Attack the margin, not merely the bot $114M announced funding One platform for bots, identities and agents From Brisbane games to global fraud defense Attack the margin, not merely the bot $114M announced funding One platform for bots, identities and agents From Brisbane games to global fraud defense

Company profile / Cybersecurity

Arkose Labs Put a Price on Being a Pest

The internet taught machines to behave like people. Arkose Labs built a business by making the badly behaved ones pay for the privilege.

There is a small comedy at the heart of internet security. A website asks a machine to prove it is a person, so the machine learns to click the traffic lights with increasingly human confidence. The website makes the pictures grainier. The machine gets better. Meanwhile, an actual person is squinting at a bicycle rack and wondering why buying socks has become an entrance examination.

Arkose Labs began by taking that comedy seriously. The Brisbane-born company, originally known for FunCaptcha, replaced mangled text with short game-like tasks. But the games were never quite the point. Founder Kevin Gosschalk, whose earlier work crossed game development and assistive technology, had noticed that the contest was being scored incorrectly. Perfectly identifying every attacker is difficult. Making an attack unprofitable is more tractable.

The short version

  • Arkose sells enterprise fraud defense for login, signup, payments, APIs, content and AI-agent traffic.
  • Its trick is adaptive friction: good users usually pass silently; suspicious visitors receive increasingly costly challenges.
  • Customers include Adobe, Anthropic, Dropbox, Expedia, Meta, Microsoft, OpenAI, Roblox and Sony.
  • It works best where fraud is frequent, measurable and expensive enough to justify a substantial enterprise contract.

A tollbooth that moves

Most fraud products resemble a nightclub bouncer. They inspect the visitor, consult a list and choose yes or no. Arkose adds the temperament of a toll-road operator. A low-risk session moves through. A suspicious session may be asked to complete an interactive challenge. If an attacker automates the answer, Arkose changes the challenge. If the attacker hires people in a fraud farm, the work can become longer or more varied. Every adaptation spends the attacker's time, compute or wages.

The clever part is not proving who you are. It is making bad behavior too tedious to scale.

That is why the company's favorite language is economic. The desired result is not a triumphant arrest. It is abandonment. Credential stuffing, fake account creation, bonus abuse and SMS toll fraud are businesses, even when the office is a Telegram channel and the staff are stolen passwords. Increase the cost per attempt above the expected return and the enterprise stops being an attractive customer of crime.

Arkose Labs founder and CEO Kevin Gosschalk
Kevin Gosschalk, the game designer who discovered that a fraudster's least favorite puzzle is an unprofitable one.

What failed first was the blunt instrument

The most revealing Arkose customer story is not about an exotic attacker. It is about a defense that worked badly. Roblox had deployed bot mitigation, but verification became difficult enough to cause a double-digit reduction in account-creation conversion. The lock was guarding the door by discouraging guests. Arkose says its tailored deployment stopped automated abuse within two weeks without reducing conversion.

This is the permanent constraint. Security friction has a cost even when it catches a crook. A blocked genuine buyer, player or traveler is not a false positive in a spreadsheet; it is a lost customer with a story to tell. Arkose therefore watches behavior, device attributes, email risk, network patterns and global attack telemetry before deciding whether a session deserves a challenge. The company says its Bot Manager draws on more than 225 risk signals. Its public customer page reports 99.9 percent frictionless pass-through for good users and a 95 percent reduction in automated attacks among highlighted results. Those are Arkose's aggregates, not promises that every buyer will reproduce them.

ObserveBehavior, device, email and network clues form a risk view.
DecideKnown-good traffic moves; uncertain traffic earns scrutiny.
EnforceAdaptive work raises the price of persistence.

The puzzle grew into a platform

A decade of adversarial adaptation has made Arkose less of a CAPTCHA company and more of a control plane. Arkose Titan now coordinates Bot Manager, Device ID, Email Intelligence, Phishing Protection, Scraping Protection and Edge, a server-side risk API. In 2026, Agent Trust Manager joined the collection. It classifies autonomous traffic by intent, allowing an enterprise to welcome a shopper's authorized assistant while challenging an agent attempting account takeover.

This change matters because “bot” has stopped being a useful insult. A booking agent and a credential-stuffing script may both be automated. Blocking both protects the login page while sabotaging the checkout. Arkose's newer proposition is graduated control: allow, monitor, challenge or block according to what the visitor appears to be doing. The one-integration pitch is attractive to security teams tired of chaining point products, and the platform can feed SIEM tools such as Splunk, Sumo Logic and Microsoft Sentinel.

$114Mannounced funding by 2021
750M+fake accounts disrupted in the Microsoft operation
$1Mmaximum on selected warranties

The customers are large, exposed and impatient: global banks, game platforms, cloud products, social networks, airlines and retailers. Public names range from Adobe and Dropbox to Meta, Microsoft, Roblox and Sony. Microsoft also became an operational partner. Arkose's threat-research group supplied intelligence in the action against Storm-1152, an Egypt-based operation accused of selling fraudulent Microsoft accounts. Arkose says the disruption touched more than 750 million fake accounts. Here the tollbooth became a detective: traffic observed across customers produced clues useful beyond a single login.

What it costs, and who should copy it

Arkose does not post a universal price card. Its terms describe annual subscriptions, implementation fees per API key, transaction allowances and three support levels, including a managed service with around-the-clock security operations. A public AWS Marketplace offer listed a 12-month package at $250,000, with extra capacity priced at $1,000 per million sessions. That is a reference point, not a general quote. The company sells to enterprises because enterprise-sized losses make enterprise-sized prevention legible.

The transferable lesson costs less. Measure the attacker's burden alongside your own detection rate. Instrument conversion before adding friction. Reserve the hardest intervention for the riskiest traffic. Study how an adversary changes after each defense, because the first thing to fail is often yesterday's rule. Finally, connect fraud loss to an operational metric that finance understands: chargebacks avoided, messages not sent, accounts not remediated, compute not wasted.

The condition

Economic deterrence needs room to adapt. It is a poor fit for a small, lightly attacked site, an organization unable to tune policy, or a transaction so valuable that an attacker will absorb almost any challenge cost. It can also backfire when clumsy rules send good customers into hard tests. Friction is medicine with a dosage, not a moral good.

Arkose raised a $70 million Series C led by SoftBank Vision Fund 2 in 2021, bringing its announced total to $114 million. The capital widened the old FunCaptcha thesis across identity, APIs, phishing, scraping and now AI agents. Yet the amusing core remains unchanged. The web's defenders once tried to invent a question only a human could answer. Arkose instead asks how many times a criminal can afford to answer it.