AI Spear Phishing Is Getting Better: A Practical Defense Guide for Small Businesses
AegisAI’s $36M Series A highlights how AI-written spear phishing is beating legacy email filters. Use this SMB guide for verification habits, training, and layered defenses.

On July 23, 2026, TechCrunch reported that AegisAI raised a $36 million Series A led by Battery Ventures, bringing total capital to $49 million. The startup—founded by former Google Safe Browsing and reCAPTCHA executives Cy Khormaee and Ryan Luo—aims to stop AI-driven spear phishing. Named customers include Mesh, LangChain, and Lokker. Competitors in coverage include Ocean and Abnormal, plus incumbents Proofpoint and Mimecast.
This article is not a product pitch. The funding news is a signal: AI-written phishing is already strong enough to beat many controls small businesses still rely on. The useful response is a practical defense plan—habits, process, and layered tools.
What happened
Spear phishing is targeted email fraud. Instead of a generic spam blast, attackers impersonate someone your team trusts: an owner requesting gift cards, a vendor changing bank details, or a “lawyer” asking for a quiet wire.
AI changes the economics. In TechCrunch’s interview, Khormaee said AI-powered attacks now bypass existing controls more than half the time—nearly twice as effective as before. Attackers can aggregate coworkers’ names, project clues, and travel details, then generate authentic-sounding messages in seconds.
AegisAI argues that rule-based “if-then” filters struggle against this style of attack, and that defenders need systems that inspect messages more like a careful human—including tricky attachments that use passwords or CAPTCHA-like friction to dodge scanners. Whether or not you evaluate that product category, the threat claim matches what many SMBs already see: cleaner English, better timing, and fewer obvious typos.
Why it matters for small businesses
Large companies often have security teams and managed email gateways. Many SMBs have Microsoft 365 or Google Workspace, default spam filtering, a bookkeeper who also handles wires, and an owner who approves payments from a phone. That combination is attractive: one successful finance email can move more money than months of noisy commodity attacks.
Three reasons this matters now:
- Trust cues are weaker. Typos used to be a tell. Fluent AI writing removes that crutch.
- Context is cheap. Public sites, social posts, and breached data help attackers sound internal.
- Controls lag behavior. If your only defense is “the filter will catch it,” a claimed >50% bypass rate is an operational warning.
Battery Ventures’ Dharmesh Thakker told TechCrunch that attackers are using AI over email faster than many companies can respond. A crowded competitive field—Ocean, Abnormal, Proofpoint, Mimecast, and others—reinforces that this is an industry-wide shift, not one startup’s marketing story.
How businesses can benefit: a defense-first playbook
Redesign money movement, not just inbox filters. Write a rule: no bank-detail changes from email alone; no urgent wires, gift cards, or crypto from chat/email alone; any payment-instruction change requires a second channel (known phone number, video call, or in person). Put it in onboarding docs.
Train for verification, not “spot the typo.” Update examples to include perfect tone that creates secrecy (“don’t loop in finance yet”), familiar project names used incorrectly, vendor invoices with new payment details, passworded PDFs, and lookalike domains. Run a 20-minute refresher quarterly—including the owner.
Harden identity basics first. Enforce phishing-resistant MFA where available; alert on new mail-forwarding rules; restrict inbox rules and OAuth apps; use a password manager; keep a call-back list for vendors with numbers collected out-of-band.
Add process friction on purpose. Dual approval above a dollar threshold; a delay for first-time payees; a shared checklist before releasing funds. Attackers hate durable process. Employees accept it when leadership models it.
Evaluate email-security tools with clear questions. If you outgrow native filtering, compare AI-native options and incumbents against your risks: executive impersonation detection, payment-change quarantine, false-positive load for a small finance pod, admin time, and SMB-friendly pricing. Choose on fit—not press-release energy.
Practical examples
Fake “owner” gift-card request. Attacker emails the office manager using the founder’s real travel city. Defense: “Per policy I need voice confirmation on the office line.” Attacker disappears.
Vendor bank-detail switch. Clean PDF, one-character-off domain. Defense: accounting calls the number from the last signed contract—not the email signature. Real supplier confirms nothing changed.
Credential theft via “candidate portal.” Lookalike login after a busy interview week. Defense: password manager does not autofill the fake URL; manager reports it instead of typing credentials.
Password-protected “invoice.” Password in the email body to dodge scanners, dressed up with AI cover text. Defense: open unexpected attachments only after phone verification; prefer known vendor portals.
Nonprofit board “emergency” transfer. Urgent matching request to a public board list. Defense: dual control on the bank account and two officers on a call before any same-day transfer.
A one-week SMB action plan
- Day 1: Write a one-page payment verification policy.
- Day 2: Review MFA and unexpected forwarding rules in Workspace or Microsoft 365.
- Day 3: Build a vendor call-back directory for your top 20 payees.
- Day 4: Brief staff with two AI-phishing examples from your industry.
- Day 5: Set dual approval thresholds in bank and accounting tools.
- Days 6–7: If volume is high, shortlist email-security upgrades—after process controls exist.
Tools help most when people already know they are allowed to slow down and verify.
Conclusion
AegisAI’s $36 million Series A is best read as confirmation that AI-assisted spear phishing is a mainstream business risk. Attackers can personalize at scale; typo-hunting and legacy filters are not enough. Small businesses benefit most from boring excellence: verify payment changes out of band, enforce MFA, require dual approval above clear thresholds, train people to challenge urgent secrecy, and only then evaluate advanced email-security tools. The goal is not perfect detection. The goal is making fraud expensive and slow while your team keeps working with confidence.
Sources
Key takeaway
AegisAI’s $36M Series A highlights how AI-written spear phishing is beating legacy email filters. Use this SMB guide for verification habits, training, and layered defenses. For more step-by-step guides, browse our blog or explore Productivity.
Frequently asked questions
Do we need a specialized startup like AegisAI to be safe?
Not necessarily. Start with verification policies, MFA, dual approvals, and strong workspace settings. Specialized AI email defenses can help as a layer, but they do not replace payment process controls.
How is this different from ordinary spam?
Spam is high volume and generic. Spear phishing is targeted and contextual. AI reduces the cost of that targeting.
What should employees do when something feels urgent and secret?
Treat urgency plus secrecy as a warning. Verify on a known channel. No one should be punished for confirming a payment request.
Which vendors are commonly mentioned in this space?
TechCrunch’s coverage names AegisAI customers such as Mesh, LangChain, and Lokker, and notes competition from Ocean, Abnormal, Proofpoint, and Mimecast. Use that as a research map—not an endorsement ranking.
Written by
AI Growthub StaffEditorial Team
The AI Growthub editorial team covers practical AI news, tools, and workflows for small business owners. Every article is fact-checked against primary sources before publication.
Comments are coming soon
We’re building a discussion space for business owners. Until then, reply to any newsletter issue — we read everything.
Related posts

How to Design AI Agent Personality for Customer Messaging
A practical guide to building a brand-safe AI agent personality for SMS, email, WhatsApp, and Apple Messages for Business—tone, humor, escalation, compliance, and CSAT measurement.

ChatGPT vs Claude vs Gemini for Daily Productivity
A practical comparison of ChatGPT, Claude, and Gemini for founders—morning planning, email, meeting cleanup, and docs—so you pick one daily driver.

How to Use Claude Opus 5 for Everyday Small-Business Workflows
A practical beginner guide to setting up Claude Opus 5, choosing the right model for each job, and running five real small-business workflows without wasting money.
The AI edge, delivered every Tuesday
One 5-minute email: the tools worth your money, the plays that are working right now, and zero hype. Unsubscribe anytime.
No spam. No selling your data. Read by owners of restaurants, gyms, clinics, and agencies across the US, UK, Canada, and Australia.