TLDRocket
Sign in

AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing

TechCrunch Marina Temkin

AegisAI just raised $36M to fight AI-written phishing emails with AI agents of its own. Hackers now dodge normal email filters more than half the time, so this arms race is heating up fast.

Based on reporting by TechCrunch, Marina Temkin — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Phishing used to be easy to spot: bad grammar, weird links, a Nigerian prince asking for your bank details. That era is over. AI can now scrape someone's coworkers, current projects, and even their recent travel plans, then spin up an email that reads like it came from a trusted colleague. AegisAI, founded by former Google security veterans Cy Khormaee and Ryan Luo, is betting that only AI can catch AI at this game, and investors just handed the startup $36 million in Series A funding to prove it.

Khormaee and Luo spent years building safe browsing tools and reCAPTCHA at Google, so they know exactly how rule-based spam filters work and, more importantly, where they fail. Traditional systems run on if-then logic: if this sender is unfamiliar and that link looks suspicious, then flag it. Fine for yesterday's scams, useless against messages custom-written for a specific target. AegisAI instead deploys AI agents that read each email the way a suspicious human would, catching subtle tells that no checklist was ever written to detect, including fake PDF attachments rigged with hidden passwords or CAPTCHAs designed specifically to slip past spam filters.

The pitch is clearly landing. Less than a year after launch, AegisAI counts LangChain, crypto payments firm Mash, and Google's own Lokker among its dozens of customers. Battery Ventures led the new round, with Accel and Foundation Capital returning to back a company they'd already bet on, pushing AegisAI's total funding to $49 million. Battery's Dharmesh Thakker says he went looking specifically for a startup willing to fight AI with AI rather than patch legacy tools, and Khormaee's Gmail pedigree apparently sealed the deal.

The numbers Khormaee cites are the real story here. AI-generated attacks now slip past existing defenses more than half the time, roughly double the success rate of older, templated phishing attempts. That's not a marginal improvement for attackers, it's a different threat model entirely, one where the bad guys know your travel itinerary and your project deadlines before they even hit send.

AegisAI isn't alone in chasing this problem. Lightspeed-backed Ocean is pursuing the same contextual-analysis approach, and both startups are gunning for entrenched vendors like Proofpoint, Mimecast, and Abnormal Security. Khormaee's ambitions don't stop at inboxes either. He talks about building agents that can investigate threats broadly, hinting that email defense might just be the opening chapter for a company that wants to become the next major name in security.

My take — AI-written commentary, not fact-checked reporting

Fifty-plus percent bypass rates should worry anyone who still thinks spam filters are a solved problem, and I'd rather see that money going into AegisAI's founder-led approach than another rebrand of Proofpoint's decade-old playbook. That said, funding rounds always outpace real-world proof, so I'll believe the hype once independent red-teamers, not press releases, confirm these agents actually outsmart AI-crafted attacks at scale.

Read more about this at: TechCrunch

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.