AegisAI's $36M says AI spear phishing beats your filter
AegisAI raised $36M to fight AI spear phishing with its own models. The lesson for small businesses: stop tuning detection, harden the money path.
Battery Ventures just put $36 million behind a simple, uncomfortable premise: the email filter you're paying for was built to match patterns, and AI spear phishing doesn't leave patterns. AegisAI announced its Series A on July 23, less than a year out of stealth, to replace rule-matching with models that read an email the way a suspicious human would. If you run a small business, the fundraise isn't the news. The reason it happened is.
What actually happened
Per TechCrunch and the company's announcement, AegisAI raised $36M led by Battery Ventures with existing backers Accel and Foundation Capital, bringing total funding to $49M. Founders Cy Khormaee and Ryan Luo came out of Google's security org — the team behind reCAPTCHA, Safe Browsing, and Web Risk.
The product trains its own language models and runs autonomous agents that evaluate messages contextually instead of scoring them against signatures. TechCrunch names the payloads it's built for: malicious PDFs with embedded passwords and CAPTCHAs used as a gate so automated scanners never reach the phishing page. Both are designed specifically to defeat a scanner, not a person. Early customers include Mesh, LangChain, and Lokker. The money goes toward scaling the agent fleet and pushing Vanguard — an agent that hunts beyond the inbox — to general availability.
Khormaee told TechCrunch that AI-powered attacks now bypass existing controls more than half the time. That's a vendor's number, and we'd treat it as one. The direction it points is not in dispute.
Why AI spear phishing matters for your business
Because you can't out-buy this. Every detection layer, AegisAI's included, is probabilistic — it will be right most of the time and wrong on the one that matters. The attacker only needs the wire transfer.
So put the deterministic control where the money is. Vendor bank details should be a locked field that requires a second approver and a callback to a phone number already on file — not the number in the email. Any payment over a threshold you pick gets two humans. Invoice changes trigger a notification to the person who owns that vendor relationship, automatically, not when someone notices. None of that is AI. All of it is a few hours of work in whatever system already holds your AP process, and it holds even when the filter misses.
Keep the good filter. Just don't let it be the only thing standing between a convincing email and your bank account.
Key takeaways
- AegisAI raised a $36M Series A led by Battery Ventures on July 23, $49M total, founded by ex-Google reCAPTCHA and Safe Browsing leads
- It builds its own models and autonomous agents to read email contextually instead of matching signatures
- Named attack shapes — password-protected malicious PDFs, CAPTCHA-gated phishing pages — exist purely to defeat automated scanners
- Detection is probabilistic; put hard approval gates on vendor bank changes and payments so a single miss can't cost you money
Is your payment approval a rule, or a habit? We build the boring controls into the systems you already run — locked vendor fields, second-approver gates, automatic change alerts — so fraud has to beat a process, not a person having a busy Tuesday. Tell us how your AP flow works today or see what we build.
Sources: TechCrunch, AegisAI via PR Newswire.
- #email-security
- #spear-phishing
- #ai-agents
- #fraud
- #aegisai
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Cursor's ₹649 India tier: dev seats go geographic
Cursor launched a ₹649/month India-only plan, roughly a third of its $20 Pro tier. AI dev tool pricing is now segmented by market, and that changes your budget math.
Read itvBulletin RCE exploit went public: get to 6.2.2 today
A working exploit for vBulletin CVE-2026-61511 dropped four weeks after the patch. Unauthenticated remote code execution, no in-the-wild reports yet. That window closes fast.
Read it