AI

Bolster, creator of the CheckPhish phishing tracker, raises $14M led by Microsoft’s M12

Comment

Deepfake or Deep Fake Concept as a symbol for misrepresenting or identity theft or faking identification and misrepresentation in a 3D illustration style.
Image Credits: wildpixel (opens in a new window) / Getty Images

A dodgy email containing a link that looks “legit” but is actually malicious remains one of the most dangerous, yet successful, tricks in a cybercriminal’s handbook. Now, an AI startup called Bolster that has built a novel approach to tackle that trick has raised $14 million in funding to expand its work, both across a popular free phish-checking portal it operates called (appropriately) CheckPhish, as well as with its primary paying customers: brands and other businesses.

Microsoft’s venture fund M12 led the round as a new backer in the company, with participation also from Thomvest Ventures, Crosslink Capital, Liberty Global Ventures, Cheyenne Ventures, Cervin Ventures and Transform Capital. Bolster’s not disclosing its valuation but it has now raised around $40 million. 

Bolster’s business model is based around providing brand and URL checking services to businesses that spend a lot of time emailing their customers, and thus are prime candidates for malicious hackers to imitate in hopes of tricking people, or to simply copy with branding to sell products of their own. (Its client list includes big names like Dropbox, Uber, LinkedIn and Coinbase.) Phishing, according to the Cybersecurity Infrastructure Security Agency, is the start of more than 90% of all “cyberattacks,” which might include data breaches, network infiltrations or device viruses.

The ability to set up suspiciously similar-looking domain pages for these companies, and to start using them to run malicious phishing activities, has become very cheap and easy to do. 

“There are tools that you can purchase for $10 or $20 to launch phishing attacks,” said Bolster CTO Shashi Prakash (who co-founded the company with CEO Abhishek Dubey) in an interview. With malicious hackers now well versed in using AI, they create realistic login pages for banks, for example, and use phishing-as-a-service to launch these attacks “within minutes.” 

These have become more sophisticated, and more targeted, over time, he said. One recent example was the incident involving the CEO of WPP, Mark Read, who was at the center of a scam to try to solicit money. It sounds improbable when you read that out, and indeed it was unsuccessful, but it is just a sign of where these scams are going.

Bolster’s approach uses machine learning algorithms and AI techniques to track the wider internet — URLs, domain registration databases, conversations in open and closed forums and social media platforms, as well as emails (when it works with a client) and more — to detect scam operations, which it does on a continuous basis. When it identifies iffy links, it then shuts them down at their root by way of automated takedowns.

The approach is notable because it complements the myriad email security products that are on the market today that are adopted by organizations to help filter emails as they come into a person’s inbox: That’s still important as one mechanism to halt phishing activity. But in cases where those bad links pass through the gates unencumbered, the idea here is that, if a person does click on a link, now that person might not get anywhere. 

Considering that the wider funnel of email can be so complicated to contain, and hackers themselves makes themselves hard to find, identifying and shutting down the root of their operations becomes very valuable. 

“One of the advantages that Bolster has is its ability to automatically shut down where these attacks are originating from, they can shut down where those are hosted,” said Todd Graham, managing partner at M12, in an interview. “That is really, really important, given the scale at which these criminal enterprises operate.” Microsoft does not yet work directly with Bolster, Prakash said, but the idea is that this investment is a signal of how they will in the future.

Microsoft’s interest would be on a couple of levels: The company is a major international brand in itself, operating a number of services that would trigger emails to users (and I can personally attest to getting way, way too many “account login” emails from suspicious “Microsoft” links). On top of that, it’s a provider of cloud and managed and software services to numerous businesses, and thus an important link through to a large market of would-be customers. Lastly, it’s making a major move into putting more AI into all aspects of its business, and so threat protection inevitably has to be a part of that equation, too.

Graham added that while the company is effectively just a B2B business — with even the CheckPhish tool aimed at scanning websites rather than offering tools to individual users — the fact that it works with big brands by default gives it a consumer angle, in that it’s ultimately aiming at protecting the customers of the business in question. 

“If you are getting an impersonated email that claims to be from Microsoft, but it probably isn’t, it’s in the best interest of Microsoft or Wells Fargo or whoever, to ensure that that email, if it does go out, gets detected.”

More TechCrunch

Huffington Post founder Arianna Huffington and OpenAI CEO Sam Altman are throwing their weight behind a new venture, Thrive AI Health, that aims to build AI-powered assistant tech to promote…

OpenAI Startup Fund backs AI healthcare venture with Arianna Huffington

The essential labor of data work, like moderation and annotation, is systematically hidden from those who benefit from the fruits of that labor. A new project puts the lived experiences…

Data workers detail exploitation by tech industry in DAIR report

Hello and welcome back to TechCrunch Space. I hope everyone had a great Independence Day. On to the news!

TechCrunch Space: SpaceX’s big plans for Starship in Florida

Featured Article

Valuations of startups have quietly rebounded to all-time highs. Some investors say the slump is over. 

Generative AI businesses aside, the last couple of years have been relatively difficult for venture-backed companies. Very few startups were able to raise funding at prices that exceeded their previous valuations.   Now, approximately two years after the venture slump began in early 2022, some investors, like IVP general partner Tom…

5 hours ago
Valuations of startups have quietly rebounded to all-time highs. Some investors say the slump is over. 

VPN makers report having received a notification from Apple that their apps have been removed from the App Store in Russia.

Apple removes VPN apps at request of Russian authorities, say app makers

Europe’s next-generation launch vehicle, the Ariane 6, is poised to lift off for the first time tomorrow, as the continent looks to build out sovereign access to space and ensure…

Ariane 6 is the future of European heavy-lift launch — for better or worse

Over the past few days, Ghost says it has achieved two major milestones in its move to become a federated service.

Substack rival Ghost federates its first newsletter

The Samsung event will feature updates to the Galaxy Z Fold, Galaxy Z Flip, as well as more details on the Galaxy Ring and Galaxy AI.

Samsung Unpacked 2024: What we expect and how to watch Wednesday’s hardware event

Amazon has released an all-new version of its Echo Spot ahead of Prime Day, the company announced on Monday. The 2024 version of the Alexa-enabled smart alarm clock costs $79.99,…

Amazon revives its Echo Spot with an upgraded look and improved audio

One of the vendors to benefit from the database boom is Tembo, a startup creating a platform that lets developers deploy different flavors of Postgres.

Tembo capitalizes on the database boom and lands new cash to expand

TechCrunch Disrupt 2024 is set to welcome an impressive lineup of judges for the Startup Battlefield 200 competition, presented this year by Google Cloud. These judges will decide which company…

Mayfield’s Navin Chaddha is coming to TechCrunch Disrupt 2024

Numerous concerns are weighing on the minds of many, whether it’s current global conflicts, climate change or the precarious state of the economy, it is no surprise that the world…

Art therapy app Scribble Journey lets you express emotions through doodles

Pestle addresses the common problem of finding recipes on the web.

Pestle’s app can now save recipes from Reels using on-device AI

These efforts have come as Lucid is looking to start building its Gravity SUV by the end of this year.

Lucid Motors sets new record for EV deliveries as it seeks ‘escape velocity’

Berlin-based food delivery giant Delivery Hero has warned investors it may “ultimately” face an antitrust fine of up to €400 million. The development, reported earlier by Reuters, follows unannounced raids…

Delivery Hero warns it could face €400M antitrust fine

Featured Article

Investors chase wealth tech startups in India as affluent class grows

The high-net-worth and ultra-high-net-worth segments are booming in India, prompting some wealth management firms to aggressively expand their relationship manager networks to capture this market.

23 hours ago
Investors chase wealth tech startups in India as affluent class grows

Featured Article

Seed VCs are turning to new ‘pro rata’ funds that help them compete with the big firms

Three companies with new funds deploy capital to support seed and Series A VCs looking to exercise their pro rata rights.

1 day ago
Seed VCs are turning to new ‘pro rata’ funds that help them compete with the big firms

Here are the latest companies venturing into the gaming scene and details about each offering, including pricing, examples of titles and supported devices. 

YouTube and LinkedIn have games now, and here’s how you can play them

Featured Article

CIOs’ concerns over generative AI echo those of the early days of cloud computing

CIOs trying to govern generative AI have the same concerns they had about cloud computing 15 years ago, but they’ve learned some things along the way.

1 day ago
CIOs’ concerns over generative AI echo those of the early days of cloud computing

It sounds like the latest dispute between Apple and Fortnite-maker Epic Games isn’t over. Epic has been fighting Apple for years over the company’s revenue-sharing requirements in the App Store.…

Epic Games CEO promises to ‘fight’ Apple over ‘absurd’ changes

As deep-pocketed companies like Amazon, Google and Walmart invest in and experiment with drone delivery, a phenomenon reflective of this modern era has emerged. Drones, carrying snacks and other sundries,…

What happens if you shoot down a delivery drone?

A police officer pulled over a self-driving Waymo vehicle in Phoenix after it ran a red light and pulled into a lane of oncoming traffic, according to dispatch records. The…

Waymo robotaxi pulled over by Phoenix police after driving into the wrong lane

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. This week, Figma CEO Dylan…

Figma pauses its new AI feature after Apple controversy

We’ve created this guide to help parents navigate the controls offered by popular social media companies.

How to set up parental controls on Facebook, Snapchat, TikTok and more popular sites

Featured Article

You could learn a lot from a CIO with a $17B IT budget

Lori Beer’s work is a case study for every CIO out there, most of whom will never come close to JP Morgan Chase’s scale, but who can still learn from how it goes about its business.

2 days ago
You could learn a lot from a CIO with a $17B IT budget

For the first time, Chinese government workers will be able to purchase Tesla’s Model Y for official use. Specifically, officials in eastern China’s Jiangsu province included the Model Y in…

Tesla makes it onto Chinese government purchase list

Generative AI models don’t process text the same way humans do. Understanding their “token”-based internal environments may help explain some of their strange behaviors — and stubborn limitations. Most models,…

Tokens are a big reason today’s generative AI falls short

After multiple rejections, Apple has approved Fortnite maker Epic Games’ third-party app marketplace for launch in the EU. As now permitted by the EU’s Digital Markets Act (DMA), Epic announced…

Apple approves Epic Games’ marketplace app after initial rejections

There’s no need to worry that your secret ChatGPT conversations were obtained in a recently reported breach of OpenAI’s systems. The hack itself, while troubling, appears to have been superficial…

OpenAI breach is a reminder that AI companies are treasure troves for hackers

Welcome to Startups Weekly — TechCrunch’s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Most…

Space for newcomers, biotech going mainstream, and more