Series A
$36M led by Battery Ventures
, with Accel and Foundation Capital
→
Product
Email security
Inbound Email Security
Stop phishing and malware by API in 5 minutes
Phishing Prevention
Catch zero-day and payload-less attacks
BEC Prevention
Stop CEO fraud and vendor impersonation
Identity and AI risk
Shadow AI and SaaS Discovery
Find unsanctioned apps, ranked by risk
AI Red Team Agent
Consented spear-phishing against your people
Replacing a SEG?
Get your 14-day threat report
Connect by API in minutes, read-only. No MX changes, no rip and replace. Our threat analysts review 14 days of delivered mail and report what got through.
See the comparison
Case Studies
Blog
Company
Events
Cyber.Sec.Con Innovator Booth #36
RSA Booth #2356 South Hall
Careers
Request a demo
Insights at the Edge of Email Security
Deep dives, research, and analysis to help security leaders defend smarter.
Google Calendar Phishing: The Invite That Installs an RMM Agent
Malicious Google Calendar invites rose tenfold in a week. Inside a campaign that auto-creates events from stolen mailboxes and installs a signed RMM agent.
September 2, 2026
Read more
How Mirage2FA bypasses Microsoft 365 MFA with stolen session cookies
Yes, attackers bypass Microsoft MFA. The Mirage2FA AiTM kit relays the real login and takes the session cookie the moment MFA clears. Here is how it works.
August 28, 2026
Read more
Credential Phishing With No Payload: Inside the IEH Microsoft 365 Mailbox Breach
A credential phishing email with no malware opened a Microsoft 365 mailbox at IEH Corporation, a U.S. defense supplier. How the account takeover worked.
August 17, 2026
Read more
Kali365: How a Device-Code Phishing Kit Defeated MFA Without Breaking It
A $250-a-month phishing kit turned a legitimate Microsoft sign-in feature into a way to steal Microsoft 365 access without a password, a credential form, or a single attacker-owned domain, then staged its own shutdown and kept running under a new name.
July 31, 2026
Read more
TIDALGUEST: A Self-Replicating Invitation Phishing Cluster
TIDALGUEST is a self-replicating invitation phishing cluster that turns each stolen inbox into a new sender and layers five evasion techniques past URL scanning.
July 4, 2026
Read more
Introducing the AegisAI Red Team Agent: Test Your Own People Before an Attacker Does
We built an AI agent that runs spear-phishing the way attackers now run it, against your own people, scoped and approved by your security team, so you see who clicks before a real attacker finds out.
June 30, 2026
Read more
Introducing Shadow AI & SaaS Discovery: The Agents Protecting Your Email Now Map Every App It Touches
We are taking the same agents that read your email to stop phishing and pointing them at a new problem: the AI and SaaS apps your team adopted without telling anyone.
June 23, 2026
Read more
A Spam Filter for the AI Era
Your most important email shouldn't be in junk. We are taking the exact same agentic reasoning that stops advanced phishing and malware, and applying it to the rest of your mail.
June 17, 2026
Read more
AegisAI Threat Intelligence Series: How to Bypass a Secure Email Gateway Part 1
Backscatter phishing is an emerging threat where attackers exploit legitimate Non-Delivery Reports (NDRs) to bypass Secure Email Gateways (SEGs). By sending emails to non-existent addresses with a spoofed From field, attackers force legitimate mail servers to bounce a notification, containing the original malicious payload, directly to the intended victim. Since these bounce messages originate from trusted, RFC-compliant Mail Transfer Agents (MTAs) and pass SPF and DKIM checks, they are often invisible to traditional security tools.
April 22, 2026
Read more
The New World of AI Spearphishing
Attackers stopped writing malware. They started writing emails. This paper breaks down the $11.64B shift from payload-based attacks to identity exploitation — and why your existing stack can't see it coming.
April 20, 2026
Read more
AI Email Attacks Grew 5x in 2025 - AegisAI Launches Vanguard to Neutralize Adversarial AI CAPTCHAs
New research from AegisAI reveals that AI-generated email attacks grew 5X in 2025, with sophisticated threats now bypassing traditional security filters more than 50% of the time. In response to this escalating threat landscape, the company is pre-announcing Project Vanguard, the industry’s first proactive defense specifically engineered to defeat adversarial CAPTCHAs. Built by the team behind Google’s reCAPTCHA, Project Vanguard applies decades of elite bot-defense experience to neutralize the next generation of AI-driven exploits.
March 9, 2026
Read more
How LangChain Stopped Thousands of AI Phishing Attacks
Learn how LangChain uses AegisAI to stop thousands of AI-generated phishing attacks, deployed in under 5 minutes.
February 23, 2026
Read more
DMARC Rollout Without Breaking Mail: p=none → quarantine → reject
Master the DMARC Transition: A Risk-Free Path to Full Email Enforcement in Google Workspace + Microsoft 365
February 16, 2026
Read more
AI Security Threats Ranked By What's Actually Exploited
Part 2 of 6: AI Security Market Analysis Series
February 15, 2026
Read more
The $8.5 Billion AI Security Misallocation
Part 1 of 6: AI Security Market Analysis Series
February 10, 2026
Read more
Agents Protecting the Architects: LangChain Selects Aegis AI as Email Security Partner
LangChain, the leading AI agent platform, partners with Aegis AI's autonomous security agents to defend against AI-powered phishing and email threats.
January 30, 2026
Read more
Operation Social Undertow: A Phishing Campaign Spoofing the Social Security Administration
Threat actors deploy SimpleHelp RAT via sophisticated SSA phishing.
January 25, 2026
Read more
A Practical Guide to Microsoft 365 Email Security & Google Workspace Hardening Against AI-Generated Phishing
A native-controls checklist to stop BEC and AI phishing in Microsoft 365 and Google Workspace, plus the post-click hardening most orgs miss.
January 23, 2026
Read more
Semantic Defense
Fighting Fire with Fire: How Semantic Defense Catches the Invisible
January 6, 2026
Read more
The Bullseye Report: Criminal Account-Based Marketing (ABM) Attacks and the New VIP Risk
Why C-Suites Face 51% of All AI Attacks
December 14, 2025
Read more
The Anatomy of an AI Attack
Anatomy of a Hack: How AI Clones Your Company in 3 Steps
December 9, 2025
Read more
Designing Email AI Agents Analysts Actually Trust: Detect → Explain → Act
Everybody sells “AI for email security.” The difference between hype and value comes down to three words: Detect, Explain, Act.
December 4, 2025
Read more
AI Email Security: Why ROI Shows Up Here First
AI agents are finally delivering real security outcomes. The first place that shows up? Your inbox.
December 3, 2025
Read more
The AI Supply Chain You Can’t See: Mixpanel, OpenAI, and the Risk of Third-Party Model Exposure
A smishing attack at Mixpanel exposed OpenAI API user metadata and blew open a bigger question: which of your vendors are quietly sending data to OpenAI or custom models? Break down the hidden AI supply chain and what to do about it.
December 2, 2025
Read more
S-Curve of Crime: Why AI Phishing Growing 100% YoY
Phishing click rates are up 190% in 2024. New research from Aegis AI reveals why AI-powered attacks are following the "S-Curve" of SaaS adoption.
December 1, 2025
Read more
The 2025 Holiday Heist: 5 AI-Powered Scams Targeting Employees This Black Friday
From deepfake ads to 'HR bonus' phishing, AI has changed the game this holiday season. Here are the 5 threats IT Admins need to warn their teams about right now—and the corporate risks attached to each.
November 26, 2025
Read more
Trusted but Not Verified: A Case Study of Compromised Infrastructure Spearphishing Attacks
New research analyzes the "UN Summit" phishing campaign, a textbook example of "Living off the Land" attacks that evade rule and reputation based detection. With 40% of identified government impersonation attacks now originating from spoofed or compromised domains, this post explains why Artificial Intelligence analyzing emails like an analyst is the only viable defense against the next generation of AI Spearphishing.
September 14, 2025
Read more
Why Aegis
Why We Started AegisAI
September 8, 2025
Read more
Lokker + AegisAI - Customer Story
Learn how Lokker thwarts attacks seamlessly while reducing overhead for their security team.
September 3, 2025
Read more
Aegis Threat Intelligence: Sharpening the Harpoon – Direct Send Abuse Still Fueling Modern Spearphishing
The call is coming from inside the house: How threat actors act as 'internal' users to bypass your security stack.
Read more
Technical Reference: The Architecture of Google Workspace and Microsoft 365 Email Security (Beyond the Defaults)
The Engineering Behind the Defaults: SPF, DKIM, and DMARC Failure Modes Explained
Read more
What Security Leaders Should Actually Measure with AI in Email
If “AI for email security” is on your roadmap, the real question isn’t what to buy—it’s what to measure.
Read more
Accel and Foundation Capital lead our $13M Seed fundraise
The era of AI-powered threats requires AI-powered defense. That's why we're proud to announce our $13M Seed Round for AegisAI Security, led by Accel and Foundation Capital. Our mission is clear: to reimagine email security and create a future where every inbox is inherently safe.
Read more
Our Latest Posts
Why Email Security False Positives Happen and How to Fix the Root Cause
Why signal-stacking email filters block legitimate mail, how to measure precision, recall and false-positive rate, and how reasoning-based detection cuts both error types at once.
September 9, 2026
Email Security Threats in 2026: BEC, AiTM, and Zero-Day Phishing Explained
The 2026 email threat landscape: BEC, vendor email compromise, AiTM session theft, and zero-day phishing, the attacker tooling behind them, and why legacy filters miss them.
September 8, 2026
How to Evaluate Email Security Vendors: A Practical Framework for Security Leaders
A buyer's framework for evaluating email security vendors: detection testing, false-positive verification, architecture, explainability, total cost, and a POV checklist.
September 8, 2026
How to Evaluate API Based Email Security: MX Records, Mail Flow, and SIEM
A practical framework for evaluating API based email security: what to ask about MX record changes, mail flow impact, and SIEM and fraud tool integration.
September 3, 2026
Google Calendar Phishing: The Invite That Installs an RMM Agent
Malicious Google Calendar invites rose tenfold in a week. Inside a campaign that auto-creates events from stolen mailboxes and installs a signed RMM agent.
September 2, 2026
Half of AI Phishing Reaches the Inbox. Then 60% of People Click.
CrowdStrike puts AI phishing click-through past 60%. Our analysis of 20,000+ emails shows why it arrives: 50.3% clears Gmail and Microsoft filters.
September 2, 2026
How Mirage2FA bypasses Microsoft 365 MFA with stolen session cookies
Yes, attackers bypass Microsoft MFA. The Mirage2FA AiTM kit relays the real login and takes the session cookie the moment MFA clears. Here is how it works.
August 28, 2026
Credential Phishing With No Payload: Inside the IEH Microsoft 365 Mailbox Breach
A credential phishing email with no malware opened a Microsoft 365 mailbox at IEH Corporation, a U.S. defense supplier. How the account takeover worked.
August 17, 2026
Kali365: How a Device-Code Phishing Kit Defeated MFA Without Breaking It
A $250-a-month phishing kit turned a legitimate Microsoft sign-in feature into a way to steal Microsoft 365 access without a password, a credential form, or a single attacker-owned domain, then staged its own shutdown and kept running under a new name.
July 31, 2026
Load more articles
Ready to See What AI Native Security Feels Like?
Experience faster deployments, smarter detections, and fewer false positives, without the gateway headaches.
See it in action
Download our free report