When a mid-sized IT services company in Bangalore noticed their confidential proposals turning up inside competitor pitches, they walked straight into every leadership team's worst case: an insider they couldn't name.
I've sat across the table from a lot of companies in this exact spot. The frustration is always the same. They know someone is stealing. They just can't prove who, and they can't prove intent.
Their Bids Kept Showing Up in Someone Else's Deck
It started with a tip from a partner. A competitor had pitched a potential client with a proposal that looked suspiciously like the company's own confidential bid. The pricing structure, the technical approach, even the specific terminology, all of it lined up almost word for word.
Over the next few weeks, more signals piled up:
- A client mentioned seeing their "upcoming product features" in a competitor's pitch deck
- Salary information for senior roles appeared on industry forums
- Proprietary project methodologies showed up in a competitor's marketing material
The conclusion was hard to avoid. Someone inside the company was feeding sensitive files to the market.
Where Traditional Security Ran Out of Road
The leadership team kept hitting the same wall:
| Challenge | Why It Failed |
|---|---|
| Access logs | Hundreds of employees accessed shared folders daily—impossible to distinguish legitimate work from theft |
| Surveillance | Installing invasive monitoring would damage trust and potentially violate privacy laws |
| Legal action | Without concrete evidence, they couldn't pursue the culprit |
This is the same dead end I described in why insider threats need honeytokens: access logs tell you who opened a file, never why.
The Approach: Mine2 Cyber Deception
The company brought in Mine2 to run a focused deception play using honeytoken files: realistic-looking fake documents that quietly alert the security team the moment anyone touches them.
Strategic Honeytoken Deployment
Using Mine2Mate, the team seeded honeytokens across 15 file servers and 30 workstations within 48 hours:
Word Document Honeytokens:
Q3_2024_Client_Proposals_CONFIDENTIAL.docx— Fake client proposalsExecutive_Compensation_Package_2024.docx— Fake salary structuresMerger_Acquisition_Target_Analysis.docx— Fake M&A documents
Excel Document Honeytokens:
Client_Database_Master_2024.xlsx— Fake customer contact listsProduct_Pricing_Strategy_Confidential.xlsx— Fake pricing sheets
Binary File Honeytokens:
ProjectAlpha_SourceCode_v2.4.zip— Fake source code archivePartnership_Agreement_Draft_NDA.pdf— Fake PDF documents
We placed the files where a thief would naturally hunt: shared network drives, executive assistant workstations, project management folders, and HR file servers.
The Detection: Catching the Insider
Four weeks after deployment, Mine2 picked up suspicious activity.
Week 4: The Alerts Begin
| Timeline | File Accessed | Time | Action |
|---|---|---|---|
| Monday | Q3_2024_Client_Proposals_CONFIDENTIAL.docx |
6:47 PM | Opened and copied to USB drive |
| Wednesday | Executive_Compensation_Package_2024.docx |
11:34 PM | Copied from HR server |
| Following week | Pricing spreadsheet | Various | Uploaded to personal Gmail |
| Following week | Source code archive | Various | Copied to external hard drive |
Every alert traced back to one workstation: a senior sales manager with 5 years at the company.
The Investigation
Once we had a name, the rest of the picture filled in fast:
- Network logs: Systematic browsing of folders marked "Confidential" or "Executive Only"
- USB device logs: Multiple external storage devices connected
- Email forensics: Encrypted communications with external contacts
- Financial investigation: Unexplained deposits of ₹8-10 lakhs
Why Honeytokens Closed the Case
| Evidence Point | Implication |
|---|---|
| No legitimate business need | A sales manager has no reason to access HR compensation files or executive M&A documents |
| Off-hours access | Accessing files at 11:34 PM indicated covert activity |
| Exfiltration behavior | Copying to USB drives and personal email proved intent to steal |
| Multiple honeytokens triggered | Systematic hunting for valuable documents—not accidental access |
The Resolution
Faced with concrete evidence, the employee admitted he'd been selling confidential files to competitors. He'd stolen and sold over 40 legitimate files before he ever tripped a honeytoken, earning roughly ₹12-15 lakhs.
Actions Taken:
- Employment terminated immediately for cause
- Criminal complaint filed under IT Act 2000 Section 43
- Civil lawsuit initiated for breach of confidentiality
- Legal notices sent to competitors who received stolen files
Results at a Glance
| Metric | Value |
|---|---|
| Detection Time | 35 days from deployment to confirmed insider |
| Investigation Time | 2 days from first alert to identification |
| False Positives | Zero |
| Prevented Future Loss | ₹10+ crore annually |
| Evidence Quality | Sufficient for legal prosecution |
Why It Worked
In my post-incident review, the win came down to four things:
- Realistic naming. Files sounded valuable, exactly what a thief would target.
- Strategic placement. Honeytokens blended naturally with real sensitive files.
- Multiple file types. The traps covered every kind of document an insider might grab.
- Comprehensive tracking. Mine2 logged opens, copies, USB transfers, and email uploads.
What This Engagement Taught Us
File access logs alone don't prove intent. Hundreds of employees access shared folders daily. Honeytokens prove malicious intent when someone accesses files they have no legitimate reason to touch.
Insiders know how to dodge traditional security. This employee carefully avoided DLP alerts by using USB drives and personal email. Honeytokens caught him anyway, because the files themselves were the traps.
Deception works because greed is predictable. A file named
Executive_Compensation_Package_2024.docxis irresistible to someone selling secrets.
Prosecution needs concrete proof. Access logs are circumstantial. Honeytoken interactions are definitive proof of unauthorized access and theft.
The same lesson shows up when secrets leak through code, not people. The Toyota GitHub exposure is a useful companion read on how quickly exposed material gets weaponized.
Expanded Protection
After the incident, the company widened their Mine2 deployment considerably:
| Solution | Purpose |
|---|---|
| MineField | Fake file servers that trigger alerts on any access |
| Cloud Mines | Decoy AWS S3 buckets and IAM credentials |
| Fortify | Regular scans for exposed credentials and misconfigurations |
Current Status: Zero file theft incidents since expanded deployment.
That same honeytoken model stopped an external supply-chain attack at another customer, which I broke down in how a SaaS company prevented a $2.4M breach.
Mine2's solution ran about ₹8-10 lakhs annually, less than the revenue lost on a single stolen proposal. More to the point, it produced the legal evidence needed to prosecute the perpetrator and put every other employee on notice.
Worried about what's walking out your own front door? Talk to the Mine2 team and we'll map a honeytoken deployment for your environment. Mine2 provides cyber deception across honeytokens, Mine2Mate deployment tools, MineField decoy systems, Cloud Mines for AWS, and Fortify hardening, so you catch insider theft and external attacks before they cost you.
Kabir
Incident Response Lead, Mine2
Kabir leads incident response work at Mine2, dissecting breaches after the fact to show where earlier detection would have changed the outcome.
Recent Articles
Need Security Help?
Protect your organization with MINE2's cyber deception platform.
