All Vendors
advertising

Pubmatic

Pubmatic is an advertising vendor with a VRS of 80, flagged for 5 BTI codes including session recording (C07), cross-domain sync (C08), and identity resolution (C14). The supply-side platform deploys comprehensive visitor tracking across publisher inventory, creating moderate signal corruption (15) but maximal cost attribution exposure (100) and full legal tail risk (100).

108 IOCs54 detections22% pre-consent53 sites
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Pubmatic discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

54 detections across 53 sites22% pre-consent activity
HIGH

Pre-Consent Activity

Pubmatic was observed loading and executing before user consent was obtained on 22% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

1 gaps

pending

UNKNOWN
They Claim

Unknown

Observed Behavior

Requires claims extraction via CDT

Customer Impact

What This Means For You

Publishers face three core risks: (1) Yield optimization analytics distort revenue strategy by misattributing demand sources or over-crediting programmatic channels, making monetization decisions unreliable. (2) Complete bidstream visibility exposes publisher floor prices, audience composition, and inventory strategy to demand-side participants through Pubmatic infrastructure. (3) Legal exposure from cross-domain tracking and identity resolution creates GDPR/CCPA liability that compliance teams cannot mitigate while maintaining programmatic monetization.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Pubmatic

  • Require data processing addendum with explicit identity resolution and cross-domain tracking disclosure
  • Demand consent framework integration that blocks ID sync until user acceptance
  • Implement bidstream data minimization to limit visitor signal exposure to demand partners
  • Configure yield optimization to balance privacy preservation with revenue maximization
  • Establish retention limits for visitor profiles and identity graphs

If You're Evaluating Pubmatic

  • Test consent mechanism to verify ID syncing respects publisher consent state
  • Verify geographic data processing boundaries for GDPR compliance in EU traffic
  • Review identity resolution techniques and cross-device matching mechanisms
  • Assess bidstream data sharing with demand partners and third-party enrichment
  • Request disclosure of secondary data use for vendor intelligence or platform optimization

Negotiation Leverage

  • Pubmatic deploys cross-domain identity resolution across publisher inventory—demand contractual liability protection for GDPR/CCPA violations and explicit DPA terms covering ID syncing
  • Full bidstream visibility exposes publisher floor prices and inventory strategy to demand ecosystem—negotiate data minimization controls and audience signal limitations
  • Identity resolution creates unified visitor profiles across publisher properties—require transparency into matching techniques and user data deletion capabilities
  • Yield optimization signals may distort revenue attribution and monetization strategy—establish baseline measurement methodology for programmatic performance
  • Legal tail risk of 100% reflects programmatic infrastructure requirements—evaluate whether SSP value justifies regulatory exposure or consider privacy-preserving alternatives like contextual-only bidding
Runtime Detections

Runtime Detections

5 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Ad viewability patterns and interaction signals create behavioral profiles for audience segmentation and targeting.

BTI-C07Session Recording

Full session replay

Impact: Interaction capture for viewability measurement records visitor behavior during ad exposure sessions.

BTI-C08Cross-Domain Sync

Identity stitching

Impact: Identity synchronization across publisher properties enables visitor tracking throughout the programmatic ecosystem.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: SSP infrastructure processes bidstream data regardless of publisher consent state, collecting visitor signals before permission.

BTI-C14Identity Resolution

PII deanonymization

Impact: Cross-device and cross-site identity matching creates unified visitor profiles for programmatic targeting.

IOC Manifest

IOC Manifest

95 INDICATORS

Indicators of compromise across 4 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*pubmatic.com/wp-content/themes/pubmatic/js/jquery.3.7.1.js*
Tracking script
TRACK
*pubmatic.com/wp-content/themes/pubmatic/js/slick.js*
Tracking script
TRACK
*pubmatic.com/wp-content/themes/pubmatic/js/zoomify.js*
Tracking script
TRACK
*pubmatic.com/wp-content/themes/pubmatic/js/jquery.waitforimages.js*
Tracking script
TRACK
*pubmatic.com/wp-content/themes/pubmatic/js/jquery.matchHeight-min.js*
Tracking script
TRACK
*pubmatic.com/wp-content/themes/pubmatic/js/jquery.alignHeight.js*
Tracking script
TRACK
*pubmatic.com/wp-content/themes/pubmatic/js/jquery.waypoints.js*
Tracking script
TRACK
*pubmatic.com/wp-content/themes/pubmatic/js/splide.js*
Tracking script
TRACK
*pubmatic.com/wp-content/themes/pubmatic/js/splide-extension-auto-scroll.js*
Tracking script
TRACK
*pubmatic.com/wp-content/themes/pubmatic/js/bootstrap.js*
Tracking script
TRACK
*pubmatic.com/wp-content/themes/pubmatic/js/scripts.js*
Tracking script
TRACK
*pubmatic.com/wp-content/plugins/pardot/js/asyncdc.js*
Tracking script
TRACK
*pubmatic.com/wp-content/themes/pubmatic/js/home.js*
Tracking script
TRACK
*pubmatic.com/wp-includes/js/wp-emoji-release.js*
Tracking script
TRACK
*go.pubmatic.com/analytics*
Tracking script
TRACK
pubmatic.com/wp-content/themes/pubmatic/js/jquery.3.7.1.min.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-content/themes/pubmatic/js/slick.min.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-content/themes/pubmatic/js/zoomify.min.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-content/themes/pubmatic/js/bootstrap.min.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-content/themes/pubmatic/js/jquery.alignHeight.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-content/themes/pubmatic/js/jquery.matchHeight-min.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-content/themes/pubmatic/js/jquery.waypoints.min.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-content/themes/pubmatic/js/jquery.waitforimages.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-content/themes/pubmatic/js/scripts.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-content/themes/pubmatic/js/splide.min.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-content/themes/pubmatic/js/splide-extension-auto-scroll.min.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-content/themes/pubmatic/js/home.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-content/plugins/pardot/js/asyncdc.min.js
Auto-extracted from scan
TRACK
pubmatic.com/wp-includes/js/wp-emoji-release.min.js
Auto-extracted from scan
TRACK
go.pubmatic.com/analytics
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Pubmatic integrates with header bidding wrappers (Prebid.js), ad servers (GAM), and demand-side platforms. The vendor participates in real-time bidding with access to full bid request data including visitor signals, contextual information, and publisher floor prices. Integration architecture creates bidirectional data flows where publisher inventory intelligence flows to demand partners while advertiser bid behavior flows back.
Loaded By (2)
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

108 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details