The Shadowserver Foundation is a nonprofit security organization working altruistically behind the scenes to make the Internet more secure for everyone.

Our Story

What We Do

We collect vast amounts of threat data, send tens of thousands of free daily remediation reports, and cultivate strong reciprocal relationships with network providers, national governments and law enforcement. We bring malicious activities and abusable vulnerabilities out of the shadows, expedite their remediation and help to better secure the Internet.

Find Out More
201

National CSIRTs depending
on our free daily reports, covering 175 countries and territories

1,115,000

unique malware samples ingested & analyzed every day by our sandboxes

1.9 billion+

malware samples in our malware repository

Who We Serve

National CSIRTs

We give CSIRTs the vantage point to understand the big picture of what’s happening on the networks they’re responsible for.

Industry Sectors

We work with business and tech firms, financial institutions and academia, to improve network security, enhance product capability, and advance threat research.

Law Enforcement

We partner with law enforcement to help protect victims, take down global cybercrime infrastructures and prevent attacks before they occur.

News & Insights

  • Shadowserver Critical Community Infrastructure Cyber Resilience Project August 5, 2026

    August 5, 2026 — The Shadowserver Critical Community Infrastructure (CCI) Project is designed to improve the cybersecurity posture of essential public-serving organizations across Central and Eastern Europe (CEE), with a special focus on Ukraine. The project will deliver free Cyber Threat Intelligence (CTI), training, and hands-on support to these underserved public good organizations, and is possible thanks to the support of Google.org.

    Read More »
  • StealC Historical Bot Infection Special Report June 25, 2026

    On Wednesday 24th June 2026, international law enforcement partners announced additional successful cyber crime disruption actions as part of the ongoing Operation Endgame initiative. This time the StealC infostealer and Amadey malware-as-a-service families were targeted.

    Read More »
  • SocGholish Compromised WordPress Sites Special Report June 18, 2026

    On Thursday 18th June 2026, international law enforcement partners announced another successful cyber crime disruption action. This time it targeted the SocGholish malware platform and threat actors.

    Read More »