Skip to content

Threat actor

SafeGraph

Last fetched

SafeGraph is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.

Description

SafeGraph is a data broker known for collecting and selling aggregated location data derived from mobile apps. The company has faced significant criticism for selling data related to visits to sensitive locations, such as abortion clinics, including Planned Parenthood facilities. This data, marketed under its "Patterns" product, tracks where visitors come from, how long they stay, and where they go afterward. In addition to its commercial ventures, SafeGraph has expanded its operations into government and military contracts. Notably, it secured a contract with the U.S. Air Force to provide data for purposes such as analyzing human activity for military operations. The company also markets its data for monitoring "adversaries" and supporting intelligence initiatives. SafeGraph's investors include In-Q-Tel, the VC arm of the CIA, Peter Thiel and the former head of Saudi intelligence.

Techniques by tactic

No ATT&CK techniques are recorded for SafeGraph in WhisperGraph.

Attributed infrastructure

None published. WhisperGraph carries no ATTRIBUTED_TO edge to SafeGraph today — this states the absence of a published link, not that SafeGraph has no infrastructure.

References

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from SafeGraph into its techniques, tactics and any attributed infrastructure.

Queries

Resolves the slug to this actor, merging every duplicate node sharing the same name.


MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
       a.references AS references, a.campaigns AS campaigns
LIMIT 25
Run yourself →

Techniques this actor uses, grouped by the tactic each one serves.


MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000
Run yourself →

Infrastructure publicly attributed to this actor.


MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.