EN
Back to the archive

The archive · Developer & Business Tools · Product decision · 2024–2026

MokN bets 'phish-back' decoys recover stolen credentials; GV's first French bet, $15M

Paris startup plants fake VPNs and webmail to trap attackers into exposing stolen credentials; €2.6M seed, then a $15M Series A from Google Ventures.

MokN

The betDeploy ultra-realistic decoy portals that trap attackers and recover stolen credentials before use — a new category, Active Identity Recovery.Scaling

What the business is

MokN is a Paris-based cybersecurity startup whose 'phish-back' platform plants decoy VPN, webmail and authentication portals that lure attackers into exposing stolen credentials, triggering automated recovery workflows.

Starting capital€2.6M seed led by Moonfire (October 2025); $15M Series A led by GV (June 2026).

How it started

MokN was founded in 2024 in Paris by Gautier Bugeon, a former Security Operations Centre manager at mining multinational Eramet, with co-founders Adrien Casteleiro, Alexis Georges and Antoine Coudoux. Bugeon's insight: traditional security detects stolen credentials only after they appear on the dark web or get used.

What happened

In October 2025 MokN raised a €2.6M seed led by Moonfire with OVNI Capital and Kima Ventures, protecting over 500,000 users with more than €1M in ARR. Seven months later it closed a $15M Series A led by GV (Google Ventures) — the firm's first French investment — with Datadog, Moonfire and OVNI; by then it protected over 1M users across large enterprises including Fortune Global 500 companies.

How it ended up

Still scaling: Series A funds a multi-product Active Identity Recovery platform and expansion into the US and UK.

Background

MokN is a Paris-based cybersecurity startup founded in 2024 by Gautier Bugeon, a former SOC manager at mining group Eramet, with three co-founders. Its bet inverts the security playbook: instead of detecting breaches after stolen credentials are abused, it recovers the credentials before attackers can weaponize or sell them.

The flagship product, Baits, deploys ultra-realistic decoy environments — fake VPN portals, authentication pages and webmail systems mirroring a company's real infrastructure. When attackers try stolen credentials against the decoys, security teams are alerted and recovery workflows trigger before accounts are actually breached.

MokN announced a €2.6M seed led by Moonfire in October 2025, protecting 500,000+ users with €1M+ ARR. Seven months later, GV (Google Ventures) led a $15M Series A — its first investment in a French startup — with Datadog, Moonfire and OVNI; by then MokN protected over 1M users at enterprises including Fortune Global 500 companies.

What has to be true

  • Detection-only security reacts after the damage; intercepting stolen credentials before use attacks the actual loss event.
  • Founder-market fit: as a SOC manager Bugeon experienced how late response teams learn about credential theft.
  • High-fidelity decoys turn the attacker's own tooling against them and trigger automated recovery, a wedge incumbents hadn't built.
  • GV's first French investment signaled the category (Active Identity Recovery) was credible to institutional investors.

What can be applied

The incumbent playbook acts after the loss. Inverting the order — letting attackers hit decoys first — creates a wedge no incumbent owns and a category a startup can define.

Aftermath

As of 2026-06-01, MokN protected more than one million users across large enterprises, including Fortune Global 500 companies, and planned to build what it calls the first multi-product platform for Active Identity Recovery: expanding beyond credentials to stolen browser cookies, active sessions and customer account compromises, with new products due by end of 2026. Leadership operated between Paris and New York, with UK offices planned and 30 hires targeted by end of 2027.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases