MokN Banks $15M to Turn Phishing Infrastructure Against Attackers
The startup's decoy access-point platform tries to catch credential thieves in the act — before stolen logins get used.

MokN just closed a $15 million funding round for a platform built around a simple adversarial idea: if attackers are going to phish your users, make some of those targets fake.
The core mechanic is honeypot-flavored. MokN deploys decoy access points — convincing enough to attract credential-harvesting attacks — and watches what happens when threat actors bite. When an attacker submits credentials to a decoy, the platform flags it. The organization gets an early-warning signal before any real account sees abuse.
It's a classic deception-defense approach dressed in modern phishing clothes. Honeytokens and canary credentials have existed for years; the wrinkle here is applying the logic specifically to phishing infrastructure at scale, so defenders can surface attacker tooling and timing rather than just clean up after a breach.
Call it "phish-back" if you want the marketing term. The underlying primitive is closer to a tarpit with logging.
Why does timing matter so much here? Because the window between credential theft and credential use keeps shrinking. Automated infostealer pipelines can move from phished login to account takeover in under an hour in documented campaigns. A detection signal that fires at compromise time — not post-login — buys defenders something genuinely useful: lead time.
That said, the obvious question is attacker awareness. Sophisticated threat actors already probe targets before committing to a full campaign. Decoy access points only work if adversaries can't trivially distinguish them from real ones. MokN's competitive moat lives entirely in how convincing those fakes are and how quietly the detection telemetry runs.
Fifteen million dollars is a reasonable seed-to-A range for an identity-adjacent security product right now. The deception-defense market has been quietly consolidating — Attivo Networks folded into SentinelOne, IllusionBLACK got absorbed — so there's room for a focused phishing-specific play if MokN can demonstrate real detection rates rather than demo-ware fidelity.
No CVEs involved. No zero-days. Just old-school deception tradecraft, repackaged for the current phishing threat surface.


