Place a realistic Word or Excel decoy beside sensitive files. When someone opens it, Hacked sends you the IP, location, device, and network details, with no macros and no software to install.
Create your account, choose a document lure, download it, and place it where a real file belongs. Hacked starts watching immediately, with nothing to install on employee devices.
A phished password, a leaked credential, or an unpatched server creates the opening. Hacked watches what happens after access begins.
Place a believable document beside the data someone would copy. Its filename and contents give no reason to leave it behind.
It can open on another device or network hours or weeks later. The file renders normally, with no popup or visible warning.
The signal fires silently from documents, links, pixels, or QR codes. You install no agent on your network or employee devices.
The alert carries the IP, city, device, network flags, and exact lure that opened. Send it by email, Slack, Microsoft Teams, or webhook.
CHF 199 per workspace per month gives your team up to 25 active lures, 5 recipients, richer network context, integrations, and 1 year of alert history. Start with 3 document lures free and upgrade when the workflow proves useful.
A salary lure assigned to HR opens from a finance laptop. The alert identifies the device and gives your investigation a clear first step.
A board minutes lure opens at 02:00 from an unfamiliar device. The alert puts the file, IP, operating system, and location in one view.
A client export lure opens on a residential network in another country. The alert shows which decoy travelled and where it appeared.
Use 10 lure types across documents, shortcuts, images, email, web pages, links, and QR codes. Business adds custom filenames and uploaded Word or Excel templates.
Deployment zones label approved access while the source IP, ASN, device fingerprint, and network flags explain the signal. VPN, proxy, and Tor traffic appears separately.
Route signals to Slack, Microsoft Teams, webhooks, or your own REST API workflow. Business keeps 1 year of history and exports CSV or JSON.
Yearly billing is CHF 1'910 per workspace, saving 20 percent.
You place and monitor decoys on systems you own or are authorized to protect. Hacked records access to those decoys and does not enter or modify another system.
Lures are designed to behave like the file, page, link, or code they represent. Tracking runs silently in the background without a visible popup, warning, or marker.
Create a lure in the dashboard, download it or copy its tracker URL, and place it where it belongs. You install no agent and push no endpoint configuration.
Use deployment zones to label approved access. Each alert includes the source IP, ASN, device fingerprint, and separate VPN or proxy flags, giving you enough context to dismiss expected activity.
Business alerts flag VPN, proxy, and Tor exit traffic. The dashboard shows the observed IP and ASN, then labels known commercial VPN providers so expected remote work is easier to recognize.
The platform runs in Frankfurt on encrypted volumes, while Swiss jurisdiction applies to your customer agreement. Hacked keeps Free alert data for 30 days and Business alert data for 1 year.
Business includes a REST API with eh_ prefix keys and webhook delivery to Slack, Microsoft Teams, or any endpoint that accepts JSON. Export CSV or JSON for offline analysis.