# Nine Years Bootstrapped, Then a $200 Million Check: What Spur's Raise Says About Fraud's New Terrain
Most venture-backed cybersecurity startups burn through two or three funding rounds before their product reaches maturity. Spur Intelligence took a different road — nine years building its IP intelligence platform without outside money, learning the fraud infrastructure market the slow, hard way — and then landed $200 million from Insight Partners in a single shot.
That backstory is not incidental. It tells you something about both the business and the moment.
## The Problem Nobody Solved Until Recently
The way most fraud and security systems work, the IP address is a proxy for intent. Geo-block certain regions. Flag Tor exit nodes. Throttle datacenter ranges. It's blunt-force risk scoring that worked adequately when fraudsters were unsophisticated.
That era is over.
Today's fraud infrastructure doesn't look like a rented datacenter block in Eastern Europe. It looks like a retired schoolteacher's broadband connection in Ohio — because that's exactly what it is. Residential proxy networks, many built on compromised consumer devices installed through shady VPN apps or adware, now route criminal traffic through millions of legitimate-looking IP addresses worldwide. Mobile proxy gateways route through real carrier IPs. Sophisticated VPN services specifically marketed to fraud operators — what the industry calls "criminal VPNs" — are designed to blend in with benign traffic.
Your fraud stack sees an IP with a clean reputation, a residential ISP, a plausible geolocation, and waves it through. The activity is visible. The infrastructure behind it is not.
That's the blind spot Spur was built to close.
## What Spur Actually Does
The company's core capability is continuous observation of what it calls "anonymized infrastructure" — mapping which IP addresses belong to residential proxy pools, VPN exit nodes, mobile gateways, bot networks, and other obfuscation layers. It delivers that intelligence through data feeds, APIs, and integrations with fraud scoring, authentication, and compliance systems.
The differentiation is real-time and behavioral. Static blocklists age out within hours in this space; operators rotate infrastructure constantly. Spur's value proposition is that it tracks network behavior continuously, not quarterly.
The practical use cases span fraud prevention, bot detection, account takeover defense, compliance enforcement, and ad fraud — anywhere that "where is this traffic actually coming from" is a question with money riding on the answer.
## The Funding Context: Why $200 Million, Why Now
Residential proxy abuse has reached a scale that would have seemed implausible five years ago. When the FBI took down the 911.S5 proxy botnet in 2024, they found it had enrolled roughly 19 million compromised IP addresses across 190 countries — one of the largest residential proxy networks ever dismantled, built largely through malicious free VPN apps that conscripted users' devices without their knowledge. 911.S5's takedown didn't solve the problem; it temporarily displaced demand to other services.
Concurrently, major e-commerce platforms, financial institutions, and ad networks have been hammered by fraud that specifically exploits residential proxy blind spots. The economic pressure to solve this is real.
Insight Partners' managing director Thomas Krane framed the investment around that "critical blind spot" — security teams can see activity but not origin. That framing is accurate, and it's also good marketing for a round this size. But the underlying market reality supports it: as anonymization infrastructure becomes commoditized and cheap, IP intelligence becomes load-bearing for fraud stacks that previously didn't need it.
The bootstrapped history matters here too. Spur had nine years to build proprietary data assets — years of network observation, customer integrations, and signal accumulation that a VC-backed company racing to product-market fit couldn't afford to take. That moat is what Insight is buying.
## Who Else Is in This Market
Spur isn't alone. IPQS, IPinfo, MaxMind, and DigitalElement all operate in the IP intelligence space. Human Security (formerly White Ops) occupies adjacent territory in bot detection. Arkose Labs addresses fraud from a challenge/response angle.
What distinguishes the competitive landscape right now is convergence: fraud detection, bot management, and threat intelligence are collapsing toward a common data layer that says "this traffic is proxied, here's the network it originates from, here's what we've seen that infrastructure do before." Spur has positioned itself as that foundational layer rather than an end-user product, which is a defensible place to be if the data is genuinely better.
The $200 million will reportedly fund hiring and scaling operations. The real question is whether it accelerates data coverage — more sensors, more network vantage points, faster classification — or whether it goes primarily toward sales and go-to-market. The former extends the moat; the latter just monetizes it faster.
---
## HackWire Analysis
The Spur raise deserves more than a funding brief treatment because it signals something specific about where the fraud arms race is heading.
For the last decade, fraud prevention was largely a behavioral problem — build enough machine learning on transaction signals, device fingerprints, and user patterns to separate good actors from bad. That approach still works, but fraudsters have learned to poison every layer of it. You can fake a device fingerprint. You can simulate human mouse movement. You can buy aged accounts with legitimate transaction histories. What's harder to fake is where your traffic physically originates — and that's exactly why residential proxies became so valuable to fraud operators. They solve the "origin" problem.
Spur's bet is that there's a layer of infrastructure intelligence that behavioral signals can't replace. The timing of a $200 million raise suggests a significant swath of enterprise fraud and security teams now agree.
What other coverage is missing: the investment also matters for the regulatory side. Know-Your-Customer and anti-money-laundering programs are increasingly expected to verify not just identity but transaction origin — where is this user actually connecting from? IP intelligence that can pierce proxy obfuscation becomes compliance infrastructure, not just fraud infrastructure. That's a different buyer, a different budget, and potentially a much larger market than security teams alone.
For defenders in financial services, e-commerce, and any business that enforces geographic compliance: static IP reputation is table stakes. If your fraud stack doesn't have a signal for residential proxy and mobile gateway traffic specifically, you are flying with a hole in your instruments. The fraudsters figured that out years ago.
— HackWire Editorial
---
## Related Coverage