AegisAI, a startup co-founded by former Google security executives Cy Khormaee and Ryan Luo, has raised $36 million in Series A funding to combat AI-driven spear phishing attacks. The company’s AI agents are designed to detect and neutralize threats that traditional rule-based systems miss. Khormaee explained that AI-powered attacks bypass existing controls more than half the time, making them nearly twice as effective as before. “They’ve researched you, they understand everything about you, and they’re targeting attacks that are perfectly bespoke to you,” Khormaee said. The funding, led by Battery Ventures with participation from Accel and Foundation Capital, brings AegisAI’s total capital to $49 million. The startup has already gained traction with customers like Mash, LangChain, and Lokker, demonstrating the urgency of its mission in an era where AI is being weaponized by hackers.

AegisAI’s technology analyzes each email as a human would, paying attention to small anomalies that even the most elaborate checklist might overlook. For example, the startup’s AI can detect malicious PDF attachments that appear legitimate, including those with built-in passwords and CAPTCHAs, which are often used to bypass standard spam filters. Dharmesh Thakker, general partner at Battery Ventures, noted the rising threat of AI-powered email attacks and sought to invest in a company that could defend against them with AI. “Defending against that is going to be a number one priority for a lot of companies,” Thakker said. AegisAI is not the only startup tackling this issue, but its founders’ experience in securing Gmail gives it a competitive edge.

AegisAI’s co-founders, who previously worked on safe browsing technology and reCAPTCHA, recognized that existing email security systems are too slow and limited to catch AI-crafted malicious emails. They developed AI agents that quickly analyze messages, focusing on subtle indicators that traditional systems might miss. The startup’s approach is part of a broader trend in cybersecurity, where AI is being used to analyze the context of incoming emails to detect fraud and impersonation attempts. While AegisAI is starting with email, the company aims to expand to other areas of defense, such as data security. Khormaee emphasized that the core idea of building customized, highly advanced agents will determine who becomes the next dominant security company.

Source: techcrunch