Memcyco

Fraud PreventionDeceptionThreat Intelligence also known as Memcyco Inc.

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Defensible: Defensibility of 15 or above. A position that stays hard for rivals to replicate.
Founded 2021
Funding $47M
Last updated 2026-08-18

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Memcyco protects a bank's or a retailer's customers from fake copies of its website. On its own account, it spots the impersonating site while attackers are still staging it and names the individual users who reach it. When one of those users types a password, Memcyco swaps it for a marked decoy that exposes the attacker on replay. Its four founders sold their previous security company, Memco Software, for more than $500 million in 1999, CTech reports. National Bank of Canada's venture arm helped lead a $37 million Series A in January 2026 and calls itself a customer as well as an investor. Every efficacy number in the reviewed record comes from Memcyco, including a 65% drop in account takeovers at a bank it does not name.

Sourced Details

Description Memcyco sells real-time defence against website impersonation, phishing and account-takeover fraud, detecting scams against a customer's own brand as they unfold and identifying the individual end users exposed to them. [f1]
Founded 2021 [f2]
HQ Bnei Brak, Israel [f2]
Funding $47M total [f3]
Latest funding Series A [f3]

Products

Product What it does
Memcyco Digital Impersonation Threats & Account Takeover Protection Detects impersonating sites as they are staged and launched, flags the end users who reach them, and substitutes marked decoy credentials for the ones those users submit.
Memcyco Device Account Takeover Protection Surfaces device and session signals tied to man-in-the-browser activity, session hijacking and remote-access manipulation during customer journeys.
Memcyco Website CTI Reports impersonation campaigns, attacker infrastructure, phishing-kit components and credentials harvested through phishing pages as evidence for investigation.
Memcyco Social Media Monitoring Tracks social profiles, pages and paid ads that impersonate an organisation, its executives or its customer-facing accounts.
Memcyco Takedown Coordinates removal of impersonating websites, social profiles, fraudulent ads and unauthorised mobile apps across web, social and mobile channels.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Memcyco Digital Impersonation Threats & Account Takeover Protection finds impersonating copies of a customer's website, names the users who reach them and swaps their credentials for decoys, and Memcyco Takedown removes the fake assets. These capabilities are mapped to the Cyber Defense Matrix. [f4]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 26 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 Memcyco names the buyer and the moment precisely, selling to banks, credit unions, card issuers and retailers whose own customers are robbed through a convincing copy of the brand's website, at the stage before those customers reach a login page. The pain is quantified by figures Memcyco relays rather than generates: its Series A announcement puts account-takeover attacks up 250% across 2024 and 2025 against a projected $343 billion in online payment fraud losses by 2027, and CTech carried the same two numbers. [s5, s6, s7, s11]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 3/5 Memcyco's own pages describe the mechanism, naming in-page sensors it calls Nano-Defenders, a persistent device identity it calls Device DNA that survives IP changes and VPN use, detection of cloning and impersonating certificates before a fake site reaches users, and substitution of marked decoy credentials in fake login forms. The reviewed record carries no third-party technical evaluation and no inspectable implementation, and the customer accounts of it are case studies Memcyco publishes itself, so vendor material alone evidences that depth. [s4, s3, s10]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5 The enabler Memcyco names is cheap automation: its January 2026 announcement says AI-driven tooling, off-the-shelf phishing kits and one-click website cloning now let scammers deceive customers long before traditional controls activate. The buyer-side demand behind that is analyst commentary the company itself announced plus one banking-platform deal, so no budget-line evidence, buyer survey or regulatory driver from an independent source reaches the record. [s5, s10, s11]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 CTech reports that the four founders previously built and exited several companies, most notably Memco Software, sold for more than $500 million in 1999, and names each with a current role. The Jerusalem Post separately describes Israel Mazin as a serial entrepreneur whose career includes founding multiple cybersecurity ventures, and names no exit, so a prior in-domain exit reported by one independent outlet clears the verifiable-prior-exit rung, and the record shows no sustained publication record and no independent recognition of the individuals that would carry it higher. [s6, s8]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Distribution is the strongest evidence and it is multiply sourced: Deloitte agreed to offer the software to its clients in 2024, Integrity Software resells it in Israel, Trident Digital Tech announced an Asia-Pacific integration, and Candescent's own vice-president is quoted confirming a marketplace partnership. National Bank of Canada's venture arm helped lead the Series A and describes itself as a customer as well as an investor. Named end customers stay thin, and every reference beyond that bank appears on Memcyco's own pages. [s12, s11, s14, s13, s5, s6]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5 Memcyco has raised $47 million in total, including an oversubscribed $37 million Series A in January 2026 that is proportional to a company selling since 2023 and naming enterprise distribution. Its chief executive told CTech the company grew sevenfold over the prior year and had not needed outside money at first. No revenue level, margin or measure of output per dollar appears in the reviewed sources, so efficiency itself stays unconfirmed. [s6, s5]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 CB Insights files Memcyco against a set that spans brand protection, account-fraud detection and bot management, naming Allure Security, Verosint and Netacea. Memcyco's own pages address security teams and fraud and risk teams separately, with different promises to each. A buyer can place the product, but still needs Memcyco to say which budget line pays for it. [s15, s16, s17]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5 Absorbing this would take more than a feature release, because the code runs inside the customer's own site or WAF, the device history accumulates across attack stages, and the outputs feed the buyer's SIEM and fraud engines. The signals underneath are ones a vendor that already handles the customer's web traffic could gather too, so the friction is real without being structural. [s4, s3, s16]
Business Risks Memcyco could keep every efficacy figure in-house, leaving a bank's procurement team with a 65% reduction claim and a 50% reduction claim that only Memcyco has published…
  • Memcyco could keep every efficacy figure in-house, leaving a bank's procurement team with a 65% reduction claim and a 50% reduction claim that only Memcyco has published.
  • A vendor that already handles the customer's web traffic, such as a content delivery network or bot-management provider, could add in-page impersonation detection and reach the same customers through an existing contract.
  • Memcyco could leave its published counts unreconciled, with more than 13 million account takeovers roadblocked in a single month on its home page against more than 3.5 million account-takeover attempts prevented to date in its funding announcement, and invite a buyer to discount both.
  • Named distribution could stay concentrated in Deloitte, Candescent, Integrity Software and Trident Digital Tech, leaving Memcyco's reach dependent on partners' priorities.
  • Memcyco could keep displaying ISO and SOC 2 seals without publishing a readable report or trust portal, leaving a regulated buyer no attestation to read.
  • Named end customers could remain confined to Memcyco's own publications, leaving a prospect no independent account of what a deployment delivered.
Problem & Market Memcyco sells to organisations whose customers can be robbed through a convincing copy of the organisation's own website…

Memcyco sells to organisations whose customers can be robbed through a convincing copy of the organisation's own website. Its argument is about timing rather than tooling. Multi-factor authentication, its Series A announcement says, activates at the login stage, well after the deception has begun, and Memcyco positions itself in the window between a fake site's creation and its takedown.

The size of the problem comes from figures Memcyco relays rather than measures. That announcement puts account-takeover attacks up 250% across 2024 and 2025 against a projected $343 billion in online payment fraud losses by 2027, and CTech carried the same two numbers in its report of the round. Neither figure has a generator named in the reviewed sources.

Memcyco addresses two teams inside a buyer. The page written for security teams promises lower operating expense, stronger compliance readiness and audit evidence a reviewer can pull on demand. The page written for fraud and risk teams promises fewer incidents, better fraud predictions and more key targets met faster. Memcyco's Candescent announcement frames the same gap, saying that many existing controls stay focused on authentication and transaction monitoring while users are exposed earlier. [s5, s6, s16, s17, s11]

Product Capabilities The product watches the attack from inside the customer's own web pages…

The product watches the attack from inside the customer's own web pages. Memcyco calls its in-page sensors Nano-Defenders and its device identifier Device DNA, and says the two work together to detect scam exposure, identify lured users and hold attack context together across devices and credentials. Device DNA is described as a persistent identity that survives IP changes and VPN use, which is how Memcyco says it recognises a returning attacker device.

The distinctive move is what happens when a customer's user types a password into a fake page. Memcyco substitutes marked decoys for those credentials, states that the decoys cannot open the genuine account, and detects the decoys when an attacker replays them against the real login flow. The same substitution is offered for payment-card data, and Memcyco can block access to the genuine site from an identified attacker device.

Memcyco adds intelligence and removal around that. Memcyco Website CTI reports impersonating sites, lookalike domains, phishing-kit components and credentials harvested through phishing pages, and Memcyco Takedown coordinates removal of impersonating websites, social profiles and fraudulent advertisements. Its APIs push high-priority alerts and pre-login session risk into the buyer's existing systems, and Memcyco says the correlated output lands in SIEM, fraud, access-control and response workflows.

Deployment is the commercial argument. Memcyco describes an agentless install into site code or through a WAF, running as managed software in AWS with United States and European hosting, and states that it starts in hours rather than weeks. It asks no app installation or involvement of the end user. [s4, s3, s2, s16]

Competitive Positioning Memcyco competes on two fronts at once, and an outside directory records it…

Memcyco competes on two fronts at once, and an outside directory records it. CB Insights names its top competitors as Allure Security, Verosint and Netacea, describing Allure Security as brand protection and disinformation security, Verosint as account fraud detection and prevention, and Netacea as behaviour-based bot management. Those are three different budget conversations.

Against the takedown vendors, Memcyco argues about the interval rather than the removal. Its about page describes safeguarding the exposure window between a fake site's creation and its takedown, and Memcyco Takedown coordinates removal as one product among several rather than as the whole offering. Against account-fraud vendors, Memcyco argues on timing: its funding announcement says multi-factor authentication typically activates at the login stage, well after the deception has begun.

What the record protects is narrower than what the company sells. Two granted United States patents assigned to Memcyco Ltd cover proving a website presentation authentic to the user, the earlier approach rather than the decoy and device work the company now leads with, and the reviewed sources name no patent, dataset or certification behind that later work. The other accumulating asset is device history, which the January 2026 announcement sizes at more than half a billion device identities mapped. [s15, s2, s27, s28, s5]

Go-to-Market & Traction The go-to-market evidence in the reviewed record is mostly other people's channels…

The go-to-market evidence in the reviewed record is mostly other people's channels. Deloitte agreed in January 2024 to offer the software to its own clients, Integrity Software sells and supports it in Israel, and Nasdaq-listed Trident Digital Tech announced an Asia-Pacific integration in April 2026. Memcyco separately announced itself as a certified marketplace partner of Candescent, saying it will be featured in the marketplace of a banking platform. Candescent's own boilerplate states that platform serves more than 1,300 financial institutions and over 30 million registered users, and its vice-president of fintech partnerships is quoted saying the arrangement helps clients detect and respond to fraud earlier in the attack flow.

National Bank of Canada's venture arm helped lead the Series A, and its representative is quoted saying that as both a customer and investor the venture arm has experienced how Memcyco enhances protection. Beyond that, the named end customers in the reviewed record are small. A case study names Holon Institute of Technology after a 2021 phishing attack on its students and staff, and the banking case studies describe their three subjects only by size and region.

Growth is described rather than audited. The Series A announcement reports a tripled customer base and an increase in annual recurring revenue, and Memcyco's chief executive told CTech in January 2026 that the company began selling in 2023 and had grown sevenfold over the past year. Memcyco's announcement of the Integrity Software agreement states the product is present in most banks in Israel, which is the vendor's own account rather than an independent count. [s12, s14, s13, s11, s5, s6, s21]

Team & Credibility The founders have done this before, and an independent outlet says so…

The founders have done this before, and an independent outlet says so. CTech reports that Israel Mazin, Gideon Hazam, Ori Mazin and Eli Mashiah previously built and exited several companies, most notably Memco Software, which sold for more than $500 million in 1999. The Jerusalem Post describes Mazin as a serial entrepreneur whose career includes founding multiple cybersecurity ventures.

The company they built this time is small and concentrated. CTech puts headcount at 90 people, about 60 of them in Israel, and the Jerusalem Post placed the headquarters in Bnei Brak in October 2025 while the funding announcement carries a Boston dateline. Mazin told CTech that the team agreed to stay out of cyber for several years after the earlier exit and started this company with revenue arriving quickly.

What the record does not carry is a research or publication standing for the current team, so a buyer weighing it has the earlier exit and two patents to go on. The reviewed sources contain no peer-reviewed work and no named vulnerability research, and the recognition they do carry, such as the 2026 Calcalist and CTech listing, names the company. Where an individual does appear is on the patents: two granted United States patents assigned to Memcyco Ltd name Eliyahu Mashiah, the co-founder who serves as chief technology officer, in their inventor field. [s6, s8, s5, s27, s28, s1]

Trust Readiness Memcyco displays its own compliance seals, and the reviewed record carries no report behind them…

Memcyco displays its own compliance seals, and the reviewed record carries no report behind them. A probe on 2026-08-18 found no trust portal. The /security and /trust paths return a not-found page, the trust and security subdomains answer with the home page, and so does a nonsense control subdomain, so the domain answers any name. Rendering each of the home page's four badge images in a browser shows an AICPA SOC 2 Type II seal and seals for ISO 27001, ISO 27017 and ISO 27018. No audit report, certificate number or registry entry for any of them appears in the reviewed sources.

The data question is sharper than the certificate question. Memcyco's privacy policy states that it collects personal information about the people who visit its customers' websites and mobile applications, under those customers' direction, and that it acts as a processor rather than a controller under GDPR. That places the buyer's own customers inside a third party's collection.

A regulated buyer would still have work to do. The product runs inside the buyer's own website and observes that buyer's own customers, and the reviewed record offers no attestation a reviewer can read, no penetration-test summary and no federal authorisation. [s20, s29, s30, s34, s35, s23, s31, s32, s33, s22, s4]

Competitors Allure Security, Verosint, Netacea…
Company Relationship Note Compare
Allure Security competes with CB Insights lists it among Memcyco's top competitors, describing it as brand protection and disinformation security.
Verosint competes with CB Insights lists it among Memcyco's top competitors, describing it as account fraud detection and prevention.
Netacea adjacent CB Insights lists it among Memcyco's top competitors, describing it as behaviour-based bot management.

Add analyzed competitors to compare them side by side with Memcyco.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Defensible 15 /21 Defensible: Defensibility of 15 or above. A position that stays hard for rivals to replicate. press the advantage

Memcyco's differentiating techniques are reproducible by a funded rival. The reviewed sources name no patent, dataset or certification behind the decoy-credential and device-identity work the company now leads with. Two granted United States patents assigned to Memcyco Ltd cover the earlier proof-of-authenticity approach, which shows a visitor that the page is genuine. What accumulates is device history, which the January 2026 funding announcement sizes at more than half a billion device identities mapped. The code also runs inside customers' own websites and its signals feed their fraud engines, so a replacement has to be rewired into both. The cited record does not size what that would cost.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 2/3 Memcyco ships software the customer installs into its own site, and attaches work its own people do. Memcyco Takedown coordinates removal of impersonating sites, profiles, advertisements and mobile apps, and the company's threat intelligence analyst posting describes producing reports and briefings for clients. Code and expertise blend in what the buyer receives, and the reviewed record documents no outcome liability the company accepts.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Leaving means pulling Memcyco's sensors out of the customer's own site code or WAF and rewiring the feeds into its SIEM, fraud engine and access controls, which is the meaningful friction of integrations and learned workflows. No qualifying rung-3 mechanism is documented: the record does not show that migrating requires re-architecting the dependent flows, and it names no state that cannot be exported. The cited record does not size the migration.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The seals Memcyco displays are commercial certifications, and the reviewed record carries no report behind them: rendering the home page badge images shows ISO 27001, ISO 27017, ISO 27018 and AICPA SOC 2 Type II, while the probed trust paths return a not-found page. No federal authorisation and no regime naming this product class appears in the reviewed record, so the assurance is procurement paperwork rather than a barrier to replacement.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Recognising a cloned page while attackers stage it, tying a returning device to earlier activity across IP and VPN changes, and substituting decoy credentials inside a live phishing flow are real-time systems work carried out against adversaries who change their infrastructure. Memcyco's announcement of a Frost & Sullivan brief describes the same interception inside impersonation infrastructure in real time.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The evidenced buyers are regulated institutions. The venture arm of National Bank of Canada that helped lead the Series A describes itself as a customer as well as an investor, Memcyco announced that Candescent will offer the product to banks and credit unions, the announcement of the Integrity Software agreement states the product is present in most banks in Israel, and the banking case studies describe an international bank, a card issuer and a North American top-ten bank. Those buyers require procurement and legal review before a replacement.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 Other security and banking products consume Memcyco's output rather than only end users. Its APIs push high-priority alerts and pre-login session risk into SIEM, fraud, access-control and response workflows, Memcyco announced that it will integrate within Candescent's banking platform, and Trident Digital Tech integrates it into an identity platform. It remains an application a fraud or security team works in rather than infrastructure other software depends on.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 2/3 The accumulated asset is device history: Memcyco's Series A announcement counts more than half a billion device identities mapped, and Device DNA is described as holding that history across attack stages. Two granted United States patents assigned to Memcyco Ltd cover proving a website authentic to the user, the earlier approach rather than the decoy and device work the company now leads with. The reviewed record names no exclusive corpus and no licensed content.
Strategic Market Segmentation Memcyco aims at organisations whose end customers transact on a branded website…

Memcyco aims at organisations whose end customers transact on a branded website. The Jerusalem Post reports the company describing that market as banking, card companies, e-commerce, airlines, logistics, online travel, financial information providers and cross-industry loyalty programmes. Financial services dominates the evidence behind that list, and the exceptions in the reviewed record are a case study naming an academic institution and an identity-platform partnership aimed across industries.

Inside a buyer, two teams are addressed with different promises. The page written for security teams offers lower operating expense and stronger compliance readiness, and points at audit evidence a reviewer can pull on demand. The page written for fraud and risk teams offers fewer incidents, better fraud predictions and more key targets met faster, with a live attack feed into the risk engine. Memcyco's Candescent announcement frames the same gap, saying that many existing controls stay focused on authentication and transaction monitoring while users are exposed earlier.

The widest reach in the reviewed record comes through a partner rather than through direct sales. Memcyco announced that it will be featured in the marketplace of a platform Candescent states serves more than 1,300 financial institutions and over 30 million registered users, and that the arrangement puts preemptive anti-fraud capability within reach of credit unions and regional institutions without expanding their resources.

Product Capabilities & AI Advantages Memcyco's technical claim is that it watches from inside the customer's own pages rather than from a scanner outside them…

Memcyco's technical claim is that it watches from inside the customer's own pages rather than from a scanner outside them. It calls the in-page sensors Nano-Defenders and the device identifier Device DNA, and says the two detect scam exposure, identify lured users and hold attack context together across devices and credentials. Device DNA is described as a persistent identity that survives IP changes and VPN use, which is how the company says it recognises a returning attacker device.

The deception layer is what separates the product description from monitoring. Memcyco substitutes marked decoys for credentials submitted into supported fake login flows, states that those decoys cannot open the genuine account, and detects them when an attacker replays them on the real site. It offers the same substitution for payment-card data and can block access to the genuine site from an identified attacker device.

Detection runs earlier than the fake site's launch, on the company's account. Memcyco says it detects reconnaissance and cloning activity, including lookalike domains and impersonating certificates, before an attack reaches users, and that it identifies signals of impersonating-site creation and staging before the site goes live. Memcyco's announcement of a Frost & Sullivan brief says the analyst firm highlights this approach as an example of preemptive fraud defence.

No independent evaluation of any of it appears in the reviewed sources. There is no third-party benchmark, no inspectable implementation and no customer technical writeup, so the mechanism is evidenced only by Memcyco's own documentation and by analyst commentary the company itself announced.

Sales Engagement & Go-to-Market The go-to-market evidence in the reviewed record is mostly partnerships…

The go-to-market evidence in the reviewed record is mostly partnerships. Deloitte agreed in January 2024 to extend Memcyco's software to its own clients, Integrity Software leads sale, implementation and first-line support in Israel, Nasdaq-listed Trident Digital Tech announced an Asia-Pacific integration in April 2026, and Memcyco announced itself as a certified marketplace partner of Candescent's banking platform.

The partner programme is built for that shape. Memcyco's partner page offers multi-tenant management of a portfolio of client accounts, integration with a partner's SIEM and fraud risk engine, and predictable pricing with no extras, which is how a vendor talks to resellers rather than to its own sales team.

Named direct references are fewer than the partnerships. National Bank of Canada's venture arm helped lead the Series A, and its representative says the venture arm experienced the product as a customer as well as an investor. Beyond that, Memcyco's case studies name Holon Institute of Technology and describe three banking customers only by size and region, and Memcyco's announcement of the Integrity Software agreement states that the product is present in most banks in Israel.

Growth figures come from the company. Its Series A announcement reports a tripled customer base and an increase in annual recurring revenue, and its chief executive told CTech in January 2026 that selling began in 2023 and that the company had grown sevenfold over the past year.

Pricing Model No price appears in the reviewed record…

No price appears in the reviewed record. The 69 page addresses in Memcyco's own sitemap include no pricing page, and the route it offers a buyer instead is a demo booking, so the number arrives in a sales conversation.

What the company publishes is a return argument. It tells partners to expect predictable pricing with no hidden extras or last-minute additions, and its own announcement of a Datos Insights mention says customers have reported up to tenfold return on investment in a first year of use. The Jerusalem Post repeats a tenfold figure and attributes it to the company.

The commercial logic is filling a gap rather than replacing what a bank already runs. Memcyco tells partners the product closes fraud risk gaps left by scanning-and-takedown-only services, and Candescent describes the neighbouring gap in a bank's stack as the stage before authentication and transaction monitoring engage.

Product Delivery & Operations Delivery is software the customer installs into its own site, and speed is the selling point…

Delivery is software the customer installs into its own site, and speed is the selling point. Memcyco describes an agentless deployment into site code or through a WAF, states that it starts in hours rather than weeks and months, and stresses that it asks no app installation or involvement of the end user. It runs as fully managed software in AWS with United States and European hosting.

Memcyco's own people do work behind the software. Memcyco Takedown coordinates removal of impersonating websites, social profiles and fraudulent advertisements, and the company's job posting for a threat intelligence analyst describes producing detailed threat intelligence reports and briefings for clients. Code and expertise blend in what the buyer receives.

Output is designed to leave the platform. Its APIs push high-priority alerts and pre-login session risk into other systems, and Memcyco says correlated events, intelligence, risk signals and takedown evidence land in SIEM, fraud, access-control and response workflows. That posture makes the product a source of signal for tools a bank already runs.

Earning Customers' Trust Memcyco displays compliance seals, and the reviewed record carries nothing a reviewer can read behind them…

Memcyco displays compliance seals, and the reviewed record carries nothing a reviewer can read behind them. A probe on 2026-08-18 found the /security and /trust paths returning a not-found page, found that the trust and security subdomains answer with the home page, and found a nonsense control subdomain doing the same, so the domain answers any name. Rendering each of the home page's four badge images in a browser shows an AICPA SOC 2 Type II seal and seals for ISO 27001, ISO 27017 and ISO 27018, and the reviewed sources carry no audit report, certificate number or registry entry for any of them.

The data-protection paperwork is more complete than the assurance paperwork. Memcyco's privacy policy states that it collects personal information about people who visit its customers' websites and mobile applications, under those customers' direction, and that it acts as a processor rather than a controller under GDPR. That places the buyer's own customers inside a third party's collection.

The exposure a regulated buyer would weigh is the placement. Memcyco's code runs inside the buyer's own website and its sensors observe that buyer's own customers. Against that, the reviewed record offers self-displayed seals, no readable attestation and no federal authorisation.

Platform Strategy & Ecosystem Positioning Memcyco is built to feed the systems its buyers already run…

Memcyco is built to feed the systems its buyers already run. Its APIs feed high-priority alerts to connected systems and pre-login session risk into authentication and access-control decisions, and the company says its correlated output reaches SIEM, fraud, access-control and response workflows.

Two integrations follow that pattern. Memcyco announced that it will integrate within Candescent's Intelligent Banking platform and be featured in its marketplace as an extensible identity and security solution. Trident Digital Tech integrates the detection and account-takeover prevention technology into its blockchain-based identity and authentication platform for Asia-Pacific.

The ecosystem position cuts both ways. One integration reaches a platform Candescent states serves more than 1,300 financial institutions. Memcyco then reaches that institution through the partner rather than directly.

Team & Execution Capability This founding team has built and sold a security company before…

This founding team has built and sold a security company before. CTech reports that Israel Mazin, Gideon Hazam, Ori Mazin and Eli Mashiah previously built and exited several companies, most notably Memco Software, sold for more than $500 million in 1999, and the Jerusalem Post describes Mazin as a serial entrepreneur whose career includes founding multiple cybersecurity ventures.

CTech puts headcount at 90 people, about 60 of them in Israel, and the Jerusalem Post placed the headquarters in Bnei Brak in October 2025 while the funding announcement carries a Boston dateline. Mazin told CTech that the founders agreed to stay out of cyber for several years after the earlier exit, that revenue arrived quickly, and that they had not needed to raise money at first.

The individual technical record runs through patents rather than publications. Two granted United States patents assigned to Memcyco Ltd name Eliyahu Mashiah, the co-founder who serves as chief technology officer, in their inventor field, and both cover proving a website presentation authentic to the user. No peer-reviewed work and no named vulnerability research appear in the sources reviewed, and the recognition they carry, such as the 2026 Calcalist and CTech listing, names the company.

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Memcyco home page: what the platform shows a customer during an attack official 2026-08-18
f2 Jerusalem Post feature, October 2025, stating the founding year press 2026-08-18
f3 CTech: Memcyco Series A, reported by Meir Orbach, January 2026 press 2026-08-18
f4 Memcyco products page: detection, decoy substitution and takedown capabilities official 2026-08-18
Profile Analysis Sources (35)
Id Source Tier Accessed
s1 Memcyco home page: positioning, decoy-swap claim and 2026 Calcalist and CTech listing
“Get real-time visibility of attack, attacker and each individual victim. Finally detect, protect and counter scams as they unfold.”
official 2026-08-18
s2 Memcyco about page: company description, agentless claim and leadership listing
“Memcyco is a digital risk protection company that provides real-time protection against digital impersonation, phishing and account takeover (ATO) attacks.”
official 2026-08-18
s3 Memcyco products page: the five product families and their stated capabilities
“Substitute marked decoys for credentials submitted through supported fake-login flows. The decoys cannot provide genuine account access and reveal attempted replay on the genuine site.”
official 2026-08-18
s4 Memcyco technology page: Nano-Defenders, Device DNA, hosting and the banking case-study headline
“Memcyco Nano Defenders and Device DNA work together to detect scam exposure, identify lured users, preserve attack continuity across devices and credentials, and enable earlier protection before impersonation becomes fraud.”
official 2026-08-18
s5 Memcyco Series A announcement, January 2026: investors, traction figures and the customer-investor quote
“Boston, January 27, 2026 – Memcyco, the real-time digital risk protection platform safeguarding enterprises from brand impersonation scams and account takeover (ATO), today announced it has secured $37 million in Series A funding, bringing the company’s total funding to $47 million.”
official 2026-08-18
s6 CTech: Memcyco Series A, reported by Meir Orbach, January 2026
“Israeli cybersecurity company Memcyco has raised $37 million in a Series A funding round, bringing its total capital raised to $47 million.”
press 2026-08-18
s7 Jerusalem Post report on the Memcyco Series A, January 2026
““These unique capabilities lead directly to measurable business impact. Customers have observed more than 10× ROI within the first year, a reduction of over 50% in ATO incidents, and significantly lower reimbursement costs,” the company assured.”
press 2026-08-18
s8 Jerusalem Post feature on Memcyco, October 2025, with an interview quote from the chief executive
“Memcyco, founded in 2021 and headquartered in Bnei Brak, has emerged as a global innovator in real-time scam detection and prevention”
press 2026-08-18
s9 Memcyco announcement of a Datos Insights Q1 2025 Fintech Spotlight mention, April 2025
““Credential-harvesting and ATO attacks have been notoriously difficult to detect, much less predict and prevent,” said David Mattei, Strategic Advisor at Datos Insights.”
official 2026-08-18
s10 Memcyco announcement of a Frost & Sullivan analyst brief, February 2026
“Frost & Sullivan highlights Memcyco’s approach as an example of this shift toward preemptive fraud defense.”
official 2026-08-18
s11 Memcyco announcement of the Candescent digital-banking partnership, May 2026
“NEW YORK, MAY 20, 2026 Memcyco today announced a strategic partnership with Candescent as a certified Marketplace partner.”
official 2026-08-18
s12 Memcyco announcement of the Deloitte partnership, January 2024
“New York, United States / Jan 22, 2024 – Memcyco Inc, the real-time digital impersonation detection and prevention solution provider, and Deloitte, the leading consulting, advisory, and audit services firm, today announced their strategic partnership in the cybersecurity sector.”
official 2026-08-18
s13 Memcyco announcement of the Trident Digital Tech partnership in Asia-Pacific, April 2026
“SINGAPORE, April 09, 2026 (GLOBE NEWSWIRE) — Trident Digital Tech Holdings Ltd (Nasdaq: TDTH) today announced a strategic partnership with Memcyco”
official 2026-08-18
s14 Memcyco announcement of the Integrity Software reseller agreement for Israel
“Integrity Software, a Matrix company specializing in providing software solutions to enterprises in Israel, has signed a partnership agreement with Memcyco.”
official 2026-08-18
s15 CB Insights profile page listing Memcyco competitors
“MEMCYCO's top competitors include Allure Security, Verosint, and Netacea.”
research 2026-08-18
s16 Memcyco solution page addressed to security teams
“Memcyco’s enhanced ATO protection saves global enterprises tens of millions in scam-related expenses from the first year.”
official 2026-08-18
s17 Memcyco solution page addressed to fraud and risk teams
“Monthly, Memcyco prevents over 1.4 million potential fraud incidents that clients would have had to deal with.”
official 2026-08-18
s18 Memcyco events listing, first page, showing 2026 conference appearances
“Memcyco at Datos Insights FinCrime Forum 2026”
official 2026-08-18
s19 Memcyco financial-institution case study describing three unnamed banking customers
“When these three financial institutions approached us about our flagship Customer ATO and Fraud Protection solution, foresight and visibility is exactly what Memcyco delivered.”
official 2026-08-18
s20 Probe of the Memcyco /security path on 2026-08-18, which returns HTTP 404
“Page not found - Memcyco”
official 2026-08-18
s21 Memcyco case study naming Holon Institute of Technology as a customer
“HIT, Holon Institute of Technology, is a well-established, unique, and multidisciplinary academic institution.”
official 2026-08-18
s22 Memcyco privacy policy: the data it processes on behalf of customers
“For the purposes of GDPR and other global privacy laws, Memcyco acts as a processor/instruction taker which accesses and processes Customer Data on behalf of its customers, which are the controllers/owners of such data.”
official 2026-08-18
s23 Memcyco home page badge image rendered in a browser 2026-08-18: an AICPA SOC 2 Type II certified seal official 2026-08-18
s24 Memcyco job posting for a Cyber Threat Intelligence Analyst
“Produce detailed threat intelligence reports and briefings for clients and internal stakeholders.”
official 2026-08-18
s25 Memcyco partner program page: what it offers resellers and service partners
“Enjoy attractive, predictable pricing you'll love, with no hidden extras, surprises, or last minute additions.”
official 2026-08-18
s26 Probe of the Memcyco page sitemap on 2026-08-18: 69 page URLs, none of them a pricing page
“https://www.memcyco.com/solution/credit-unions/”
official 2026-08-18
s27 Google Patents record for granted US patent US12393662B1
“US12393662B1 - Method for notifying a user upon access of an imposter website”
regulatory 2026-08-18
s28 Google Patents record for granted US patent US12248559B1
“US12248559B1 - Website presentation proof of authenticity and method for proving thereof”
regulatory 2026-08-18
s29 Probe of the Memcyco /trust path on 2026-08-18, which returns HTTP 404
“Page not found - Memcyco”
official 2026-08-18
s30 Wildcard-DNS control probe on 2026-08-18: a nonsense memcyco.com subdomain returns the home page
“Real-Time Digital Impersonation & ATO Fraud Protection”
official 2026-08-18
s31 Memcyco home page badge image rendered in a browser 2026-08-18: an ISO 27001 information security management certified seal official 2026-08-18
s32 Memcyco home page badge image rendered in a browser 2026-08-18: an ISO 27017 information security management certified seal official 2026-08-18
s33 Memcyco home page badge image rendered in a browser 2026-08-18: an ISO 27018 information security management certified seal official 2026-08-18
s34 Probe of trust.memcyco.com on 2026-08-18: the subdomain answers with the Memcyco home page rather than a trust portal
“Real-Time Digital Impersonation & ATO Fraud Protection”
official 2026-08-18
s35 Probe of security.memcyco.com on 2026-08-18: the subdomain answers with the Memcyco home page rather than a security portal
“Real-Time Digital Impersonation & ATO Fraud Protection”
official 2026-08-18
Deep-Dive Sources (35)
Id Source Tier Accessed
s1 Memcyco home page: positioning, decoy-swap claim and 2026 Calcalist and CTech listing
“Get real-time visibility of attack, attacker and each individual victim. Finally detect, protect and counter scams as they unfold.”
official 2026-08-18
s2 Memcyco about page: company description, agentless claim and leadership listing
“Memcyco is a digital risk protection company that provides real-time protection against digital impersonation, phishing and account takeover (ATO) attacks.”
official 2026-08-18
s3 Memcyco products page: the five product families and their stated capabilities
“Substitute marked decoys for credentials submitted through supported fake-login flows. The decoys cannot provide genuine account access and reveal attempted replay on the genuine site.”
official 2026-08-18
s4 Memcyco technology page: Nano-Defenders, Device DNA, hosting and the banking case-study headline
“Memcyco Nano Defenders and Device DNA work together to detect scam exposure, identify lured users, preserve attack continuity across devices and credentials, and enable earlier protection before impersonation becomes fraud.”
official 2026-08-18
s5 Memcyco Series A announcement, January 2026: investors, traction figures and the customer-investor quote
“Boston, January 27, 2026 – Memcyco, the real-time digital risk protection platform safeguarding enterprises from brand impersonation scams and account takeover (ATO), today announced it has secured $37 million in Series A funding, bringing the company’s total funding to $47 million.”
official 2026-08-18
s6 CTech: Memcyco Series A, reported by Meir Orbach, January 2026
“Israeli cybersecurity company Memcyco has raised $37 million in a Series A funding round, bringing its total capital raised to $47 million.”
press 2026-08-18
s7 Jerusalem Post report on the Memcyco Series A, January 2026
““These unique capabilities lead directly to measurable business impact. Customers have observed more than 10× ROI within the first year, a reduction of over 50% in ATO incidents, and significantly lower reimbursement costs,” the company assured.”
press 2026-08-18
s8 Jerusalem Post feature on Memcyco, October 2025, with an interview quote from the chief executive
“Memcyco, founded in 2021 and headquartered in Bnei Brak, has emerged as a global innovator in real-time scam detection and prevention”
press 2026-08-18
s9 Memcyco announcement of a Datos Insights Q1 2025 Fintech Spotlight mention, April 2025
““Credential-harvesting and ATO attacks have been notoriously difficult to detect, much less predict and prevent,” said David Mattei, Strategic Advisor at Datos Insights.”
official 2026-08-18
s10 Memcyco announcement of a Frost & Sullivan analyst brief, February 2026
“Frost & Sullivan highlights Memcyco’s approach as an example of this shift toward preemptive fraud defense.”
official 2026-08-18
s11 Memcyco announcement of the Candescent digital-banking partnership, May 2026
“NEW YORK, MAY 20, 2026 Memcyco today announced a strategic partnership with Candescent as a certified Marketplace partner.”
official 2026-08-18
s12 Memcyco announcement of the Deloitte partnership, January 2024
“New York, United States / Jan 22, 2024 – Memcyco Inc, the real-time digital impersonation detection and prevention solution provider, and Deloitte, the leading consulting, advisory, and audit services firm, today announced their strategic partnership in the cybersecurity sector.”
official 2026-08-18
s13 Memcyco announcement of the Trident Digital Tech partnership in Asia-Pacific, April 2026
“SINGAPORE, April 09, 2026 (GLOBE NEWSWIRE) — Trident Digital Tech Holdings Ltd (Nasdaq: TDTH) today announced a strategic partnership with Memcyco”
official 2026-08-18
s14 Memcyco announcement of the Integrity Software reseller agreement for Israel
“Integrity Software, a Matrix company specializing in providing software solutions to enterprises in Israel, has signed a partnership agreement with Memcyco.”
official 2026-08-18
s15 CB Insights profile page listing Memcyco competitors
“MEMCYCO's top competitors include Allure Security, Verosint, and Netacea.”
research 2026-08-18
s16 Memcyco solution page addressed to security teams
“Memcyco’s enhanced ATO protection saves global enterprises tens of millions in scam-related expenses from the first year.”
official 2026-08-18
s17 Memcyco solution page addressed to fraud and risk teams
“Monthly, Memcyco prevents over 1.4 million potential fraud incidents that clients would have had to deal with.”
official 2026-08-18
s18 Memcyco events listing, first page, showing 2026 conference appearances
“Memcyco at Datos Insights FinCrime Forum 2026”
official 2026-08-18
s19 Memcyco financial-institution case study describing three unnamed banking customers
“When these three financial institutions approached us about our flagship Customer ATO and Fraud Protection solution, foresight and visibility is exactly what Memcyco delivered.”
official 2026-08-18
s20 Probe of the Memcyco /security path on 2026-08-18, which returns HTTP 404
“Page not found - Memcyco”
official 2026-08-18
s21 Memcyco case study naming Holon Institute of Technology as a customer
“HIT, Holon Institute of Technology, is a well-established, unique, and multidisciplinary academic institution.”
official 2026-08-18
s22 Memcyco privacy policy: the data it processes on behalf of customers
“For the purposes of GDPR and other global privacy laws, Memcyco acts as a processor/instruction taker which accesses and processes Customer Data on behalf of its customers, which are the controllers/owners of such data.”
official 2026-08-18
s23 Memcyco home page badge image rendered in a browser 2026-08-18: an AICPA SOC 2 Type II certified seal official 2026-08-18
s24 Memcyco job posting for a Cyber Threat Intelligence Analyst
“Produce detailed threat intelligence reports and briefings for clients and internal stakeholders.”
official 2026-08-18
s25 Memcyco partner program page: what it offers resellers and service partners
“Enjoy attractive, predictable pricing you'll love, with no hidden extras, surprises, or last minute additions.”
official 2026-08-18
s26 Probe of the Memcyco page sitemap on 2026-08-18: 69 page URLs, none of them a pricing page
“https://www.memcyco.com/solution/credit-unions/”
official 2026-08-18
s27 Google Patents record for granted US patent US12393662B1
“US12393662B1 - Method for notifying a user upon access of an imposter website”
regulatory 2026-08-18
s28 Google Patents record for granted US patent US12248559B1
“US12248559B1 - Website presentation proof of authenticity and method for proving thereof”
regulatory 2026-08-18
s29 Probe of the Memcyco /trust path on 2026-08-18, which returns HTTP 404
“Page not found - Memcyco”
official 2026-08-18
s30 Wildcard-DNS control probe on 2026-08-18: a nonsense memcyco.com subdomain returns the home page
“Real-Time Digital Impersonation & ATO Fraud Protection”
official 2026-08-18
s31 Memcyco home page badge image rendered in a browser 2026-08-18: an ISO 27001 information security management certified seal official 2026-08-18
s32 Memcyco home page badge image rendered in a browser 2026-08-18: an ISO 27017 information security management certified seal official 2026-08-18
s33 Memcyco home page badge image rendered in a browser 2026-08-18: an ISO 27018 information security management certified seal official 2026-08-18
s34 Probe of trust.memcyco.com on 2026-08-18: the subdomain answers with the Memcyco home page rather than a trust portal
“Real-Time Digital Impersonation & ATO Fraud Protection”
official 2026-08-18
s35 Probe of security.memcyco.com on 2026-08-18: the subdomain answers with the Memcyco home page rather than a security portal
“Real-Time Digital Impersonation & ATO Fraud Protection”
official 2026-08-18

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.