← News

Armadin raises $255.5M Series B at over $2.5B for agentic cyber offense

Armadin said Thursday it raised $255.5 million in Series B funding co-led by Andreessen Horowitz and Accel, valuing the AI cybersecurity company at more than $2.5 billion seven months after launch.

AI is shrinking the window between a bug becoming public and someone weaponizing it. Mandia’s bet is that the only defense that keeps pace is a swarm of AI agents that attack your own systems every day and show the exact path an adversary would take. A $2.5B+ valuation seven months after launch shows how hard investors are leaning into that offensive-for-defense thesis.

On Thursday, 1 October 2026, Armadin said it raised $255.5 million in a Series B. A Series B is a growth round, the money that follows a startup’s earlier venture checks. Andreessen Horowitz, which the release also shortens to a16z, and Accel co-led it. Co-led means the two firms ran the round together. The release says that money brings the company’s valuation to over $2.5 billion. A valuation is the price this announcement puts on the whole company. Armadin is private, so that price is not a stock-market quote. Over $2.5 billion means more than $2.5 billion. The release does not print a tighter number. The dateline is Palo Alto, California. The release went out on PR Newswire, and the page prints Oct 01, 2026, 06:00 ET, which is 6:00 a.m. Eastern. The subhead says the valuation arrives just seven months after launch, as AI compresses the time between a vulnerability being discovered and someone exploiting it. Those lines are the release.

Who put money in, as the release names them. New investors are Bain Capital Ventures, which the release shortens to BCV, and Redpoint. Investors that came back are 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins, and Menlo Ventures. Came back means they had already backed the company and wrote another check. The release does not say how much each firm put in. It says total funding is now $445 million. Total funding is every dollar raised so far, including this round. It is not the valuation. $445 million is cash in. Over $2.5 billion is the price on the whole firm, more than five times the cash raised. Take this $255.5 million off the $445 million and the earlier raises add up to $189.5 million. That subtraction is arithmetic. The release does not split the earlier money into a seed and a Series A, and it does not print those earlier amounts.

What Armadin says it is already running. Seven months after it emerged from stealth, the company says it is running agentic attack campaigns in production for Fortune 500 enterprises and government customers. Stealth means it was not yet selling in public. Seven months is the release’s count. The page does not print the calendar day the company came out. The subhead says “seven months after its launch.” The next paragraph says “seven months after emerging from stealth.” The release treats those as the same span. Agentic, here, means software that carries an attack through, not a chatbot that only writes a memo. In production means the campaigns are running on real customer systems, not only in a demo. Fortune 500 enterprises are among the largest companies in the United States. The release says government customers. It does not name a company, an agency, or a country, and it does not say the software covers a whole government. Those lines are Armadin’s.

Why the company says a scheduled test is no longer enough. Frontier AI models, the release says, compress the time between a vulnerability being disclosed and a working exploit. A vulnerability is a flaw. Disclosed means it has been made public. An exploit is a way to use that flaw. A periodic penetration test is a scheduled attack a company hires people to run, then waits for the next one. The release says those tests cannot keep pace. It says scanner output fails in a different way, because a scanner scores each finding on its own. A scanner is a tool that lists weaknesses one by one. On its own, in that sentence, means each flaw is graded alone, so a path that needs several small flaws can stay hidden. Those lines are the release.

What Armadin says it sends in instead. An autonomous swarm of specialized agents that reason like a skilled adversary across the attack surface, chaining individually low-severity weaknesses into validated kill chains. Autonomous means the swarm proceeds without a person steering each step. A swarm is many agents, not one. Specialized means they are built for different jobs. An attack surface is every place an outsider could try to get in. Low-severity means a weakness that, alone, looks small. A kill chain is the path from the first way in to control of the target. Validated means the company says it checked that the path works, rather than only listing a guess. The release says those chains run from unauthenticated remote code execution at the perimeter, through lateral movement, to full cloud compromise. Unauthenticated remote code execution means running code on a machine from the outside without a login. The perimeter is the outer edge of the network. Lateral movement means stepping from that first machine to others inside. Cloud compromise means control of the computing the company rents. The release says security teams then see the exact paths an adversary would use in production today, the blast radius of each path, and can sever them before they are exploited. Blast radius is how far the damage would spread. Sever means cut the path. Those are Armadin’s words for what the product shows. The release does not name a customer system, and it does not print the steps of an exploit.

Kevin Mandia, the chief executive, is quoted in the release. “Offense is uniquely advantaged right now,” he said. “AI lets an attacker find and chain weaknesses faster than any human team can respond. The only way to build a defense that keeps pace is to train it against the best offense available, every day. That is what we built. With a16z and Accel co-leading and the support of every investor in this round, we are going to put that offense to work for the enterprises and government agencies defending the world’s most critical systems.” Offense, in that quotation, means attacking your own systems the way an adversary would, so the defense can practice against it. The quotation is his, in the release. “Government agencies” is his phrase. The product paragraph says “government customers.”

Two investors are quoted on the same release. Ping Li, a partner at Accel, said that against agentic adversaries the best defense is a great offense powered by AI, and that this was Accel’s conviction when it led Armadin’s Series A. He said that case is more pressing today. He said that in less than a year Armadin has set the standard for AI-powered offensive security and remediation across enterprises and governments, and that Accel is excited to keep partnering. Remediation means fixing what the test finds. The Series A line is his. The release does not print the size of that earlier round. David George, a general partner at Andreessen Horowitz, said every major platform shift creates a new generation of security leaders, and that AI is the biggest shift he has seen. He said Mandia has been on the front lines of the most consequential breaches in history, and has built a team that pairs elite red teamers with world-class AI engineers. A red teamer is a person paid to attack a system the way an adversary would, with permission. George said the firm invested because it believes Armadin will become the defining security company of the AI era. Those quotations are theirs, in the release. They are the investors’ view. They are not a count of attacks stopped.

Where the money goes. The release says Armadin will use it to scale the agentic security platform, and to scale research, training, and go-to-market. Go-to-market is the work of selling and delivering the product. That plan is the company’s. The release does not print a hiring target or a date for a new office. The about box calls Armadin an AI-native cybersecurity company, and calls the product the definitive offensive security platform for finding and removing exploitable risk. It says the platform safely delivers AI Hyperattacks, the company’s name for these attack runs, to find new attack paths before an adversary uses them. It says the company is engineers, researchers, and hackers, led by Mandia, on a mission to create effective autonomous security. “Definitive” and “most comprehensive and powerful” are the about box’s words.

Who Mandia is, on the company’s own pages. The funding release identifies him as chief executive. His bio on the company site lists him as founder and chief executive. The bio says he is known as the founder of Mandiant and the former chief executive of FireEye, with more than 30 years in digital defense. It says that after Mandiant was acquired by Google Cloud for $5.4 billion, his work turned to AI-driven threats. It also says he is a general partner at Ballistic Ventures, which is one of the firms returning in this round. Those lines are the bio. The funding release does not retell the Mandiant sale. Reuters, the same day, says the company was founded by chief executive Kevin Mandia, who also founded the cybersecurity firm Mandiant and later sold it to Google. Reuters does not print the $5.4 billion. That figure stays with the bio. The company leadership page names the other founders: Travis Lanham, chief technology officer; Evan Peña, chief offensive security officer; and David Slater, chief architect. It lists Ping Li of Accel, Jake Seid of Ballistic Ventures, and George Kurtz, chief executive of CrowdStrike, among the directors, and it says they joined the board in 2026. The page says Seid led the seed round. The funding release does not announce board seats, and it does not name Kurtz, Lanham, Peña, Slater, or Seid.

Reuters reported the round the same Thursday. The headline is “AI cybersecurity startup Armadin valued at over $2.5 billion after new funding round.” The Reuters page stamps October 1, 2026, 10:43 a.m. UTC. The wire says Armadin said on Thursday that it raised $255.5 million in a Series B, which values the company at more than $2.5 billion. It says investors have poured large sums into early-stage startups building defenses against AI-driven cyberattacks. That market sentence is Reuters’s. The bullets say Andreessen Horowitz and Accel co-led, joined by new investors Bain Capital Ventures and Redpoint and by existing backers including Google Ventures, Kleiner Perkins, Menlo Ventures, and In-Q-Tel. “Including” is the wire’s word. That list does not print 8VC or Ballistic Ventures. Those two names are on the company release. The wire says the round took total funding to $445 million, that Armadin said so, and that the company will use the money to scale its platform, research, training, and go-to-market efforts. It says Armadin uses a swarm of AI agents that act like hackers to find weaknesses. “Act like hackers” is Reuters’s phrase. The release’s phrase is a swarm that reasons like a skilled adversary. The wire was reported by Anzar Mehraj in Bengaluru and edited by Joyjeet Das. The $255.5 million, the valuation over $2.5 billion, the co-leads, and the $445 million match the release.

The picture is a desk graphic for the round. A dark blue field warms to amber along the bottom. An orange line sits over the word Armadin. The type reads Series B, $255.5 million, a valuation over $2.5 billion, and Kevin Mandia, chief executive. A pale ARMA sits behind the type. On the right is Armadin’s portrait of Mandia, in a navy suit and an open-collar light blue shirt, one hand in a pocket and the other on a wooden stair rail. It is the company’s portrait. The graphic does not print a calendar date.

In plain terms, Armadin said on Thursday that a16z and Accel co-led a $255.5 million Series B, at a valuation over $2.5 billion, and that total funding is $445 million. The company says a swarm of AI agents attacks customer systems the way an adversary would, chains small weaknesses into a path it has checked, and shows that path so a team can cut it. Mandia, who founded Mandiant, says the defense has to train against that offense every day because AI has shortened the time between a public bug and a working exploit. Reuters confirms the round, the valuation, the total, and the use of the money. The pages do not name a customer, and they do not print a valuation tighter than over $2.5 billion.

RELATED

ONLINE…

Comments

guidelines

Loading…

Loading…

Sources