All Vendors
tag_manager

Oktopost

Tag manager with aggressive behavioral biometrics, session recording, identity resolution, and persistent cross-platform tracking deployed pre-consent.

72 IOCs9 detections78% pre-consent7 sites
70
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Oktopost discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

9 detections across 7 sites78% pre-consent activity
CRITICAL

Pre-Consent Activity

Oktopost was observed loading and executing before user consent was obtained on 78% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps

disclosure

CRITICAL
They Claim

Pending claims extraction

Observed Behavior

CRITICAL severity - Broker (90) and Counselor (95) scores indicate catastrophic data exposure and consent violations. Tag manager architecture multiplies violations across ecosystem. Privacy policy almost certainly fails to disclose downstream vendor scope and social profile linking.

Customer Impact

What This Means For You

Removing Oktopost eliminates social media attribution and cross-platform analytics. Marketing loses unified view of social and web engagement. Tag management infrastructure failure disrupts multiple dependent systems. However, retention creates catastrophic liability: GDPR violations multiplied across all downstream vendors, identity resolution creating Article 9 special category data processing without consent, potential class action for social profile surveillance, regulatory enforcement for tag manager enabling systematic consent bypass.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Oktopost

  • IMMEDIATE consent gate before Oktopost tag manager loads - this is CRITICAL
  • Comprehensive audit of ALL downstream vendors loaded via Oktopost
  • GDPR Article 9 compliance review for social profile identification and behavioral biometrics
  • Session recording disclosure with explicit opt-in separate from general tracking consent
  • Data Processing Agreement review for social data sharing and identity graph construction
  • Privacy policy overhaul to disclose tag manager consent bypass scope

If You're Evaluating Oktopost

  • Defer Oktopost entirely until explicit consent with granular downstream vendor disclosure
  • Require vendor attestation on GDPR Article 5, 6, and 9 lawful basis for tag orchestration without consent
  • Assess alternative tag management with native consent integration
  • Consider social media analytics alternatives without cross-platform identity resolution
  • Demand technical controls preventing tag firing before consent confirmation

Negotiation Leverage

  • Oktopost contract enables tag manager consent bypass for all downstream vendors - this is EXISTENTIAL liability, demand technical consent enforcement
  • Social profile identification likely violates platform ToS and GDPR - negotiate immediate cessation and identity graph deletion
  • Session recordings across social and web properties may contain special category data - demand strict retention limits and PII redaction
  • Tag manager architecture makes downstream vendor violations YOUR liability - negotiate indemnification for consent bypass violations
  • Request complete inventory of ALL vendors activated via Oktopost and their data processing purposes
  • Demand proof of GDPR Article 9 lawful basis for behavioral biometrics and social identity resolution
Runtime Detections

Runtime Detections

5 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

BTI-C07Session Recording

Full session replay

BTI-C09Consent Bypass

Ignoring CMP signals

BTI-C14Identity Resolution

PII deanonymization

BTI-C15Tag Manager

Container/loader (neutral)

IOC Manifest

IOC Manifest

72 INDICATORS

Indicators of compromise across 3 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*cdn.www.oktopost.com/dist/vendor/wpp-4.1.0.js*
Tracking script
TRACK
*cdn.www.oktopost.com/dist/js/vendor.js*
Tracking script
TRACK
*cdn.www.oktopost.com/dist/js/views.js*
Tracking script
TRACK
*cdn.www.oktopost.com/dist/vendor/highlight.pack.js*
Tracking script
TRACK
*cdn.www.oktopost.com/dist/js/app.js*
Tracking script
TRACK
*static.oktopost.com/oktrk.js*
Tracking script
TRACK
static.oktopost.com
Tracking script
TRACK
cdn.www.oktopost.com/dist/js/vendor.min.js
Auto-extracted from scan
TRACK
cdn.www.oktopost.com/dist/vendor/highlight.pack.min.js
Auto-extracted from scan
TRACK
cdn.www.oktopost.com/dist/vendor/wpp-4.1.0.min.js
Auto-extracted from scan
TRACK
cdn.www.oktopost.com/dist/js/views.min.js
Auto-extracted from scan
TRACK
cdn.www.oktopost.com/dist/js/app.min.js
Auto-extracted from scan
TRACK
static.oktopost.com/oktrk.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Oktopost integrates social media platforms, marketing automation, CRM systems, and analytics tools. Tag manager architecture means visitor data flows to potentially dozens of downstream vendors simultaneously. Social media profile data merges with website behavioral data in real-time.
Loaded By (1)
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

72 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details