[go: up one dir, main page]

AI

Bolster, creator of the CheckPhish phishing tracker, raises $14M led by Microsoft’s M12

Comment

Deepfake or Deep Fake Concept as a symbol for misrepresenting or identity theft or faking identification and misrepresentation in a 3D illustration style.
Image Credits: wildpixel (opens in a new window) / Getty Images

A dodgy email containing a link that looks “legit” but is actually malicious remains one of the most dangerous, yet successful, tricks in a cybercriminal’s handbook. Now, an AI startup called Bolster that has built a novel approach to tackle that trick has raised $14 million in funding to expand its work, both across a popular free phish-checking portal it operates called (appropriately) CheckPhish, as well as with its primary paying customers: brands and other businesses.

Microsoft’s venture fund M12 led the round as a new backer in the company, with participation also from Thomvest Ventures, Crosslink Capital, Liberty Global Ventures, Cheyenne Ventures, Cervin Ventures and Transform Capital. Bolster’s not disclosing its valuation but it has now raised around $40 million. 

Bolster’s business model is based around providing brand and URL checking services to businesses that spend a lot of time emailing their customers, and thus are prime candidates for malicious hackers to imitate in hopes of tricking people, or to simply copy with branding to sell products of their own. (Its client list includes big names like Dropbox, Uber, LinkedIn and Coinbase.) Phishing, according to the Cybersecurity Infrastructure Security Agency, is the start of more than 90% of all “cyberattacks,” which might include data breaches, network infiltrations or device viruses.

The ability to set up suspiciously similar-looking domain pages for these companies, and to start using them to run malicious phishing activities, has become very cheap and easy to do. 

“There are tools that you can purchase for $10 or $20 to launch phishing attacks,” said Bolster CTO Shashi Prakash (who co-founded the company with CEO Abhishek Dubey) in an interview. With malicious hackers now well versed in using AI, they create realistic login pages for banks, for example, and use phishing-as-a-service to launch these attacks “within minutes.” 

These have become more sophisticated, and more targeted, over time, he said. One recent example was the incident involving the CEO of WPP, Mark Read, who was at the center of a scam to try to solicit money. It sounds improbable when you read that out, and indeed it was unsuccessful, but it is just a sign of where these scams are going.

Bolster’s approach uses machine learning algorithms and AI techniques to track the wider internet — URLs, domain registration databases, conversations in open and closed forums and social media platforms, as well as emails (when it works with a client) and more — to detect scam operations, which it does on a continuous basis. When it identifies iffy links, it then shuts them down at their root by way of automated takedowns.

The approach is notable because it complements the myriad email security products that are on the market today that are adopted by organizations to help filter emails as they come into a person’s inbox: That’s still important as one mechanism to halt phishing activity. But in cases where those bad links pass through the gates unencumbered, the idea here is that, if a person does click on a link, now that person might not get anywhere. 

Considering that the wider funnel of email can be so complicated to contain, and hackers themselves makes themselves hard to find, identifying and shutting down the root of their operations becomes very valuable. 

“One of the advantages that Bolster has is its ability to automatically shut down where these attacks are originating from, they can shut down where those are hosted,” said Todd Graham, managing partner at M12, in an interview. “That is really, really important, given the scale at which these criminal enterprises operate.” Microsoft does not yet work directly with Bolster, Prakash said, but the idea is that this investment is a signal of how they will in the future.

Microsoft’s interest would be on a couple of levels: The company is a major international brand in itself, operating a number of services that would trigger emails to users (and I can personally attest to getting way, way too many “account login” emails from suspicious “Microsoft” links). On top of that, it’s a provider of cloud and managed and software services to numerous businesses, and thus an important link through to a large market of would-be customers. Lastly, it’s making a major move into putting more AI into all aspects of its business, and so threat protection inevitably has to be a part of that equation, too.

Graham added that while the company is effectively just a B2B business — with even the CheckPhish tool aimed at scanning websites rather than offering tools to individual users — the fact that it works with big brands by default gives it a consumer angle, in that it’s ultimately aiming at protecting the customers of the business in question. 

“If you are getting an impersonated email that claims to be from Microsoft, but it probably isn’t, it’s in the best interest of Microsoft or Wells Fargo or whoever, to ensure that that email, if it does go out, gets detected.”

More TechCrunch

Featured Article

How Abridge became one of the most talked about healthcare AI startups

Ask any of the health-focused VCs to name one of the top AI startups and one name comes up over and over again: a company  based in Pittsburgh called Abridge. And it’s a startup that launched before OpenAI was a household name and LLMs entered the common Valley vocabulary.  In…

2 hours ago
How Abridge became one of the most talked about healthcare AI startups

Cheap irrigation has transformed many regions around the world into breadbaskets, but it also means that there can be little left for other uses.

Kilimo helps farmers save water and get paid for it

Two years ago, an employee at Fisker Inc. told me that the most pressing concern inside the EV startup was not whether its Ocean SUV would get built. Fisker was…

Fisker failed because it wasn’t ready to be a car company

The agency was investigating the company over potential violations of the Children’s Online Privacy Act.

FTC refers TikTok child privacy case to Justice Department

Apple’s changes may affect apps that today have an estimated $393 million in revenue and have been downloaded roughly 58 million times over the past year.

iOS 18 could ‘sherlock’ $400M in app revenue

At the Augmented World Expo on Tuesday, Snap teased an early version of its real-time, on-device image diffusion model that can generate vivid AR experiences. The company also unveiled generative…

Snap previews its real-time image model that can generate AR experiences

A researcher has found a bug that allows anyone to impersonate Microsoft corporate email accounts, making phishing attempts look credible and more likely to trick their targets.  As of this…

Security bug allows anyone to spoof Microsoft employee emails

Welcome to TechCrunch Fintech! This week, we’re looking at layoffs at BaaS startup Unit and car insurance company Loop, as well as Brex’s decision to abandon its co-CEO model, Apple…

Unit and Loop lay off staff and Brex ditches co-CEO model

We all know the feeling when we send a funny TikTok video, anticipating a response from a friend, only to receive a basic laughing emoji or, worse, no reaction at…

Meet Seen, a new app for friends to record reactions to TikToks and other content

Butterflies wants to let users create AI personas that then take on their own lives and coexist with others. 

Former Snap engineer launches Butterflies, a social network where AIs and humans coexist

Genspark taps generative AI to write custom summaries in response to search queries.

Genspark is the latest attempt at an AI-powered search engine

Apple is continuing its AI push, this time with its education offering. The company announced on Tuesday that it will train all Apple Developer Academy students and mentors on the…

Apple Developer Academy adds AI training for students and alumni

TechCrunch has learned that the arrested hacker is the alleged leader of the group that masterminded the Twilio hacks in 2022.

UK national accused of hacking dozens of US companies arrested in Spain

Decagon is a generative AI platform that automates various aspects of customer support channels.

Decagon claims its customer service bots are smarter than average

Pok Pok’s growth caught investors’ attention, leading to a $6 million Series A.

Now a Series A startup, kids’ app and ‘digital toy’ Pok Pok is coming to Android

Series A to B startups — check out the ScaleUp Startups Exhibitor Program at TechCrunch Disrupt 2024! Why Join the ScaleUp Startups Exhibitor Program? Amplify Your ReachShowcase your groundbreaking innovation…

Series A to B startups scale up at Disrupt 2024

SurrealDB, a startup developing a database architecture of the same name, has closed a new round of funding as it readies a managed service.

SurrealDB is helping developers consolidate their databases

The $200 Beam pro looks like an Android phone, but instead it’s a mobile device designed specifically for Xreal’s glasses.

XReal introduces a $200 device that brings Android apps to its AR glasses

Being a solo GP hasn’t slowed Bilimoria a bit. He went on to raise three additional funds and has now closed a new fund to invest in biotech, climate and…

Zal Bilimoria just raised a $50M fourth Refactor Capital fund, and still relishes his solo GP status

Golf has exploded in popularity in recent years thanks to the pandemic and the popularity of Netflix’s Full Swing documentary series. More than 531 million rounds of golf were played…

Loop Golf looks to take the stress out of booking a tee time

Self-driving vehicles rely on many sensors to detect objects and the world around them. The conventional approach is to work with cameras and lidars. But some tech companies and startups…

Bitsensing raises $25M for its high-resolution radar in autonomous driving

Balto Energy hopes to speed the electrification by helping homeowners choose and finance the projects that make the most sense for them.

Dandelion co-founder is back to help you electrify your home for less

SewerAI sells cloud-based, AI-powered subscription products designed to streamline field inspections and data management of sewer infrastructure.

SewerAI uses AI to spot defects in sewer pipes

For the last two decades, Raquel Urtasun, founder and CEO of autonomous trucking startup Waabi, has been developing AI systems that can reason as a human would.  The AI pioneer…

Waabi’s GenAI promises to do so much more than power self-driving trucks

Fisker Group Inc., the EV startup founded by famed designer Henrik Fisker, filed for Chapter 11 bankruptcy protection — a capstone to months of problems with its Ocean SUV that included…

EV startup Fisker files for bankruptcy

Meta said today that it finally launched its much-awaited API for Threads so developers can build experiences around it.

Threads finally launches its API for developers

The company says its platform functions like a search engine for materials, enabling the fast evaluation of a “vast number of novel structures.”

CuspAI raises $30M to create a GenAI-driven search engine for new materials

Suse on Tuesday is announcing its AI strategy and SUSE AI solutions, a new vendor- and LLM-agnostic generative AI platform.

SUSE wants a piece of the AI cake, too

Google has released its dedicated AI mobile app Gemini in India — over four months after its debut in the U.S. — with support for nine Indian languages alongside English. The…

Google brings Gemini mobile app to India with support for 9 Indian languages

Finbourne, founded out of London’s financial center, has built a platform to help financial companies organize and use more of their data in AI and other models.

Finbourne taps $70M for tech that turns financial data dust into AI gold