Trusteer
Trusteer is an IBM-owned cybersecurity brand focused on online fraud prevention, endpoint protection, malware detection, and account-takeover risk reduction.
Last updated August 26, 2026
Overview
Trusteer is a cybersecurity software and services brand originally developed by Trusteer, Inc., an Israeli software company founded in 2006 by Mickey Boodaei and Rakesh K. Loonkar. The company built products for financial institutions, enterprises, and their customers, with an emphasis on preventing online banking fraud, phishing, malware-assisted theft, credential compromise, and account takeover. IBM acquired Trusteer in September 2013 for approximately $1 billion, after which Trusteer became part of IBM's security portfolio. The brand's best-known consumer product is Trusteer Rapport, an endpoint security client commonly distributed by banks at no direct charge to their customers. Rapport was designed to provide an additional protective layer around online banking sessions by helping block phishing, man-in-the-browser attacks, man-in-the-middle attacks, session hijacking, malicious screen capture, and attempts by malware to steal credentials. It was positioned as complementary to conventional antivirus software and was made available through supported browser extensions and desktop components. A number of banks in North America, Europe, Africa, and other markets offered or previously offered Rapport to customers. Trusteer also developed enterprise and financial-sector services. Trusteer Pinpoint used web-based analysis, device fingerprinting, proxy detection, and malware-infection detection to help financial institutions identify compromised devices and account-takeover attempts without requiring software to be installed on every endpoint. Trusteer's mobile fraud-prevention offerings addressed mobile and cross-channel attacks through device intelligence, mobile risk analysis, out-of-band authentication, application components, and application programming interfaces. Trusteer Apex targeted enterprise endpoints, particularly applications frequently exploited by attackers, and combined exploit prevention, data-exfiltration prevention, and protection against credential theft. A central feature of Trusteer's approach was the use of telemetry and behavioral analysis from a large installed base. The company stated that its malware research operation analyzed information from tens of millions of user endpoints and hundreds of organizations. This intelligence was intended to help detect emerging threats, identify infected devices, alert organizations, and support remediation at the point of attack. The brand has also attracted criticism. Users and consumer advocates have reported performance problems, browser instability, software conflicts, high resource consumption, and difficulty uninstalling Rapport. The UK consumer organization Which? described Rapport as legitimate but questioned whether its claimed benefits justified the operational problems for some users, noting that modern browsers and other security controls can already mitigate many phishing risks. In 2011, researchers demonstrated a way to bypass part of Rapport's keylogger protection; Trusteer said the issue was corrected and that additional protections remained available. Trusteer also faced a lawsuit filed by rival Blue Gem in California in 2011, allegations that Trusteer characterized as baseless. Trusteer is best understood today as an IBM security brand rather than as an independent software company. Its historical scope spans consumer banking protection, financial-institution fraud intelligence, mobile risk management, and enterprise endpoint security. Product availability, naming, and support can vary by market and by IBM's current security portfolio.
History
Trusteer was established in Israel in 2006 by Mickey Boodaei and Rakesh K. Loonkar. Its original business addressed the growing problem of online banking fraud, especially attacks in which malware intercepted credentials or manipulated browser sessions. Rather than relying only on conventional antivirus products, Trusteer developed software intended to protect financial transactions at the browser and endpoint level while also giving banks visibility into compromised customers and emerging attack campaigns. The company's best-known product became Trusteer Rapport. Banks distributed Rapport to their customers as an additional security layer for online banking. The software was designed to help identify or block phishing sites, man-in-the-browser attacks, man-in-the-middle attacks, session hijacking, malicious screen capture, and malware attempting to steal account credentials. It also attempted to remove certain financial malware during installation and prevent reinfection. Rapport was offered across several desktop operating systems and browsers, with availability and support changing over time. Trusteer expanded beyond consumer endpoint software into services for banks and large organizations. Trusteer Pinpoint provided web-based malware and account-takeover detection without requiring software on every visitor's device. Its methods included device fingerprinting, proxy identification, and analysis intended to determine whether a device was infected or whether credentials were being used from a suspicious environment. When an infected user accessed a protected banking site, the service could alert the financial institution and help identify the type of malware involved, allowing the bank to contact the customer and recommend remediation. The company also developed mobile fraud-prevention capabilities. Its Mobile Risk Engine and related components were designed to assess mobile devices, identify compromised or vulnerable devices, detect suspicious access attempts, and address attacks moving between PC and mobile channels. These offerings incorporated mobile applications, software-development components, out-of-band authentication, device intelligence, and risk APIs. This reflected the industry's shift from desktop-only banking threats toward fraud involving smartphones, applications, and multiple channels. For enterprise customers, Trusteer Apex focused on endpoint exploit prevention and the protection of credentials and sensitive data. The product concentrated on commonly targeted application families, including Java, Adobe Reader, Adobe Flash, and Microsoft Office. Its model emphasized observing application behavior and blocking suspicious activity rather than depending solely on signatures or static lists. Apex was designed to prevent exploits, stop untrusted processes from sending data to external destinations, protect enterprise credentials from phishing, and discourage the reuse of corporate credentials on public websites. Trusteer stated that its research operation used intelligence from a very large installed base, described in reference material as approximately 30 million endpoints and hundreds of organizations. This data was intended to support rapid detection, threat analysis, alerting, and mitigation. The company's geographic reach included North America, South America, Europe, Africa, Japan, and China. In September 2013, IBM acquired Trusteer for approximately $1 billion. The acquisition moved Trusteer from an independent Israeli software company into IBM's security portfolio and expanded IBM's capabilities in fraud prevention, endpoint protection, and threat intelligence. Trusteer thereafter functioned primarily as an IBM security brand. The brand's history also includes criticism of Rapport's technical and operational impact. Some users reported high processor or memory use, incompatibility with other security products, browser instability, system crashes, and difficulty uninstalling the software. Which? advised caution after collecting complaints, while acknowledging that Rapport was legitimate security software. In 2011, a security presentation demonstrated a method for bypassing a portion of Rapport's keylogger protection. Trusteer said it fixed the flaw and maintained that other security layers remained active. Separately, rival Blue Gem sued Trusteer in California in March 2011; Trusteer rejected the allegations as baseless. Trusteer's present identity is tied to IBM rather than to a standalone public company. Its historical product family illustrates a progression from consumer banking protection to institution-facing fraud intelligence, mobile risk assessment, and enterprise endpoint defense. Product names, availability, and support should be treated as subject to IBM portfolio changes and regional arrangements with financial institutions.
- 2019NatWest and RBS stop offering Rapport
The two banking groups withdraw the consumer software, citing newer and broader security technologies.
- 2013IBM acquires Trusteer
IBM acquires Trusteer in September for approximately $1 billion.
- 2011Blue Gem files a lawsuit
Rival company Blue Gem brings a lawsuit against Trusteer in a California court. Trusteer denies the accusations.
- 2011Rapport keylogger-protection bypass is presented
A 44con presentation demonstrates a way to bypass part of Rapport's keylogger protection; Trusteer later says the flaw was corrected.
- 2006Trusteer is founded in Israel
Mickey Boodaei and Rakesh K. Loonkar establish Trusteer to develop technology for online fraud and cyberattack prevention.
Products and positioning
A cybersecurity and fraud-prevention brand serving banks, enterprises, and online-service users, with protection focused on malware, phishing, compromised devices, credential theft, and account takeover.
Trusteer RapportConsumer online-banking security
Rapport is endpoint and browser security software distributed by participating financial institutions to help protect online-banking credentials and sessions. It was designed to supplement antivirus protection by addressing phishing, man-in-the-browser attacks, man-in-the-middle attacks, session hijacking, malicious screen capture, and malware-based credential theft. The software also attempted to remove certain financial malware during installation and prevent later infections. Support covered selected Windows and macOS browser configurations, while availability depended on the bank and market.
Trusteer PinpointWeb-based fraud detection
Pinpoint is a service for financial institutions that analyzes web traffic and device characteristics to detect malware infections, phishing-related risk, suspicious proxies, and account-takeover attempts without requiring endpoint software installation. Device fingerprinting and infection analysis can help a bank identify compromised credentials or devices and initiate customer remediation. The service was designed for real-time or near-real-time intervention during online transactions.
Trusteer Mobile Fraud Risk PreventionMobile fraud prevention
This product family, including the Mobile Risk Engine, Mobile SDK, mobile application components, out-of-band authentication, and Mobile Risk API, was designed to assess mobile-device risk and prevent account takeover. Its capabilities included device fingerprinting, detection of compromised or vulnerable devices, identification of suspicious criminal access, and analysis of attacks moving between PC and mobile channels.
Trusteer ApexEnterprise endpoint security
Apex is an enterprise endpoint protection product built around exploit prevention, data-exfiltration prevention, and credential protection. It focused on application behaviors associated with frequently exploited software such as Java, Adobe Reader, Adobe Flash, and Microsoft Office. Rather than depending exclusively on threat signatures or application whitelists, it attempted to recognize abnormal behavior, block exploit activity, prevent unauthorized outbound data transfer, and reduce exposure of corporate credentials to phishing and public websites.
Flagship businesses
- Trusteer Rapport
- Trusteer Pinpoint
- Trusteer Mobile Fraud Risk Prevention
- Trusteer Apex
Brand decisions
- 2019NatWest and RBS withdraw RapportStrategy
The banks reviewed their consumer online-banking security arrangements and concluded that newer technologies provided broader protection.
What changed. NatWest and RBS stopped offering Trusteer Rapport to customers.
Aftermath. The banks directed customers toward their newer security and fraud-prevention measures; the source does not establish a broader effect on Rapport's availability.
- 2013IBM acquires TrusteerM&A
Trusteer had developed a broad portfolio spanning consumer banking protection, financial fraud detection, mobile risk, and enterprise endpoint security.
What changed. IBM acquired Trusteer in September 2013 for approximately $1 billion.
Aftermath. Trusteer became part of IBM's security business and continued as an IBM security brand rather than an independent listed company.
Acquisition value. $1 billion (September 2013)
Leadership
| Name | Title | Tenure |
|---|---|---|
| Mickey Boodaei | Co-founderformer | 2006– |
| Rakesh K. Loonkar | Co-founderformer | 2006– |
Controversies
- 2011Blue Gem lawsuitControversy
Rival company Blue Gem filed a California lawsuit against Trusteer in March 2011. Trusteer characterized the accusations as baseless.
- 2011Rapport protection bypass demonstrationControversy
A presentation at 44con demonstrated a method for bypassing Rapport's keylogger protection. Trusteer said the issue was subsequently fixed and that additional defensive technologies remained active.
- Consumer complaints about Rapport performance and compatibilityControversy
Users reported slowdowns, high resource consumption, browser crashes, conflicts with other security tools, system instability, and uninstall difficulties. Which? described Rapport as legitimate but questioned whether its benefits outweighed these problems for affected users.
Recent events
- 2019NatWest and RBS discontinue offering Trusteer Rapport
NatWest and RBS stopped offering Rapport to customers, stating that their newer security and fraud-prevention technologies provided broader protection.
Other - 2013IBM acquires Trusteer for approximately $1 billion
IBM acquired Trusteer in September 2013, bringing the Israeli cybersecurity company's fraud-prevention and endpoint-security technologies into IBM's security business.
M&A
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/trusteer · Editorial policy · How profiles are compiled