Why AegisAI raised $36 million to fight AI spear phishing

AegisAI has raised a $36 million Series A to build AI agents that detect AI-driven spear phishing in email. The startup was founded by former Google security executives Cy Khormaee and Ryan Luo and says its customers already include Mesh, LangChain, and Lokker.

WTF Index TERMINATOR
◄ Terminator 3 Idiocracy 1 ►

The story centers on AI making spear phishing more powerful and harder to control, even though the company is building defensive tools.

Why AegisAI raised $36 million to fight AI spear phishing

AI is changing the economics of spear phishing. According to the source article, attackers can now gather personal context quickly and turn it into messages that appear to understand a target’s work, colleagues, projects, and travel plans.

That shift is the problem AegisAI is trying to solve. The startup, founded last year by former Google security executives Cy Khormaee and Ryan Luo, has raised a $36 million Series A to use AI agents against AI-driven email attacks.

Why email is under pressure

Email remains a primary target because it is personal, routine, and deeply connected to company workflows. The source article describes attackers using AI to assemble details about a person and then create messages that look authentic.

That matters because spear phishing depends on believability. A generic suspicious email may be easier to ignore, but a message that appears tailored to the recipient can be much harder for people and filters to judge quickly.

AegisAI’s core argument is that older defenses are not well suited to this new pace. Its co-founders, who previously worked on safe browsing technology and reCAPTCHA, had a decade of experience preventing email hacks before starting the company.

What AegisAI says is different

The company says traditional rule-based systems rely on “if-then” logic. In AegisAI’s view, that approach is too slow and too limited when attackers are using AI to produce more convincing malicious emails.

Instead, AegisAI has built AI agents that review messages more like a human investigator. The goal is to notice small anomalies that may not fit neatly into a checklist.

Khormaee told TechCrunch: “AI-powered attacks bypass existing controls more than half the time now, which means they’re almost twice as effective as they used to be.” He added: “They’ve researched you, they understand everything about you, and they’re targeting attacks that are perfectly bespoke to you.”

The startup claims its agents can identify threats that traditional email security systems may miss. One example in the source article is malicious PDF attachments that appear legitimate at first, including files with built-in passwords and CAPTCHA, which can be used to fool standard spam filters.

The funding and early customers

AegisAI’s $36 million Series A was led by Battery Ventures. Existing backers Accel and Foundation Capital also participated.

The new round brings the company’s total capital to $49 million. Less than a year after launch, AegisAI says its technology has been adopted by dozens of customers.

The customers named in the source article include:

  • Mesh, a crypto payments company
  • LangChain, an AI startup
  • Lokker, a privacy compliance platform

Battery Ventures general partner Dharmesh Thakker said he had noticed an increase in email attacks and wanted to invest in a company that could defend against AI with AI. He described the challenge this way: “The bad guys are using email to attack us using AI at a much faster pace than we can keep up with.”

Thakker also told TechCrunch: “Defending against that is going to be a number one priority for a lot of companies.”

A crowded race to replace legacy tools

AegisAI is not alone in applying AI to email security. The source article notes that Ocean, backed by Lightspeed, is also using AI to analyze the context of incoming email and detect fraud and impersonation attempts.

Both companies are positioned against established vendors such as Proofpoint and Mimecast, as well as newer players like Abnormal Security. The competitive question is whether AI-native systems can become the next default layer for email defense.

Thakker believes AegisAI has a strong chance because its founders helped secure Gmail, described in the source article as the most popular email system in the world. That background is central to the company’s pitch: the team has direct experience with large-scale security problems and is now applying it to AI-era attacks.

Where the company wants to go next

AegisAI is starting with email, but it does not plan to stop there. The source article says the startup eventually wants to expand into other areas of defense, including data security.

Khormaee framed the broader ambition around agents that can investigate complex security problems. “The core idea of building customized, highly advanced agents that can do investigations is going to [determine] who becomes the next dominant security company,” he said.

For companies evaluating email security, the larger signal is clear from the source: attackers are using AI to make phishing more personal and more scalable, and security startups are racing to answer with AI systems of their own.