AegisAI Raises $36M Series A to Fight AI-Generated Spear Phishing
AegisAI, a San Francisco-based cybersecurity startup founded in 2025 by CEO Cy Khormaee and co-founder Ryan Luo, announced on July 23 that it raised US$36 million in a Series A round led by Battery Ventures, with participation from existing investors Accel and Foundation Capital. The round brings AegisAI's total funding to US$49 million less than a year after its public launch in September 2025. Khormaee and Luo both spent nearly a decade in Google's core security group, where they helped build reCAPTCHA, Safe Browsing, and Web Risk, before starting AegisAI to apply AI agents against AI-generated phishing.
AegisAI's platform deploys autonomous AI agents inside corporate inboxes that evaluate a message's intent and sender identity contextually, rather than relying on the pattern-matching rules legacy filters use, a method the company says cuts false positives by up to 90%. In March 2026, the company launched Vanguard, a threat-hunting agent that follows suspicious links and attachments outside the inbox, including navigating adversarial CAPTCHAs and weaponized documents. Customers already using the platform include crypto payments firm Mesh, AI developer platform LangChain, and privacy compliance company Lokker, among dozens of enterprise clients signed in the company's first year. AegisAI plans to use the new funding to scale its fleet of autonomous agents, bring Vanguard to general availability, and expand enterprise sales.
Market Context
AegisAI's raise comes as AI-generated spear phishing has grown sharply more common and more effective. In a study presented at the M3AAWG anti-abuse conference analyzing more than 20,000 malicious emails, the company found AI-generated attacks rose from 2.8% of observed phishing in early 2025 to 13.9% by year's end, roughly a fivefold increase, and reach inboxes at nearly double the rate of human-written phishing. About 73% of successful AI-driven attacks cleared email authentication checks by using compromised legitimate accounts, and the company notes that generating a convincing AI spear-phishing email now costs attackers roughly the price of a cup of coffee. The FBI reported US$20.8 billion in cybercrime losses in 2025, with business email compromise alone accounting for US$11.64 billion of that total.
The funding places AegisAI in a crowded and fast-moving email security field that includes established players like Proofpoint and Mimecast, along with newer, AI-native rivals such as Abnormal Security and Lightspeed-backed Ocean, both of which take a similarly behavioral, agentic approach to detection. Battery Ventures partner Dharmesh Thakker, who led the investment, framed the broader threat driving investor interest bluntly: attackers are already using AI to target email "at a much faster pace than we can keep up with."
The Signal
"You cannot patch human trust. When the attack is AI, the defense has to be AI." — Cy Khormaee, co-founder and CEO, AegisAI
Regional Relevance
For the United States: AegisAI's raise reinforces San Francisco's position as a hub for cybersecurity startups founded by veterans of the region's largest tech companies, and it lands as business email compromise remains one of the costliest categories of cybercrime tracked by the FBI, directly affecting US companies' finances and operations. As AI lowers the cost and raises the sophistication of these attacks, enterprise security budgets are likely to keep shifting toward AI-native defenses, a trend that benefits well-capitalized startups like AegisAI but also raises the stakes for companies that lag in adopting them.
For the global enterprise security landscape: Email-based attacks do not respect borders, and the fivefold surge in AI-generated phishing that AegisAI documented reflects a threat facing organizations worldwide, not just US firms. The emergence of AI agents defending inboxes against AI agents attacking them signals a broader shift in how cybersecurity vendors globally are being forced to compete, potentially accelerating a "re-platforming" of email security away from legacy, rule-based systems across markets far beyond Silicon Valley.
The Other Side
Can $36 million meaningfully keep pace with attackers who can now launch AI phishing campaigns for the cost of a cup of coffee? AegisAI's own research underscores how cheap and scalable AI-driven attacks have become, raising the question of whether a Series A-stage startup can out-invest or out-innovate both deep-pocketed incumbents like Proofpoint and Mimecast and well-funded AI-native rivals such as Abnormal Security and Ocean in what looks increasingly like an arms race.
Does deploying autonomous AI agents with access to all corporate email introduce its own risk? A system built to read and reason about the full contents of an organization's inbox traffic represents a significant expansion of what a third-party tool can see, raising legitimate questions about data privacy, compliance, and what happens if the defensive AI system itself is compromised or manipulated.
Is "AI versus AI" actually a sustainable defense framing, or does it just shift where the arms race happens? AegisAI's fivefold-growth statistic suggests attackers are adapting quickly; if adversaries can retrain their generative tools faster than AegisAI and its competitors can retrain detection models, the fundamental cat-and-mouse dynamic between attackers and defenders may simply move up a level rather than resolve.
Sources & Transparency
- TechCrunch — AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing
- SiliconANGLE — AegisAI banks $36M as AI spear-phishing surges fivefold in a year
- PR Newswire — AegisAI Raises $36 Million Series A Led by Battery Ventures to Fight the New Wave of AI Spear Phishing
- citybiz — AegisAI Raises $36 Million Series A to Combat AI-Powered Spear Phishing
- AI Chat Daily — AegisAI raises $36M to fight AI-generated spear phishing with AI agents