All Vendors
data_enrichment

Hithorizons

Hithorizons is a data enrichment platform with a VRS of 80, combining low Oracle (15), maximum Broker (100), and severe Counselor (95) threats. The platform deploys behavioral biometrics, cross-domain sync, consent bypass, identity resolution, and tag manager infrastructure to enrich contact records with behavioral and demographic data.

54 IOCs1 detections100% pre-consent1 sites
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Hithorizons discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

1 detection across 1 site100% pre-consent activity
CRITICAL

Pre-Consent Activity

Hithorizons was observed loading and executing before user consent was obtained on 100% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps

pending

UNKNOWN
They Claim

Unknown

Observed Behavior

Requires claims extraction via CDT

Customer Impact

What This Means For You

Sales and marketing teams using Hithorizons for contact enrichment face three critical liabilities: (1) Data quality corruption as probabilistic matching creates false enrichment that pollutes segmentation, (2) Competitive intelligence leakage as contact data feeds the platform's cooperative improving competitor enrichment accuracy, (3) Severe GDPR exposure from behavioral tracking, identity resolution, and consent bypass creating per-contact violation risk. The platform's data sharing model makes it impossible to provide individuals with meaningful transparency about data sources.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Hithorizons

  • Demand contractual transparency on enrichment data sources and matching methodology
  • Require data processing agreement explicitly prohibiting contact data sharing across customer base
  • Implement consent-first deployment where behavioral enrichment only occurs after explicit opt-in
  • Configure CRM integration to log all enrichment data sources for GDPR Article 15 subject access requests

If You're Evaluating Hithorizons

  • Request third-party audit of consent bypass mechanisms and cross-domain tracking practices
  • Evaluate alternative enrichment providers with first-party data sources and documented consent flows
  • Consider whether enrichment accuracy (after correcting for probabilistic matching errors) justifies competitive intelligence leakage
  • Assess GDPR compliance posture with legal team before renewal given identity resolution without consent

Negotiation Leverage

  • Hithorizons VRS 80 = Broker (100) + Counselor (95) threat. Contact data sharing = competitive intelligence leakage. Demand exclusive data processing.
  • Identity resolution (BTI-C14) without consent violates GDPR transparency requirements. Contacts must be notified of enrichment; request technical remediation.
  • Cross-domain sync (BTI-C08) enables tracking across properties. Require documentation of all cookie syncing domains and data flows.
  • Behavioral biometrics (BTI-C06) appended to contact records = special category data risk. Minimize behavioral enrichment fields to reduce exposure.
  • Data cooperative model means your contact intelligence improves competitor enrichment. Negotiate data minimization or seek alternatives.
  • Ask: What enrichment data is shared across customers? How are match rate false positives handled? What is the data source documentation for GDPR compliance? Expect vague answers.
Runtime Detections

Runtime Detections

5 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Mouse tracking and interaction patterns captured across web properties feed behavioral enrichment fields appended to contact records.

BTI-C08Cross-Domain Sync

Identity stitching

Impact: Cookie syncing across multiple domains enables contact tracking across unrelated websites, violating privacy expectations and ePrivacy requirements.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Contact enrichment continues without explicit user consent, violating GDPR transparency obligations and creating per-record violation liability.

BTI-C14Identity Resolution

PII deanonymization

Impact: Anonymous visitor linking to known contacts enables persistent tracking and profiling that individuals cannot detect or control.

BTI-C15Tag Manager

Container/loader (neutral)

Impact: Client-side tag deployment creates third-party script execution environment enabling comprehensive contact activity capture.

IOC Manifest

IOC Manifest

52 INDICATORS

Indicators of compromise across 4 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*www.hithorizons.com/eu/dist/main.js*
Tracking script
TRACK
*www.hithorizons.com/eu/dist/chunks/multiselectfilter.component-DuCLF-X6.js*
Tracking script
TRACK
*www.hithorizons.com/eu/dist/chunks/rxjs-hsFLViLs.js*
Tracking script
TRACK
*www.hithorizons.com/eu/dist/chunks/signalr-C4vZ8GKh.js*
Tracking script
TRACK
*www.hithorizons.com/eu/dist/chunks/layout.controller-D-FVYqmO.js*
Tracking script
TRACK
*www.hithorizons.com/eu/dist/chunks/home.controller-BtZ2RfxH.js*
Tracking script
TRACK
www.hithorizons.com/eu/dist/main.js
Auto-extracted from scan
TRACK
www.hithorizons.com/eu/dist/chunks/layout.controller-D-FVYqmO.js
Auto-extracted from scan
TRACK
www.hithorizons.com/eu/dist/chunks/multiselectfilter.component-DuCLF-X6.js
Auto-extracted from scan
TRACK
www.hithorizons.com/eu/dist/chunks/rxjs-hsFLViLs.js
Auto-extracted from scan
TRACK
www.hithorizons.com/eu/dist/chunks/signalr-C4vZ8GKh.js
Auto-extracted from scan
TRACK
www.hithorizons.com/eu/dist/chunks/home.controller-BtZ2RfxH.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Hithorizons operates within the data enrichment ecosystem alongside ZoomInfo, Clearbit, and Cognism. The platform likely participates in a data cooperative where enrichment data from one customer improves match rates for others, creating systematic competitive intelligence sharing. Integration with CRM and marketing automation platforms creates bidirectional data flow where enriched contacts are used for targeting and engagement tracking feeds back to enrich future records.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

54 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details