
Flashpoint is a global leader in threat intelligence and risk prevention, providing meaningful intelligence that enables organizations to confront cyber threats, fraud, and physical security risks. Headquartered in New York, Flashpoint has established itself as the trusted partner for governments and Fortune 1000 enterprises. The company's platform, Flashpoint Ignite, integrates various intelligence streams, including Cyber Threat Intelligence (CTI), Vulnerability Intelligence (powered by VulnDB), and Brand Intelligence. By combining sophisticated automated data collection with human-powered analysis from experts fluent in over 35 languages, Flashpoint delivers actionable insights that go far beyond standard automated feeds. Following the acquisition of Risk Based Security in 2022, Flashpoint solidified its position as the premier source for vulnerability data, making VulnDB the cornerstone of its risk management ecosystem.
Flashpoint was founded in 2011 by Josh Lefkowitz and Evan Kohlmann, who aimed to provide visibility into the deepest corners of the internet where threat actors operate. Simultaneously, Risk Based Security (RBS) was founded in 2011 in Richmond, Virginia, by security veterans, including Jake Kouns. RBS focused on providing high-quality, independent vulnerability and data breach intelligence, with VulnDB becoming its flagship product. The two companies shared a vision of intelligence-led security. In January 2022, Flashpoint acquired Risk Based Security, successfully merging RBS's industry-leading vulnerability and breach data with Flashpoint's deep-web threat intelligence to create a unified risk prevention powerhouse.
Flashpoint has been backed by several high-profile venture capital and private equity firms throughout its growth. Notable investors include Audax Private Equity, Georgian, Greycroft, TechOperators, and K2 Intelligence. In 2021, the company announced a significant growth investment from Audax Private Equity, which facilitated the acquisition of Risk Based Security (RBS) in early 2022 and Echosec Systems later that year. This backing has allowed Flashpoint to scale its operations globally and continuously invest in AI-driven technologies to enhance its intelligence platform. While exact valuation figures are often private, Flashpoint is recognized as one of the largest and most well-funded independent threat intelligence companies in the industry.
Flashpoint's primary offering is the 'Flashpoint Ignite' platform, which serves as a centralized hub for various intelligence modules. The core modules include Vulnerability Intelligence (VulnDB), which provides deep insights into over 415,000 flaws; Cyber Threat Intelligence (CTI), which monitors threat actor forums and illicit marketplaces; and Brand Intelligence, which protects against brand impersonation and executive threats. Additionally, they offer 'Flashpoint Flow' for automated workflows and 'Managed Attribution' for safe investigative browsing. For the public sector, they provide specialized National Security intelligence. These offerings are available via a SaaS portal, custom data feeds (CDF), and a robust API for seamless integration into SIEM, SOAR, and GRC tools.
Flashpoint has expanded its geographic footprint significantly since its inception, moving from its New York roots to establish a global presence. The company has major offices in Washington D.C., and London, and has aggressively expanded into the Middle East with offices in Dubai (Dubai Internet City) and Riyadh. Their regional expansion is supported by partnerships with local distributors like CyberKnight in the GCC. Furthermore, Flashpoint has localized its intelligence gathering, employing over 100 analysts who are fluent in more than 35 languages, ensuring they can monitor regional threats in their native context across Europe, Asia, and the Middle East.
In the last 18 months, Flashpoint has introduced several major enhancements to the VulnDB and Ignite platform. A standout addition is 'Ignite AI', an integrated AI assistant that helps analysts summarize large volumes of threat data and query intelligence using natural language. They also launched the 'Flashpoint Known Exploited Vulnerabilities' (FP KEV) list, which provides real-time tracking of flaws actively being weaponized in the wild. Other recent updates include enhanced 'Ransomware Likelihood' scores, improved MITRE ATT&CK mapping for vulnerabilities, and a new SBOM (Software Bill of Materials) analysis tool that allows organizations to upload and scan their software supply chain for known vulnerabilities directly within the platform.
Flashpoint fosters a culture of innovation, mission-driven work, and analytical excellence. The company emphasizes its 'people-first' approach, offering flexible remote and hybrid work environments. Their core values center on empowering teams to solve complex security problems, maintaining a high standard of integrity in data collection, and fostering a diverse and inclusive workplace. Flashpoint often highlights its commitment to the broader security community through research sharing and public service. The company's leadership is known for being accessible and for driving a vision where intelligence is not just a data point but a strategic asset that protects real-world lives and assets.
Flashpoint actively engages with the global security community through several channels. They host the 'Flashpoint National Security Solutions' (FNSS) advisory board and participate in major industry conferences like Black Hat, RSA, and GISEC. The company provides a wealth of free resources, including whitepapers, webinars, and the 'Intel Insights' blog, which analyzes major breaches and vulnerability trends. For users, they offer 'Flashpoint University', a comprehensive learning platform with certifications and training modules. They also maintain active relationships with researchers and open-source projects, often providing credit and feedback to vulnerability discoverers, thereby strengthening the overall security ecosystem.