AegisAI raises $36M to fight AI-driven spear phishing with autonomous agents

2 Sources

Share

Former Google security executives Cy Khormaee and Ryan Luo launched AegisAI to combat the surge in AI-generated email attacks. The startup just raised $36 million in Series A funding led by Battery Ventures to deploy AI agents that analyze messages like humans do, catching threats traditional systems miss. AI-driven spear phishing now represents nearly 14% of all phishing attacks, up from just 2.8% in early 2025.

Former Google Security Executives Build AI-Powered Defense

AegisAI has secured $36 million in Series A funding to address a rapidly escalating threat that traditional email security systems struggle to contain. Founded by former Google security executives Cy Khormaee and Ryan Luo, the startup deploys autonomous AI agents designed to detect and neutralize AI-driven spear phishing attacks that bypass conventional defenses

1

. The round was led by Battery Ventures, with participation from existing backers Accel and Foundation Capital, bringing the company's total raised to $49 million less than a year after its public launch

2

.

Khormaee and Luo spent years developing core security technologies at Google, including reCAPTCHA, Safe Browsing, and Web Risk. Their decade of experience preventing email hacks revealed a critical gap: existing rule-based systems relying on if-then logic prove too slow and limited to catch AI-crafted malicious emails

1

. This realization drove them to launch AegisAI in 2025, with a public debut in September.

Source: SiliconANGLE

Source: SiliconANGLE

AI-Generated Spear Phishing Attacks Surge Nearly Fivefold

The threat landscape has shifted dramatically. AI-generated spear phishing represented just 2.8% of phishing attacks observed by AegisAI in early 2025, but that figure jumped to 13.9% by year's end, according to research the company presented at the M3AAWG conference

2

. The study analyzed more than 20,000 malicious emails and revealed that these AI-driven attacks prove significantly more effective at evading detection.

"AI-powered attacks bypass existing controls more than half the time now, which means they're almost twice as effective as they used to be," Khormaee told TechCrunch

1

. The attacks leverage generative AI to scrape personal information about targets, including details about coworkers, active projects, and recent travel itineraries, then instantly craft convincing messages that appear authentic. What once required time and skill now costs about the price of a cup of coffee

2

.

The financial impact is staggering. The U.S. Federal Bureau of Investigation's latest Internet Crime Report documented a record $20.8 billion in losses last year, with business email compromise accounting for $11.64 billion of that total

2

. Nearly 73% of AI-generated attacks that reached inboxes had cleared email authentication, sent from legitimate accounts that attackers had quietly compromised.

Source: TechCrunch

Source: TechCrunch

How Autonomous AI Agents Detect What Legacy Systems Miss

AegisAI builds its own large language models to guard corporate inboxes, running a network of autonomous AI agents that analyze each message as a human would

2

. Traditional filters search for patterns lifted from past scams, but AegisAI's approach reads the intent and identity behind each message, paying attention to small anomalies that even the most elaborate checklist wouldn't catch

1

.

The startup claims its technology cuts false positives by up to 90% compared to legacy tools

2

. The AI can catch malicious PDF attachments that appear legitimate, including ones with built-in passwords and CAPTCHAs designed to fool standard spam filters

1

. At web privacy firm Lokker, one of AegisAI's customers, the agents caught an attack routed through a vendor's compromised Salesforce systems, a message that carried no malicious link or attachment

2

.

Market Traction and Competitive Landscape

Less than a year after launch, AegisAI has been adopted by dozens of customers across fintech and technology sectors, including crypto payments company Mash, AI startup LangChain, and Google-owned privacy compliance platform Lokker

1

. The startup faces competition from Lightspeed-backed Ocean and established vendors like Proofpoint and Mimecast, along with newer players like Abnormal Security

1

.

Dharmesh Thakker, general partner at Battery Ventures, believes AegisAI's leadership by experts who helped secure Gmail gives it the best shot at becoming the leading hack-prevention company. "The bad guys are using email to attack us using AI at a much faster pace than we can keep up with," Thakker said. "Defending against that is going to be a number one priority for a lot of companies" . He noted that generative AI "just broke every assumption legacy email security was built on"

2

.

Expansion Plans and Future Cyber Threats

The Series A funding will scale AegisAI's roster of defense agents and push toward general availability for Vanguard, the company's threat-hunting agent that operates outside the inbox

2

. Introduced in March, Vanguard follows suspicious links and attachments onto the open web and returns a threat report within minutes.

While AegisAI starts with email security, the company plans to expand into other areas of defense, including data security. "The core idea of building customized, highly advanced agents that can do investigations is going to [determine] who becomes the next dominant security company," Khormaee said

1

. As Khormaee emphasized, "The most immediate, catastrophic risk to your organization isn't an AI agent hacking your firewall. It's an AI model manipulating someone in your organization into handing over the keys. You cannot patch human trust. When the attack is AI, the defense has to be AI"

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved