SERIES B Adaptive Security raises $81M led by Bain Capital Ventures BACKERS NVIDIA and the OpenAI Startup Fund on the same cap table TRACTION 500+ enterprise customers in under a year CLIENTS PayPal · Bose · the NHL · Figma · Ramp · Perplexity TOTAL RAISED $146.5M across 2025 THREAT Deepfake-enabled attacks rose 17x in a single year
Company · AI Cybersecurity

The Company That Attacks You Before the Scammers Do

AI made it cheap to clone a CEO's voice and email 10,000 employees at once. Adaptive Security's answer is to run those attacks first - as a drill - and see who clicks.

The pitch takes about one sentence to land, and it makes people uncomfortable, which is the point. Adaptive Security wants to attack your employees. It will study the public trail your staff leave online, clone an executive's voice, write a text message that reads exactly like a panicked vendor, and send it - all before a real criminal does the same thing. The company that does this is not a rogue operation. It is a New York cybersecurity firm that raised $146.5 million in 2025 and counts PayPal, Bose, and the NHL among more than 500 enterprise customers.

The logic is straightforward once you get past the discomfort. Generative AI has made social engineering cheap, fast, and disturbingly convincing. A voice that once took a studio to fake now takes a few seconds of audio. An email that once had telltale typos now reads like it came from your own CFO. Adaptive's bet is that you cannot lecture people out of falling for that. You have to rehearse them against it - using the same tools the attacker would.

$146.5M
Total raised in 2025
500+
Enterprise customers
17x
Rise in deepfake attacks, one year

01 / What it actually doesReconnaissance, weaponized - politely

Most security-awareness training is a chore: an annual video, a canned phishing email with an obvious typo, a completion checkbox. Adaptive Security threw that model out. Its platform starts where a real attacker starts - with open-source intelligence. It scans the public data a criminal would collect on each employee: job title, reporting lines, recent projects, vendor names, LinkedIn activity, headshots, even voice recordings pulled from public talks. The company says it evaluates more than 1,000 public data points per person.

From that reconnaissance it builds a simulation the target has no obvious reason to doubt. Not a generic "your password expired" template - a scenario tuned to who they are and who they trust. Then it runs the drill across the channels attackers actually use.

The channels Adaptive drills
Email
AI-written spear phishing, no typos
📱
SMS / Smishing
Text lures on personal phones
📞
Voice / Vishing
AI-cloned exec and helpdesk calls
🎥
Deepfake video
Impersonated faces on camera
Adaptive Security phishing simulation interface
The drill, dressed as the real thing. Adaptive builds each simulated lure from the same public breadcrumbs an attacker would collect - then grades the click.

When an employee fails a drill, it is not filed away as a statistic. The platform lowers that person's risk score, can restrict access, and delivers targeted training tied to exactly the exposure they showed. Training content runs in 39-plus languages with accessibility controls. The result is less a course and more a live readiness metric for the human layer of a company.

Social engineering accounts for over 95% of successful cyber breaches. Adaptive's argument is that the defense has to start there too.

From Adaptive Security's Series B announcement

02 / How the loop runsFrom public data to a retrained employee

Strip away the branding and the product is a closed loop, run continuously rather than once a year.

The Adaptive loop
1

Gather

Scan 1,000+ public data points per employee - the same OSINT an attacker would use.

2

Simulate

Generate a personalized attack across email, SMS, voice, or deepfake video.

3

Score

Measure who engages and adjust a live human risk score - not a completion rate.

4

Train

Deliver targeted content tied to the exact weakness the drill revealed.

03 / Who is behind itThe Attentive team, doing it again

Adaptive Security was founded in 2024 by Brian Long and Andrew Jones - not first-time founders, and that matters to the story. The two previously co-founded Attentive, the marketing platform they grew to more than 8,000 customers and $500 million-plus in annual revenue. Before that they built TapCommerce, a mobile advertising company they sold to Twitter, where both went on to work. Long is CEO; Jones is Chief Product Officer.

Brian Long, CEO and co-founder of Adaptive Security
Brian Long, CEO. He grew Attentive past $500M in revenue, then went looking for the version of that reach that keeps CISOs awake at night.

They could have retired. Instead they picked a problem that rhymes with their old one: Attentive was about reaching people at scale through their phones. The dark version of that same capability - reaching people at scale to deceive them - is exactly what generative AI unlocked for criminals. The founders knew the go-to-market playbook and the channel. They pointed it at defense.

04 / The moneyOpenAI's first security bet - and NVIDIA's too

The funding history is unusual for how fast it moved and who showed up. In April 2025, the OpenAI Startup Fund and Andreessen Horowitz led a $43 million Series A - described as OpenAI's first and only cybersecurity investment. In December 2025, Bain Capital Ventures led an $81 million Series B, with NVIDIA's NVentures joining alongside the OpenAI fund, a16z, Abstract Ventures, Capital One Ventures, and Citi Ventures. Total raised: $146.5 million.

Funding, 2025 (USD millions)
Series A
Apr '25
$43M · OpenAI + a16z
Series B
Dec '25
$81M · Bain + NVIDIA
Adaptive Security Series B announcement graphic
Three raises in one year. The Series B closed in December 2025 and pushed total funding to $146.5 million - fast, even by New York standards.

Getting both the OpenAI Startup Fund and NVIDIA's venture arm onto one cap table is rare - the two rarely land on the same deal. It signals a shared read: that AI-driven social engineering is a defining breach vector, and that the defense will be built with AI, not against it.

05 / Who buys itEnterprises that got the wake-up call

In under a year of public launch, Adaptive signed more than 500 enterprise customers. The named ones span industries where impersonation is expensive:

PayPalBoseNHL XeroxFigmaRamp VimeoPerplexity

The buyer is usually a CISO or a security-awareness lead watching a specific number climb: the share of CISOs reporting sophisticated deepfake attacks rose from roughly 10% to over 50% in 18 months. For those teams, the old annual-video model stopped feeling like coverage. Adaptive sells against that gap.

06 / Where it sitsNext-gen versus the incumbents

Security-awareness training is not a new category. Incumbents like KnowBe4, Proofpoint, and Cofense have sold phishing simulation and training for years, and challengers like Hoxhunt have pushed on personalization. Adaptive's wedge is the part that is hardest to fake with a template library: AI-generated, multi-channel simulation that includes deepfake voice and video, built on OSINT personalization rather than canned scenarios. The competitive question is whether that realism stays a durable edge as the incumbents add their own AI features - and whether enterprises are comfortable, long term, deepfaking their own executives to train their own staff.

The product's job is to fool your own employees - convincingly - so that the real attack, when it comes, does not.

The uncomfortable core of the model

07 / What you can take from itThe copyable idea

You do not need Adaptive's platform to use its central move. The idea any security team can borrow is to stop treating awareness as content and start treating it as rehearsal - run the attack you are afraid of, on your own people, before someone else does, and measure who is ready rather than who finished the video. Adaptive productized that instinct and pointed it at the channels AI made dangerous. The limit worth naming honestly: this works when leadership will authorize realistic, sometimes unsettling simulations of their own executives and staff. Where that authorization is missing, the drills soften into the same box-ticking they were meant to replace.

Not everything Adaptive does is enterprise-priced, either. In late 2025 it launched free training to help protect older adults - a group hit hardest by AI voice scams - from the same attacks its paying customers rehearse against.