# Ocean's $28M Bet on AI Agents to Combat Sophisticated Email Attacks


Email remains the most exploited attack vector in enterprise security, but the threat landscape has evolved dramatically. Attackers now use generative AI to craft messages that bypass traditional filters, impersonate trusted colleagues with accuracy that's hard to distinguish from reality, and weave legitimate business context into social engineering attempts. Against this backdrop, Ocean—a New York and Tel Aviv-based startup—has emerged from stealth with $28 million in funding to deploy a new class of defense: AI agents that inspect every incoming email, verify sender intent, and detect threats hidden within seemingly legitimate messages.


The funding round, led by Lightspeed Venture Partners and including Picture Capital, Cerca Partners, and prominent angel investors, validates a thesis that surface-level email filtering is no longer sufficient. Instead, what organizations need is intelligent analysis at scale—the kind of deep contextual evaluation that once required human security analysts but can now be augmented by specialized AI agents.


## The Threat Landscape: When Email Filtering Fails


Email-based attacks have evolved significantly over the past five years. The days when malware-laden attachments and obvious phishing links dominated the threat landscape are largely gone. Today's most effective attacks are business email compromise (BEC), vendor email compromise (VEC), and AI-generated phishing—all of which exploit the fundamental weakness of email security: the assumption that if a message appears to come from a trusted source and contains plausible business context, it's safe.


Consider the modern BEC attack:

  • An attacker researches a company's organizational structure and ongoing projects
  • Using AI tools, they craft an email from a spoofed executive address with near-perfect grammar and tone
  • The message references a real project and requests a wire transfer with appropriate urgency
  • Traditional spam filters see no malware, no suspicious links, no obvious red flags—and the message lands in the inbox

  • By the time a human security analyst reviews it, the damage may already be done.


    ## Background: The Rise of Agentic Security


    The cybersecurity industry has been trending toward "agentic" solutions—systems that use AI to autonomously perform tasks that previously required human intervention. Companies like Exaforce (which recently raised $125 million for an agentic SOC platform) and others are applying this pattern to security operations centers, threat detection, and incident response.


    Ocean applies this concept specifically to email security, a logical evolution given:


    1. Email volume at scale: Enterprise organizations receive millions of emails daily, making human triage impossible

    2. Sophisticated threats require contextual analysis: Detecting intent requires understanding sender history, project context, financial patterns, and organizational relationships

    3. Human review is the bottleneck: Security teams spend disproportionate time analyzing emails that ultimately turn out to be legitimate


    Founded in 2024 by Shay Shwartz (CEO) and Oran Moyal, Ocean has built a platform purpose-designed for this problem. The timing is significant—2024 saw a sharp increase in AI-generated phishing and BEC attacks that bypassed traditional security controls, creating urgent demand for solutions that don't rely on pattern matching alone.


    ## Technical Approach: Beyond Pattern Matching


    Ocean's platform operates fundamentally differently from legacy email security tools. Rather than relying on IP reputation, sender authentication protocols (SPF/DKIM/DMARC), or content scanning, Ocean deploys specialized AI agents that investigate each message across multiple dimensions:


    | Analysis Category | What Ocean Examines |

    |---|---|

    | Sender Verification | Identity and infrastructure analysis—is this actually from the claimed sender? |

    | Intent Assessment | Conversational context and historical communication patterns with the sender |

    | Contextual Validation | Project references, organizational knowledge, financial request legitimacy |

    | Technical Evidence | Links, attachments, embedded files, and malware analysis |

    | Behavioral Patterns | Deviations from normal communication—unusual tone, urgency, or requests |

    | Abuse Signal Review | Cross-reference against reported phishing, breach databases, and threat intelligence |


    According to Shwartz, this approach addresses a fundamental gap in existing email security: "The challenge is no longer just detecting malicious emails. It's identifying harmful intent hidden inside messages that appear completely legitimate. Attackers now use AI to write flawlessly, reference real projects, and impersonate trusted colleagues, making it nearly impossible to spot the difference."


    The platform also automates downstream security operations. Rather than simply blocking or quarantining suspicious emails, Ocean provides:


  • Automated triage of user-reported emails with risk scoring and recommended actions
  • Quarantine management with contextual analysis to support quarantine release decisions
  • Real-time employee guidance when suspicious messages are detected—helping end users understand *why* a message is suspicious rather than just marking it as spam
  • Incident response automation that reduces the time from detection to containment

  • ## Market Opportunity and Strategic Positioning


    The $28 million funding speaks to investor confidence in both the market opportunity and Ocean's execution. Email security remains a fundamental need for every organization with corporate email, making it a large serviceable addressable market. However, the specific focus on sophisticated attacks—BEC, vendor compromise, and AI-generated threats—positions Ocean in a growing segment of the market where existing solutions have demonstrable gaps.


    Competitive dynamics matter here. Traditional email gateway providers like Proofpoint, Mimecast, and Cisco have dominated enterprise email security through reputation-based filtering and sandboxing. However, these approaches are increasingly blind to context-aware attacks that *look* legitimate. Ocean's approach of deploying AI agents to verify intent rather than filter based on surface indicators represents a genuine architectural shift.


    ## Implications for Enterprise Security


    For organizations evaluating email security solutions, Ocean's emergence signals several important trends:


    1. Email security is moving toward AI-augmented analysis. Expect other vendors to adopt similar agentic approaches, making AI-powered email investigation table stakes rather than differentiation.


    2. User reporting and incident response automation matter. The ability to rapidly triage and respond to user-reported emails reduces mean time to response and prevents social engineering attacks from succeeding.


    3. Context matters more than signatures. Organizations should expect their email security to understand their business context—who talks to whom, what projects are active, what financial processes matter—rather than relying purely on technical indicators.


    4. Vendor consolidation may increase. As email security becomes more sophisticated and AI-powered, smaller point solutions may be acquired by larger security platforms or consolidate with SOC and detection tools (like Exaforce's agentic approach).


    ---


    ## HackWire Analysis


    Ocean's emergence reflects a critical inflection point in how enterprises defend against email-based attacks. The traditional email security model—reputation lists, attachment sandboxing, and authentication protocols—was built for a threat landscape where attackers needed to use obvious malware or trick users with obvious phishing. That landscape no longer exists.


    What Ocean has recognized, and what we're seeing across the "agentic security" space more broadly, is that the next generation of defensive AI isn't about automating *detection*—it's about automating *analysis*. A system can detect that an email exists; what's valuable is a system that understands whether that email represents a genuine threat despite appearing legitimate. That requires context, historical knowledge, and reasoning—exactly what specialized AI agents can provide at scale.


    The $28M funding and investor roster (Lightspeed is a serious venture firm with a track record in security) suggests this isn't a niche play. What's particularly significant is the timing: BEC and AI-generated phishing have become *normalized* enough that enterprises recognize these aren't edge cases anymore—they're routine attacks that current security tools miss. Ocean is betting that the solution is deeper analysis, not better filters. We think that bet is sound, and we expect competitive pressure from incumbent email security vendors to increase accordingly.


    The practical implication for security teams is that email security is no longer primarily a *perimeter* problem. It's a *detection and response* problem that requires understanding context, intent, and deviation from baseline behavior. Organizations should evaluate their current email security not on whether it blocks known malware, but on whether it catches sophisticated social engineering attempts that *look* legitimate to pattern-matching systems. By that measure, many existing deployments fall short—which explains both the funding and the urgency.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)