All stories
Threat Intelligence12 min read

How a Startup Unmasked the Insider Leaking Its Roadmap to a Rival

Their unreleased plans kept showing up in a competitor's pitches. Here's how a founder used Expose to trace the leak - carefully, and without accusing the innocent - back to where it was really coming from.

How a Startup Unmasked the Insider Leaking Its Roadmap to a Rival
On this page

The plans that kept arriving early

The first time it happened, Daniel told himself it was a coincidence. His startup - a forty-person company building developer tools - had an unreleased feature on its private roadmap, known to maybe a dozen people internally. Then a customer mentioned, almost in passing, that a competitor's sales rep had pitched them something nearly identical the week before, framed as a preview of what was coming. Coincidence in a crowded market. It happens.

The second and third times, it stopped feeling like coincidence. Internal-only positioning showed up almost verbatim in the rival's messaging. A pricing experiment the team had only discussed in a closed meeting surfaced in a competitor's counter-offer to a deal still in progress. The pattern was unmistakable and stomach-turning: something the company knew only internally was reaching a competitor, repeatedly and quickly. There was a leak, and it was almost certainly a person.

This is the moment a leak investigation either goes well or goes badly, and the difference is entirely in the temperament of whoever runs it. Done wrong, it becomes a paranoid witch hunt that poisons a small company's culture, accuses the innocent, and often misses the guilty. Done right, it's a careful, evidence-led process that protects everyone who didn't do it. Daniel, to his credit, understood the stakes of getting it wrong. He opened Expose - not to point a finger, but to find facts.

Defining the problem before chasing a person

Daniel's first discipline was to resist the urge to suspect someone. The fastest way to ruin a leak investigation is to start with a theory of who and then collect only the evidence that fits it. Instead he started with the information: what exactly leaked, and who had access to each piece? Mapping the access list for each leaked item is unglamorous, but it's the foundation. The leak had to come from the intersection of people who knew all of the leaked things - which was a much smaller set than the company as a whole, but still more than one person.

With that internal access map drawn, the question became external: was there any discoverable connection between anyone in that small set of people and the competitor that kept benefiting? This is where Expose came in - not to surveil employees, which would be both wrong and counterproductive, but to examine the public, open-source footprint for relationships and signals that an internal access list can't reveal. People's professional lives, affiliations, and connections leave traces in the open record, and those traces are visible to anyone.

What the open record showed

Daniel was careful here, and the care matters. He looked only at what was already public - the kind of professional footprint anyone can see - and he looked across everyone with access, not just a pre-chosen suspect, precisely so the investigation wouldn't become a targeted hunt. He ran the access-list names and the competitor's identity through Expose and asked a neutral question: are there any public connections between these people and that company?

Most of the access list came back clean, which was itself valuable - it cleared people who would otherwise have lived under a cloud of vague suspicion. But the correlation surfaced a set of signals around one individual that the others didn't have:

  • a public professional connection - a long-standing, openly visible relationship - between that employee and a senior person at the competitor;
  • a recently created, lightly disguised social account whose handle echoed one the same person used elsewhere, surfaced via a reused profile image through reverse-image search;
  • a public post, since half-deleted, hinting at dissatisfaction and an imminent move;
  • a timing correlation between that person's access to each leaked item and the competitor's subsequent use of it.
"The relationship being public was the whole point," Daniel said. "I wasn't reading anyone's DMs - I'd never. I was looking at what the person had themselves chosen to put in the open, and asking whether it lined up with the access map. When it did, over and over, that wasn't a hunch anymore."

Handling it the right way

Daniel did not march into the office and confront anyone. Acting on an open-source lead as if it were proven is how companies create wrongful-termination suits and defamation claims, and how they sometimes punish the wrong person while the real leaker watches. Instead, he did the measured things.

First, he preserved the findings in a structured export from Expose, with sources and dates, so the record was contemporaneous and clean. Second, he brought in employment counsel and, given the confidential-information dimension, the appropriate specialists - handing them a documented starting point rather than a rumor, and letting the formal, lawful process take over from there. Third, working with counsel, the company used legitimate internal means - the access logs and controls it already had every right to examine - to corroborate or refute the open-source lead through evidence that could actually establish transmission, rather than relying on public correlation alone.

The internal evidence, examined properly and lawfully, aligned with the lead. The matter was then handled as a serious confidential-information issue through the correct legal and HR channels - not as a public spectacle, and not on the strength of OSINT alone, but on a complete, defensible record that protected the company and treated even the person at the center of it with due process. Just as importantly, the careful, evidence-led approach meant the eleven other people on the access list never spent a day under suspicion they hadn't earned.

The footprint cuts both ways

The case left Daniel with a sharper view of his own company's exposure, in two directions. The first was obvious: confidential roadmap information was reaching too many people too casually, and access discipline - who needs to know what, and when - tightened considerably afterward. A leak is partly a people problem and partly an access-design problem, and the second is the one a company actually controls.

The second realization was subtler. The same open-source visibility that helped trace the leak also meant the company's own people - and the company itself - were legible to outsiders in ways worth understanding. A competitor running the same kind of footprint analysis could map relationships, spot disgruntled employees, and identify who to approach. Periodically understanding your own organization's open-source shadow - not to surveil employees, but to grasp what an adversary can see - became part of how Daniel thought about security. You defend differently once you know what's visible.

The quiet lesson

The thriller version of this story has a founder playing detective and dramatically unmasking a traitor in a conference room. The real one is more careful and more responsible. The leak was real and it was a person, but the way Daniel handled it mattered as much as catching it: he protected eleven innocent colleagues by looking at everyone fairly, he refused to confuse a strong lead with proof, and he let a lawful process - not his own certainty - determine the outcome.

The signals that pointed to the source had been public the whole time, placed there by the person themselves. The difference was a founder who looked at the open record rather than the team's faces, who kept a lead a lead until real evidence made it more, and who understood that in a leak investigation, getting it right means protecting the innocent just as much as finding the guilty.

Could you trace a leak without accusing the wrong person?

Expose correlates handles, emails, and public footprints into one picture - so a leak investigation surfaces a documented lead instead of a witch hunt.