AI Pulse by Inblix

AI-powered hacks now bypass email defenses 50% of the time, say ex-Google execs

TechCrunch AI · Jul 23, 2026 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: AI-powered hacks now bypass email defenses 50% of the time, say ex-Google execs

The numbers should make every CISO uncomfortable. Former Google security executives Cy Khormaee and Ryan Luo say AI-generated attacks are bypassing traditional email controls more than half the time — nearly double the previous success rate. The problem isn’t just volume; it’s precision. Hackers now use AI to scrape your projects, your coworkers, even your travel plans, then craft messages so contextually perfect they sail past legacy rule-based filters.

Khormaee and Luo spent a decade building safe browsing tech and reCAPTCHA at Google. They left to launch AegisAI, a startup that flips the script: using AI agents to hunt AI-generated threats. Their pitch resonated fast. Less than a year out of stealth, the company has locked in a $36 million Series A led by Battery Ventures, with Accel and Foundation Capital chipping in. Total funding now sits at $49 million, with customers including LangChain and Google-owned Lokker already on board.

What separates AegisAI’s approach is an agent that reads emails like a person would — scanning for the subtle wrongness that checklists miss. Khormaee points to malicious PDFs rigged with passwords and CAPTCHAs as a textbook example. Those look clean to standard spam filters. His agents flag them. Battery general partner Dharmesh Thakker told TechCrunch he went hunting for a startup that could do exactly this — defend against AI with AI — after watching the attack sophistication spike inside his own portfolio companies.

AegisAI isn’t alone in the hunt. Lightspeed-backed Ocean is chasing the same incumbent displacement, eyeing the turf of Proofpoint, Mimecast, and Abnormal Security. But Thakker is betting the Gmail security pedigree gives Khormaee’s team an edge. The startup’s roadmap reaches beyond email into broader data security — a recognition that the real arms race isn’t about any single channel. It’s about who builds the smarter investigator.

💡 Key Takeaways

  1. AI-generated spear phishing emails now evade traditional rule-based defenses more than 50% of the time because they are contextually tailored using publicly scraped personal and professional data.
  2. AegisAI's detection agents do not rely on static rules but instead analyze messages holistically, catching subtle anomalies — such as password-protected PDFs with CAPTCHAs — that legacy filters miss.
  3. The $36 million Series A, led by Battery Ventures, signals strong investor confidence that former Google security engineers have the domain expertise to unseat incumbents like Proofpoint and Abnormal Security.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

Glossary terms

← Back to all articles