Spur Secures $200M Investment to Scale IP Intelligence and Bot Detection
- CVE ID
- N/A
- Affected Products / Orgs
- Enterprise Fraud Prevention, Fraud Scoring Platforms, Security Operations Centers
Insight Partners has invested $200 million into IP intelligence platform provider Spur Intelligence, marking a major institutional round for a security firm that operated fully bootstrapped since its founding in 2017. Spur plans to use the fresh injection of capital to scale its engineering and operations, expanding its real-time telemetry capabilities across enterprise fraud prevention, identity management, and threat detection markets.
Spur delivers specialized intelligence designed to give organizations visibility into anonymized, proxied, and intentionally obfuscated web traffic. Operating through real-time data feeds, APIs, session enrichment, and pre-built integrations, the platform helps security and compliance teams identify when incoming connections are masking their true origin behind residential proxies, commercial or criminal VPNs, mobile gateways, and automated bot networks.
Funding Overview
In a major funding milestone within the cyber intelligence sector, US-based Spur announced its $200 million round led by Insight Partners. Since launching in 2017, the firm spent nine years quietly building and scaling its detection infrastructure without external venture funding.
The core value proposition centers on identifying connection infrastructure that bypasses standard perimeter defenses. Rather than relying on static IP reputation blocklists or simple WHOIS lookups, Spur builds continuous behavioral models by directly observing anonymized infrastructure and real-world network activity. This telemetry feeds directly into existing analytics engines, authentication workflows, compliance monitoring, fraud scoring models, and Security Operations Center (SOC) detection stacks.
As Insight Partners managing director Thomas Krane highlighted, organizations face a systemic blind spot in modern fraud prevention: security tools can easily log incoming activity, but they frequently fail to detect the complex anonymization infrastructure operating behind the client’s IP address.
The Shift Toward Anonymization Infrastructure and Residential Proxies
This continuous growth in the IP intelligence market reflects a fundamental evolution in how cybercriminals, fraud rings, and automated bot operators route traffic. Historically, bulk malicious activity—such as basic credential stuffing, scraping, or brute-force attacks—originated directly from inexpensive cloud data centers or hosting providers (such as AWS, DigitalOcean, or Hetzner). Security teams could easily mitigate those attacks by applying ASN-based blocking or subscribing to basic static IP reputation feeds.
Over the last several years, sophisticated threat actors have largely migrated to residential proxy networks and obfuscation services to evade detection. Modern attack infrastructure relies heavily on several key vector types:
- Residential Proxy Networks: Services that route malicious traffic through compromised IoT devices, infected home routers, or consumer mobile applications carrying embedded proxy SDKs. Because these requests terminate at residential internet service provider (ISP) IP addresses, legacy blocklists cannot flag them without causing severe false positives.
- Criminal and High-Anonymity VPNs: Custom virtual private network services engineered specifically for protocol masking, rapid IP rotation, and zero-logging, defeating simple ISP-classification lookups.
- Mobile Gateways and CGNAT: Routing automated attacks through mobile carrier infrastructure and Carrier-Grade NAT setups where thousands of legitimate users share a single external IP address, making IP-based bans impractical.
- Transient Bot Networks: High-velocity proxy networks capable of rotating source IP addresses on every HTTP request, flattening attack distributions to bypass standard rate-limiting controls.
How Obfuscated Traffic Defeats Traditional Security Controls
Understanding why specialized residential proxy detection has become critical requires examining how enterprise security controls inspect inbound connections. Modern Web Application Firewalls (WAFs), Identity and Access Management (IAM) solutions, and risk-based authentication engines rely on contextual signals such as IP reputation, TLS fingerprints, User-Agent strings, and geolocation metadata.
When an attacker leverages a residential proxy or obfuscated gateway, these traditional controls break down across several dimensions:
- Reputation Bypass: Traffic originates from an IP address assigned to a legitimate home broadband user with a long history of benign activity. Standard IP reputation feeds classify the source as trustworthy.
- Impossible Travel Evasion: Attackers select proxy egress nodes situated in the exact city or geographic region of the target account owner, completely bypassing geo-fencing policies and impossible-travel security triggers.
- Threshold-Based Evasion: By spreading a single credential stuffing campaign across tens of thousands of unique residential proxy IPs, an attacker can limit activity to one login attempt per IP per day, remaining completely under rate-limiting detection thresholds.
- Collateral Damage Risks: Because legitimate consumers share IP space across mobile and broadband networks, defensive teams cannot implement blanket subnet blocks without risking significant business disruption and locking out valid customers.
This dynamic leaves organizations vulnerable to undetected account takeover (ATO), automated payment fraud, inventory hoarding, API abuse, and stealthy initial access activity.
Integrating IP Intelligence into Enterprise Security Stacks
To address the limitations of binary IP blocking, security engineering teams are increasingly embedding continuous session enrichment into their automated defense pipelines. Real-time IP intelligence operates as an authoritative metadata layer that converts raw source IP data into actionable risk metrics.
In practice, security teams deploy these intelligence feeds across several critical control points:
- Identity and Access Workflows: Injecting proxy risk scores directly into login endpoints to trigger adaptive, step-up multi-factor authentication (MFA) or CAPTCHAs whenever traffic originates from an obfuscated node.
- Fraud Scoring Engines: Contextualizing e-commerce checkouts, wire transfer requests, and high-risk account modifications by flagging residential proxies and anonymized gateways in real time.
- SIEM and SOAR Enriched Triage: Providing SOC analysts with immediate context during alert investigations, allowing them to distinguish between a remote worker connecting via an approved corporate VPN and an attacker masking traffic behind a residential proxy host.
- Regulatory and Geo-Compliance: Enforcing strict geographical boundary restrictions by detecting tools designed to bypass digital rights management and regional financial compliance rules.
By providing deep, real-time visibility into the hidden network infrastructure routing internet traffic, modern IP intelligence platforms allow enterprise security teams to neutralize evasive automation while maintaining a frictionless experience for genuine users.
Related content
The Non-Human Identity Trap: Why Broad AI Agent Permissions Guarantee Breaches
Security NewsCenters Laboratory Discloses Breach Affecting Over 540,000 Individuals
Security NewsCISA Discloses Internal AWS GovCloud Credential Leak and Lack of Incident Response Plan
Security NewsU.S. DHS Homeland Security Information Network (HSIN) Compromised
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call