Skip to content

Armadin raises $255.5M for AI attack agents at $2.5B

Kevin Mandia's Armadin raised $255.5 million at a valuation above $2.5 billion to sell AI agent swarms that attack company networks before criminals do.

By Tech AI Wire Team

3 min read

XLinkedIn
Armadin chief executive Kevin Mandia in a navy suit, leaning on a wooden stair rail in a bright white atrium.
Photo: Armadin

By the numbers

Series B, co-led by Andreessen Horowitz and Accel
$255.5M
valuation after the round
$2.5B+
total raised since launch
$445M

Armadin, the security startup run by Mandiant founder Kevin Mandia, has raised $255.5 million at a valuation above $2.5 billion. Three security outlets reported the Series B round on October 1, 2026. Armadin sells swarms of AI agents that attack a company's own systems to find holes before criminals do. The size of the round shows how much money now backs automated hacking as a defense tool.

Andreessen Horowitz and Accel co-led the round, according to SecurityWeek. All three outlets put Armadin's total funding at $445 million.

Who is backing Armadin

New investors Bain Capital Ventures and Redpoint joined the round. Existing backers returned too, including 8VC, Ballistic Ventures, Google Ventures, Kleiner Perkins, Menlo Ventures and In-Q-Tel.

The company is based in Palo Alto, California, and launched publicly in March 2026, SecurityWeek reports. The sources describe its earlier funding differently:

DetailSecurityWeekUnite.AI
Seed round$24 million, late 2025Included in $189.9 million
Launch funding, March 2026$189.9 million$189.9 million, combined seed and Series A
Series B, October 2026$255.5 million$255.5 million
Total raised$445 million$445 million

Unite.AI called the March raise the largest combined seed and Series A round in cybersecurity history.

Mandia has led big security businesses before. He founded the incident-response firm Mandiant in 2004 and sold it in a $1 billion deal in 2014, SecurityWeek notes.

How Armadin's AI agents work

Companies have long paid human "red teams" to break into their own networks. This kind of test is called penetration testing. It usually happens a few times a year, and it only shows the gaps that one team found in one window of time.

Armadin replaces that with software agents that run all the time. Each agent probes part of a company's systems, such as its websites, cloud accounts or user logins. When one finds a weakness, others try to build on it.

The goal is a full "attack path," according to Help Net Security. That is the chain of steps from a first foothold, through moving between machines, to full control of a company's cloud. Chaining matters because most serious breaches are several small weaknesses used in a row, not one dramatic flaw.

Armadin says its customers include Fortune 500 companies and government agencies. None of the three reports names a customer or gives revenue figures.

"AI lets an attacker find and chain weaknesses faster than any human team can respond," Mandia said in the announcement. He argued that a defense can only keep pace if it trains "against the best offense available, every day."

Investors leaned on Mandia's record. David George of Andreessen Horowitz said Mandia "has been on the front lines of the most consequential breaches in history." Accel's Ping Li said Armadin had set "the standard for AI-powered offensive security" in under a year.

The new money will expand the platform and pay for research, model training and sales, all three outlets report.

What this means for developers

Expect automated attacks against your code to become constant. If defenders now run agent swarms every day, attackers can use the same methods. Code that passed a yearly penetration test may face thousands of probes a week.

Fix small issues, not just critical ones. An attack path is built from weaknesses that each look minor on their own. An open debug endpoint, an over-broad cloud role and a leaked token can chain into a full breach. Review low-severity findings for how they combine.

Ask hard questions before buying. Armadin has published no customer names or revenue. Ask any vendor in this space how its agents stay inside agreed limits, and how it avoids breaking production systems. Ask what evidence it gives for each attack path it reports.

Set rules before agents touch your systems. An AI that attacks your network needs written scope, test accounts and a quick way to stop it. Agree with your security team on which environments are in scope and who gets alerted when an agent finds something.

Sources

  1. Kevin Mandia's Armadin Raises $255 Million at $2.5 Billion Valuation - SecurityWeek
  2. Armadin raises $255.5 million to expand AI offensive security platform - Help Net Security
  3. Armadin Raises $255.5M Series B at Over $2.5B Valuation to Scale Its Agentic Security Platform - Unite.AI

Related articles

The daily brief

Three to five stories a day, and what each one means for the people who build software. Free, no spam.