People

Mandiant Founder Kevin Mandia Raised $190 Million for a New AI Security Startup — While His Old Team Tracks Attackers Abusing AI

4 min read

Kevin Mandia, the cybersecurity veteran who founded incident-response firm Mandiant in 2004 and sold it to Google for approximately $5.4 billion in 2022, has launched a new startup called Armadin, according to TechCrunch. The company has raised $189.9 million in combined seed and Series A funding, led by venture firm Accel, with participation from GV (Google’s venture arm), Kleiner Perkins, Menlo Ventures, 8VC, Ballistic Ventures, and In-Q-Tel, the CIA’s own venture capital arm — a notably deep and security-establishment-heavy investor list reflecting Mandia’s standing in both the commercial cybersecurity industry and U.S. government security circles.

Armadin is positioned as an autonomous AI agent security startup, though full technical details of its product remain limited given the company’s early stage. Mandia’s decision to build a new company focused specifically on securing AI agents — rather than traditional endpoint or network security, the categories Mandiant itself originally specialized in — reflects a broader industry recognition that AI agents capable of autonomously taking action inside corporate systems represent a genuinely new and still poorly understood attack surface, distinct from the threats traditional cybersecurity tools were built to address.

His Former Team’s Own Findings on AI-Enabled Attacks

Mandiant, now operating as a specialist incident-response and threat-intelligence unit inside Google Cloud following its 2022 acquisition, released its M-Trends 2026 report grounded in more than 500,000 hours of frontline incident investigations conducted globally in 2025. The report documents attackers actively abusing AI within already-compromised corporate environments, identifying specific malware families — including ones tracked as PROMPTFLUX and PROMPTSTEAL — that query large language models mid-execution during an active breach, using the AI responses to help evade detection systems or dynamically adapt their behavior in real time rather than relying on a static, pre-written attack script.

Mandia founded Mandiant in 2004 after an earlier career as a U.S. Air Force computer security officer, building the company into one of the most prominent names in cybersecurity incident response, particularly known for investigating and publicly attributing major nation-state cyberattacks to specific foreign government-linked hacking groups. Mandiant was acquired by rival security firm FireEye in 2013, before FireEye later divested its product business and rebranded around the Mandiant name in 2021, ahead of Google’s own acquisition the following year.

A Founder Returning to Build Rather Than Consult

Mandia’s new venture represents a notable career shift: after years spent leading Mandiant through its various corporate transitions and eventually integrating it into Google Cloud’s broader security offerings, he is now building an entirely new company from scratch focused on a threat category — autonomous AI agent security — that did not meaningfully exist as a distinct discipline when he founded Mandiant two decades earlier. The scale and composition of Armadin’s funding round, including participation from In-Q-Tel, suggests significant confidence among both traditional venture investors and government-security-adjacent funders that AI agent security will become a substantial, well-funded category in its own right over the coming years.

Investors Betting Heavily on a Founder’s Track Record

The composition of Armadin’s funding round is itself notable within the cybersecurity venture landscape: In-Q-Tel’s participation, in particular, signals that U.S. intelligence-community-adjacent investors view autonomous AI agent security as a strategically significant category worth backing early, a level of government-linked investor interest that relatively few early-stage cybersecurity startups attract at the seed and Series A stage. Mandia’s own reputation, built over two decades of high-profile incident response work investigating breaches attributed to state-sponsored hacking groups from Russia, China, and elsewhere, gives Armadin a credibility advantage with enterprise security buyers that a first-time founder in the same space would likely lack.

Mandiant’s M-Trends 2026 findings on AI-enabled attacker behavior arrive at a moment when enterprise adoption of AI agents inside production business systems is accelerating rapidly across nearly every major industry, a timing dynamic that has made securing those same agents an urgent, immediate commercial priority rather than a longer-term research question — precisely the gap Mandia’s new company is positioned to address.

What This Means for Philippine Founders

Mandiant’s M-Trends findings on attackers using AI models mid-breach to evade detection are directly relevant to Philippine banks, BPOs, and government agencies currently deploying their own AI tools and agents into production systems, since the same automation and adaptability that makes AI agents useful for legitimate business tasks can be turned against defenders by sophisticated attackers using nearly identical techniques. Filipino cybersecurity founders and IT security teams should treat Mandia’s decision to build an entirely new company around AI agent security, rather than simply adding an AI security feature to Mandiant’s existing product line, as a signal that this threat category is being treated by veteran security practitioners as different enough in kind — not just in degree — to warrant a fresh architectural approach, a distinction worth weighing carefully for any local team currently treating AI agent security as a minor extension of existing endpoint or network protection tools.

AI Security cybersecurity Google Cloud Kevin Mandia Mandiant

Share this article

Share on X Share on LinkedIn Share on Facebook

Related Articles

Newsletter

By subscribing, you agree to our Privacy Policy.