close
Jump to content

IOActive

From Wikipedia, the free encyclopedia
IOActive, Inc.
IndustryComputer Security
Founded1998
Headquarters,
Area served
Worldwide
Key people
Jennifer Sunshine Steffens[1]
Websitehttps://ioactive.com

IOActive is a cybersecurity consulting firm that provides security research and testing services. [2] The company was founded in 1998 by Joshua J. Pennell in Seattle, Washington. [3] It originated from an ethical hacking group that participated in the DEF CONCapture the Flag” competition. [3] The organization later transitioned to providing security services to private sector clients, leading to the formation of IOActive.[3]

IOActive expanded beyond its original Seattle base to establish offices and research facilities in North America, Europe, and the Middle East.[4] The company has reported operations in more than 30 countries, with offices including Seattle, Atlanta, London, Madrid, and Dubai. [2]

In 2008, Jennifer Sunshine Steffens joined IOActive and was appointed chief executive officer later that year.[3] IOActive is a privately held company and has conducted research on security vulnerabilities in areas including industrial control systems, transportation technologies, and hardware devices.[2]

Research and publications

[edit]

IOActive conducts security research focused on identifying vulnerabilities in hardware, software, and connected systems.[2] The company maintains research facilities, including hardware and embedded systems laboratories, to support technical analysis of security issues.[5] Its research has examined topics including industrial control systems, transportation technologies, semiconductor security, and emerging computing platforms.[2]

IOActive publishes its findings through technical reports, white papers, blog posts, and conference presentations. The company’s research publications have addressed topics such as artificial intelligence security,[6] hardware fault injection, and secure boot mechanisms.[7] Research is often disclosed following coordination with affected vendors, and the company publishes advisories related to identified vulnerabilities.[2]

Notable publications by IOActive researchers include analyses of automotive cybersecurity risks,[8] hardware and semiconductor attack techniques,[9] avionics systems,[10] satellite communications security,[11] and biometric authentication technologies.[12] These publications have been presented at industry conferences including Black Hat, DEF CON, and the RSA Conference.[2]

Notable research and impact

[edit]

IOActive researchers have contributed to several publicly reported security demonstrations and vulnerability disclosures across multiple industries. In 2010, researcher Barnaby Jack demonstrated an attack on automated teller machines (ATMs) that allowed remote manipulation of cash dispensing.[3]

In 2012, IOActive researchers identified vulnerabilities in certain wireless-enabled medical devices, including implantable cardiac devices, that could be accessed using radio-frequency communication under specific conditions.[3]

IOActive has also conducted research on industrial control systems and smart infrastructure, including studies of smart meters and urban traffic systems that identified vulnerabilities related to unencrypted communications.[2]

In 2015, researchers associated with IOActive participated in a widely reported demonstration of remote exploitation of a Jeep Cherokee, showing that vulnerabilities in connected vehicle systems could allow control of certain vehicle functions.[13]

IOActive researchers have also published analyses of aviation and satellite communication systems, including potential attack paths within aircraft networks and vulnerabilities in satellite communication terminals.[14]

Additional research has examined vulnerabilities in hardware and embedded systems, including automated card shuffling devices used in casinos.[15][16]

In several cases, disclosures by IOActive researchers have been followed by vendor patches, regulatory attention, or changes in industry security practices.[2]

Global presence

[edit]

IOActive operates offices and research facilities in North America, Europe, and the Middle East.[4] Its listed locations include Seattle, Atlanta, London, Madrid, and Dubai.[4]

The company’s Seattle location includes a hardware laboratory, and IOActive has also described research facilities associated with embedded device and silicon security work in Seattle and Madrid.[4][2] IOActive has reported operations in more than 30 countries.[2]

Leadership and notable personnel

[edit]

IOActive is led by chief executive officer Jennifer Sunshine Steffens, who joined the company in 2008 and was promoted to CEO later that year.[3][17]

Notable current and former personnel have included researchers working in hardware security, industrial control systems, transportation systems, embedded systems, and medical device security. Former IOActive researcher Barnaby Jack was known for public demonstrations involving automated teller machine vulnerabilities and research into wireless-enabled medical devices.[18][19]

Other IOActive researchers have been associated with work on smart city infrastructure and satellite communications security, including Cesar Cerrudo and Ruben Santamarta.[20][21]

IOActive researchers have presented findings at security conferences including Black Hat, DEF CON, and the RSA Conference.[2]

Certifications and affiliations

[edit]

IOActive has held accreditation from CREST for penetration testing services.[22][23] CREST is an international not-for-profit accreditation and certification body for the technical cybersecurity industry.[24]

IOActive has also participated in initiatives related to public infrastructure and smart city security. In 2015, IOActive was listed among the companies and organizations involved in the launch of Securing Smart Cities, a non-profit initiative focused on cybersecurity issues affecting connected urban systems.[20][25]

References

[edit]
  1. ^ "TEAM – IOActive". Retrieved 2023-07-14.
  2. ^ a b c d e f g h i j k l "Who We Are". IOActive. Retrieved 2026-04-19.
  3. ^ a b c d e f g "Jennifer Steffens: cybersecurity and the rise of smart device hacking". The Independent. Retrieved 2026-04-19.
  4. ^ a b c d "Contact". IOActive. Retrieved 2026-04-19.
  5. ^ "Contact". IOActive. Retrieved 2026-04-19.
  6. ^ "The Security Imperative in Artificial Intelligence". IOActive. Retrieved 2026-04-19.
  7. ^ "Research". IOActive. Retrieved 2026-04-19.
  8. ^ "Commonalities in Vehicle Vulnerabilities (2022 Update)". IOActive. Retrieved 2026-04-19.
  9. ^ "IOActive Silicon Security Services". IOActive. Retrieved 2026-04-19.
  10. ^ "Reverse Engineering of Certified Avionics: Collins Pro Line Fusion". IOActive. Retrieved 2026-04-19.
  11. ^ "Cyberattacks on SATCOM: Understanding the New Risks". IOActive. Retrieved 2026-04-19.
  12. ^ "Facial Recognition Security Research" (PDF). IOActive. Retrieved 2026-04-19.
  13. ^ Greenberg, Andy (2015-07-21). "Hackers Remotely Kill a Jeep on the Highway—With Me in It". Wired. Retrieved 2026-04-19.
  14. ^ "Cyberattacks on SATCOM: Understanding the New Risks". IOActive. Retrieved 2026-04-19.
  15. ^ "Shuffle Up and Deal: Analyzing the Security of Automated Card Shufflers". IOActive. Retrieved 2026-04-19.
  16. ^ Greenberg, Andy. "Researchers Show How to Hack a Casino's Automated Card Shuffler". Wired. Retrieved 2026-04-19.
  17. ^ "Interview: Jennifer Steffens, CEO of IOActive". Infosecurity Magazine. 2016-12-28. Retrieved 2026-05-05.
  18. ^ Finkle, Jim (2013-07-26). "Famed hacker Barnaby Jack dies a week before hacking convention". Reuters. Retrieved 2026-05-05.
  19. ^ Greenberg, Andy (2012-07-26). "Meet the hacker who can break into ATMs and pacemakers". Forbes. Retrieved 2026-05-05.
  20. ^ a b Kovacs, Eduard (2015-05-27). "New Global Initiative Aims at Securing Smart Cities". SecurityWeek. Retrieved 2026-05-05.
  21. ^ "Security flaws let hackers hit in-flight and at sea WiFi". Axios. 2018-08-08. Retrieved 2026-05-05.
  22. ^ "IOActive Awarded CREST Accreditation for its Penetration Testing Services". IOActive. 2018-09-11. Retrieved 2026-05-05.
  23. ^ "IOActive, Inc Services". CREST. Retrieved 2026-05-05.
  24. ^ "Cyber Security Services, Accreditations & Training". CREST. Retrieved 2026-05-05.
  25. ^ "Securing Smart Cities: Leading Security Experts Join Forces to Make Modern Cities Safer". Kaspersky. 2015-05-27. Retrieved 2026-05-05.