PolarPath Journal

AI-Powered Phishing Is Accelerating. Here Is What Field-Service and Contracting Teams Need to Know.

AI-Powered Phishing Is Accelerating. Here Is What Field-Service and Contracting Teams Need to Know.

AI-Powered Phishing Is Growing Fast. Here Is What That Means for Contractors Running on Email.

Your email is not just for scheduling and status updates. It is the channel where change order approvals land, where clients confirm scope, where subcontractors submit invoices, and where lenders and insurance contacts send sensitive documents. For most field-service and project businesses in the 20 to 300 employee range, email is the operational nervous system. That also makes it the highest-value attack surface a bad actor can target.

A funding announcement out this week is worth paying attention to, not because you need to buy what they are building, but because of what the underlying research reveals about where the threat is heading.


What AegisAI Just Announced (and Why the Numbers Matter)

AegisAI raised a $36 million Series A, led by Battery Ventures, to scale its AI-native email security platform. The company was founded by engineers who previously worked on Google's reCAPTCHA and Safe Browsing systems, and it takes a different approach from legacy email security tools: rather than matching emails against known patterns of bad behavior, AegisAI builds proprietary large language models and a network of autonomous AI agents that evaluate the intent behind a suspicious email in real time.

That distinction matters. Traditional pattern-matching security looks for known signatures. AI-generated phishing can write a convincing, grammatically clean, contextually aware email that matches no known pattern at all. It just sounds like your client, your project owner, or your accountant.

AegisAI's own research found that AI-generated spear phishing grew nearly five times year-over-year and now accounts for nearly 14% of all observed phishing attacks. The company plans to use the new funding to scale its autonomous defense agent fleet and bring its Vanguard agent to general availability.

The story was reported by SecurityWeek on July 24, 2026.


Why This Is a Field-Service and Contracting Problem, Not Just a "Tech Company" Problem

The narrative around sophisticated email attacks tends to center on financial institutions and large enterprises. But consider the actual attack surface of a mid-size HVAC, electrical, or mechanical contractor:

  • Client communications confirming project scope and payment schedules
  • Change order approvals, often handled by email between a PM and a facilities manager
  • Subcontractor invoices arriving by email and processed without a formal AP system
  • Vendor POs and compliance documents routed through an owner's or controller's inbox
  • Credit applications, insurance certificates, and permit submissions

Every one of those workflows is a potential entry point for a business email compromise (BEC) attack. BEC specifically targets the moment when money or sensitive information is about to move, by impersonating someone the recipient trusts. A well-crafted fake email from what appears to be a project owner asking you to redirect a payment, or from a "vendor" asking you to update banking details, does not look like spam. It looks like Thursday.

Lean operations teams are especially exposed because they typically have no dedicated IT security staff. The owner, the ops lead, or the controller handles everything. They are moving fast, juggling dispatch, project timelines, and invoicing simultaneously. They are the exact kind of target a spear phishing campaign is designed to exploit.


A Practical Framework for Thinking About Email Risk in Your Operation

You do not need to become an information security expert. You do need a mental model for where the real exposure sits in your business.

Step 1: Map Where Money Moves Through Email

Start by listing every workflow where an email directly precedes or triggers a financial event:

  1. Client approves a change order by reply email, and your team invoices off that approval.
  2. A subcontractor or vendor sends an invoice by email, and it gets processed for payment.
  3. A project owner sends updated wire or payment instructions.
  4. Your controller receives payroll-related documents or banking change requests.

These are your highest-risk touchpoints. If someone can intercept or impersonate a party at any of these moments, they can redirect money or extract sensitive data.

Step 2: Separate "Email as Notification" from "Email as Record of Truth"

One of the most useful things a field-service operation can do is reduce the number of workflows where an email alone constitutes the authoritative record. Change orders approved by email reply, then manually re-entered into your project system, are a double risk: they are easy to intercept and easy to lose. When the approval lives in a structured workflow inside your operational platform, the email becomes a notification layer, not the source of truth.

Step 3: Verify Anything That Involves a Payment Change Out of Band

This is the simplest and most immediate protective behavior: if an email requests a change to payment instructions, bank details, or wire routing, pick up the phone. Call a known number, not one in the email. This single habit blocks the majority of BEC attempts because the attack depends on the target not verifying through a separate channel.

Step 4: Evaluate Your Email Security Layer

Most small and mid-size contractors rely on whatever security came bundled with their email provider. That may be adequate for commodity spam, but AI-generated spear phishing is a different category. It is worth asking your IT contact or managed service provider whether your current tooling evaluates intent, not just pattern matching. What AegisAI is building represents a broader shift in the industry toward intent-aware, AI-native defense. You do not have to use their product specifically, but the concept should be part of the conversation when you review your tooling.

Step 5: Tighten the Operational Workflows That Create the Risk

The deepest solution is not purely a security layer on top of email. It is reducing how much critical operational data and approval authority lives in unstructured email threads in the first place.


The Operational Angle: Where Structure Reduces Exposure

Here is the honest assessment of why field-service and project businesses are disproportionately vulnerable to email-based attacks: too many critical workflows live in inboxes.

A change order that goes from conversation to email to spreadsheet to invoice, with four people touching it manually, is not just operationally inefficient. It is also hard to verify, easy to intercept at any stage, and impossible to audit cleanly after the fact. That same change order, generated inside a platform with a documented approval trail, a linked work order, and an invoice that flows directly from the field data, is structurally harder to attack because the authoritative record is not in any one person's inbox.

This is part of the reason PolarPath was built the way it was. The platform is designed to own the operational execution layer, meaning the quotes, work orders, change orders, field data, project documents, and invoices that field-service and project businesses run on every day. When those records live in one connected system rather than scattered across emails and spreadsheets, you get two things at once: operational visibility and a natural reduction in the workflows that make email the single point of trust. Email stays useful as a communication tool. It just stops being the authoritative record of whether work was approved, what scope was agreed to, or how much a client owes.

PolarPath coexists with QuickBooks, so the accounting system of record stays where it is. What changes is the layer between your field operations and your books, which is where most of the email-driven risk actually lives.


The Practical Takeaway

AI-generated phishing is a real and growing threat, and the AegisAI raise is a signal that the investment community sees it that way too. For contractors, the response is two-pronged.

First, add a behavioral layer: verify payment changes out of band, ask your IT provider whether your email security evaluates intent, and build a culture where your team knows that unusual financial requests get a phone call before any action is taken.

Second, reduce your structural exposure over time by moving critical operational workflows out of unstructured email and into systems that maintain a clear, auditable record. That is good operations practice regardless of the security angle, and the security benefit comes along for free.

The businesses that will be least affected by AI-powered email attacks are the ones that were already running tight operational discipline. Start there.