techcrunch.com web signal

AegisAI raises $36M to counter AI-crafted spear phishing

TL;DR

  • AegisAI raised $36 million in Series A funding led by Battery Ventures, with Accel and Foundation Capital, bringing total capital to $49 million.
  • Co-founders Cy Khormaee and Ryan Luo, former Google security executives, previously worked on safe browsing technology and reCAPTCHA.
  • Khormaee says AI-powered attacks now bypass existing controls more than half the time, almost twice as effective as before.

Email security has been a fairly settled market for a decade, dominated by a handful of incumbents built around rule-based filtering. A new Series A suggests the ground has moved under them. TechCrunch reports that AegisAI, a startup founded last year by former Google security executives Cy Khormaee and Ryan Luo, has raised $36 million in a Series A led by Battery Ventures, with Accel and Foundation Capital participating, bringing total capital to $49 million.

The pitch is specific. Khormaee and Luo previously worked on Google's safe browsing technology and reCAPTCHA, and they argue that the if-then logic behind existing anti-phishing systems is too slow to catch messages an attacker just generated with a model. In place of the rulebook, AegisAI runs AI agents that, in the company's framing, quickly analyze each message as a human would, paying attention to small anomalies, the kind of tell that lives in a password-protected PDF or a CAPTCHA embedded to defeat traditional spam scanners.

The number that gives the round its urgency comes from Khormaee himself, who told TechCrunch that AI-powered attacks bypass existing controls more than half the time now, which he says makes them almost twice as effective as they used to be. Battery general partner Dharmesh Thakker frames it the same way, saying the bad guys are using email to attack at a much faster pace than defenders can keep up with. Early customers include crypto payments company Mesh, AI startup LangChain, and privacy compliance platform Lokker, which reads like a bet on companies that already treat email as a high-value target.

The honest caveat is that the bypass rate is the founder's own claim, not an independently measured benchmark, and the reporting doesn't give you the false-positive rate, the pricing model, or whether AegisAI is displacing Proofpoint and Mimecast at these accounts or layering on top of them. Lightspeed-backed Ocean is chasing similar ground, so the category is not uncontested.

What's worth watching is where the enterprise email-security budget goes over the next year. If AI-generated spear phishing really is roughly twice as effective as the older kind, security leaders will have to decide whether their current stack was designed for the wrong threat, and rounds like this one make that question harder to defer.