RB2B Investigation
Status: Active Investigation Severity: CRITICAL Classification: KILL
Executive Summary
RB2B is a visitor identification vendor that claims to provide "ethical" B2B website visitor identification. BLACKOUT investigation revealed significant discrepancies between marketed behavior and actual technical implementation.
This case demonstrates a "smoking gun" pattern: vendor API documentation directly contradicts marketing claims.
The Contradiction
Marketing Claims
From RB2B's website:
"We only identify business visitors. Personal emails are never captured."
API Documentation
From RB2B's API docs:
{
"email": "john.doe@gmail.com",
"personal_email": true,
"work_email": "john.doe@company.com"
}The API explicitly returns personal email addresses, contradicting marketing claims.
Technical Findings
Data Collection
| Data Point | Disclosed | Actually Collected |
|---|---|---|
| Business email | β Yes | β Yes |
| Personal email | β No | β Yes |
| Full name | β Yes | β Yes |
| Phone number | β No | β Yes |
| LinkedIn URL | β Yes | β Yes |
| Company data | β Yes | β Yes |
Piggyback Chain
yoursite.com
ββ rb2b.com
ββ clearbit.com
ββ apolloapi.io
ββ zoominfo.com (undisclosed)RB2B loads additional data enrichment vendors without disclosure.
Consent Behavior
| Scenario | Expected | Actual |
|---|---|---|
| Before consent | No tracking | Tracking active |
| After opt-out | No tracking | Tracking continues |
| DNT header | No tracking | Ignored |
Evidence
HAR Analysis
POST https://api.rb2b.com/identify
Request Body: {
"url": "https://victimsite.com/pricing",
"fingerprint": "a1b2c3d4...",
"timestamp": 1705312800
}
Response: {
"person": {
"email": "john@gmail.com", // Personal email
"work_email": "john@company.com",
"phone": "+1-555-0123",
"linkedin": "linkedin.com/in/johndoe"
}
}Cookie Inventory
| Cookie | Domain | Expiration | Purpose |
|---|---|---|---|
_rb2b_id | .rb2b.com | 2 years | Visitor ID |
_rb2b_session | .rb2b.com | Session | Session tracking |
_rb2b_fp | .rb2b.com | 1 year | Fingerprint hash |
BTSS Score
Score: 18/100 (FAIL)
| Factor | Score | Notes |
|---|---|---|
| Consent compliance | 0/25 | Pre-consent tracking |
| Data minimization | 5/25 | Excessive PII collection |
| Disclosure accuracy | 3/25 | API contradicts claims |
| Piggyback depth | 10/25 | 3 undisclosed vendors |
Recommendation
KILL β Remove RB2B immediately.
Rationale
- Marketing claims are demonstrably false
- Personal email collection without disclosure
- Pre-consent tracking violates GDPR
- Undisclosed data sharing with third parties
Remediation Steps
- Remove RB2B script from all properties
- Audit data already collected
- Consider breach notification obligations
- Evaluate alternative compliant solutions
Evidence Pack
Download the full evidence pack for this investigation:
Includes:
- Full HAR capture
- API response samples
- Cookie analysis
- Screenshot timeline
- Chain of custody certification