COMMON MAPS
Map version new-york activity top-down
Main site Contact
Menu
↑ parent activity group ·
research dossier

CYBERSECURITY REACH FOUNDATION INC

NEW YORK, NY · EIN 994835568 · Form 990EZ · FY2025 · NTEE U41 · Science & Technology · Micro (<$100K) · cybersecurityreach.org
revenue
$6K
expenses
$7K
net assets
$-3K
employees
mission · from form 990

Community-driven nonprofit dedicated to making cybersecurity accessible. Empower individuals with practical solutions and knowledge to navigate the digital world safely.

profile · synthesized from sources

Cybersecurity Reach Foundation is a community-driven nonprofit focused on making cybersecurity accessible through practical knowledge and threat analysis. The organization publishes technical reports on emerging cyber threats, such as supply chain attacks in open-source software and vulnerabilities in AI systems. It emphasizes rapid public disclosure, reverse engineering, and actionable guidance for defenders and developers.

named programs · 3 · from sources

What they call their work

Incident Response Guidance
Provides actionable mitigation steps for developers and organizations affected by security breaches, such as npm supply chain attacks
Security Best Practices Advocacy
Promotes secure development workflows, credential management, and defensive tooling through public reports and technical advisories
Threat Intelligence Reporting
Produces in-depth technical analyses of active cyber threats, including malware reverse engineering, supply chain compromises, and AI-related vulnerabilities
activities · 4 groups

What they do

  • Privacy-Preserving Cybersecurity & Data Collaboration 2 activities
    • Conduct and publish original cybersecurity threat research
      Conducts in-depth investigations into emerging cyber threats including malware, phishing campaigns, and vulnerable infrastructure. Publishes findings on topics such as port 445 scans, npm worms like Shai-Hulud, OpenClaw vulnerabilities, and fraudulent cryptocurrency platforms to inform public understanding and mitigation strategies.
    • Develop and distribute free scam-detection and digital safety tools
      Creates and maintains no-signup, no-download cybersecurity tools such as ScamArchive, InboxSpotter, Internet Safety Center, and CyberScout that enable instant scam detection and analysis. These tools are designed to be accessible via web and WhatsApp without requiring user accounts or data transmission.
  • Cybersecurity Skills Development 2 activities
    • Host hands-on cybersecurity education events
      Organizes and delivers in-person and virtual workshops, CTF competitions, and Scam Search Parties to teach practical cybersecurity skills and build community resilience against digital threats.
    • Provide cybersecurity internships and skill-building opportunities
      Offers hands-on internships in cybersecurity research, engineering, communications, and community outreach, placing participants on real projects to build practical skills and contribute to organizational missions.
  • Scam Prevention Education 1 activity
    • Produce illustrated educational materials on scam prevention
      Creates accessible, narrative-based educational content featuring a mascot named Cyber to explain real-world scams and how to avoid them through illustrated storytelling.
  • Uncategorized 3 activities
    • Build and maintain a real-world scam archive
      Develops and curates the Scam Archive, a repository of documented real-world scam examples contributed by investigators to support research, education, and public awareness efforts.
    • Deliver public-awareness campaigns on cybersecurity threats
      Runs high-visibility public awareness campaigns using LinkNYC kiosks, Google, Meta, and co-branded partnerships to distribute plain-language scam alerts and digital safety guidance at scale, reaching over 5 million people.
    • Provide personalized scam recovery assistance and support
      Offers free, private assistance to individuals who have been scammed, generating personalized, step-by-step recovery plans based on their reported experiences. All processing occurs locally on the user's device to ensure privacy, with no storage or transmission of user data.
financials · form 990EZ · fy2025
revenue
Total revenue$6K
Contributions & grants$6K100%
Program service revenue$00%
Investment income$00%
Other revenue$0
expenses
Total expenses$7K
Program expenses
Admin / overhead
Fundraising
Salaries & benefits$0
Grants paid out$0
balance sheet
Total assets$0
Cash
Investments
Liabilities
Net assets$-3K
2 years on record · 2024–2025 · YoY revenue +66077.8%
leadership · form 990 part vii · fy2025

Who runs it

board members · 2
  • GENT GAZHELI — Director
  • STEFANIE COHEN — Director
relationships · 19

Who they work with

  • Annual Credit Report Partner — Directs users to annualcreditreport.com to obtain free weekly credit reports.
  • Baruch ISACA Partner — Hosts cybersecurity workshops in partnership with Cybersecurity Reach Foundation.
  • Consumer Financial Protection Bureau Partner — Guides users to file complaints with the CFPB when financial institutions do not assist with fraud resolution.
  • Equifax Partner — Provides access to Equifax's free credit freeze service as part of identity protection.
  • FBI IC3 Partner — Directs users to report online fraud, wire transfers, and cryptocurrency scams to the FBI's Internet Crime Complaint Center.
  • FTC Partner — Directs users to report fraud through the official FTC reporting portal.
  • Google Partner — Collaborates on digital platforms to expand reach of cybersecurity awareness campaigns.
  • IdentityTheft.gov Partner — Provides a link to IdentityTheft.gov for personalized identity theft recovery plans.
  • Indonesian Oil Palm Research Institute Partner — Research institution linked to IP 157.15.117.26 through hostname PPKS.MARIHAT on Shodan.
  • LinkNYC Partner — Partners with LinkNYC to place cybersecurity awareness content in citywide digital kiosks.
  • LinkNYC Partner — Partnership to run high-visibility cybersecurity awareness campaigns on public kiosks.
  • Meta Partner — Collaborates on social media platforms to expand reach of cybersecurity awareness campaigns.
  • PT Green Mobile Technology Partner — ISP associated with IP 157.10.107.99, identified via AbuseIPDB and Shodan.
  • PT Trias Infra Sarana Partner — ISP associated with IP 157.15.117.26, identified via AbuseIPDB.
  • PT XL Axiata Tbk Partner — ISP associated with IP 157.85.212.10, identified via Whois and IPInfo during investigation.
  • Security Scorecard Partner — Collaborates with Security Scorecard in researching and monitoring OpenClaw risks.
  • StepSecurity Partner — Collaborates with or references work from researchers at StepSecurity in incident analysis.
  • info@cybersecurityreach.org Partner — Email contact point for user inquiries and support
  • scamarchive.org Partner — Collaborates by providing a platform for reporting and researching scams.
strategies · 5

How they approach the work

Named approaches extracted from this org’s sources. Where others share an approach, follow it to see the full set of orgs running it.

  • Illustrated Narrative and Plain-Language Education
    methodology: illustrated narrative education
    By using scholar-created illustrations, narrative storytelling, and plain-language campaigns, the organization improves public understanding and retention of cybersecurity threats, because complex technical content becomes more accessible and memorable when conveyed through relatable stories and visuals.
  • Interactive, Personalized Intervention
    methodology: personalized-intervention
    By using interactive, user-driven assessments to generate tailored recovery guidance, the organization improves outcomes for scam victims, because personalized responses increase relevance, trust, and follow-through compared to generic advice.
  • Meet People Where They Are
    methodology: meet-people-where-they-are
    By placing scam-awareness content on platforms and devices where the public already spends time (e.g., LinkNYC, Google, Meta), the organization increases reach and relevance, because interventions are more effective when delivered in context and without requiring changes in user behavior.
  • Public-Awareness Through Investigative Research
    methodology: public-awareness-through-investigative-research
    By producing original investigative reports and research on scams and cybersecurity threats, the organization increases public understanding and drives behavior change, because credible, evidence-based narratives make abstract threats tangible and actionable.
  • Volunteer-Driven, Community-Participatory Model
    methodology: volunteer-driven_model
    By relying entirely on volunteer labor and recruiting investigators based on curiosity and thoroughness rather than credentials, the organization sustains scalable, community-driven cybersecurity initiatives, because inclusive participation lowers barriers to entry and fosters civic ownership of digital safety.