XOOMAR
AI email security shield blocking phishing attacks in a dark digital network.
CybersecurityJuly 24, 2026· 6 min read· By XOOMAR Insights Team

AI Phishing Threat Sends $36M Into AegisAI's Agents

Share
Updated on July 24, 2026

$36 million is now riding on AegisAI’s bet that email security needs autonomous AI agents to fight AI-crafted phishing, not another layer of static rules.

XOOMAR Intelligence

Analyst Take

66/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness100Source Trust85Factual Grounding94Signal Cluster20

The email security startup announced a Series A led by Battery Ventures, with participation from Accel and Foundation Capital, bringing total funding to $49 million, according to SecurityWeek. The company said it will use the money to expand its autonomous detection agents, push its Vanguard agent toward general availability, and build out enterprise sales.

AegisAI’s $49 million bet targets AI-powered email security

AegisAI was founded in 2025 by Cy Khormaee and Ryan Luo, former members of Google’s security team who worked on reCAPTCHA, Safe Browsing and Web Risk. The company emerged from stealth in September 2025.

Its platform reviews incoming email for phishing, business email compromise and other threats. The key claim: AegisAI does not rely mainly on static rules or known-bad signatures. It uses a network of AI agents to assess the intent and identity behind a message.

That distinction matters because the company is positioning itself directly against what it calls AI spear phishing. In AegisAI’s framing, attackers can use language models to research a target, map work relationships and write a personalized lure at a cost and speed that would have been harder to match with human operators alone.

“The most immediate, catastrophic risk to your organization isn't an AI agent hacking your firewall. It's an AI model manipulating someone in your organization into handing over the keys, often through the most trusted, most vulnerable contact of the person it's targeting,” said Khormaee, AegisAI’s CEO.

The product connects to Microsoft 365 and Google Workspace through an API, which AegisAI says requires no changes to a customer’s MX records. That is a practical sales point for security teams that don’t want an email security rollout to become an infrastructure project.

AegisAI introduced Vanguard in March. The companion agent investigates suspicious links and attachments by navigating to them the way a human recipient would, then produces a threat report within minutes.


Email attacks are pulling budgets toward AI defense tools

The company’s funding pitch is built around a blunt security thesis: if attackers are using AI to make email lures more convincing, defenders need AI that can reason through context, identity and intent in real time.

Company materials cited in the source set the scale sharply. AegisAI says AI-generated spear phishing rose from 2.8% to 13.9% of observed phishing in 2025, based on its State of the AI Threat in Email study of more than 20,000 phishing, scam and malware emails. The same materials say AI-generated emails evade traditional filters at nearly double the rate of human-written attacks and reach the inbox more than half the time.

AegisAI also cites the FBI’s 2025 Internet Crime Report, saying reported cybercrime losses hit $20.8 billion. The company says phishing complaint volume stayed roughly flat, while losses tied to those complaints rose from about $70 million to more than $215 million.

The sharper point is business email compromise. AegisAI says BEC accounted for $11.64 billion in losses, compared with less than $52 million for ransomware and malware combined.

That explains the investor interest. The risk is not only malicious attachments or sketchy URLs. It is trust abuse at scale.

Security approach What it looks for AegisAI’s claimed edge
Traditional filtering Known-bad signatures, rules, past scam patterns Can miss novel, personalized lures
AegisAI agents Message intent, sender identity, contextual anomalies Designed to catch AI-crafted attacks that pass technical checks
Vanguard Suspicious links and attachments beyond the inbox Navigates links and files like a user, then reports within minutes

Analysis: funding momentum does not prove AegisAI has a durable product lead. It does show that investors are backing a clear category thesis: email remains a high-value attack surface, and buyers need detection that catches more sophisticated lures without flooding security teams with noise.

That thesis also sits beside other security funding stories XOOMAR has tracked, including Abstract Security Funding Wagers $25M Against SIEM Lock-In and $1.2B AI Risk Bet Hurls Glow Endpoint Security Into View. The common thread is not a single product category. It is pressure to prove AI can reduce security workload, not just rename old tooling.

AegisAI now has to turn capital into enterprise proof

AegisAI says the $36 million round will support three priorities: more autonomous defense agents, general availability for Vanguard, and enterprise go-to-market expansion.

That next phase is harder than a funding announcement. Enterprise security buyers will want evidence that AegisAI’s agents outperform existing controls in production, not just in demos or controlled studies.

The company’s strongest technical story is its focus on intent and identity. If AI phishing can pass authentication, mimic tone and avoid known malicious infrastructure, then a filter that only asks whether something matches a known pattern will miss too much.

Khormaee put the argument more directly.

“You cannot patch human trust. If your security program still relies on template-based phishing tests and awareness training, you are training your people to spot last year's threat, not a capable agent crafting a novel lure just for them. When the attack is AI, the defense has to be AI,” Khormaee said.

The unresolved question is measurement. AegisAI says its approach can cut false positives by up to 90% compared to traditional solutions, according to company materials. Buyers will want to see how that holds across industries, tenant sizes, email platforms and attack types.

Customer traction will matter too. TechCrunch reported that AegisAI has been adopted by dozens of customers, including Mesh, LangChain and Lokker. That is useful early validation, but enterprise security markets usually demand deeper proof: retention, deployment scale, incident reduction and integration quality.

AegisAI’s next pressure point is clear. It has notable backers, a timely threat narrative and founders with Google security credentials. The market will now judge whether AegisAI can show measurable protection against real AI-powered email attacks, especially the ones that look clean to legacy filters and convincing to humans.

The Bottom Line

  • AegisAI’s $36 million Series A signals investor demand for security tools built to counter AI-generated phishing.
  • The company is betting autonomous detection agents can outperform static rules against personalized email attacks.
  • Its API-based support for Microsoft 365 and Google Workspace could make enterprise adoption easier.

Email Security Approaches

AegisAITraditional Static Rules
Uses autonomous AI agents to assess message intent and identityRelies mainly on static rules or known-bad signatures
Targets AI-crafted phishing and business email compromiseBetter suited to previously identified threat patterns
Connects to Microsoft 365 and Google Workspace via API without MX record changesDeployment details vary by product

AegisAI Funding

Series A
$ million36
Total funding
$ million49
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Futuristic identity security hub connecting human users and AI agents through protected access layers.Cybersecurity

$60M Seed Bets Oak Identity Management Can Tame AI Agents

Oak emerged from stealth with $60M to build an AI-native identity layer for enterprises dealing with human and AI-agent access.

Jul 15, 20266 min
AI-powered endpoint security shield protecting employee devices in a dark tech environmentCybersecurity

$1.2B AI Risk Bet Hurls Glow Endpoint Security Into View

Glow exits stealth at $1.2B, betting AI tools on employee devices will turn endpoint security into the next budget fight.

Jul 22, 20269 min
Rogue AI agent node threatens an enterprise network protected by digital shields and security monitoring.Cybersecurity

AI Agents Trip Alarms in Enterprise AI Security Rush

DigiCert says 78% of AI-using enterprises saw an incident or vulnerability, mostly from rogue or misconfigured AI agents.

Jul 11, 20267 min
Dark server network under investigation with shields, locks, and cybercrime infrastructure visuals.Cybersecurity

42 US Attacks Pull Russian Cybercrime Hosts Into Court

DOJ says Russian bulletproof hosts enabled attacks on 42 US entities, shifting pressure from hackers to infrastructure sellers.

Jul 19, 20267 min
Phishing attack targeting encrypted messaging users with shields, locks, and dark cyber espionage visuals.Cybersecurity

Russian Signal Phishing Hijacks VIP Accounts in Support Scam

Russian actors are phishing Signal users for recovery keys, targeting officials, military figures and journalists without breaking encryption.

Jun 30, 20269 min
Futuristic AI hub with glowing neural networks and screens symbolizing Gemini’s rapid user growth.Technology

950M Google Gemini Users Force AI Race Into a Habit War

Gemini has passed 950 million monthly users, proving Google's AI edge may be distribution as much as model quality.

Jul 23, 20267 min
Voice-controlled AI desktop workstation with glowing waveform and futuristic task panels.Technology

ChatGPT Voice Grabs the Desktop and Starts Doing Work

ChatGPT Voice is moving from conversation to desktop control, letting users direct agents and tasks by speaking.

Jul 24, 20266 min
Trading floor with market charts, factory silhouette, and inflation-colored data visualsTrading

Factory Miss Spoils July Flash PMI Rally in Services

US PMI looked hotter in July, but the beat came from services as manufacturing cooled and price pressures returned.

Jul 24, 20267 min
Corporate crypto treasury scene with bitcoin, debt claims, and falling market visuals in a boardroom.Fintech

Strategy Bitcoin Metrics Strip $22B From Saylor's BTC Bet

Strategy's new net bitcoin math deducts $22.3B in senior claims, exposing less upside for common shareholders as BTC slumps.

Jul 24, 20267 min
London club legal case scene with courthouse, police lights, celebrity silhouette, and global map connections.Global Trends

Chris Brown Affray Plea Narrows London Bottle Case

Chris Brown admitted affray in London, narrowing the club case while leaving prison risk and bottle attack claims in the spotlight.

Jul 24, 20267 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.