Hackers are increasingly using artificial intelligence to launch attacks on a massive scale, with email as a primary target. AI can quickly gather personal information—such as information about colleagues, active projects, and recent travel itineraries—allowing bad actors to instantly craft persuasive messages that appear authentic.
Last year, former Google security executives Cy Khormaee and Ryan Luo, who previously worked on the development of secure browsing technology and reCAPTCHA, teamed up to launch AegisAI, a startup that uses AI agents to neutralize these threats, known as spear phishing.
With a decade of experience preventing email intrusions, AegisAI’s co-founders realized that existing rule-based intrusion prevention systems—based on if-then logic—were too slow and limited to catching malicious AI-generated emails. So they developed AI agents that quickly analyze each message as a human would, paying attention to small anomalies that even the most sophisticated checklist wouldn’t catch.
Less than a year after its launch, AegisAI says its technology has been adopted by dozens of customers, including crypto payments company Mash, AI startup LangChain and Google’s privacy compliance platform Lokker. That demand just helped AegisAI raise a $36 million series round led by Battery Ventures, with participation from existing backers Accel and Foundation Capital. The new funding brings the startup’s total capital to $49 million.
“AI-powered attacks bypass existing controls more than half the time now, which means they are almost twice as effective as they used to be,” Khormaee told TechCrunch. “They’ve researched you, they understand everything about you, and they’re targeting attacks that are perfectly tailored to you.”
Khormaee claims that AegisAI agents can detect threats that traditional email security systems might miss entirely. For example, the startup’s AI can catch malicious PDF attachments that look legitimate at first, including those with embedded passwords and CAPTCHAs, which are often used to trick standard spam filters.
When Dharmesh Thakker, general partner at Battery Ventures, noticed an increase in email attacks, he began investing in a startup that could defend against artificial intelligence with AI, aiming to replace legacy email security tools with agent-based defenses.
“The bad guys are using email to attack us using artificial intelligence at a much faster rate than we can keep up with,” Thakker told TechCrunch. “Defending against this will be the number one priority for many companies.”
AegisAI isn’t the only startup using artificial intelligence to analyze the context of every incoming email to detect fraud and impersonation attempts. Lightspeed-backed Ocean is also trying to displace established vendors like Proofpoint and Mimecast, along with newer players like Abnormal Security.
But since AegisAI is led by experts who helped secure Gmail, the world’s most popular email system, Thakker believes the startup has the best shot at becoming the top new hack prevention company.
While AegisAI is starting with email, the startup aims to eventually expand into other areas of defense, such as data security. “The basic idea of creating personalized, highly advanced agents that can do surveys will be [determine] which becomes the next dominant security company,” Khormaee said.
When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.
