Skip to content

ThreatFabric

ThreatFabric is an Amsterdam-based mobile threat intelligence and fraud detection company whose SDK and research team track banking malware, scams, and account-takeover attacks for financial institutions.

Visit Website ↗ + Add to Compare
72/100Meaningful Innovator

Overview

ThreatFabric was founded in Amsterdam in 2015 by a group of malware researchers and has built its business around a specific, narrow observation: most large-scale mobile banking fraud is driven by a relatively small number of malware families and campaign infrastructures that get reused and re-packaged across targets. The company’s in-house intelligence team tracks these families — banking trojans, remote access trojans (RATs), overlay/accessibility-abuse malware, and increasingly scam and social-engineering campaigns — and feeds that intelligence into a Mobile Threat Intelligence (MTI) research feed and a client-side Fraud Risk Suite (FRS) SDK that banks and fintechs embed in their mobile apps.

The SDK approach lets ThreatFabric detect device-level compromise signals (overlay attacks, screen-sharing/remote-access abuse, malware presence) at the point of a transaction, rather than relying purely on post-hoc transaction-pattern analysis. That is the company’s core differentiation versus generic fraud-scoring platforms: it combines device telemetry with a threat-research function that is actively hunting new malware families, rather than only reacting to fraud patterns after losses occur.

ThreatFabric has grown steadily rather than explosively — around $12.6M in disclosed funding over several small rounds, roughly 56-57 employees, and backing that now includes a strategic investment from OneSpan (an established digital identity/authentication vendor), alongside earlier investors Rabobank-linked funds, Motive Partners, and 10x Founders. The OneSpan relationship in particular signals the company is being positioned as a specialized threat-intelligence layer that larger identity and fraud-prevention vendors can integrate with rather than build in-house.

Innovation Matrix Assessment

Innovation Velocity 8/10

The research team continuously discovers and reverse-engineers new mobile malware families before they are widely deployed, and has expanded its intelligence coverage from banking trojans into scam/social-engineering campaigns and APP fraud, indicating an active and evolving research and product pipeline.

Operational Value 7/10

A ten-year-old company with roughly 56-57 employees running production SDKs embedded in banking apps reaching over 60 million end users (per company disclosure) reflects genuine operational scale for a specialist vendor, though it remains a mid-sized company relative to broad fraud-platform incumbents.

Market Momentum 7/10

The 2025 strategic investment from OneSpan, on top of earlier backing from Rabobank-affiliated funds and Motive Partners, signals a larger, more established security vendor is betting on ThreatFabric's intelligence as a component technology, which is a meaningful third-party growth signal beyond self-reported metrics.

Category Disruption 7/10

Pairing device-level compromise detection (overlay attacks, remote-access/screen-sharing abuse) with a dedicated malware-research function is a genuinely different approach from generic post-transaction fraud scoring, and the company has been referenced in Gartner's Emerging Tech coverage for this category.

Real-World Efficacy 6/10

The claim of protecting 60+ million banking customers is vendor-reported and not independently audited; however, Gartner's inclusion of the company in Emerging Tech research on mobile fraud is a third-party signal of credibility, and the malware-family research the team publishes is independently verifiable technical work rather than marketing copy.

Enduring Relevance 8/10

Malware-assisted mobile banking fraud, remote-access scams, and APP fraud are large and growing problems for financial institutions worldwide, making this category directly relevant to bank and fintech CISOs and fraud teams.

Why CISOs Should Care

For CISOs and fraud leaders at banks and fintechs, ThreatFabric provides device-level malware and remote-access detection at the point of transaction, backed by a dedicated threat-research team rather than only backend transaction-pattern analytics.

What Makes It Different

Most fraud platforms focus on transaction-pattern analysis after the fact; ThreatFabric leads with device-side malware and remote-access telemetry combined with proactive threat-family research, aiming to catch compromise before a fraudulent transaction completes.

The Matrix Verdict

72/100 — MEANINGFUL INNOVATOR

A credible, narrowly-focused specialist in mobile banking malware and fraud intelligence with real financial-institution deployments and a notable strategic investor (OneSpan); its core user-count claims are vendor-reported, but the underlying threat research is independently verifiable and well-regarded in the fraud-prevention community.

Editorial Note: Claims vs. Verified Findings

The '60+ million banking customers protected' figure and the effectiveness of detection are vendor-reported and not independently audited in public sources. Funding totals ($12.6M), the OneSpan strategic investment, and Gartner Emerging Tech recognition are independently corroborated through press releases and third-party research trackers (Crunchbase, PitchBook, OneSpan investor communications).

Sources