Hackers are increasingly using AI to launch large-scale attacks, and email has emerged as a prime target. AI can quickly aggregate personal information such as co-workers, ongoing projects, and recent travel itineraries, allowing bad actors to instantly create convincing messages that look authentic.
Last year, former Google security executives Cy Khormaee and Ryan Luo, who previously worked on Safe Browsing technology and reCAPTCHA, teamed up to launch AegisAI, a startup that uses AI agents to thwart these threats, known as spear phishing.
After a decade of experience preventing email hacks, the co-founders of AegisAI realized that existing rules-based systems for preventing hacks (relying on “if-then” logic) were too slow and limited in their ability to catch malicious emails created by AI. So they developed an AI agent that quickly analyzes each message, just as a human would, and looks out for tiny anomalies that even the most sophisticated checklists can’t detect.
AegisAI says that in less than a year since its launch, its technology has been adopted by dozens of customers, including cryptocurrency payments company Mesh, AI startup LangChain, and privacy compliance platform Lokker. This demand led AegisAI to raise $36 million in Series A led by Battery Ventures with participation from existing backers Accel and Foundation Capital. The new funding brings the startup’s total capital to $49 million.
“AI-powered attacks now evade existing controls more than half the time, meaning they are nearly twice as effective as before,” Komey told TechCrunch. “They study you, they know everything about you, and they target attacks that are completely tailored to you.”
Khormaee claims that AegisAI’s agents can discover threats that traditional email security systems may miss completely. For example, the startup’s AI can catch malicious PDF attachments that appear legitimate, including attachments with embedded passwords or CAPTCHAs, which are often used to fool standard spam filters.
When Dharmesh Thakker, general partner at Battery Ventures, noticed an increase in email attacks, he started investing in startups that could protect against AI with AI. The startup aims to replace traditional email security tools with agent-driven protection.
“The bad guys are using email and using AI to attack us at a faster pace than we can keep up with,” Thakker told TechCrunch. “Preventing that will be a top priority for many companies.”
AegisAI is not the only startup that uses AI to analyze the context of every incoming email to detect fraud and impersonation attempts. Lightspeed-backed Ocean is also trying to displace established vendors like Proofpoint and Mimecast, as well as startups like Abnormal Security.
But given that AegisAI is led by experts who helped secure Gmail, the world’s most popular email system, Thacker believes the startup has the best chance of becoming the new top hack-proofing company.
AegisAI is starting with email, but eventually aims to expand into other defense areas such as data security. “The core idea of building a customized, advanced agent that can perform investigations is to determine which companies will be the next leading security company,” Cormay said.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.
