AegisAI, founded by former Google security executives, gets $36 million to stop AI-based phishing


Hackers are increasingly using artificial intelligence to launch large-scale attacks, with email emerging as a primary target. AI can quickly collect personal information — such as information about co-workers, active projects, and recent travel itineraries — allowing bad actors to instantly craft compelling messages that appear real.

Last year, former Google security executives Cy Kormaee and Ryan Luo, who previously worked on developing safe browsing technology and reCAPTCHA, teamed up to launch AegisAI, a startup that uses artificial intelligence agents to eliminate these threats, known as phishing.

With a decade of experience preventing email breaches, the founders of AegisAI realized that current rules-based systems for preventing breaches – which rely on “if it happens” logic – are too slow and limited in catching malicious AI-generated emails. So they developed AI agents that quickly analyze each message as a human would, paying attention to small anomalies that even the most detailed checklist couldn’t detect.

Less than a year after its launch, AegisAI says its technology has been adopted by dozens of customers, including cryptocurrency payments company Mash, AI startup LangChain, and Google-owned privacy compliance platform Lokker. This demand helped AegisAI raise a $36 million Series A led by Battery Ventures, with participation from existing backers Accel and Foundation Capital. The new financing raises the total capital of the startup company to $49 million.

“AI-powered attacks bypass existing controls more than half the time now, which means they are almost twice as effective as they were before,” Khormay told TechCrunch. “They’ve researched you, they understand everything about you, and they target attacks tailored to you.”

Khormay claims that AegisAI agents can detect threats that traditional email security systems might miss entirely. For example, the startup’s AI can detect malicious PDF attachments that initially appear legitimate, including those with built-in passwords and CAPTCHAs, which are often used to fool standard spam filters.

When Dharmesh Thakur, general partner at Battery Ventures, noticed an increase in email attacks, he set out to invest in a startup that could defend against AI with AI, a company that aims to replace legacy email security tools with agent-based defense.

“Bad guys are using email to attack us with AI at a much faster pace than we can keep up,” Thacker told TechCrunch. “Defending against this will be the first priority for many companies.”

AegisAI isn’t the only startup using AI to analyze the context of every incoming email to detect fraud and impersonation attempts. Lightspeed-backed Ocean is also trying to unseat established vendors like Proofpoint and Mimecast, along with newer players like Abnormal Security.

However, given that AegisAI is led by experts who helped secure Gmail, the world’s most popular email system, Thakker believes the startup has the best chance of becoming the new leader in hack prevention.

While AegisAI started with email, the startup aims to eventually expand into other defense areas, such as data security. “The basic idea of ​​building highly specialized and sophisticated agents that can conduct investigations is to (determine) who will become the next dominant security company,” Khormay said.

When you make a purchase through the links in our articles, We may earn a small commission. This does not affect our editorial independence.

Leave a Reply

Your email address will not be published. Required fields are marked *