Hackers are increasingly using AI to launch attacks on a massive scale, with email being the primary target. AI can quickly aggregate personal information, such as information about coworkers, active projects, and recent travel itineraries, allowing criminals to instantly craft compelling messages that appear authentic. Last year, former Google security executives Cy Khormaee and Ryan
Hackers are increasingly using AI to launch attacks on a massive scale, with email being the primary target. AI can quickly aggregate personal information, such as information about coworkers, active projects, and recent travel itineraries, allowing criminals to instantly craft compelling messages that appear authentic.
Last year, former Google security executives Cy Khormaee and Ryan Luo, who previously worked on developing secure browsing and reCAPTCHA technology, teamed up to launch AegisAI, a startup that uses artificial intelligence agents to take down these threats, known as phishing.
With a decade of experience preventing email attacks, AegisAI’s co-founders realized that existing rule-based systems for preventing attacks (which rely on “if-then” logic) are too slow and limited to detecting malicious emails crafted by AI. That’s why they developed artificial intelligence agents that quickly analyze each message like a human would, paying attention to small anomalies that even the most elaborate checklist wouldn’t detect.
Less than a year after its launch, AegisAI says its technology has been adopted by dozens of customers, including crypto payments company Mesh, artificial intelligence startup LangChain, and privacy compliance platform Lokker. That lawsuit just helped AegisAI raise a $36 million Series A led by Battery Ventures, with participation from existing backers Accel and Foundation Capital. The new financing brings the startup’s total capital to $49 million.
“AI-powered attacks bypass existing controls more than half of the time now, meaning they are almost twice as effective as they used to be,” Khormaee told TechCrunch. “They’ve researched you, they understand everything about you, and they’re targeting attacks that are perfectly tailored to you.”
Khormaee says AegisAI agents can detect threats that traditional email security systems may miss entirely. For example, the startup’s AI can detect malicious PDF attachments that at first appear legitimate, including those with embedded passwords and CAPTCHAs, which are often used to fool standard spam filters.
When Dharmesh Thakker, general partner at Battery Ventures, noticed an increase in email attacks, he set out to invest in a startup that could defend against AI with AI, which aimed to replace legacy email security tools with agent-powered defense.
“Bad guys are using email to attack us using AI at a much faster pace than we can keep up with,” Thakker told TechCrunch. “Defending against that will be the number one priority for many companies.”
AegisAI is not the only startup using AI to analyze the context of every incoming email to detect fraud and phishing attempts. Lightspeed-backed Ocean is also trying to displace established vendors like Proofpoint and Mimecast, along with newer players like Abnormal Security.
However, since AegisAI is led by experts who helped secure Gmail, the world’s most popular email system, Thakker believes the startup has a better chance of becoming the leading new attack prevention company.
While AegisAI is starting with email, the startup has its sights on eventually expanding into other areas of defense, such as data security. “The core idea of creating personalized, highly advanced agents that can conduct investigations is going to [determine] who will become the next dominant security company,” Khormaee said.
When you buy through links in our articles, we may earn a small commission. This does not affect our editorial independence.
Check back often for more exciting news!

















