ThreatMark began from an attacker's view of online banking. Founders Michal Tresner and Kryštof Hilar were ethical hackers, and the company says they created the business in 2015 after seeing how poorly conventional fraud systems handled rapidly changing digital attacks.
The insight was that fraud cannot always be reduced to a bad credential, device or transaction. A legitimate customer may be logged into a familiar phone and still be manipulated by a scammer. Malware can alter a session after authentication. An authorised transfer can be fraudulent in intent even when every conventional security check passes.
ThreatMark built around the behaviour surrounding the transaction. Its platform combines signals from devices, sessions, user actions, known threats and payments, then uses machine-learning models to identify deviations that may indicate fraud.
Brno was already fertile ground for security companies
ThreatMark's location matters. Brno has a deep technical university base and a cybersecurity lineage that includes major antivirus and security operations. A fraud-detection company can recruit from engineering, malware-analysis and security communities without needing to begin life in London or Silicon Valley.
But the customer market is international by necessity. Banks buy on trust, regulatory fit and demonstrated fraud reduction, and the sales cycles are long. A Czech security company therefore has to pair technical credibility with enterprise distribution much earlier than a consumer startup would.
ThreatMark's growth has followed that pattern: technical development in the Czech ecosystem, customers across international banking markets and external capital aimed at accelerating UK and US expansion.
The product had to move beyond malware detection as scams changed
Digital fraud has shifted toward social engineering and authorised push-payment scams, where a victim is persuaded to make the payment personally. Those attacks undermine security systems that rely too heavily on whether the session was authenticated correctly.
Behavioural intelligence can add another layer. How a user navigates, types, moves through a banking flow or changes established patterns may provide risk signals before the transaction completes. Device and threat intelligence still matter, but they become part of a wider context rather than the sole decision.
This is a difficult product category because false positives have a direct cost. Blocking a legitimate payment damages customer trust and creates support work. A fraud system therefore has to improve detection without making ordinary banking feel hostile.
The $23 million 2025 financing funded expansion rather than a first product
In January 2025 ThreatMark announced $23 million of financing. Fifteen million dollars came from Octopus Ventures and Riverside Acceleration Capital, while Springtide Ventures provided an additional $8 million convertible note. The company said the transaction brought cumulative fundraising since founding to $37 million.
ThreatMark also reported 75% year-on-year ARR growth over the preceding twelve months. CzechCrunch, covering the round, described the company as protecting more than 40 million bank accounts at the time and put cumulative capital raised at close to CZK 900 million.
Those operating metrics are based on company statements and reporting around the financing rather than audited public-company filings. They are still useful for placing the round: this was capital for a product already deployed at meaningful scale, not a speculative seed-stage build.
The competitive advantage is the feedback loop, not simply the model
Machine learning is no longer a distinctive sentence in a cybersecurity pitch. Banks already buy products using behavioural biometrics, device fingerprinting, transaction monitoring and threat intelligence. ThreatMark's defensibility depends on how those signals are combined, how quickly new fraud patterns can be learned and how well the system performs in each institution's real traffic.
Scale can help because more diverse fraud encounters create more examples from which detection logic can improve, subject to privacy, customer boundaries and model governance. Deep banking integrations can also raise switching costs once a product becomes part of the transaction-risk workflow.
The opposite is true as well. Large incumbent fraud vendors have enormous datasets and distribution. ThreatMark has to prove that specialist focus and product speed outweigh the procurement comfort of buying from a much larger platform.
ThreatMark is a useful Czech company profile because it sells trust abroad
Many Czech software successes are praised for building a global product from a small home market. ThreatMark has an additional difficulty: it sells a product that financial institutions use to decide when not to trust a digital interaction.
That requires more than clever detection. It requires security certifications, explainability, operational support, privacy controls and a commercial reputation strong enough that a bank will place the system in a sensitive path.
The company says it now protects more than 50 million online users. The more meaningful long-term test is whether its behaviour-based approach can continue reducing fraud as attackers adapt to AI-assisted scams, remote-access tools and increasingly convincing social engineering. If it can, Brno will have produced not just another security startup but a durable piece of banking infrastructure.
| Period | Milestone | Why it mattered |
|---|---|---|
| 2015 | Founded by ethical hackers Michal Tresner and Kryštof Hilar | Applied offensive-security thinking to digital banking fraud |
| Following years | Expanded behavioural, device, session and transaction intelligence | Moved from isolated threat indicators toward contextual fraud detection |
| 2025 | Announced $23 million in financing | Funded international expansion and R&D at a later growth stage |
| 2025 financing disclosure | Company reported 75% year-on-year ARR growth | Indicated commercial momentum, though not an audited public metric |
| 2026 | Company reports protecting more than 50 million online users | Suggests broad deployment while leaving market-share comparisons open |
Frequently asked questions
Who founded ThreatMark?
ThreatMark says it was founded in 2015 by ethical hackers Michal Tresner, CEO, and Kryštof Hilar, CTO.
Where is ThreatMark from?
ThreatMark was founded in Brno, Czech Republic, and has expanded internationally to serve financial institutions in multiple markets.
How does ThreatMark detect fraud?
Its platform combines behavioural, device, session, threat and transaction signals and applies machine-learning models to identify patterns that may indicate account takeover, scams or payment fraud.