THE DISPATCH
ILLUSIVE → PROOFPOINT · ACQUISITION COMPLETED DECEMBER 2022 · SPOTLIGHT + SHADOW CONTINUE THE WORK

COMPANY / CYBERSECURITY / IDENTITY DEFENSE

Illusive laid a trap for the password thief

A forgotten admin account can turn one stolen login into a company-wide disaster. Illusive built a business by clearing away the real shortcuts and planting convincing false ones.

At an online retailer, Captain America had acquired an unexpected power: administrative access. Illusive’s researchers found an account named Steve Rogers among the company’s hidden privileged identities. Tony Stark and Bruce Banner were there too. A penetration-testing team had created the Avengers accounts, then left them behind. According to Illusive’s 2022 identity risk report, they remained in Active Directory for more than two years. Apparently, saving the world did not include tidying up afterward.

THE STORY IN THREE MOVES
  • Find real credentials and privileges that attackers could exploit.
  • Remove unnecessary access; plant believable false leads.
  • Detect intruders when they take the bait. The technology now belongs to Proofpoint.

The amusing names concealed an ordinary enterprise problem. Organizations accumulate access. Someone gets temporary privileges; an application saves a password; a test account outlives its test. A security policy may describe one network while an attacker encounters another. Illusive made that discrepancy its business: discover the shortcuts, remove what can be removed, and turn the remaining journey into a trap.

The thief needs directions

Ofer Israeli founded Illusive in 2014 with Team8, the Israeli company builder. Israeli came from research and development at Check Point. Shlomo Touboul served as the early CEO; Team8’s Nadav Zafrir chaired the board. Team8’s first launch operated in Tel Aviv and New York. An intruder inside a network still needs reliable information to make the next move.

A stolen login does not automatically reveal the important server, the useful connection or the more powerful account. Illusive’s Deceptions Everywhere technology distributed plausible false information across real enterprise assets. NEA’s investment explanation emphasized centralized, agentless deployment rather than a few isolated honeypots. The bait could resemble credentials or connections the attacker expected to find. Acting on it gave defenders evidence of movement that routine legitimate activity could otherwise obscure.

THE MOMENT ILLUSIVE WATCHES
01Initial access
02Find credentials
03Move sideways
04Reach the data
Bad directions, useful alarm. An illustrative attack path: remove the real shortcut or detect someone taking the false one.

This was a different detection premise from matching a known malware signature or deciding whether behavior looked unusual. A convincing credential that no legitimate user needs offers a narrower question: why is anyone using it? The distinction matters when an attacker operates through ordinary administration tools.

A tax collector tests the inside

An anonymous US state Department of Revenue supplies the practical example. Its published customer account describes substantial perimeter defenses but anxiety about traffic between internal systems. A breach at another state’s revenue department, reportedly unnoticed for over a year, sharpened that concern. The CISO investigated five deception vendors and tested Illusive with two loaned servers before buying its Attack Detection System.

“we realized we were hard and crunchy on the outside, but chewy in the middle.”Anonymous Department of Revenue CISO
Illusive customer case study

What changed the buyer’s mind was a proof of concept directed at a particular gap. The case describes responsive setup support and useful forensic detail. Treat this vendor-published account as customer testimony. The purchasing logic is worth copying: test the internal movement you fear, using your own environment, before committing to a rollout.

The audience was enterprises with valuable data and complicated networks. In May 2017, Merck KGaA, Darmstadt, Germany, selected Illusive to supplement existing controls across its global operations and protect scientific intellectual property. Published cases also describe banking, energy and retail environments. Security operations teams wanted an actionable intrusion signal; incident responders wanted evidence about where an attacker had gone.

Illusive employees gathered outdoors for a team photograph
The people behind the false leads. Illusive’s team, pictured on Team8’s portfolio page. Photograph supplied by Team8; original filename identifies 2018.

The real passwords were the other half

By February 2022, Illusive had introduced Spotlight and Shadow as an identity risk management platform. Spotlight discovered and mitigated exposed or excessive privileges. Shadow supplied deception-based protection for risks that could not readily be fixed. The expansion addressed a sensible objection to theatrical traps: if a real credential offers an easy route to valuable data, first remove that credential.

The accompanying AIR study examined 2021 assessments from 25 organizations, with environments ranging from roughly 1,500 to 75,000 endpoints. It reported exploitable identity risks on one in six endpoints. This was an assessed sample, not a census of every enterprise. Nevertheless, its examples explained the mechanism: a routine help-desk account could possess unintended authority, while cached privileged passwords gave an intruder access without inventing a new exploit.

1 in 6endpoints had exploitable identity risks
in Illusive’s 2021 assessments
A sampled finding, not your diagnosis. AIR 2022 covered 25 organizations; assess your own environment before borrowing the number.

The resulting product split remains legible in Proofpoint’s platform description: discover and prioritize vulnerabilities, remediate exposed identities, then detect active threats. The attraction is the combination of prevention and detection. It also makes Illusive adjacent to identity management and privileged access management, while complementing endpoint defenses. Acalvio’s ShadowPlex and SentinelOne’s Attivo-derived offerings occupy overlapping territory; deception alone does not distinguish one vendor from every rival.

What the buyer actually buys

Illusive’s enterprise software business relied on recurring revenue. Its October 2020 funding announcement reported 228% growth in new annual recurring revenues over twelve months and a $24 million B1 round, involving Spring Lake, NEA, Bessemer, Cisco, Microsoft and others. The growth percentage did not reveal the revenue base. Earlier announcements included a $5 million Series A and a $22 million Series B in 2015.

A 2024 UK procurement price sheet makes the successor economics more concrete. Spotlight was listed at £22.40 per endpoint for a twelve-month term in the 1-2,500 tier; the Spotlight-and-Shadow bundle at £26.88. Volume bands reduced the unit price. Those are dated procurement prices, not a universal current offer. Historical customer case studies do not disclose their contract bills.

Proofpoint announced its agreement to buy Illusive on December 12, 2022, and reported completion on December 28. Financial terms were undisclosed. The strategic fit was straightforward: protecting the inbox addresses an entry point; identity defense addresses what happens after entry. Today, the former Illusive website sends visitors to Proofpoint. Spotlight and Shadow carry the work onward, including a documented Shadow integration that alerts CrowdStrike to isolate a compromised host.

Start with the account nobody owns

The portable lesson is procedural. Inventory exposed identities as seriously as vulnerable software. Make someone responsible for removing test accounts. Check that temporary privileges actually expire. Test whether an intrusion alert reaches a responder who can act. These are editorial takeaways from Illusive’s cases, and they remain useful before any purchase.

Deception needs coverage and believable bait; an attacker who never encounters a lure may never trigger it. Credential cleanup needs care around business dependencies. Neither task abolishes the need for patching, access controls or incident response. Illusive’s proposition is persuasive where organizations have sprawling identities and uncertainty about internal movement. Even superheroes, it turns out, should leave the directory when the assignment is over.

Follow the trail