's Operation Ramz collaboration and provides highly comparable threat intelligence services to CSIRTs and enterprises.
- PhishTank: PhishTank is a community-based collaborative clearinghouse for phishing data, providing a free, shared database of verified phishing URLs. It shares Shadowserver's nonprofit, public-benefit approach to community threat data sharing and serves a partially overlapping CSIRT and network operator audience.
- SANS Internet Storm Center: The SANS Internet Storm Center is a nonprofit cyber threat monitoring and early warning service that aggregates incident data from a global community of security professionals. It serves a similar community-oriented threat intelligence function and shares Shadowserver's free, public-benefit operating model.
- Spamhaus Project: Spamhaus is a nonprofit organization that tracks spam, malware, and phishing operations and provides real-time blocklists widely used by networks and email providers. It is highly comparable as a nonprofit, data-driven threat intelligence provider serving network operators globally.
- CERT Division (Carnegie Mellon / SEI): CERT/CC at Carnegie Mellon's Software Engineering Institute is a federally funded R&D center focused on cybersecurity incident response, vulnerability analysis, and CSIRT coordination. It shares Shadowserver's nonprofit, public-benefit mission and serves a similar CSIRT and government audience.
Market position
Strengths1 record
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
The Shadowserver Foundation social profiles
Digital presenceThe Shadowserver Foundation compliance and trust
Trust signalCompliance2 records
The Shadowserver Foundation financial estimates
Financial estimateRevenue estimate
Valuation estimate
The Shadowserver Foundation leadership team
Management profileNumber of profiles
Profiles2 records
The Shadowserver Foundation funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
The Shadowserver Foundation M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about The Shadowserver Foundation
What does The Shadowserver Foundation do?
The Shadowserver Foundation is a nonprofit cybersecurity organization that collects vast amounts of threat data through internet-wide scanning, sinkhole operations, honeypots, sandboxes, and darknet monitoring, and delivers free daily remediation reports to vetted subscribers including network owners, National CSIRTs, and law enforcement. It maintains one of the world's largest malware repositories exceeding 1.9 billion samples and scans 3.7 billion IPv4 addresses daily across 148 ports.
Is The Shadowserver Foundation a public or private company?
The Shadowserver Foundation is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was The Shadowserver Foundation founded?
The Shadowserver Foundation was founded in 2004. It employs 11 to 50 people.
Where is The Shadowserver Foundation based?
The Shadowserver Foundation is headquartered in California City, United States, in the North America region.
How does The Shadowserver Foundation make money?
Three revenue lines are on record. Sponsorships are the primary driver. The others are grants and charitable Donations.
Who are The Shadowserver Foundation's main competitors?
Broad incumbents on record are Mandiant (Google Cloud), Recorded Future (Insikt Group) and Kaspersky (GReAT / Threat Intelligence). Group-IB is listed as an emerging player. Direct peers are AbuseIPDB, Team Cymru, PhishTank, SANS Internet Storm Center, Spamhaus Project and CERT Division (Carnegie Mellon / SEI).
Does The Shadowserver Foundation have an API?
Yes. Shadowserver provides a RESTful API for accessing reports. The API uses HMAC (hash-based message authentication code) for authentication, requiring an API key and secret. Users can query available report types, list downloadable reports, download specific reports, and query stored data. The API is available to report recipients who request an API key. Reports are delivered in CSV format. Developer documentation is at www.shadowserver.org/what-we-do/network-reporting/api-documentation.
What industry is The Shadowserver Foundation in?
The Shadowserver Foundation's product category is Cybersecurity Threat Intelligence. Its primary akta.pro industry code is BPAKAHAO, Fraud, Cybercrime Investigations & Brand/Dark Web Monitoring, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 5616 and its SIC code is 7381.