AegisAI Raises $36M to Fight AI-Generated Spear Phishing With Its Own LLMs
Source: TechCrunch — 2026-07-23
Summary
AegisAI, founded by former Google security executives, raised a $36 million Series A led by Battery Ventures (bringing its total funding to $49 million) to build an email-security product that runs its own LLMs to detect AI-generated spear phishing. The round comes as AI-generated spear phishing has grown from 2.8% to 13.9% of observed attacks year over year, and the company already has deployments with fintech and crypto clients including Mesh.
Key Takeaways
- The core problem AegisAI targets is a measured, verified year-over-year jump: AI-generated spear phishing rose from 2.8% to 13.9% of observed attacks — roughly a 5x increase in a single year.
- AegisAI's approach is to run its own LLMs inside the email-security pipeline specifically to detect AI-generated phishing content, rather than relying purely on traditional signature or heuristic-based filters.
- The $36M Series A (led by Battery Ventures, total funding now $49M) comes with real customer traction already in place, including fintech/crypto clients like Mesh — industries that are disproportionate targets for sophisticated spear phishing.
Reel Script
Hook (~16s): AI-generated spear phishing didn't creep up gradually — it jumped nearly five-fold in a year, from under 3% of attacks to almost 14%. A new startup just raised $36 million to fight AI-written phishing with AI of its own.
Core Concept (~75s): Spear phishing is the targeted version of phishing — instead of a generic scam email blasted to millions, it's a message crafted specifically around one target, often referencing real details about their company or role to seem legitimate. The reason AI made this worse fast is that writing a convincing, personalized phishing email used to take real human effort per target — now a language model can generate a highly tailored, well-written message in seconds, at essentially zero marginal cost, which is exactly why the share of attacks that are AI-generated jumped from 2.8% to 13.9% year over year. Traditional email security tools were largely built to catch patterns in older-style phishing — bad grammar, generic templates, known bad links — and those signals are exactly what AI-generated phishing is good at removing.
Hands-On (~90s): AegisAI's answer is to fight fire with fire architecturally: instead of relying purely on the traditional heuristics (known bad senders, suspicious links, template matching), it runs its own LLMs inside the detection pipeline, using them to evaluate incoming email the way a skeptical, well-informed human reader would — checking for the subtler tells of AI-generated, context-aware social engineering that don't reduce to a simple keyword or pattern rule. That's a meaningful shift in the arms race: when the attack side is generative, a purely rule-based defense increasingly can't keep up, so the defense has to become generative-aware too. The company already has this running with fintech and crypto clients, including a named deployment at Mesh — industries that are frequent, high-value spear-phishing targets, which makes early production traction here a meaningful signal rather than just a lab result.
Takeaway (~20s): The 2.8%-to-13.9% jump is the number to remember: AI-generated phishing isn't a future risk, it's already roughly one in seven attacks today. If your organization's email security still leans on pre-LLM-era heuristics, that gap is closing faster than most security roadmaps account for.