HackMyIP
← Back to News
2026-07-24 SecurityWeek

AegisAI Raises $36M Series A to Combat AI-Powered Phishing

PhishingAI SecurityAI Threats

Email security startup AegisAI has secured $36 million in a Series A funding round led by Battery Ventures, with participation from Accel and Foundation Capital. The raise brings the company's total funding to $49 million, which it will use to expand its lineup of autonomous detection agents, push its Vanguard agent toward general availability, and scale enterprise go-to-market operations. AegisAI was founded in 2025 by Cy Khormaee and Ryan Luo, both former members of Google's security team who contributed to reCAPTCHA, Safe Browsing, and Web Risk, and the company emerged from stealth in September 2025.

The platform is built around a network of AI agents that review inbound email for phishing, business email compromise, and other advanced threats. Unlike legacy tools that rely on static rules or known-bad signatures, AegisAI's system evaluates the intent and identity behind each message. It integrates with Microsoft 365 and Google Workspace via API without requiring changes to customer MX records, lowering deployment friction. In March, the company introduced Vanguard, a companion agent that navigates suspicious links and attachments the way a human recipient would, compiling a threat report within minutes. Organizations concerned about exposure can run an email breach checker to see whether employee credentials have already surfaced in known dumps, a common precursor to targeted phishing.

AegisAI frames its mission around what it calls "AI spear phishing," referring to attacks where adversaries use language models to research targets, map their professional relationships, and generate personalized lures at a fraction of the historical cost. "The most immediate, catastrophic risk to your organization isn't an AI agent hacking your firewall. It's an AI model manipulating someone in your organization into handing over the keys, often through the most trusted, most vulnerable contact of the person it's targeting," said CEO Khormaee. He added that traditional awareness training is no longer sufficient: "If your security program still relies on template-based phishing tests and awareness training, you are training your people to spot last year's threat, not a capable agent crafting a novel lure just for them. When the attack is AI, the defense has to be AI."

The funding round highlights growing investor confidence in AI-native defenses against AI-native attacks. As generative tools make convincing social engineering accessible to lower-skilled threat actors, defenders are racing to deploy agents that can reason about context at machine speed. Security teams evaluating their own exposure can pair email monitoring with a privacy checkup to audit which third-party services have access to corporate inboxes and cloud accounts, closing gaps that phishing campaigns routinely exploit.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →