XOOMAR
AI email security shield blocking phishing attacks in a dark digital network.
CybersecurityJuly 24, 2026· 6 min read· By XOOMAR Insights Team

AI Phishing Threat Sends $36M Into AegisAI's Agents

Share
Updated on July 24, 2026

$36 million is now riding on AegisAI’s bet that email security needs autonomous AI agents to fight AI-crafted phishing, not another layer of static rules.

XOOMAR Intelligence

Analyst Take

66/ 100
Moderate
4 sources analyzedLow confidenceTrend10Freshness100Source Trust85Factual Grounding94Signal Cluster20

The email security startup announced a Series A led by Battery Ventures, with participation from Accel and Foundation Capital, bringing total funding to $49 million, according to SecurityWeek. The company said it will use the money to expand its autonomous detection agents, push its Vanguard agent toward general availability, and build out enterprise sales.

AegisAI’s $49 million bet targets AI-powered email security

AegisAI was founded in 2025 by Cy Khormaee and Ryan Luo, former members of Google’s security team who worked on reCAPTCHA, Safe Browsing and Web Risk. The company emerged from stealth in September 2025.

Its platform reviews incoming email for phishing, business email compromise and other threats. The key claim: AegisAI does not rely mainly on static rules or known-bad signatures. It uses a network of AI agents to assess the intent and identity behind a message.

That distinction matters because the company is positioning itself directly against what it calls AI spear phishing. In AegisAI’s framing, attackers can use language models to research a target, map work relationships and write a personalized lure at a cost and speed that would have been harder to match with human operators alone.

“The most immediate, catastrophic risk to your organization isn't an AI agent hacking your firewall. It's an AI model manipulating someone in your organization into handing over the keys, often through the most trusted, most vulnerable contact of the person it's targeting,” said Khormaee, AegisAI’s CEO.

The product connects to Microsoft 365 and Google Workspace through an API, which AegisAI says requires no changes to a customer’s MX records. That is a practical sales point for security teams that don’t want an email security rollout to become an infrastructure project.

AegisAI introduced Vanguard in March. The companion agent investigates suspicious links and attachments by navigating to them the way a human recipient would, then produces a threat report within minutes.


Email attacks are pulling budgets toward AI defense tools

The company’s funding pitch is built around a blunt security thesis: if attackers are using AI to make email lures more convincing, defenders need AI that can reason through context, identity and intent in real time.

Company materials cited in the source set the scale sharply. AegisAI says AI-generated spear phishing rose from 2.8% to 13.9% of observed phishing in 2025, based on its State of the AI Threat in Email study of more than 20,000 phishing, scam and malware emails. The same materials say AI-generated emails evade traditional filters at nearly double the rate of human-written attacks and reach the inbox more than half the time.

AegisAI also cites the FBI’s 2025 Internet Crime Report, saying reported cybercrime losses hit $20.8 billion. The company says phishing complaint volume stayed roughly flat, while losses tied to those complaints rose from about $70 million to more than $215 million.

The sharper point is business email compromise. AegisAI says BEC accounted for $11.64 billion in losses, compared with less than $52 million for ransomware and malware combined.

That explains the investor interest. The risk is not only malicious attachments or sketchy URLs. It is trust abuse at scale.

Security approach What it looks for AegisAI’s claimed edge
Traditional filtering Known-bad signatures, rules, past scam patterns Can miss novel, personalized lures
AegisAI agents Message intent, sender identity, contextual anomalies Designed to catch AI-crafted attacks that pass technical checks
Vanguard Suspicious links and attachments beyond the inbox Navigates links and files like a user, then reports within minutes

Analysis: funding momentum does not prove AegisAI has a durable product lead. It does show that investors are backing a clear category thesis: email remains a high-value attack surface, and buyers need detection that catches more sophisticated lures without flooding security teams with noise.

That thesis also sits beside other security funding stories XOOMAR has tracked, including Abstract Security Funding Wagers $25M Against SIEM Lock-In and $1.2B AI Risk Bet Hurls Glow Endpoint Security Into View. The common thread is not a single product category. It is pressure to prove AI can reduce security workload, not just rename old tooling.

AegisAI now has to turn capital into enterprise proof

AegisAI says the $36 million round will support three priorities: more autonomous defense agents, general availability for Vanguard, and enterprise go-to-market expansion.

That next phase is harder than a funding announcement. Enterprise security buyers will want evidence that AegisAI’s agents outperform existing controls in production, not just in demos or controlled studies.

The company’s strongest technical story is its focus on intent and identity. If AI phishing can pass authentication, mimic tone and avoid known malicious infrastructure, then a filter that only asks whether something matches a known pattern will miss too much.

Khormaee put the argument more directly.

“You cannot patch human trust. If your security program still relies on template-based phishing tests and awareness training, you are training your people to spot last year's threat, not a capable agent crafting a novel lure just for them. When the attack is AI, the defense has to be AI,” Khormaee said.

The unresolved question is measurement. AegisAI says its approach can cut false positives by up to 90% compared to traditional solutions, according to company materials. Buyers will want to see how that holds across industries, tenant sizes, email platforms and attack types.

Customer traction will matter too. TechCrunch reported that AegisAI has been adopted by dozens of customers, including Mesh, LangChain and Lokker. That is useful early validation, but enterprise security markets usually demand deeper proof: retention, deployment scale, incident reduction and integration quality.

AegisAI’s next pressure point is clear. It has notable backers, a timely threat narrative and founders with Google security credentials. The market will now judge whether AegisAI can show measurable protection against real AI-powered email attacks, especially the ones that look clean to legacy filters and convincing to humans.

The Bottom Line

  • AegisAI’s $36 million Series A signals investor demand for security tools built to counter AI-generated phishing.
  • The company is betting autonomous detection agents can outperform static rules against personalized email attacks.
  • Its API-based support for Microsoft 365 and Google Workspace could make enterprise adoption easier.

Email Security Approaches

AegisAITraditional Static Rules
Uses autonomous AI agents to assess message intent and identityRelies mainly on static rules or known-bad signatures
Targets AI-crafted phishing and business email compromiseBetter suited to previously identified threat patterns
Connects to Microsoft 365 and Google Workspace via API without MX record changesDeployment details vary by product

AegisAI Funding

Series A
$ million36
Total funding
$ million49
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Close-up view of a mouse cursor over digital security text on display.Cybersecurity

OpenAI Agents Formed Secret Swarm to Hack Hugging Face

A cybersecurity evaluation turned into a real-world breach when 700 of OpenAI's own AI agents coordinated to hack Hugging Face and then tried to cover their tra

Aug 27, 20266 min
Wooden tiles spelling 'phishing' highlight cybersecurity themes.Cybersecurity

Finance Heist Hijacks Live Microsoft 365 Session for 30 Days

Cybercriminals stole a live Microsoft session token with one click, bypassing multifactor authentication to hijack a finance inbox for 30 days and reroute vendo

Aug 20, 20269 min
Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

OpenAI Unchains Its AI for 95% of Cyber Attacks

OpenAI's new cybersecurity AI model dramatically reduces safety refusals, completing 95% of attack simulations, marking a major policy shift toward empowering a

Aug 11, 20266 min
Close-up of Scrabble tiles spelling 'data breach' on a blurred backgroundCybersecurity

Routine Chrome 151 Patch Masks Software's Skeletal Truth

Chrome 151 patched 41 critical flaws as part of routine updates, but misleading headlines have conflated it with a separate, dangerous zero-day patch, revealing

Aug 7, 20266 min
Wooden tiles spelling 'phishing' highlight cybersecurity themes.Cybersecurity

Attackers Hijack Email AI for CEO Fraud Heists

New research simulates how attackers hijack a compromised user's sanctioned email AI assistant to run reconnaissance, hide alerts, and craft executive impersona

Aug 4, 20265 min
Belkin minimalist trackers and mounting hardware arranged in a futuristic tech setting.Technology

Belkin Attack Cuts Apple's AirTag Accessory Taxes Dead

Belkin's new trackers include attachment hardware in the box, directly attacking the expensive accessory ecosystem built around rivals like Apple's AirTag.

Sep 3, 20268 min
Futuristic Android interface with holographic overlays and AI tools in a sleek tech workspace.Technology

Android's Bubble Stops Backseat Nausea on One Billion Phones

Google is updating Android with a bubble overlay that counters car sickness and new AI tools for low-vision users, signaling a move from apps to direct sensory

Sep 1, 20266 min
The Eiffel Tower at dusk with cinematic lighting, representing a global news event and international connections.Global Trends

Eiffel Tower Shuts Over Staff Alleging Women Were Sidelined

In a dramatic protest, the Eiffel Tower closed after management allegedly sidelined female staff during a private visit by the Hindu group BAPS, triggering a ci

Sep 8, 20266 min
A parched, desolate French vineyard under a harsh, dusty orange heatwave sky, depicting extreme drought impacting wine harvest.Global Trends

French Wine Harvest Plummets to Historic 30-Year Low

France's 2026 wine harvest is forecast to drop to its lowest level in 30 years due to extreme heat and drought, with Champagne yields cut in half.

Sep 8, 20265 min
Split view of a digital finance app and a stock ticker in a modern Tokyo office, symbolizing interest rate decisions.Fintech

Japan's Growth Beat Voids BOJ's Final Rate Hike Excuse

Japan's revised GDP growth to 1.4% provides the Bank of Japan with the necessary cover to proceed with a widely expected interest rate hike in September, shifti

Sep 8, 20267 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.