Group-IB
Threat intelligence and cybercrime investigation firm originally founded in Moscow, now headquartered in Singapore following its 2019 relocation.
Visit Website ↗Overview
Group-IB was founded in Moscow in 2003 by Ilya Sachkov and Dmitry Volkov and built a strong reputation in cybercrime investigation, threat intelligence, and digital forensics, including extensive work tracking ransomware and financially motivated threat actors. In 2019 the company relocated its global headquarters to Singapore, with support from Singapore’s Cyber Security Agency, a move that predated and later took on additional significance amid the geopolitical and sanctions environment following Russia’s 2022 invasion of Ukraine. In a widely reported 2021 case, Group-IB co-founder Ilya Sachkov was arrested in Russia on treason charges, a development independently covered by international press and relevant context for evaluating the company’s ownership and jurisdictional history.
Group-IB’s platform combines threat intelligence, digital forensics tooling, and fraud-protection products, drawing on the company’s long history investigating cybercriminal groups to attribute campaigns and track infrastructure. Its threat intelligence has been cited in independent reporting on ransomware groups and cybercrime markets over many years.
The company today operates as a privately held, Singapore-headquartered entity with a global customer base, though its Russian origins and the Sachkov case remain a relevant part of its ownership history that prospective customers in sensitive sectors may wish to independently review.
Innovation Matrix Assessment
Continued expansion of threat intelligence and fraud-protection product lines since relocating to Singapore, per company and press reporting.
Long history of cybercrime investigation and threat-actor attribution gives its intelligence practical, investigation-grounded depth.
No major recent disclosed VC funding rounds were found; momentum signals are limited to government-grant support and continued market operation rather than institutional investment.
Threat intelligence and cybercrime investigation is an established category the company has operated in for two decades, rather than a newly disruptive model.
Its research has been independently cited in international press coverage of ransomware groups and cybercrime markets over many years.
Cybercrime and fraud intelligence remain relevant, though the company's complex ownership history and jurisdictional relocation are factors some enterprise buyers weigh carefully.
Why CISOs Should Care
Group-IB's two decades of cybercrime investigation experience gives its threat intelligence practical grounding in real criminal infrastructure and actor tracking, useful for fraud and ransomware-focused security teams.
What Makes It Different
Its intelligence is built on direct cybercrime investigation and law-enforcement-adjacent casework rather than purely passive data collection, though prospective customers should independently review its ownership history and jurisdictional relocation.
The Matrix Verdict
60/100 — INCREMENTAL INNOVATOR
A long-established threat-intelligence firm with genuine investigative depth, tempered by a complex corporate and jurisdictional history that merits independent due diligence; a middle-tier entry overall.
Editorial Note: Claims vs. Verified Findings
The 2019 Singapore relocation and Ilya Sachkov's 2021 arrest in Russia are corroborated by independent press coverage; current funding structure and ownership details beyond the Singapore CSA grant were not fully verifiable in this research and should be treated as an open due-diligence item.
Sources
Alternatives to Group-IB
Unknown Cyber Inc.
Malware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Pentera
Automated security validation platform that safely runs real attack techniques against production environments to prove which exposures are…
CrowdStrike
Publicly traded endpoint and cloud security leader whose Falcon Exposure Management module extends its platform into AI-driven vulnerability…
Reality Defender
Deepfake and synthetic media detection company offering real-time detection across voice, video, image, and text for enterprises and…
Recorded Future
Threat intelligence platform aggregating open, dark web, and technical sources into real-time risk scoring; acquired by Mastercard in…