AegisAI Raises $36M to Counter AI-Powered Spear Phishing Epidemic

AegisAI Raises $36M to Counter AI-Powered Spear Phishing Epidemic

As cybercriminals increasingly weaponize artificial intelligence to launch sophisticated email attacks at massive scale, a new startup founded by former Google security executives has secured significant funding to fight back with AI of its own.

AegisAI, launched last year by Cy Khormaee and Ryan Luo, has raised a $36 million Series A round led by Battery Ventures, with participation from existing investors Accel and Foundation Capital. The funding brings the startup's total capital to $49 million.

From Gmail Security to AI-Powered Defense

Khormaee and Luo bring deep expertise from their tenure at Google, where they worked on developing safe browsing technology and reCAPTCHA. With a decade of combined experience in preventing email hacks, the co-founders recognized that traditional rule-based security systems — which rely on rigid "if-then" logic — are fundamentally ill-equipped to catch AI-crafted malicious emails.

The problem has grown acute as hackers use AI to rapidly aggregate personal information about targets, including details about co-workers, active projects, and recent travel itineraries. This allows bad actors to instantly craft convincing, highly personalized messages that appear authentic to both recipients and conventional security filters.

"AI-powered attacks bypass existing controls more than half the time now, which means they're almost twice as effective as they used to be," Khormaee told TechCrunch. "They've researched you, they understand everything about you, and they're targeting attacks that are perfectly bespoke to you."

Rather than relying on static checklists, AegisAI developed AI agents that analyze each incoming message the way a human analyst would — paying attention to subtle anomalies that even the most elaborate rule-based system would miss.

Early Traction and Investor Confidence

Less than a year after its launch, AegisAI reports that its technology has been adopted by dozens of customers, including crypto payments company Mesh, AI startup LangChain, and privacy compliance platform Lokker.

Dharmesh Thakker, general partner at Battery Ventures, decided to invest after noticing a surge in email attacks. He sought a startup that could defend against AI with AI, specifically one aiming to replace legacy email security tools with agentic-driven defense rather than incremental improvements to existing systems.

"The bad guys are using email to attack us using AI at a much faster pace than we can keep up with," Thakker told TechCrunch. "Defending against that is going to be a number one priority for a lot of companies."

Thakker believes AegisAI's leadership gives the startup a decisive edge. The co-founders helped secure Gmail, the world's most widely used email system, which he argues positions them better than any other team to build the next dominant hack-prevention company.

Catching What Traditional Filters Miss

AegisAI claims its agents can identify threats that conventional email security systems overlook entirely. For example, the startup's AI can detect malicious PDF attachments that appear legitimate at first glance, including those equipped with built-in passwords and CAPTCHA features specifically designed to fool standard spam filters into letting them through.

The company is not alone in pursuing this approach. Ocean, backed by Lightspeed, is also working to displace established vendors such as Proofpoint and Mimecast, alongside newer entrants like Abnormal Security. All are racing to analyze the full context of every incoming email to detect fraud and impersonation attempts that automated systems have historically failed to catch.

Beyond Email: A Broader Security Vision

While AegisAI is starting with email protection, the startup has its sights set on eventually expanding into other defense areas, including data security. Khormaee sees the company's methodology as part of a larger shift in the cybersecurity landscape.

"The core idea of building customized, highly advanced agents that can do investigations is going to [determine] who becomes the next dominant security company," Khormaee said.

As AI-driven attacks continue to evolve at an unprecedented pace, the race between offensive and defensive AI technologies is only intensifying. With fresh capital, a growing customer base, and a team that helped secure the world's most popular email platform, AegisAI is positioning itself at the forefront of this battle — though the competition remains fierce and the stakes for enterprises worldwide have never been higher.

If you found this article informative, share it with your colleagues and network to help spread awareness about the growing threat of AI-powered phishing and the emerging technologies designed to combat it.

Source: TechCrunch AI