Skip to content
All funding roundsFunding round · MokN

MokN raises $15M in Series A: GV invests in a French startup for the first time

15 M$05.26Series A
MokN lève 15 M$ en Série A : GV investit pour la première fois dans une startup française
Analysis

MokN raises $15M in Series A: GV invests in a French startup for the first time

The essentials. MokN, founded in Paris in 2023, announces a $15 million Series A led by GV (formerly Google Ventures), with Datadog, Moonfire and Ovni Capital. The startup has developed a so-called "phish-back" technology: fake login portals exposed on the internet that trap attackers and retrieve stolen credentials before they can be used. This is GV's first investment in a French startup.

Key takeaways

  • $15M Series A (May 2026), following a €2.6M seed round (October 2025)
  • GV, Google's fund, is investing in France for the first time
  • 35 clients, including several CAC40 companies; more than one million users protected
  • ARR above €1M reported as early as the seed round (FrenchWeb, October 2025)
  • 31% of data breaches involve compromised credentials — the number one attack vector (IBM Cost of a Data Breach Report 2025)

What MokN does

Phishing remains the most common way into corporate systems. Conventional tools — email filters, team training, MFA — reduce the risk but don't eliminate it. The real question is: what happens once credentials have been stolen?

MokN answers this question with a reverse approach. The company deploys fake login portals exposed on the internet — VPNs, email services, internal tools — that are exact replicas of an organization's real environment. When an attacker tests stolen credentials on these portals, they believe they are accessing the systems. MokN validates the credentials in real time against the actual directories, triggers an immediate alert, and resets compromised access. Average time from detection to neutralization: less than three minutes.

The product is called Baits. It stands apart from traditional internal honeypots because it operates on the public internet — where attackers have time to probe, compare, and validate their data. The portals are "high fidelity": valid certificates, plausible domains, and organizational context specific to each client. MokN also offers Lantern, a complementary external attack surface management tool.

The company protects more than one million users across organizations whose combined revenue exceeds $480 billion. It counts 35 clients, including several CAC40 companies. The model targets large enterprises and mid-market companies, with CISOs as the primary points of contact.

Funding round details

  • Amount: $15 million
  • Date: May 2026
  • Round: Series A
  • Lead investor: GV (Google Ventures)
  • Co-investors: Datadog, Moonfire (existing investor), Ovni Capital (existing investor)
  • Total raised since 2023: ~$17.6M (€2.6M seed + $15M)
  • Headquarters: Paris
  • Founders: Gautier Bugeon (CEO), Alexis Georges, Adrien Casteleiro, Antoine Coudoux — all from the world of offensive security and pentesting
  • Use of funds: Strengthening R&D, new products (protecting customer accounts against stolen cookies and sessions), international expansion (United States, United Kingdom, Europe)

Why this funding round matters

Several signals deserve attention beyond the amount itself.

GV as a validation signal. GV rarely invests outside the United States and a few established hubs (Israel, UK). This is its first check in a French startup. Luna Schmid, associate at GV, said that MokN "has built a tool that turns the tables on attackers". In the vocabulary of US funds, that is rarely an empty phrase: GV is known for its in-depth technical due diligence. The fact that they are leading this round sends a strong signal of technical validation, beyond the capital itself.

Datadog as a strategic co-investor. Datadog's presence at the table is no accident. Datadog is itself a player in observability and cloud security. Its participation is most likely tied to an integration or distribution thesis, not just financial returns. This positions MokN within a broader value chain, where detection and response tools interconnect.

[UNIQUE INSIGHT] The combination of GV + Datadog in a Series A for a startup with 35 clients is unusual. It suggests MokN is seen as infrastructure, not a niche tool. "Credential deception layers" could become a standard layer of the enterprise security stack, much like EDRs did in the 2010s. If that's the thesis, 15 M$ is a modest stake to secure an option on this market.

Real ARR traction as early as the seed stage. At the time of its seed round in October 2025, MokN already reported more than one million euros in ARR. Eight months later, it claims 35 CAC40 clients. Going from seed to Series A in under a year, with a visible multiplication of its client base, suggests a short sales cycle for this type of solution — which is rare in enterprise cybersecurity.

What this raise reveals about the cybersecurity market in 2026

MokN fits into a broader trend that goes beyond phishing.

The shift in focus: from prevention to active detection

For 20 years, security has focused on stopping attacks from succeeding. Filters, MFA, training — the defensive line has been pushed back, but stolen credentials remain the number one breach vector (31 % of breaches according to IBM, 2025). The new generation of tools — MokN, along with players like Stytch, SpyCloud, and Flare — starts from the premise that compromise is inevitable and that detection and neutralization need to happen downstream. This is a doctrinal shift, not a marginal improvement.

Tech corporates as co-investors: an accelerating pattern

Datadog's participation in this round illustrates a structural trend in cybersecurity venture capital: major tech players invest in complementary startups to enrich their product ecosystem and secure acquisition or integration options. Microsoft, Palo Alto, and Crowdstrike have been running this strategy for years. Datadog is now following suit. For cybersecurity startups, attracting a corporate as a co-investor is now a signal of legitimacy almost as strong as backing from a tier-1 VC.

Paris as a credible hub for offensive cybersecurity

MokN joins a Paris-based cluster of offensive security startups — Filigran, Sekoia, Hackuity — that are steadily establishing themselves internationally. GV's decision to place its first euro in France in an offensive security company is no accident: Paris concentrates a pool of talent from pentesting, corporate red teams, and government services (ANSSI). This human capital is hard to replicate. It is a structural advantage for the sector.

FAQ

Who are MokN's founders?

MokN was founded in 2023 in Paris by Gautier Bugeon (CEO), Alexis Georges, Adrien Casteleiro, and Antoine Coudoux. The four founders have backgrounds in offensive security and pentesting. No further biographical details have been disclosed by the company to date.

How much has MokN raised in total?

MokN raised €2.6 million in seed funding in October 2025 (led by Moonfire, with Ovni Capital and Kima Ventures), then $15 million in Series A in May 2026 (led by GV, with Datadog, Moonfire, and Ovni Capital). The combined total stands at around $17.5 to $18 million, depending on the exchange rate at the time of each round.

Who are MokN's main clients?

MokN protects 35 clients, including several CAC40 companies. The company does not disclose its clients' names. It states that it protects more than one million users across organizations whose combined revenue exceeds $480 billion (official website mokn.io, retrieved 2026-05-29).

What is MokN's core technology?

The flagship product is called Baits. It deploys fake login portals (VPNs, messaging apps) exposed on the public internet. When an attacker tests stolen credentials, MokN validates them in real time, immediately alerts security teams, and triggers access resets. According to the company, neutralization takes less than three minutes.

What will the $15M raised by MokN be used for?

MokN plans to strengthen its R&D to develop new products — notably customer account protection and the detection of stolen cookies and sessions — and to accelerate its international expansion: the United States, the United Kingdom, and the rest of Europe.

Sources

Last step

You do not need more channels.
You need someone flying the plane.

Free audit · 48hSee the Uclic deck

FreeResults in 48hNo commitment

06 17 12 54 284.9Google4.96Sortlist4.3Trustpilot40+ B2B clients