# MokN Secures $15 Million Series A to Expand Honeypot-Based Credential Defense Platform


Google Ventures-led investment fuels expansion of "phish-back" technology designed to intercept attackers before stolen credentials are weaponized


French cybersecurity startup MokN has closed a $15 million Series A funding round, bringing total capital raised to $18 million, as enterprises increasingly recognize that credential theft remains one of the most dangerous—and preventable—attack vectors. The Paris-based company, founded in 2023, has created a fundamentally different approach to identity compromise: instead of passively detecting breaches after the fact, MokN's platform actively deceives attackers by deploying ultra-realistic honeypots within enterprise networks to expose compromised credentials before they can be abused.


The funding round was led by Google Ventures, with participation from monitoring and analytics platform DataDog, plus returning investors Moonfire and OVNI Capital, alongside strategic angel investors. The fresh capital will accelerate MokN's expansion into North America and Europe, where credential-based intrusions have become the dominant attack pattern.


## The Threat: Credential Compromise at Scale


Credential theft has evolved into one of the most systematic attack vectors facing enterprises. According to Verizon's 2025 Data Breach Investigations Report (DBIR), credential abuse accounted for approximately 13% of confirmed data breaches last year—a persistent threat that often goes undetected until attackers have already pivoted into critical systems.


The challenge organizations face is simple but urgent: by the time a breach is discovered, stolen credentials may already be circulating in underground forums, used for lateral movement, sold to third parties, or weaponized in subsequent attacks. Traditional credential management and monitoring solutions operate reactively—they detect compromise after access logs show suspicious activity or after a breach notification arrives.


Key statistics driving the urgency:


  • Credential abuse remains in the top three confirmed breach vectors globally
  • Average time to detect credential compromise often exceeds weeks or months
  • Stolen credentials can remain valuable for months or years after initial theft
  • Identity-based attacks bypass many network perimeter controls

  • ## How MokN's Phish-Back Platform Works


    MokN's approach inverts the traditional security model. Rather than waiting for attackers to strike, the platform actively lures threat actors into a carefully controlled environment that appears identical to legitimate company resources.


    The platform's core mechanism:


    1. Honeypot Deployment: MokN plants ultra-realistic decoy access points—fake email accounts, fake internal portals, fake database credentials—throughout the enterprise environment

    2. Credential Harvesting: When attackers attempt to use stolen credentials or phishing campaigns against these honeypots, their actions are logged and analyzed

    3. Threat Intelligence: The moment an attacker interacts with a honeypot, MokN's platform identifies which credentials are compromised and what attackers already know about the organization

    4. Rapid Neutralization: Security teams can immediately revoke compromised credentials and investigate the scope of the breach—*before* legitimate systems are accessed


    This approach, which MokN is marketing as "Active Identity Recovery," represents a new category of identity-focused defensive technology. Rather than assuming credential compromise will happen and planning for incident response, organizations can now detect and contain it proactively.


    ## Funding Details and Expansion Strategy


    MokN's Series A represents significant validation from both traditional venture capital and major tech platforms. Google Ventures' participation is particularly notable—the tech giant's investment signals serious interest in identity-based security solutions as cloud migration and hybrid work make credential theft an increasingly attractive attack surface.


    The capital will be deployed across:


  • Geographic Expansion: New offices in the United States and United Kingdom, reflecting where credential-based intrusions have become dominant
  • Sales and Marketing: Acceleration of enterprise go-to-market activities to reach organizations managing thousands of identities
  • Customer Success: Expanded support teams to help organizations operationalize the phish-back platform and integrate it with existing security tooling
  • Research and Development: Enhanced capabilities to make honeypots even more convincing and expand detection beyond traditional credential vectors

  • "As a former SOC Manager, I experienced firsthand how compromised identities remained a critical blind spot," said Gautier Bugeon, MokN co-founder and CEO. "MokN was built to change that. Today, we work with major enterprises to define a new category—Active Identity Recovery—giving them a proactive edge against identity-based attacks."


    ## The Broader Context: Identity as the New Perimeter


    MokN's funding round occurs within a broader market shift toward identity-centric security. As organizations have deperimeterized—moving workloads to cloud platforms, embracing hybrid and remote work, and implementing zero-trust architectures—the password and credential have become the new battleground.


    Threat actors have adapted accordingly. Rather than attempting to breach firewalls or exploit unpatched services, modern attackers focus on:


  • Phishing campaigns targeting employee credentials
  • Lateral movement using valid credentials inside trusted networks
  • Supply chain attacks that compromise service provider credentials
  • Account takeover targeting high-privilege identities (administrators, service accounts)

  • Traditional identity and access management (IAM) solutions focus on *governance*—ensuring the right people have the right access. But they often operate after compromise has occurred. MokN's honeypot approach addresses the detection and interception layer that sits between compromise and exploitation.


    ## Technical Implications for Enterprise Security


    Organizations deploying MokN's platform face several important considerations:


    Integration Requirements: Honeypots must be seamlessly integrated into existing workflows to remain believable. This requires careful coordination with IT teams, directory services (Active Directory, Okta), and application owners.


    Alert Fatigue vs. Sensitivity: False positives from honeypots can drown security teams in alerts. MokN's platform must balance sensitivity (catching real attackers) with specificity (not triggering on legitimate misconfigurations or mistakes).


    Forensic Value: Each honeypot interaction provides forensic data—which attacker tools were used, what reconnaissance preceded the attempt, which credential repositories were targeted. This intelligence is valuable for threat hunting and incident response.


    ---


    ## HackWire Analysis


    The timing of MokN's expansion into the U.S. market reflects a critical inflection point in how enterprises defend against modern threats. We've moved past the era where credential compromise could be treated as a containable afterthought. According to Verizon's data, credential-based attacks now represent a routine attack vector—not the exception.


    What makes MokN's approach strategically important is that it shifts the incentive structure for attackers. Honeypot-based detection doesn't just catch attackers; it actively punishes reconnaissance and early-stage exploitation attempts. An attacker can no longer safely test stolen credentials; the moment they interact with a honeypot, the organization knows a compromise has occurred *before* any legitimate damage.


    This creates a detection gap closure that traditional monitoring tools cannot achieve. You cannot retroactively detect a credential that was stolen weeks ago and only used today. But you *can* detect the moment an attacker attempts to use it, if you've planted the right trap.


    The pattern recognition here is important: we're seeing a wave of companies funded to address identity-based attacks from different angles. Geordie (AI security governance), DataDog (credential and identity analytics), and now MokN (active honeypot-based detection) all tackle the same fundamental vulnerability—that credentials are the weakest link in modern enterprise security.


    For defenders, the concrete next step is to audit the current visibility into credential usage. Do you know, in real time, when a credential harvested in a phishing attack is first used? Can you respond within minutes, or only after an alert fires? Most organizations cannot answer affirmatively. That's the gap MokN is explicitly built to close.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)