Skip to content
Benderson Media
Markets
AAPL $241.52 -0.38%
BTC $97,412 +3.21%
MSFT $478.90 +0.67%
ETH $4,128 +1.89%
GOOGL $182.34 -0.52%
TSLA $312.67 +4.23%
META $621.45 +1.05%
S&P 500 $6,142.80 +0.31%
NASDAQ $20,847.50 +0.78%
NVDA $183.06 +2.14%

AegisAI Raises $36M to Stop AI Spear Phishing

AegisAI Raises $36M to Stop AI Spear Phishing
Image: TechCrunch | Source

Spear phishing is no longer a numbers game. It’s a precision game. And AI just handed attackers a sniper rifle. AegisAI, built by former Google security executives, closed a $36 million Series A to stop it. This is one of the most important security bets of 2026, and most people haven’t heard of it yet.

Why This Is Happening Now

For years, phishing worked because attackers sent millions of generic emails and hoped someone would click. The defense was simple: train employees to spot bad grammar and suspicious links.

That playbook is dead.

According to Verizon’s 2025 Data Breach Investigations Report, phishing remains the leading cause of data breaches, responsible for 36% of all confirmed incidents. But the nature of phishing has changed. Generative AI now allows attackers to scrape a target’s LinkedIn profile, recent emails, and public records, then produce a perfectly written message in their CEO’s voice in seconds.

According to IBM’s 2025 Cost of a Data Breach Report, the average breach now costs $4.88 million. Spear phishing attacks specifically, the targeted kind that impersonate someone the victim knows, average even higher because they bypass standard filters and land in trusted inboxes.

Crypto wallets are a favorite target. According to Chainalysis, phishing attacks accounted for over $1.05 billion in crypto losses in 2024. AI makes those attacks faster, cheaper, and far more convincing. When transactions are irreversible, a single successful spear phish can wipe out years of gains in minutes.

What AegisAI Is Actually Building

AegisAI’s approach is different from most email security tools. Most legacy systems scan for known malicious links or flagged domains. AegisAI trains models on behavioral patterns: how your CEO actually writes, what language your finance team uses, the rhythm of your internal communications.

When a message comes in that mimics those patterns but doesn’t match the actual sender’s behavior fingerprint, AegisAI flags it before it reaches the inbox.

This is the right approach. Attackers got better, so the defense has to get better too. Legacy tools are playing checkers while AI powered phishing plays chess. AegisAI is building a chess engine.

The founders know what they’re doing. Former Google security executives have seen nation-state-level attacks up close. They know the playbooks. That background matters more than any feature list.

The $36 million gives them runway to train on enough corporate communication data to make the behavioral model actually work at scale. That data advantage is the real moat here, not the algorithm.

Most startups solving this problem are solving it from the outside. They see the incoming message and try to detect it. AegisAI is solving it from the inside. They understand your organization’s communication DNA. That’s a fundamentally better defense.

For businesses managing payroll data, HR communications, and sensitive financial records, this kind of detection matters. Companies using Gusto for payroll keep sensitive compensation and tax data in their systems, which makes them a high-value phishing target. Behavioral email security is exactly the kind of layer that protects those systems without adding friction for legitimate users.

What This Means for You

If you run a business, the threat is real and it is already here. Here is what I would do.

First, stop relying on employee training as your primary defense. Training people to spot phishing was already marginal before AI. Now it’s nearly useless against a well crafted spear phishing attack. You need technical controls, not just awareness.

Second, audit what data you’re exposing publicly. Attackers scrape LinkedIn, company websites, and public filings before they write the phishing email. The less they know about your org chart and internal processes, the harder they have to work.

Third, lock down your financial accounts. Most spear phishing attacks end at a wire transfer or a credential dump. Separate your business spending from your operating accounts. A tool like Wallester lets you issue virtual business cards with spending limits for specific vendors, which means even if a card number gets compromised, the damage is capped. That’s a simple, practical control that most small businesses ignore.

Fourth, pay attention to this funding round. Not because you need AegisAI’s product today, but because the category is about to blow up. When former Google security executives raise $36 million to solve a specific problem, that problem is about to get a lot more attention and a lot more funding. You want to understand this space before a vendor pitches you under pressure.

The Bottom Line

AI gave attackers superpowers in 2025. The security industry is now racing to catch up. AegisAI’s $36 million bet is that behavioral analysis can outsmart generative phishing at scale. I think they’re right. The businesses that treat this as background noise will be the ones writing breach disclosure letters in 2027. The ones that take it seriously now will have the controls in place before the attack arrives. Don’t be the cautionary tale.

Frequently Asked Questions

What is AegisAI and what does it do?

AegisAI is a cybersecurity startup founded by former Google security executives. It raised $36 million to build AI powered tools that detect and stop spear phishing attacks by analyzing behavioral patterns in corporate communications rather than scanning for known malicious links.

Why is AI spear phishing a bigger threat than traditional phishing?

Traditional phishing sends generic messages at scale and relies on volume. AI spear phishing generates personalized, convincing messages that mimic real people in your network. According to Verizon’s DBIR, phishing causes 36% of all data breaches, and the AI driven version bypasses most standard filters because it looks and reads like a real internal message.

How does AegisAI defend against AI phishing?

AegisAI builds a behavioral fingerprint of how people in your organization actually communicate. When an incoming message mimics those patterns but doesn’t match the authentic sender’s behavior, the system flags it before it reaches the inbox. It’s defending from the inside out, not the outside in.

Are crypto assets at risk from spear phishing?

Yes, significantly. According to Chainalysis, phishing accounted for over $1.05 billion in crypto losses in 2024. Crypto wallets and exchange accounts are high-value targets because transactions are irreversible. AI driven spear phishing makes these attacks harder to detect and far easier to execute at scale.

What can small businesses do right now to protect against AI phishing?

Audit your public data exposure, implement multi-factor authentication everywhere, and separate financial accounts to limit breach impact. Look for behavioral email security tools rather than relying only on employee training. The threat has outpaced awareness based defenses, and the gap is widening every month.