Spur Intelligence Raises $200 Million to Unmask Hidden Internet Traffic

The IP intelligence firm has operated without outside funding since 2017. Now it has the backing to scale tools that help companies see who is really behind anonymised web traffic.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Full-frame edge-to-edge photoreal editorial image of a modern flat-screen smart television glowing in a dim living room at night, faint blue light spilling onto
Share

Key points

  • Spur Intelligence received a $200 million investment from Insight Partners, announced in 2025.
  • The company operated without outside funding from its founding in 2017 until this deal, a span of roughly nine years.
  • Spur's platform identifies internet traffic that criminals deliberately hide behind VPNs, residential proxies, and bot networks.
  • The fresh capital will go toward expanding operations and scaling detection capabilities.

Spur Intelligence, a US firm that helps organisations figure out who is really behind suspicious web traffic, has raised $200 million from Insight Partners, a New York-based technology investment firm.

The money matters because of what Spur actually does. Criminals and fraudsters routinely disguise their location and identity online, using VPNs (software that masks a user's real internet address), residential proxies (connections routed through ordinary home devices without the owner's knowledge), and bot networks (large groups of hijacked computers acting in concert). These tools let bad actors look like legitimate everyday users.

Spur watches that infrastructure continuously and builds intelligence about it. That data flows into the security and fraud-detection systems its customers use via data feeds and APIs (programming interfaces that let different software systems talk to each other). A bank or government agency can see not just that a login is coming from a suspicious address, but that the address belongs to a known criminal VPN service.

Why does this matter to ordinary people?

Fraud driven by hidden internet traffic hits consumers directly. Stolen accounts and bogus purchases get easier when criminals can disguise their origin, and better detection upstream means fewer of those costs get passed along. Our 17 July story on why fraudsters are paying premium prices for residential proxies shows exactly the infrastructure Spur is built to expose.

Thomas Krane, managing director at Insight Partners, put the business case plainly. "Organizations are increasingly operating with a critical blind spot: they can see the activity, but not the infrastructure behind it," he said in the announcement.

What happens with the $200 million?

Spur will use the funding to hire, expand its data collection, and build integrations with fraud-scoring and authentication platforms. It bootstrapped, growing on its own revenue without outside investors, for nine years before taking this deal. That track record suggests the product was selling on its merits before the cheque arrived.

Detail Fact
Company founded 2017
Years without outside funding 9
Investment raised $200 million
Lead investor Insight Partners
Core product IP intelligence and bot detection
Key threats addressed VPNs, residential proxies, bot networks

For defenders, the story's straightforward. Detection of anonymised infrastructure has historically been a weak point in fraud and security stacks. A well-funded Spur means faster data updates and broader coverage of the tools criminals use to stay invisible. Whether the investment translates to meaningfully better detection, or simply a bigger sales team, will show in the product over the next two years.

Common questions

Does this affect how I use a VPN for privacy?

Legitimate personal VPN use is different from criminal misuse. Spur's focus is on identifying infrastructure associated with fraud and abuse, not on flagging every individual who uses a VPN for privacy.

What should businesses do right now?

Ask your fraud or security team whether your current tooling can distinguish normal traffic from traffic routed through anonymising services. If it can't, that gap is worth closing before someone exploits it.

© 2026 Threat Vectr