Customer Success: How Mine2 Caught an Insider Stealing Confidential Files
Kabir6 min read

Customer Success: How Mine2 Caught an Insider Stealing Confidential Files

A 450-employee IT services company discovered an insider selling confidential proposals and salary data to competitors. Mine2's honeytokens provided irrefutable proof of theft, enabling legal action and preventing ongoing losses.

Share:

When a mid-sized IT services company in Bangalore noticed their confidential proposals turning up inside competitor pitches, they walked straight into every leadership team's worst case: an insider they couldn't name.

I've sat across the table from a lot of companies in this exact spot. The frustration is always the same. They know someone is stealing. They just can't prove who, and they can't prove intent.

Their Bids Kept Showing Up in Someone Else's Deck

It started with a tip from a partner. A competitor had pitched a potential client with a proposal that looked suspiciously like the company's own confidential bid. The pricing structure, the technical approach, even the specific terminology, all of it lined up almost word for word.

Over the next few weeks, more signals piled up:

  • A client mentioned seeing their "upcoming product features" in a competitor's pitch deck
  • Salary information for senior roles appeared on industry forums
  • Proprietary project methodologies showed up in a competitor's marketing material

The conclusion was hard to avoid. Someone inside the company was feeding sensitive files to the market.

Where Traditional Security Ran Out of Road

The leadership team kept hitting the same wall:

Challenge Why It Failed
Access logs Hundreds of employees accessed shared folders daily—impossible to distinguish legitimate work from theft
Surveillance Installing invasive monitoring would damage trust and potentially violate privacy laws
Legal action Without concrete evidence, they couldn't pursue the culprit

This is the same dead end I described in why insider threats need honeytokens: access logs tell you who opened a file, never why.


The Approach: Mine2 Cyber Deception

The company brought in Mine2 to run a focused deception play using honeytoken files: realistic-looking fake documents that quietly alert the security team the moment anyone touches them.

Strategic Honeytoken Deployment

Using Mine2Mate, the team seeded honeytokens across 15 file servers and 30 workstations within 48 hours:

Word Document Honeytokens:

  • Q3_2024_Client_Proposals_CONFIDENTIAL.docx — Fake client proposals
  • Executive_Compensation_Package_2024.docx — Fake salary structures
  • Merger_Acquisition_Target_Analysis.docx — Fake M&A documents

Excel Document Honeytokens:

  • Client_Database_Master_2024.xlsx — Fake customer contact lists
  • Product_Pricing_Strategy_Confidential.xlsx — Fake pricing sheets

Binary File Honeytokens:

  • ProjectAlpha_SourceCode_v2.4.zip — Fake source code archive
  • Partnership_Agreement_Draft_NDA.pdf — Fake PDF documents

We placed the files where a thief would naturally hunt: shared network drives, executive assistant workstations, project management folders, and HR file servers.


The Detection: Catching the Insider

Four weeks after deployment, Mine2 picked up suspicious activity.

Week 4: The Alerts Begin

Timeline File Accessed Time Action
Monday Q3_2024_Client_Proposals_CONFIDENTIAL.docx 6:47 PM Opened and copied to USB drive
Wednesday Executive_Compensation_Package_2024.docx 11:34 PM Copied from HR server
Following week Pricing spreadsheet Various Uploaded to personal Gmail
Following week Source code archive Various Copied to external hard drive

Every alert traced back to one workstation: a senior sales manager with 5 years at the company.

The Investigation

Once we had a name, the rest of the picture filled in fast:

  • Network logs: Systematic browsing of folders marked "Confidential" or "Executive Only"
  • USB device logs: Multiple external storage devices connected
  • Email forensics: Encrypted communications with external contacts
  • Financial investigation: Unexplained deposits of ₹8-10 lakhs

Why Honeytokens Closed the Case

Evidence Point Implication
No legitimate business need A sales manager has no reason to access HR compensation files or executive M&A documents
Off-hours access Accessing files at 11:34 PM indicated covert activity
Exfiltration behavior Copying to USB drives and personal email proved intent to steal
Multiple honeytokens triggered Systematic hunting for valuable documents—not accidental access

The Resolution

Faced with concrete evidence, the employee admitted he'd been selling confidential files to competitors. He'd stolen and sold over 40 legitimate files before he ever tripped a honeytoken, earning roughly ₹12-15 lakhs.

Actions Taken:

  • Employment terminated immediately for cause
  • Criminal complaint filed under IT Act 2000 Section 43
  • Civil lawsuit initiated for breach of confidentiality
  • Legal notices sent to competitors who received stolen files

Results at a Glance

Metric Value
Detection Time 35 days from deployment to confirmed insider
Investigation Time 2 days from first alert to identification
False Positives Zero
Prevented Future Loss ₹10+ crore annually
Evidence Quality Sufficient for legal prosecution

Why It Worked

In my post-incident review, the win came down to four things:

  1. Realistic naming. Files sounded valuable, exactly what a thief would target.
  2. Strategic placement. Honeytokens blended naturally with real sensitive files.
  3. Multiple file types. The traps covered every kind of document an insider might grab.
  4. Comprehensive tracking. Mine2 logged opens, copies, USB transfers, and email uploads.

What This Engagement Taught Us

File access logs alone don't prove intent. Hundreds of employees access shared folders daily. Honeytokens prove malicious intent when someone accesses files they have no legitimate reason to touch.

Insiders know how to dodge traditional security. This employee carefully avoided DLP alerts by using USB drives and personal email. Honeytokens caught him anyway, because the files themselves were the traps.

Deception works because greed is predictable. A file named Executive_Compensation_Package_2024.docx is irresistible to someone selling secrets.

Prosecution needs concrete proof. Access logs are circumstantial. Honeytoken interactions are definitive proof of unauthorized access and theft.

The same lesson shows up when secrets leak through code, not people. The Toyota GitHub exposure is a useful companion read on how quickly exposed material gets weaponized.


Expanded Protection

After the incident, the company widened their Mine2 deployment considerably:

Solution Purpose
MineField Fake file servers that trigger alerts on any access
Cloud Mines Decoy AWS S3 buckets and IAM credentials
Fortify Regular scans for exposed credentials and misconfigurations

Current Status: Zero file theft incidents since expanded deployment.

That same honeytoken model stopped an external supply-chain attack at another customer, which I broke down in how a SaaS company prevented a $2.4M breach.


Mine2's solution ran about ₹8-10 lakhs annually, less than the revenue lost on a single stolen proposal. More to the point, it produced the legal evidence needed to prosecute the perpetrator and put every other employee on notice.


Worried about what's walking out your own front door? Talk to the Mine2 team and we'll map a honeytoken deployment for your environment. Mine2 provides cyber deception across honeytokens, Mine2Mate deployment tools, MineField decoy systems, Cloud Mines for AWS, and Fortify hardening, so you catch insider theft and external attacks before they cost you.

M2

Kabir

Incident Response Lead, Mine2

Kabir leads incident response work at Mine2, dissecting breaches after the fact to show where earlier detection would have changed the outcome.

Share this article

Secure Your Network Today

Ready to implement advanced cyber deception in your organization? See how MINE2 can transform your threat detection capabilities.