AegisAI lands $36m to counter AI spear phishing surge

AegisAI

AegisAI, an email security company that builds its own large language models to protect the inbox, has closed a $36m Series A round as it takes aim at a fast-growing wave of AI-driven email attacks that are inflicting serious damage on people and businesses.

The round was led by Battery Ventures, with existing backers Accel and Foundation Capital also taking part. It lifts AegisAI’s total capital raised to $49m, less than 12 months after the firm came out of stealth.

The new money will go towards scaling its fleet of autonomous defence agents, speeding up the general availability of Vanguard, its threat-hunting agent that operates beyond the inbox, and building out its enterprise go-to-market operation.

The company is responding to a threat category it describes as AI spear phishing, in which attackers deploy large language models to trawl the internet for details about a chosen victim and generate highly personalised messages engineered to extract sensitive information, install malware or trigger fraudulent payments.

The growing adoption of AI by consumers and employees amplifies this exposure, while the spread of AI agents that act autonomously on a person’s behalf opens up a vast new attack surface where criminals could remain hidden for extended periods.

AegisAI counters these threats with a coordinated network of AI agents built on intelligent language models, which assess and respond to malicious email in real time, in effect turning AI against AI.

Rather than matching messages against patterns drawn from historical scams, its adaptive platform applies advanced reasoning to judge the underlying intent of a suspicious email, allowing fraud to be identified far faster at a time when phishing volumes have soared since ChatGPT arrived.

The firm argues that the economics of targeted attacks have collapsed. Where researching a victim, mapping their contacts, impersonating a supplier and timing a lure once demanded a skilled operator and was largely the preserve of nation-states, off-the-shelf AI can now perform the entire process autonomously and at unlimited scale for roughly the cost of a coffee.

Data supports that claim. AegisAI’s State of the AI Threat in Email study, presented at the 2026 M3AAWG conference and drawing on more than 20,000 phishing, scam and malware emails, found AI-generated spear phishing jumped fivefold in a year, rising from 2.8% to 13.9% of all observed phishing during 2025. It also found AI-written attacks slip past traditional filters at almost twice the rate of human-crafted ones, landing in inboxes more than half the time, while 72.6% of successful AI attacks passed email authentication because they were sent from compromised legitimate accounts with established sending histories.

AegisAI co-founder and CEO Cy Khormaee said, “The most immediate, catastrophic risk to your organization isn’t an AI agent hacking your firewall. It’s an AI model manipulating someone in your organization into handing over the keys, often through the most trusted, most vulnerable contact of the person it’s targeting.

“You cannot patch human trust. If your security program still relies on template-based phishing tests and awareness training, you are training your people to spot last year’s threat, not a capable agent crafting a novel lure just for them. When the attack is AI, the defense has to be AI.”

Stay ahead of the threats and deals shaping the industry. Join FinTech leaders who rely on FinTech Global for early insight and strategic intelligence and subscribe to the FinTech Global newsletter today. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.