Ex-Google security engineers raise $36 million to fight AI-crafted phishing emails

AegisAI, founded by two former Google executives who helped build Gmail's defences, says AI is now writing scam emails so convincing that existing filters miss them more than half the time.

AI2Day NewsdeskUpdated Editor: Lee Brown3 min read
Close-up overhead shot of a plain laptop keyboard in a dimly lit office, the screen glowing pale blue, an inbox interface faintly reflected on the desk surface,
Share

Key points

  • AegisAI raised a $36 million Series A funding round, led by Battery Ventures, in 2025.
  • The startup's total funding now stands at $49 million, with backers including Accel and Foundation Capital.
  • Co-founders Cy Khormaee and Ryan Luo previously built Google's Safe Browsing and reCAPTCHA tools.
  • AegisAI's CEO says AI-powered phishing attacks now bypass standard security filters more than half the time.
  • Early customers include crypto payments company Mash, AI developer tools firm LangChain, and Google-owned privacy compliance platform Lokker.

Spam filters used to catch obvious fakes. The subject line was off, the grammar was wrong, something felt odd. That era is ending fast.

Criminal groups now feed personal details into AI, job title, active projects, recent travel, then generate a tailored scam email in seconds. These are called spear-phishing attacks: targeted fraud messages written to look as if they come from someone you know. The old filters, built on fixed rules like a checklist of warning signs, increasingly cannot keep up. Our story on Forg365, a phishing kit sold for $400 a month on Telegram, showed just how commoditised that threat has become.

Who built AegisAI, and why does their background matter?

AegisAI was founded last year by Cy Khormaee and Ryan Luo, who spent a decade at Google building security tools for Gmail, the world's most widely used email service. Khormaee led work on Safe Browsing, the system that warns you when a website looks dangerous. Luo helped build reCAPTCHA, the "I'm not a robot" test that blocks automated bots.

They concluded that rule-based filters, software that blocks email only when it matches a pre-written list of red flags, are structurally too slow to catch AI-written attacks.

"AI-powered attacks bypass existing controls more than half the time now, which means they're almost twice as effective as they used to be," Khormaee told TechCrunch. "They've researched you, they understand everything about you, and they're targeting attacks that are perfectly bespoke to you."

How does the AegisAI system actually work?

Instead of a checklist, AegisAI uses AI agents, software programs that reason through a problem step by step the way a human analyst would, to read each incoming email in full context. They catch subtle inconsistencies a fixed rule would never flag, including password-protected PDF attachments or fake CAPTCHA screens embedded in documents specifically designed to slip past standard spam filters.

What does the funding mean, and who else is in this market?

Battery Ventures led the $36 million Series A, with Accel and Foundation Capital also participating, bringing AegisAI's total raised to $49 million.

Competitor Ocean, backed by Lightspeed Venture Partners, is chasing the same market. Established players like Proofpoint and Mimecast, along with newer rivals like Abnormal Security, all offer email threat protection. Battery Ventures general partner Dharmesh Thakker, who told TechCrunch he personally noticed a rise in email attacks before investing, believes AegisAI's founding team gives it an edge no competitor can easily copy.

For people at companies handling sensitive data or financial transactions, the practical reality is blunt: even careful employees are now targeted with emails that look genuinely real. Calling a colleague before clicking a link or opening an attachment remains the simplest defence while better tools mature. Our 15 July report on how a single poisoned email can rewrite an AI assistant's long-term memory is worth reading alongside this one.

Khormaee sees email as just the starting point. "The core idea of building customised, highly advanced agents that can do investigations is going to determine who becomes the next dominant security company," he told TechCrunch.

© 2026 AI2Day