All Vendors
abm
Bombora

Bombora

Claims to create "business profiles, not profiles of individuals" while collecting email addresses, hashed emails, device advertising IDs, and performing cross-device identity resolution across multiple browsers. Acknowledges selling personal information under CCPA.

161 IOCs100% pre-consent
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Bombora discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

100% pre-consent activity
CRITICAL

Pre-Consent Activity

Bombora was observed loading and executing before user consent was obtained on 100% of sites where it was detected.

GDPRePrivacy
HIGH

Compliance Claim Mismatch

False certification claims

HIGH

Scope Creep

Collection exceeds disclosed scope

Disclosure Gaps

Claims vs. Observed Behavior

6 gaps
Classified:BTI-X05BTI-X08

Identity Resolution Scope

GDPR Recital 26 (pseudonymous data) · CCPA §1798.140(o) (personal information)HIGH
They Claim

Bombora assigns UIDs to devices but states it does not identify individuals by name

Observed Behavior

UIDs combined with cookie syncing, hashed emails, and cross-device tracking create a persistent identity graph that effectively identifies individuals even without using names

Privacy policy verbatim: assigns UIDs, cookie syncing, user matching, hashed emails, cross-device tracking

Scope Creep

GDPR Art 5(1)(b) purpose limitation · CCPA §1798.100HIGH
They Claim

Bombora describes its scope as business-level Company Surge intent data

Observed Behavior

Privacy policy explicitly discloses cookie syncing, user matching, hashed email processing, cross-device tracking, and individual-level UID assignment - scope far exceeds business profiles

Privacy policy analysis, marketing vs policy comparison

Data Retention

GDPR Art 5(1)(e) storage limitation · CCPA §1798.100(a)MEDIUM
They Claim

Claims data is retained only as long as necessary for stated purposes

Observed Behavior

No specific retention period is disclosed anywhere in the privacy policy - the statement is circular and unenforceable

Full privacy policy review via CDT MCP, no numeric retention period found

Customer Impact

What This Means For You

Organizations deploying Bombora's Data Co-op tag on their properties are contributing visitor content consumption data to a shared intelligence pool that feeds competitors' demand generation. Publishers in the cooperative effectively surrender their audience behavioral data in exchange for aggregate intent scores. The cookie syncing and user matching disclosed in Bombora's privacy policy means that individual visitor identities can be correlated across the entire cooperative network - creating a surveillance mesh that no single publisher controls or fully understands. For companies BUYING Bombora Surge data: the intent signals driving your outbound campaigns are derived from a consent architecture that shows significant gaps (pre-consent GA4, phantom CMP banner, individual-level tracking behind corporate-level branding). If Bombora faces regulatory action or a cooperative publisher pulls out due to consent concerns, the data supply chain could be disrupted. The lack of specific data retention periods means historical behavioral data may persist indefinitely, creating ongoing liability for all cooperative participants.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Bombora

  • Audit your properties for the ml314.com/bombora.com tag and understand what data flows to the cooperative
  • Review your Bombora DPA for specific retention periods - their privacy policy provides none
  • Verify whether your consent architecture covers Bombora's tag deployment (their own CMP showed gaps)
  • Map which competitors receive intent signals derived from YOUR audience data via the cooperative
  • Confirm Bombora's IAB TCF registration covers your specific use case and jurisdiction

If You're Evaluating Bombora

  • Request a complete data flow diagram showing how your property data moves through the cooperative
  • Ask for specifics on cookie syncing partners and user matching methodology
  • Demand clarity on the netFactor/VisitorTrack integration and whether it applies to your data
  • Benchmark Bombora's consent architecture against your own compliance requirements
  • Evaluate whether the Data Co-op model creates acceptable competitive intelligence risk for your business

Negotiation Leverage

  • Bombora's own website fires GA4 pre-consent despite implementing Consent Mode v2 with denied defaults - this demonstrates their internal compliance standards and may indicate how they advise cooperative publishers
  • The Usercentrics CMP is loaded but no consent banner renders - ask whether this is the same CMP configuration recommended to cooperative members
  • Privacy policy explicitly discloses data sale under CCPA while marketing materials emphasize privacy-first cooperative model - use this gap as leverage for contractual protections
  • No specific data retention period is disclosed - demand contractual retention limits with deletion verification
  • netFactor (VisitorTrack) acquisition expanded capabilities from content consumption to visitor identification - ensure your DPA covers the combined entity's full capability set
  • IAB TCFv2.2 registration (ID 163) provides a baseline but does not cover all processing activities disclosed in the privacy policy - identify the gaps
  • Dual GTM containers suggest complex tag management that may not be fully reflected in their data processing disclosures - request tag audit documentation
Runtime Detections

Runtime Detections

4 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

BTI-C08Cross-Domain Sync

Identity stitching

BTI-C14Identity Resolution

PII deanonymization

BTI-C15Tag Manager

Container/loader (neutral)

IOC Manifest

IOC Manifest

160 INDICATORS

Indicators of compromise across 5 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

EXFIL
*bombora.com/wp-content/plugins/wp-data-access/assets/js/wpda_rest_api.js*
Data collection endpoint
TRACK
*bombora.com/wp-includes/js/jquery/jquery-migrate.js*
Tracking script
TRACK
*bombora.com/wp-content/plugins/fd-footnotes/fdfootnotes.js*
Tracking script
TRACK
*bombora.com/wp-includes/js/underscore.js*
Tracking script
TRACK
*bombora.com/wp-content/plugins/weglot/dist/front-js.js*
Tracking script
TRACK
*bombora.com/wp-includes/js/backbone.js*
Tracking script
TRACK
*bombora.com/wp-includes/js/jquery/jquery.js*
Tracking script
EXFIL
*bombora.com/wp-includes/js/wp-api.js*
Data collection endpoint
EXFIL
*bombora.com/wp-includes/js/api-request.js*
Data collection endpoint
TRACK
*bombora.com/wp-content/themes/bombora*/js/priority-menu.js*
Tracking script
TRACK
*bombora.com/wp-content/themes/bombora*/js/touch-keyboard-navigation.js*
Tracking script
TRACK
*bombora.com/wp-content/themes/bombora*/_assets/js/main.js*
Tracking script
TRACK
*bombora.com/wp-content/themes/bombora*/_assets/js/fancybox.umd.js*
Tracking script
TRACK
*bombora.com/wp-content/themes/bombora*/_assets/js/gsap.js*
Tracking script
TRACK
*bombora.com/wp-content/themes/bombora*/_assets/js/ScrollTrigger.js*
Tracking script
TRACK
*bombora.com/wp-content/plugins/optinmonster/assets/dist/js/helper.js*
Tracking script
TRACK
*bombora.com/cdn-cgi/challenge-platform/scripts/jsd/main.js*
Tracking script
TRACK
*bombora.com/cdn-cgi/challenge-platform/h/g/scripts/jsd/*/main.js*
Tracking script
EXFIL
*bombora.com/CcpaData-*-*.js*
Data collection endpoint
TRACK
bombora.com/wp-includes/js/jquery/jquery.min.js
Auto-extracted from scan
TRACK
bombora.com/wp-includes/js/jquery/jquery-migrate.min.js
Auto-extracted from scan
TRACK
bombora.com/wp-content/plugins/fd-footnotes/fdfootnotes.js
Auto-extracted from scan
TRACK
bombora.com/wp-includes/js/underscore.min.js
Auto-extracted from scan
TRACK
bombora.com/wp-includes/js/backbone.min.js
Auto-extracted from scan
EXFIL
bombora.com/wp-includes/js/api-request.min.js
Auto-extracted from scan
EXFIL
bombora.com/wp-includes/js/wp-api.min.js
Auto-extracted from scan
EXFIL
bombora.com/wp-content/plugins/wp-data-access/assets/js/wpda_rest_api.js
Auto-extracted from scan
TRACK
bombora.com/wp-content/plugins/weglot/dist/front-js.js
Auto-extracted from scan
TRACK
bombora.com/wp-content/themes/bombora2021/js/priority-menu.js
Auto-extracted from scan
TRACK
bombora.com/wp-content/themes/bombora2021/js/touch-keyboard-navigation.js
Auto-extracted from scan
TRACK
bombora.com/wp-content/themes/bombora2021/_assets/js/main.js
Auto-extracted from scan
TRACK
bombora.com/wp-content/themes/bombora2021/_assets/js/fancybox.umd.js
Auto-extracted from scan
TRACK
bombora.com/wp-content/themes/bombora2021/_assets/js/gsap.min.js
Auto-extracted from scan
TRACK
bombora.com/wp-content/themes/bombora2021/_assets/js/ScrollTrigger.min.js
Auto-extracted from scan
TRACK
bombora.com/wp-content/plugins/optinmonster/assets/dist/js/helper.min.js
Auto-extracted from scan
TRACK
bombora.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
Auto-extracted from scan
TRACK
bombora.com/cdn-cgi/challenge-platform/h/g/scripts/jsd/ea2d291c0fdc/main.js
Auto-extracted from scan
EXFIL
bombora.com/CcpaData-2a6f2974-be225a26.js
Auto-extracted from scan
TRACK
*bombora*.js
Tracking script
Ecosystem

Ecosystem & Supply Chain

Bombora operates a Data Cooperative model where 5,000+ publisher and B2B media partners deploy the Bombora tag (tag.ml314.com/tag.js or ml314cdn.com/tag.js) on their properties. This tag monitors content consumption patterns across the cooperative network, aggregating signals into Company Surge intent scores. The tag communicates with ml314.com infrastructure (historically Madison Logic's domain, retained after the 2015 spinoff). Bombora acquired netFactor (VisitorTrack) in 2019 and Signal HQ in 2020, expanding from passive content consumption monitoring into active visitor identification. On its own site, Bombora runs dual GTM containers (GTM-K7KS7KT and GTM-TLQP2KD), GA4 (G-WD6TZQQ4NP), NitroPack CDN, Cloudflare, and consent-gated HubSpot. The site runs on WordPress/WP Engine. Bombora is IAB TCFv2.2 registered (Vendor ID 163) and participates in the IAB Tech Lab Data Transparency Standard. Integration partners include major ABM platforms (6sense, Demandbase, TechTarget) and CRM/MAP systems where Surge data feeds demand generation workflows.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

161 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details