Israeli startup Memcyco, which offers real-time phishing and account takeover protection, raised a $37M Series A led by NAventures and others
The round included Steve Pagliuca's Pags Group, as Memcyco focuses on stopping AI-driven attacks before credentials are misused.
Context & Ripple Effects
Memcyco’s financing extends a record of Israeli cyber companies attracting capital for increasingly automated defenses: earlier coverage ranged from phishing-awareness tools to automated attack simulation and cloud-security platforms such as Cyera’s autonomous cloud-security raise.
The distinction is where Memcyco sits in that stack: it targets the interval between a phishing attempt and the misuse of stolen credentials, framing account takeover as a real-time prevention problem rather than solely a training, testing, or response issue.
First-order effects
- Memcyco gains $37M in Series A funding to build and commercialize its real-time phishing and account-takeover protection, with NAventures leading and Pags Group participating.
- The round gives the company added backing as it sells a product positioned against AI-driven attacks before compromised credentials are used.
Second-order effects
- Security buyers evaluating phishing defenses may place greater weight on controls that protect active sessions and accounts, not just employee awareness—an evolution from the earlier employee-focused phishing model.
- Vendors in adjacent resilience, threat-simulation, endpoint, and identity-security categories will face pressure to show how their tools prevent or limit credential misuse in real time.
Third-order effects
- If this product category gains adoption, phishing defense could become more tightly integrated with identity and application-session protection, broadening the security stack around account takeover.
- The funding is another signal that cyber investment is moving toward defenses designed for more automated attacks; whether standalone tools persist or are absorbed into broader platforms remains uncertain.
The trend: AI-enabled attack methods are pushing cyber budgets from detecting or training around phishing toward continuously protecting identities, sessions, and application access.