메뉴
BL
TechCrunch AI 5일 전

전 구글 보안 임원들, AI 스피어 피싱 방어 위해 490억 원 유치

IMP
8/10
핵심 요약

해커들의 AI 기반 정교한 스피어 피싱 공격이 급증함에 따라, 기존 규칙 기반 보안 시스템의 한계가 명확해지고 있습니다. 이에 구글 보안 출신 임원들이 설립한 AegisAI가 AI 에이전트를 활용해 기존 시스템이 탐지하지 못하는 악성 이메일을 실시간으로 분석·차단하는 기술로 3천6백만 달러(약 490억 원)의 시리즈 A 투자를 유치했습니다. 이는 보안 업계에서 기존 레거시 시스템을 대체할 'AI 기반 에이전트 보안'의 중요성이 커지고 있음을 시사합니다.

번역된 본문

해커들이 대규모 공격을 감행하는 데 있어 AI의 사용이 점점 증가하고 있으며, 이메일이 주요 표적으로 떠오르고 있습니다. AI는 동료에 대한 정보, 진행 중인 프로젝트, 최근 여행 일정 등 개인정보를 빠르게 수집하여 악의적인 행위자가 진짜처럼 보이는 설득력 있는 메시지를 즉각적으로 조작할 수 있게 해줍니다. 지난해 세이프 브라우징(Safe Browsing) 기술과 reCAPTCHA 개발을 담당했던 전 구글 보안 임원 사이 코마키(Cy Khormaee)와 라이언 뤼오(Ryan Luo)가 힘을 합쳐 '스피어 피싱(Spear Phishing)'이라 불리는 이러한 위협을 박멸하기 위해 AI 에이전트를 활용하는 스타트업, 에지스AI(AegisAI)를 설립했습니다.

에지스AI의 공동 창업자들은 10년간 이메일 해킹 방지 경험을 통해 'if-then' 논리에 의존하는 기존 규칙 기반 해킹 방지 시스템이 너무 느리고, AI가 만들어낸 악성 이메일을 잡아내는 데 한계가 있다는 것을 깨달았습니다. 이에 그들은 인간처럼 각 메시지를 빠르게 분석하고, 가장 정교한 체크리스트조차 놓칠 수 있는 미세한 이상 징후에 주의를 기울이는 AI 에이전트를 개발했습니다. 에지스AI는 출범한 지 1년도 채 되지 않아 암호화폐 결제 회사 매시(Mash), AI 스타트업 랭체인(LangChain), 구글 소유의 프라이버시 컴플라이언스 플랫폼 로커(Lokker)를 포함한 수십 개 고객사가 자신들의 기술을 도입했다고 밝혔습니다.

이러한 수요 덕분에 에지스AI는 배터리 벤처스(Battery Ventures)가 주도하고 기존 투자자인 액셀(Accel)과 파운데이션 캐피탈(Foundation Capital)이 참여한 3,600만 달러의 시리즈 A 투자를 유치하는 성과를 거두었습니다. 이번 펀딩을 통해 이 스타트업의 총 자본금은 4,900만 달러에 달하게 되었습니다.

코마키는 테크크런치(TechCrunch)와의 인터뷰에서 "AI 기반 공격은 현재 기존 보안 통제를 절반 이상의 확률로 우회하고 있으며, 이는 과거보다 거의 두 배나 효과적이라는 것을 의미한다"고 말했습니다. 그는 "해커들은 당신에 대해 철저히 조사하고 당신에 대한 모든 것을 이해하며, 당신만을 위해 완벽하게 맞춤화된 공격을 감행한다"고 덧붙였습니다. 코마키는 에지스AI의 에이전트가 기존 이메일 보안 시스템이 완전히 놓칠 수 있는 위협을 발견할 수 있다고 주장했습니다. 예를 들어, 에지스AI의 AI는 표준 스팸 필터를 속이기 위해 자주 사용되는 내장 비밀번호나 캡차(CAPTCHA)가 포함된 것을 비롯해 처음에는 합법적으로 보이는 악성 PDF 첨부 파일을 잡아낼 수 있습니다.

배터리 벤처스의 제너럴 파트너인 다르메쉬 타커(Dharmesh Thakker)는 이메일 공격의 증가를 감지하고, AI를 방어하기 위해 AI를 사용하는 스타트업, 즉 기존 이메일 보안 도구를 에이전트 기반 방어로 대체하는 것을 목표로 하는 스타트업에 투자할 계획이었습니다. 타커는 테크크런치에 "사이버 범죄자들이 우리가 따라잡을 수 있는 속도보다 훨씬 빠른 속도로 AI를 사용해 이메일로 공격해 오고 있다"며, "이를 방어하는 것이 많은 기업들에게 최우선 과제가 될 것"이라고 말했습니다.

에지스AI가 사기 및 신원 도용 시도를 탐지하기 위해 들어오는 모든 이메일의 맥락을 분석하기 위해 AI를 활용하는 유일한 스타트업은 아닙니다. 라이트스피드(Lightspeed)의 지원을 받는 오션(Ocean) 역시 앱노멀 시큐리티(Abnormal Security)와 같은 신규 플레이어들과 함께 프루프포인트(Proofpoint) 및 마임캐스트(Mimecast)와 같은 기존 업체들을 시장에서 밀어내려 하고 있습니다. 하지만 에지스AI가 세계에서 가장 인기 있는 이메일 시스템인 지메일(Gmail)을 안전하게 지키는 데 도움을 준 전문가들이 이끌고 있다는 점을 고려할 때, 타커는 이 스타트업이 차세대 해킹 방지 회사로 자리 잡을 가장 유력한 주자라고 확신합니다.

에지스AI는 이메일 보안으로 시작하고 있지만, 궁극적으로는 데이터 보안 등 다른 방어 영역으로 확장하는 것을 목표로 하고 있습니다. 코마키는 "조사를 수행할 수 있는 맞춤형 고급 에이전트를 구축한다는 핵심 아이디어가 차세대 지배적인 보안 회사가 누가 될 것인지를 결정할 것"이라고 밝혔습니다.

원문 보기
원문 보기 (영어)
Hackers are increasingly using AI to launch attacks on a massive scale, with email emerging as a primary target. AI can quickly aggregate personal information—such as information about coworkers, active projects, and recent travel itineraries—allowing bad actors to instantly craft convincing messages that look authentic. Last year, former Google security executives Cy Khormaee and Ryan Luo, who previously worked on developing safe browsing technology and reCAPTCHA, teamed up to launch AegisAI, a startup that uses AI agents to stomp out these threats, known as spear phishing. With a decade of experience preventing email hacks, the AegisAI co-founders realized that existing rule-based systems for preventing hacks—relying on "if-then" logic—are too slow and limited to catching AI-crafted malicious emails. So they developed AI agents that quickly analyze each message as a human would, paying attention to small anomalies that even the most elaborate checklist wouldn’t catch. Less than a year after its launch, AegisAI says its tech has been adopted by dozens of customers, including crypto payments company Mash, AI startup LangChain, and Google-owned privacy compliance platform Lokker. That demand has just helped AegisAI raise a $36 million Series A led by Battery Ventures, with participation from existing backers Accel and Foundation Capital. The fresh funding brings the startup’s total capital to $49 million . “AI-powered attacks bypass existing controls more than half the time now, which means they're almost twice as effective as they used to be,” Khormaee told TechCrunch. “They’ve researched you, they understand everything about you, and they're targeting attacks that are perfectly bespoke to you.” Khormaee claims that AegisAI's agents can spot threats traditional email security systems may miss entirely. For instance, the startup’s AI can catch malicious PDF attachments that look legitimate at first, including ones with built-in passwords and CAPTCHAs, which are often used to fool standard spam filters. When Dharmesh Thakker, general partner at Battery Ventures, noticed an increase in email attacks, he set out to invest in a startup that could defend against AI with AI, one aiming to replace legacy email security tools with agentic-driven defense. “The bad guys are using email to attack us using AI at a much faster pace than we can keep up with,” Thakker told TechCrunch. “Defending against that is going to be a number one priority for a lot of companies.” AegisAI isn’t the only startup using AI to analyze the context of every incoming email to detect fraud and impersonation attempts. Lightspeed-backed Ocean is also trying to displace established vendors like Proofpoint and Mimecast, along with newer players like Abnormal Security. However, given that AegisAI is led by experts who helped secure Gmail, the most popular email system in the world, Thakker believes the startup has the best shot at becoming the leading new hack-prevention company. While AegisAI is starting with email, the startup has its sights on eventually expanding to other areas of defense, such as data security. “The core idea of building customized, highly advanced agents that can do investigations is going to [determine] who becomes the next dominant security company,” Khormaee said. Topics AI , battery ventures , phishing , Security , Startups When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Marina Temkin Reporter, Venture Marina Temkin is a venture capital and startups reporter at TechCrunch. Prior to joining TechCrunch, she wrote about VC for PitchBook and Venture Capital Journal. Earlier in her career, Marina was a financial analyst and earned a CFA charterholder designation. You can contact or verify outreach from Marina by emailing marina.temkin@techcrunch.com or via encrypted message at +1 347-683-3909 on Signal. View Bio October 13 - 15 San Francisco Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you. Save up to $330 toda y! REGISTER NOW Most Popular OpenAI says Hugging Face was breached by its pre-release models Russell Brandom Jack Dorsey is taking on Slack with Buzz, a group chat platform for teams and their AI agents Amanda Silberling Light made a flip phone — it's colorful and it's cheap Amanda Silberling AI music generator Suno breach affects 55M users, per Have I Been Pwned Zack Whittaker Anthropic's landmark $1.5B copyright settlement is approved Kirsten Korosec Google is working on a new AI chip designed to make Gemini more efficient Lucas Ropek Judge pauses $110B Paramount-Warner Bros. merger Aisha Malik