Home
AegisAI, backed by former Google security execs, raises $36M to fight AI-driven spear phishing

Hackers are increasingly turning to AI to launch large-scale attacks, with email becoming a prime target. AI can rapidly gather personal details—like coworkers' names, ongoing projects, or recent travel plans—enabling attackers to instantly create convincing, authentic-looking messages.
Last year, former Google security executives Cy Khormaee and Ryan Luo—who helped develop safe browsing technology and reCAPTCHA—joined forces to launch AegisAI, a startup that uses AI agents to combat these so-called spear phishing threats.
Drawing on a decade of experience preventing email hacks, the AegisAI co-founders recognized that existing rule-based systems—which rely on "if-then" logic—are too slow and limited to catch AI-crafted malicious emails. So they built AI agents that analyze each message like a human would, spotting subtle anomalies that even the most thorough checklist might miss.
Less than a year after launch, AegisAI reports that its technology has been adopted by dozens of customers, including crypto payments firm Mash, AI startup LangChain, and Google-owned privacy compliance platform Lokker. That demand has fueled a $36 million Series A round led by Battery Ventures, with participation from existing investors Accel and Foundation Capital. The new funding brings the startup's total raised to $49 million.
"AI-powered attacks now bypass existing controls more than half the time, making them nearly twice as effective as before," Khormaee told TechCrunch. "They've researched you, they know everything about you, and they launch attacks that are perfectly tailored to you."
Khormaee claims that AegisAI's agents can detect threats that traditional email security systems might completely miss. For example, the startup's AI can identify malicious PDF attachments that appear legitimate at first glance, including those with built-in passwords and CAPTCHAs, which are often used to trick standard spam filters.
When Dharmesh Thakker, a general partner at Battery Ventures, noticed a rise in email attacks, he sought to invest in a startup that could fight AI with AI—one that aims to replace legacy email security tools with agentic-driven defense.
"The bad guys are using AI to attack us via email at a much faster pace than we can keep up with," Thakker told TechCrunch. "Defending against that is going to be a top priority for many companies."
AegisAI isn't the only startup leveraging AI to analyze the context of every incoming email for fraud and impersonation detection. Lightspeed-backed Ocean is also aiming to displace established vendors such as Proofpoint and Mimecast, as well as newer players like Abnormal Security.
However, given that AegisAI is led by experts who helped secure Gmail—the world's most popular email system—Thakker believes the startup has the best chance of becoming the leading new hack-prevention company.
While AegisAI is starting with email, the startup plans to eventually expand into other defense areas, such as data security. "The core idea of building customized, highly advanced agents capable of investigations is what will determine who becomes the next dominant security company," Khormaee said.
Related article
Teen hacker turned Iron Dome researcher raises $28M to fight AI phishing
Shay Shwartz knows email phishing attacks inside and out. As a teenager, he earned money as a hacker, but after being caught at 16, he realized he could use his cybersecurity skills to stop attacks instead of launching them.He went on to spend nearly
Suno to Watermark Songs Amid Legal Battles
Suno, the platform enabling users to generate AI-created music, has unveiled new features to label platform-produced tracks, restrict downloads, and update community standards to curb unauthorized replicas. These updates arrive as Suno confronts mult
Musk Admits Grok Build Leaked User Code, Promises to Erase All Historical Data
Elon Musk directly addressed the privacy controversy surrounding Grok Build, beginning with a simple "True" to confirm the incident's validity. He pledged that all user data previously uploaded to SpaceXAI would be permanently erased, stating, "not a
Related Special Topic Recommendations
Comments (0)
0/500

Hackers are increasingly turning to AI to launch large-scale attacks, with email becoming a prime target. AI can rapidly gather personal details—like coworkers' names, ongoing projects, or recent travel plans—enabling attackers to instantly create convincing, authentic-looking messages.
Last year, former Google security executives Cy Khormaee and Ryan Luo—who helped develop safe browsing technology and reCAPTCHA—joined forces to launch AegisAI, a startup that uses AI agents to combat these so-called spear phishing threats.
Drawing on a decade of experience preventing email hacks, the AegisAI co-founders recognized that existing rule-based systems—which rely on "if-then" logic—are too slow and limited to catch AI-crafted malicious emails. So they built AI agents that analyze each message like a human would, spotting subtle anomalies that even the most thorough checklist might miss.
Less than a year after launch, AegisAI reports that its technology has been adopted by dozens of customers, including crypto payments firm Mash, AI startup LangChain, and Google-owned privacy compliance platform Lokker. That demand has fueled a $36 million Series A round led by Battery Ventures, with participation from existing investors Accel and Foundation Capital. The new funding brings the startup's total raised to $49 million.
"AI-powered attacks now bypass existing controls more than half the time, making them nearly twice as effective as before," Khormaee told TechCrunch. "They've researched you, they know everything about you, and they launch attacks that are perfectly tailored to you."
Khormaee claims that AegisAI's agents can detect threats that traditional email security systems might completely miss. For example, the startup's AI can identify malicious PDF attachments that appear legitimate at first glance, including those with built-in passwords and CAPTCHAs, which are often used to trick standard spam filters.
When Dharmesh Thakker, a general partner at Battery Ventures, noticed a rise in email attacks, he sought to invest in a startup that could fight AI with AI—one that aims to replace legacy email security tools with agentic-driven defense.
"The bad guys are using AI to attack us via email at a much faster pace than we can keep up with," Thakker told TechCrunch. "Defending against that is going to be a top priority for many companies."
AegisAI isn't the only startup leveraging AI to analyze the context of every incoming email for fraud and impersonation detection. Lightspeed-backed Ocean is also aiming to displace established vendors such as Proofpoint and Mimecast, as well as newer players like Abnormal Security.
However, given that AegisAI is led by experts who helped secure Gmail—the world's most popular email system—Thakker believes the startup has the best chance of becoming the leading new hack-prevention company.
While AegisAI is starting with email, the startup plans to eventually expand into other defense areas, such as data security. "The core idea of building customized, highly advanced agents capable of investigations is what will determine who becomes the next dominant security company," Khormaee said.
Teen hacker turned Iron Dome researcher raises $28M to fight AI phishing
Shay Shwartz knows email phishing attacks inside and out. As a teenager, he earned money as a hacker, but after being caught at 16, he realized he could use his cybersecurity skills to stop attacks instead of launching them.He went on to spend nearly
Suno to Watermark Songs Amid Legal Battles
Suno, the platform enabling users to generate AI-created music, has unveiled new features to label platform-produced tracks, restrict downloads, and update community standards to curb unauthorized replicas. These updates arrive as Suno confronts mult
Musk Admits Grok Build Leaked User Code, Promises to Erase All Historical Data
Elon Musk directly addressed the privacy controversy surrounding Grok Build, beginning with a simple "True" to confirm the incident's validity. He pledged that all user data previously uploaded to SpaceXAI would be permanently erased, stating, "not a











