Former Google Security Leads Raise 36 Million Series A for AegisAI to Combat AI-Powered Spear Phishing Attacks

The cybersecurity landscape is currently undergoing a fundamental shift as artificial intelligence transitions from a defensive tool to a weaponized instrument for digital exploitation. In response to this escalating threat, AegisAI, a startup founded by veteran security experts from Google, has announced the successful closing of a $36 million Series A funding round. Led by Battery Ventures with participation from Accel and Foundation Capital, this latest injection of capital brings the company’s total funding to $49 million. The investment underscores a growing urgency within the corporate world to move beyond legacy security protocols that are increasingly proving ineffective against the sophistication of generative AI.
The core mission of AegisAI is to neutralize "spear phishing," a highly targeted form of cyberattack that uses personalized information to deceive specific individuals within an organization. Unlike traditional phishing, which relies on broad, generic "spray and pray" tactics, spear phishing involves meticulous research. Historically, this research was conducted manually by hackers, limiting the scale of such attacks. However, the advent of large language models (LLMs) and automated data scraping has allowed bad actors to aggregate personal details—including internal project names, recent travel itineraries, and co-worker hierarchies—to craft convincing, bespoke messages at an unprecedented scale.
The Evolution of the Phishing Threat in the Age of AI
The emergence of AegisAI comes at a critical juncture for global cybersecurity. According to the FBI’s Internet Crime Complaint Center (IC3), Business Email Compromise (BEC) and phishing remain among the most financially devastating forms of cybercrime, accounting for billions of dollars in adjusted losses annually. What has changed in the last 24 months is the efficacy of these attacks.
Prior to the generative AI boom, phishing emails were often identifiable by grammatical errors, awkward phrasing, or generic templates. Today, AI allows attackers to mimic the specific writing style and tone of a company’s CEO or a trusted vendor. By analyzing publicly available data and stolen credentials, AI-driven bots can generate thousands of unique, context-aware emails in seconds.
Cy Khormaee, co-founder of AegisAI, noted that AI-powered attacks now bypass existing security controls more than 50% of the time. This represents a doubling of effectiveness compared to pre-AI attack methodologies. The "bespoke" nature of these messages means they do not contain the typical "red flags" that traditional filters look for, such as known malicious links or suspicious sender domains. Instead, they often focus on social engineering—urging a wire transfer or a password change through a narrative that seems entirely plausible given the recipient’s current workload or location.
From Google Security to Startup Innovation: The Founders’ Journey
The technical foundation of AegisAI is rooted in the deep expertise of its founders, Cy Khormaee and Ryan Luo. Both were high-level security executives at Google, where they played pivotal roles in developing some of the world’s most widely used protective technologies. Their work on Google’s Safe Browsing technology—which protects billions of devices from malicious websites—and reCAPTCHA provided them with a front-row seat to the evolution of automated bot attacks.
During their decade-long tenure at Google, Khormaee and Luo observed a recurring flaw in the way the industry approached email security. Most existing systems rely on "rule-based" logic, often referred to as "if-then" statements. For example, a system might be programmed to flag an email if it contains a specific keyword then move it to spam. While effective against high-volume, low-sophistication attacks, these static rules are too rigid to catch the fluid and adaptive nature of AI-generated content.
Realizing that the defenders were falling behind the attackers, the duo departed Google last year to build a platform that fights AI with AI. AegisAI was born from the realization that security systems needed to move away from rigid checklists and toward "agentic" defense—systems that can reason, investigate, and understand context in a manner similar to a human security analyst, but at the speed of a machine.
The Technical Edge: Agentic-Driven Defense
AegisAI’s platform utilizes specialized AI agents designed to perform deep contextual analysis on every incoming communication. Unlike traditional filters that scan for signatures of known malware, AegisAI’s agents look for "anomalies in intent."
The system analyzes the relationship between the sender and the recipient, the timing of the message, and the specific requests being made. For instance, if an employee receives a PDF attachment that looks like a legitimate invoice, AegisAI’s agents don’t just scan the file for viruses. They look deeper. They might identify that the PDF contains a built-in password or a CAPTCHA—tactics specifically designed to "blind" standard automated scanners. The AI agents can simulate the process of opening the file, solving the CAPTCHA, and inspecting the destination of the embedded links, all before the email ever reaches the user’s inbox.
This level of scrutiny allows AegisAI to detect sophisticated "living off the land" attacks, where no actual malware is used, but the intent is fraudulent. By understanding the "why" behind an email rather than just the "what," the platform can flag messages that appear perfect on the surface but are fundamentally deceptive.
Market Traction and Investor Confidence
The demand for this "human-like" automated analysis has resulted in rapid growth for the startup. In less than a year since its launch, AegisAI has secured a diverse roster of clients, including the crypto payments company Mesh, the high-growth AI development platform LangChain, and the privacy compliance firm Lokker. These companies operate in high-stakes environments where a single compromised email could lead to significant financial or data loss.
Dharmesh Thakker, General Partner at Battery Ventures, spearheaded the Series A round after observing a sharp increase in the success rate of email-based attacks among portfolio companies. Thakker argued that the industry is currently seeing a replacement cycle where legacy tools like Proofpoint and Mimecast, while still functional for basic threats, are being outpaced by "agentic" security startups.
"The bad guys are using email to attack us using AI at a much faster pace than we can keep up with," Thakker stated. He emphasized that for modern enterprises, defending against AI-driven social engineering has become a top-tier priority, shifting from a back-office IT concern to a boardroom-level risk management issue.
While AegisAI faces competition from other emerging players like Ocean (backed by Lightspeed) and Abnormal Security, investors believe the pedigree of the AegisAI team gives them a unique advantage. Having secured Gmail—the most targeted email platform on the planet—the founders possess a rare understanding of the scale and complexity required to protect global communication networks.
Chronology of AegisAI’s Rapid Rise
The timeline of AegisAI reflects the accelerated pace of the current AI venture capital market:
- Mid-2023: Cy Khormaee and Ryan Luo depart Google to begin conceptualizing a context-aware email security platform.
- Late 2023: AegisAI is officially founded and begins developing its proprietary AI agents.
- September 2024: The company emerges from stealth with a $13 million seed round led by Accel and Foundation Capital, revealing its initial technology stack.
- Early 2025: AegisAI expands its customer base to dozens of enterprise clients, demonstrating the scalability of its agentic defense model.
- Late 2025: The company closes a $36 million Series A led by Battery Ventures, bringing its total valuation to a significant premium as it prepares for global expansion.
Broader Implications for the Cybersecurity Industry
The success of AegisAI’s funding round is a clear signal of the "AI vs. AI" arms race currently defining the cybersecurity sector. As hackers lower the cost of entry for sophisticated attacks using tools like WormGPT or FraudGPT, the burden of defense is shifting. It is no longer feasible to train employees to "spot the phish" when the phish is indistinguishable from a legitimate email.
The implications of AegisAI’s technology extend beyond just email. Khormaee has indicated that the startup intends to use its fresh capital to expand into other areas of digital defense, such as data security and internal communications platforms like Slack and Microsoft Teams. The "core idea" is that specialized AI agents can perform autonomous investigations across an entire corporate ecosystem, identifying patterns of lateral movement or data exfiltration that human teams might miss.
As organizations grapple with the dual nature of AI—as both a productivity booster and a threat multiplier—startups like AegisAI are positioning themselves as the necessary "immune system" for the digital age. The shift toward agentic-driven defense suggests a future where security is not a series of barriers, but a continuous, intelligent process of verification and contextual understanding.
For the broader market, the $36 million Series A is more than just a successful fundraise; it is a validation of the theory that the next generation of dominant security companies will be those that can successfully automate the intuition of the world’s best security analysts. With the backing of major venture firms and a team of Google veterans at the helm, AegisAI is now positioned to lead that transition.






