Highlights
- 20% analyst workload alleviated
- ~24 hours from detection to takedown
- 62 attack surface detections in a single campaign
- under a day from deployment to first actionable data
Background
SoFi grew from a student loan refinancer into one of the largest mobile banks in the world. That reach carries a cost that never shows up on a balance sheet, because every campaign, product, and sponsorship widens the surface fraudsters can imitate.
The Problem
The phishing wasn’t crude. One campaign ran on a clean, plausible domain that wasn’t even a typosquat, the kind a prospective customer clicks without a second thought. Another targeted SoFi’s Hong Kong office and first-time crypto investors, hosted behind a foreign ISP known for ignoring abuse reports. All of it landed on analysts already sorting through many varieties of phishing every day, and for a bank, the thing actually at risk is trust.
The Solution
SoFi deployed Bolster AI web monitoring as one layer of defense in depth, with onboarding done in under a day. Logo detection and optical character recognition catch impersonation that domain-only tools miss entirely, and every detection arrives with the hosting provider, IP, registrar, and country of hosting an analyst needs to make a fast call. On that lookalike domain, hosting country was the signal that broke it open. Bolster AI then works the registrars, hosts, CDNs, and cloud providers to force removal, with the Bolster AI SOC on hand for complex cases.
The Results
The Hong Kong site came down in roughly 24 hours, which meant getting a normally unresponsive ISP to move. Across the program, Bolster AI has taken about 20% off intelligence analyst Megan Capdeville’s workload.
“It has reduced our workload by about 20%, and that’s 20% of your life that you would otherwise not get back.” — Megan Capdeville, Intelligence Analyst, SoFi