2 Sources
[1]
AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing
Hackers are increasingly using AI to launch attacks on a massive scale, with email emerging as a primary target. AI can quickly aggregate personal information -- such as information about coworkers, active projects, and recent travel itineraries -- allowing bad actors to instantly craft convincing
[2]
AegisAI banks $36M as AI spear phishing surges fivefold in a year
Email security startup AegisAI Inc. today said it has raised $36 million in new funding to counter a fast-growing class of artificial intelligence-generated email attacks that no amount of employee training can reliably stop. The San Francisco company builds its own large language models to guard
Share
Copy Link
Former Google security executives Cy Khormaee and Ryan Luo launched AegisAI to combat the surge in AI-generated email attacks. The startup just raised $36 million in Series A funding led by Battery Ventures to deploy AI agents that analyze messages like humans do, catching threats traditional systems miss. AI-driven spear phishing now represents nearly 14% of all phishing attacks, up from just 2.8% in early 2025.
AegisAI has secured $36 million in Series A funding to address a rapidly escalating threat that traditional email security systems struggle to contain. Founded by former Google security executives Cy Khormaee and Ryan Luo, the startup deploys autonomous AI agents designed to detect and neutralize AI-driven spear phishing attacks that bypass conventional defenses
1
. The round was led by Battery Ventures, with participation from existing backers Accel and Foundation Capital, bringing the company's total raised to $49 million less than a year after its public launch2
.Khormaee and Luo spent years developing core security technologies at Google, including reCAPTCHA, Safe Browsing, and Web Risk. Their decade of experience preventing email hacks revealed a critical gap: existing rule-based systems relying on if-then logic prove too slow and limited to catch AI-crafted malicious emails
1
. This realization drove them to launch AegisAI in 2025, with a public debut in September.
Source: SiliconANGLE
The threat landscape has shifted dramatically. AI-generated spear phishing represented just 2.8% of phishing attacks observed by AegisAI in early 2025, but that figure jumped to 13.9% by year's end, according to research the company presented at the M3AAWG conference
2
. The study analyzed more than 20,000 malicious emails and revealed that these AI-driven attacks prove significantly more effective at evading detection."AI-powered attacks bypass existing controls more than half the time now, which means they're almost twice as effective as they used to be," Khormaee told TechCrunch
1
. The attacks leverage generative AI to scrape personal information about targets, including details about coworkers, active projects, and recent travel itineraries, then instantly craft convincing messages that appear authentic. What once required time and skill now costs about the price of a cup of coffee2
.The financial impact is staggering. The U.S. Federal Bureau of Investigation's latest Internet Crime Report documented a record $20.8 billion in losses last year, with business email compromise accounting for $11.64 billion of that total
2
. Nearly 73% of AI-generated attacks that reached inboxes had cleared email authentication, sent from legitimate accounts that attackers had quietly compromised.
Source: TechCrunch
AegisAI builds its own large language models to guard corporate inboxes, running a network of autonomous AI agents that analyze each message as a human would
2
. Traditional filters search for patterns lifted from past scams, but AegisAI's approach reads the intent and identity behind each message, paying attention to small anomalies that even the most elaborate checklist wouldn't catch1
.The startup claims its technology cuts false positives by up to 90% compared to legacy tools
2
. The AI can catch malicious PDF attachments that appear legitimate, including ones with built-in passwords and CAPTCHAs designed to fool standard spam filters1
. At web privacy firm Lokker, one of AegisAI's customers, the agents caught an attack routed through a vendor's compromised Salesforce systems, a message that carried no malicious link or attachment2
.Related Stories
Less than a year after launch, AegisAI has been adopted by dozens of customers across fintech and technology sectors, including crypto payments company Mash, AI startup LangChain, and Google-owned privacy compliance platform Lokker
1
. The startup faces competition from Lightspeed-backed Ocean and established vendors like Proofpoint and Mimecast, along with newer players like Abnormal Security1
.Dharmesh Thakker, general partner at Battery Ventures, believes AegisAI's leadership by experts who helped secure Gmail gives it the best shot at becoming the leading hack-prevention company. "The bad guys are using email to attack us using AI at a much faster pace than we can keep up with," Thakker said. "Defending against that is going to be a number one priority for a lot of companies" . He noted that generative AI "just broke every assumption legacy email security was built on"
2
.The Series A funding will scale AegisAI's roster of defense agents and push toward general availability for Vanguard, the company's threat-hunting agent that operates outside the inbox
2
. Introduced in March, Vanguard follows suspicious links and attachments onto the open web and returns a threat report within minutes.While AegisAI starts with email security, the company plans to expand into other areas of defense, including data security. "The core idea of building customized, highly advanced agents that can do investigations is going to [determine] who becomes the next dominant security company," Khormaee said
1
. As Khormaee emphasized, "The most immediate, catastrophic risk to your organization isn't an AI agent hacking your firewall. It's an AI model manipulating someone in your organization into handing over the keys. You cannot patch human trust. When the attack is AI, the defense has to be AI"2
.Summarized by
Navi
[1]
01 Sept 2026•Technology

05 Dec 2025•Startups

03 Apr 2025•Technology

1
Technology

2
Science and Research

3
Technology
