Criminal IP names Reconn as MEA distributor for threat intel and ASM
AI SPERA has appointed Dubai-based cybersecurity distributor Reconn to sell and deploy its Criminal IP threat intelligence and attack surface management platform across the Middle East and Africa. The agreement gives regional security operations centres, managed security service providers, and threat analysts access to Criminal IP's continuous IP scanning, domain monitoring, OSINT enrichment, and dark web tracking capabilities.
Criminal IP currently scans all 4.29 billion routable IPv4 addresses on a continuous basis and has integrations with more than 40 security platforms, including Palo Alto Networks, Fortinet, OpenCTI, and Wazuh. Reconn will handle end-to-end deployment support, including SIEM, SOAR, and XDR integration, proof-of-concept sales engineering, and ongoing technical training.
Why the MEA region now
The timing reflects a confluence of regulatory pressure and expanding threat activity across the region. Central banks and financial regulators in several MEA jurisdictions now mandate external threat visibility as part of cyber governance frameworks. The release cites the Central Bank of the UAE, the Saudi Central Bank, the Dubai Financial Services Authority, the Central Bank of Nigeria, and Saudi Arabia's National Cybersecurity Authority, among others, as bodies that have introduced or tightened such requirements.
Byungtak Kang, chief executive of AI SPERA, said the partnership combines Criminal IP's global intelligence scale with Reconn's regional customer relationships. "Together, we aim to make actionable threat intelligence more accessible to security teams across the region and help them identify exposure, understand threats in context, and respond before those threats become incidents," he said.
Shenoy Sandeep, founder of Reconn, framed the problem simply: SOC and MSSP teams in the region need visibility into threats approaching from outside their own networks, and said conventional security tooling leaves meaningful gaps that continuous IP and domain scanning can address.
Competitive context
The threat intelligence and attack surface management market is competitive and consolidating. Established players such as Recorded Future, Mandiant (now part of Google), and Flashpoint compete at the enterprise end, while a growing cohort of API-first vendors, including Censys, Shodan, and GreyNoise, targets the same external-scanning use case that Criminal IP addresses. At the distribution layer, specialist regional value-added distributors have become a common route to market for vendors without their own MEA sales infrastructure, particularly as organisations in Saudi Arabia, the UAE, and Nigeria build out localised security operations in response to national cybersecurity strategies.
Reconn's positioning as an "AI-first" distributor with PECB-accredited training in ISO 27001 and ISO 42001 gives it a compliance services angle that pure resellers typically lack, which may help accelerate enterprise adoption where regulatory alignment is a procurement criterion.
What to watch
No deal terms, minimum revenue commitments, or headcount targets were disclosed. The partnership's success will depend partly on Criminal IP's ability to demonstrate regional data relevance, since threat intelligence quality is often judged on the specificity and recency of indicators tied to local infrastructure and threat actors. The company's free search engine at search.criminalip.io provides a low-friction entry point for evaluations, which may help pipeline development in markets where procurement cycles are long.