AegisAI Raises $36 Million Series A to Combat AI-Powered Spear Phishing
Terminal Co-Founders Ryan Luo and Cy Khormaee
AegisAI, an email security startup developing proprietary large language models to defend against AI-driven cyberattacks, has raised $36 million in a Series A funding round led by Battery Ventures, with participation from existing investors Accel and Foundation Capital.
The financing brings the San Francisco-based company’s total funding to $49 million less than a year after emerging from stealth and will support expansion of its autonomous AI security platform, broader commercial rollout of its Vanguard threat-hunting product and accelerated enterprise sales efforts.
Founded in 2025 by former Google security engineers Cy Khormaee and Ryan Luo, AegisAI is positioning itself to address what it describes as the next evolution of phishing attacks: highly personalized, AI-generated spear phishing campaigns capable of bypassing traditional email security systems and exploiting human trust rather than software vulnerabilities.
“The most immediate, catastrophic risk to your organization isn’t an AI agent hacking your firewall. It’s an AI model manipulating someone in your organization into handing over the keys,” said Cy Khormaee, co-founder and chief executive officer of AegisAI. “When the attack is AI, the defense has to be AI.”
Unlike conventional email security platforms that rely on known signatures and historical attack patterns, AegisAI uses proprietary language models and autonomous AI agents to analyze the intent, context and identity behind incoming messages in real time. The company said its reasoning-based approach enables it to identify sophisticated phishing campaigns that appear legitimate and evade conventional detection tools while reducing false positives by as much as 90%.
The company also recently introduced Vanguard, an autonomous investigation platform that extends beyond the inbox. When suspicious emails are detected, Vanguard automatically analyzes embedded links, attachments and external websites, navigating CAPTCHAs, cloaked pages and malicious documents before generating a detailed threat assessment for security teams.
AegisAI argues that advances in generative AI have fundamentally changed the economics of cybercrime. Tasks that once required skilled attackers—including researching victims, mapping business relationships and crafting convincing phishing emails—can now be automated at minimal cost, allowing cybercriminals to launch highly targeted attacks at unprecedented scale.
According to the company’s 2026 State of the AI Threat in Email report, AI-generated spear phishing accounted for 13.9% of observed phishing attacks in 2025, up from 2.8% the previous year. The study also found that AI-generated phishing emails were approximately 75% more likely to evade traditional email filters and that more than 72% of successful AI attacks originated from compromised legitimate email accounts that passed standard authentication checks.
The company’s findings align with broader industry trends. The FBI’s 2025 Internet Crime Report recorded $20.8 billion in reported cybercrime losses, with business email compromise accounting for $11.64 billion—far exceeding losses attributed to ransomware and malware.
“Email is where enterprise trust lives and generative AI just broke every assumption legacy email security was built on,” said Dharmesh Thakker, general partner at Battery Ventures. “When attacks are machine-generated, personalized and indistinguishable from legitimate mail, the only viable defense is an equally capable AI operating at machine speed.”
Since launching publicly in September 2025, AegisAI has signed customers across the fintech and technology sectors, including crypto payments company Mesh, AI software developer LangChain and cybersecurity firm Lokker. The company said its platform has detected sophisticated business email compromise attempts, AI-generated phishing campaigns and attacks leveraging compromised third-party infrastructure.
The funding underscores continued investor appetite for AI-native cybersecurity companies as enterprises seek new approaches to defend against increasingly sophisticated attacks generated by large language models. As generative AI reshapes both offensive and defensive cybersecurity capabilities, startups developing autonomous security agents have emerged as one of the fastest-growing segments of the enterprise security market.