The New Face of Email Attacks
Here's the thing about AI-powered spear phishing that keeps security teams up at night: it works. And it's getting better fast.
Hackers are using artificial intelligence to scrape personal data — co-worker details, active project names, recent travel plans — and stitch them into emails so convincing that even cautious employees take the bait. The result? AI-crafted messages that bypass traditional email security controls more than half the time, according to Cy Khormaee, co-founder of AegisAI. That's nearly twice the success rate of pre-AI attacks.
"They've researched you, they understand everything about you, and they're targeting attacks that are perfectly bespoke to you," Khormaee said. The word "bespoke" does a lot of heavy lifting there. These aren't the sloppy "Nigerian prince" emails of yore. They're tailored, contextual, and devastatingly plausible.
The problem isn't that people are careless. It's that the attackers have a weapon — AI — that traditional security tools simply can't match.
Who Built AegisAI and Why
Last year, Khormaee and his co-founder Ryan Luo — both former Google security executives who helped build Safe Browsing technology and reCAPTCHA — decided they'd seen enough.
A decade of experience preventing email hacks at Google gave them a front-row seat to the arms race between attackers and defenders. They watched rule-based systems, with their rigid "if-then" logic, struggle to keep up. The attackers were moving faster. The emails were getting smarter. And the defenses weren't adapting quick enough.
So they built something different. Instead of relying on static checklists and predefined rules, AegisAI deploys AI agents that analyze each incoming message the way a human analyst would — but at machine speed. These agents look for micro-anomalies: subtle linguistic cues, structural oddities, contextual mismatches that slip past even the most elaborate security filters.
It's not magic. It's pattern recognition at scale, trained on the kind of sophisticated threats that make traditional systems blink.
What AI in Cybersecurity Actually Looks Like
Let's get concrete. AegisAI's agents can catch malicious PDF attachments that look completely legitimate at first glance — including ones with built-in passwords and CAPTCHAs designed specifically to fool standard spam filters. Think about that for a second. A password-protected PDF with a CAPTCHA? That's not something your average security tool flags, because it mimics behavior that real users actually do.
But the AI agent sees the context. It notices the mismatch between the attachment's request for verification and the email's supposed urgency. It flags the anomaly before anyone clicks.
This is what artificial intelligence cybersecurity defense actually looks like in practice. Not a dashboard full of red alerts. Not another checklist. It's an agent that understands nuance, context, and intent — the things that make phishing emails dangerous in the first place.
Related coverage: Arcade.dev's approach to securing AI agents in enterprise environments.
Customers Already Trust the System
Less than a year after launch, AegisAI has dozens of customers. The list reads like a who's who of companies that can't afford to get hacked: Mesh, a crypto payments company; LangChain, the AI startup building the infrastructure for generative models; and Lokker, a privacy compliance platform.
These aren't beta testers. They're organizations handling sensitive data, running critical infrastructure, and sitting on attack surfaces that make them targets for precisely the kind of bespoke spear phishing AegisAI was built to stop.
The adoption tells you something important: when AI-powered attacks are bypassing half your defenses, you don't wait around for the next security vendor to catch up. You buy what works.
The Money Behind the Mission
That demand translated into a $36 million Series A led by Battery Ventures, with participation from existing backers Accel and Foundation Capital. Total funding now sits at $49 million.
Dharmesh Thakker, general partner at Battery Ventures, noticed the spike in email attacks and decided to bet on a startup that could fight AI with AI. "The bad guys are using email to attack us using AI at a much faster pace than we can keep up with," Thakker said. "Defending against that is going to be a number one priority for a lot of companies."
His confidence isn't baseless. AegisAI's founders helped secure Gmail — the most popular email system on Earth. That experience translates into an intimate understanding of the attack surface that billions of users expose daily.
Thakker believes AegisAI has "the best shot at becoming the leading new hack-prevention company" precisely because of that pedigree. In cybersecurity, experience isn't just valuable. It's everything.
The broader AI investment landscape continues to expand — from India's Sarvam securing $234M in HCLTech-led financing to GPU infrastructure bets reaching billions.
The Competitive Landscape
AegisAI isn't alone in this space. Ocean, backed by Lightspeed, is also using AI to analyze email context and detect fraud. Established players like Proofpoint and Mimecast are scrambling to adapt, while newer entrants like Abnormal Security are carving out their own niches.
But here's where AegisAI pulls ahead: its agents aren't just analyzing email content. They're built by engineers who helped secure the world's largest email system. That's not a marketing line. It's a fundamental advantage in understanding how attacks evolve and where defenses need to tighten.
The competition is real. But so is the gap between companies that understand AI-driven threats and those still fighting yesterday's war.
What Comes Next
Email is just the starting point. AegisAI has its sights set on expanding into broader data security applications — using the same agentic approach to protect information across multiple attack surfaces.
"The core idea of building customized, highly advanced agents that can do investigations is going to determine who becomes the next dominant security company," Khormaee said.
That's a bold claim. But given where the industry is heading — where AI-powered attacks are already outpacing human-driven defenses — it feels less like ambition and more like inevitability.
The question isn't whether AI will transform cybersecurity defense. It already has. The question is whether your organization is on the right side of that transformation.