AI

Halcyon lands large investment to defend against ransomware

Comment

Lock over computer circuit board meant to illustrate security in a digital context.
Image Credits: Yuichiro Chino / Getty Images

Following the Colonial Pipeline incident in 2021, Jon Miller and Ryan Smith wondered why, with the widespread adoption of security tools, ransomware was still growing exponentially.

It’s an odd dichotomy. Seventy-eight percent of companies responding to a recent survey said that they plan to increase their investments in cybersecurity in the next 12 months. But at the same time, ransomware damages are expected to exceed $30 billion worldwide in 2023.

Frustrated with the status quo, Miller and Smith — veterans of companies later acquired by Blackberry and Optiv, as well as cyber defense contractor Boldend — founded the cybersecurity startup Halcyon. They claim it can help stop ransomware from causing damage while enabling companies to lower their overall recovery times.

It’s a message that’s seemingly resonating with VCs.

Halcyon today announced that it raised $44 million in a Series A funding round (plus $6 million in debt) led by SYN Ventures and Corner Ventures, with participation from Dell Technologies Capital. The new cash and loan, Miller said, will be put toward bolstering the company’s engineering and R&D departments and strengthening its ongoing sales and marketing outreach.

“We view our product as unique in that we have no direct competitors, and in fact want to improve other security tools in use by our customers,” Miller, who serves as CEO, said. “We assume first that all security layers will fail at some point, including our own. That’s why we have focused on building a product with resilience in mind.”

Miller might assert that Halcyon is without direct competitors. But the cybersecurity space — which has seen funding fall consistently, with dealmaking reaching a two-year low in the most recent fiscal quarter, according to Crunchbase — is overflowing with vendors. The financial crunch threatens to turn up the heat even higher.

But Miller patiently lays out what he sees as Halcyon’s market-beating differentiators.

For one, the platform taps AI to recognize “malicious intent,” trained on a data set of millions of real-world ransomware events. That’s as opposed to the static, rules-based detection schemes that some cybersecurity platforms use, Miller says.

To build detection engine models, security companies will ingest millions of samples, indicators and artifacts from a variety of sources,” he added. “We have started much more narrowly in order to not pollute our models with data not relevant to ransomware campaigns or broken samples like those commonly pulled from public malware repositories.”

Halcyon attempts to detect and block known bad executables like off-the-shelf commodity ransomware and pass unknown but suspicious executables to additional “protection layers” for further analysis. In addition, the platform attempts to “trick” ransomware into aborting or revealing an attack by exploiting features hardcoded in the ransomware software itself — triggering code via deception techniques.

Halcyon’s other unique component is a “resiliency layer” that kicks in if the platform’s detection and prevent layers fail. As Miller describes it, the resilience layer captures the encryption keys generated during the attack, allowing IT and security teams with a way to automatically decrypt the impacted endpoints — rendering the attack useless.

Typically during a ransomware attack, attackers encrypt various endpoints on a network — for example, laptops — and demand ransom in exchange for decryption. Halcyon’s approach sounds like a clever way to combat this. That’s assuming that it works as well as Miller says, of course.

Halcyon
Halcyon’s platform taps AI to attempt to detect and block ransomware. Image Credits: Halcyon

In any case, Halcyon has attracted considerable interest from investors, having raised a total of $50 million since 2020 inclusive of the Series A. Miller says that business was briefly impacted by the Silicon Valley Bank collapse — Halcyon was a corporate credit card and loan customer with the bank — but that Halcyon has since “diversified its banking relationships” to better manage risk.

With a customer base of around 51 companies, Halcyon plans to grow the size of its workforce from 75 people to around 100 by the end of the year. In terms of product, Miller says that Halcyon will launch a data exfiltration tool to stop the “double extortion” techniques commonly used by ransomware groups today as well as support for additional operating systems including Linux and Mac.

Double extortion attacks usually involve hackers that threaten to encrypt sensitive data and publish it on the dark web or sell it to the highest bidder.

“With the growth of ransomware operations and the economy that supports them, gaining access to credentials and systems is easier and cheaper than ever before,” Miller said. “Products that do not start with an approach that prioritizes resilience will generate more risks to the business and higher cyber insurance premiums which have an impact across all aspects of the organization.”

Miller wouldn’t reveal Halcyon’s revenue when asked, and, when pressed on why the company raised debt, said only that it was for “flexibility” in the near term. But if surveys are anything to go by, demand for Halcyon’s product won’t wane anytime soon — which could be good news for the bottom line.

A survey by CyberCatch found that 75% of companies wouldn’t be able to survive a ransomware attack. Another poll, this by Mimecast, shows that 47% of companies have been successfully attacked by ransomware.

Considering they’re coming from vendors, is there an element of fear-mongering in those numbers? Perhaps. But fear does sell, it’s true.

More TechCrunch

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?

Google has found a way to bring a variation of its clever “Circle to Search” gesture to iPhone users. The new interaction, launched in January, allows Android users to search…

Google brings a variation on ‘Circle to Search’ to iPhone users

A new sculpture going live on Wednesday in the Flatiron South Public Plaza in New York is not your typical artwork. It combines technology, sociology, anthropology and art to let…

Always-on video portal lets people in NYC and Dublin interact in real time

Apple’s iPad event had a lot to like. New iPads with new chips and new sizes, a new Apple Pencil, and even some software updates. If you are a big…

TechCrunch Minute: When did iPads get as expensive as MacBooks?

Autonomous, AI-based players are coming to a gaming experience near you, and a new startup, Altera, is joining the fray to build this new guard of AI agents. The company announced…

Bye-bye bots: Altera’s game-playing AI agents get backing from Eric Schmidt

Google DeepMind has taken the wraps off a new version AlphaFold, their transformative machine learning model that predicts the shape and behavior of proteins. AlphaFold 3 is not only more…

Google DeepMind debuts huge AlphaFold update and free proteomics-as-a-service web app

Uber plans to deliver more perks to Uber One members, like member-exclusive events, in a bid to gain more revenue through subscriptions.  “You will see more member-exclusives coming up where…

Uber promises member exclusives as Uber One passes $1B run-rate

We’ve all seen them. The inspector with a clipboard, walking around a building, ticking off the last time the fire extinguishers were checked, or if all the lights are working.…

Checkfirst raises $1.5M pre-seed to apply AI to remote inspections and audits

Close to a decade ago, brothers Aviv and Matteo Shapira co-founded a company, Replay, that created a video format for 360-degree replays — the sorts of replays that have become…

Controversial drone company Xtend leans into defense with new $40 million round

Usually, when something starts to rot, it gets pitched in the trash. But Joanne Rodriguez wants to turn the concept of rot on its head by growing fungus on trash…

Mycocycle uses mushrooms to upcycle old tires and construction waste

Monzo has raised another £150 million ($190 million), as the challenger bank looks to expand its presence internationally — particularly in the U.S. The new round comes just two months…

UK challenger bank Monzo nabs another $190M as US expansion beckons

iRobot has announced the successor to longtime CEO, Colin Angle. Gary Cohen, who previous held chief executive role at Timex and Qualitor Automotive, will be heading up the company, marking a major…

iRobot names former Timex head Gary Cohen as CEO

Reddit — now a publicly-traded company with more scrutiny on revenue growth — is putting a big focus on boosting its international audience, starting with francophones. In their first-ever earnings…

Reddit tests automatic, whole-site translation into French using LLM-based AI

Mushrooms continue to be a big area for alternative proteins. Canada-based Maia Farms recently raised $1.7 million to develop a blend of mushroom and plant-based protein using biomass fermentation. There’s…

Meati Foods bites into another $100M amid growth to 7,000 retail locations

Cleaning the outside of buildings is a dirty job, and it’s also dangerous. Lucid Bots came on the scene in 2018 with its Sherpa line of drones to clean windows…

Lucid Bots secures $9M for drones to clean more than your windows

High interest rates and financial pressures make it more important than ever for finance teams to have a better handle on their cash flow, and several startups are hoping to…

Israeli startup Panax raises a $10M Series A for its AI-driven cash flow management platform

The European Union has deepened the investigation of Elon Musk-owned social network, X, that it opened back in December under the bloc’s online governance and content moderation rulebook, the Digital Services Act…

EU grills Elon Musk’s X about content moderation and deepfake risks

For the founders of Atlan, a data governance startup, data has always been at the heart of what they do, even before they launched the company. In fact, co-founders Prukalpa…

Atlan scores $105M for its data control plane, as LLMs boost importance of data

It is estimated that about 2 billion people, especially those in lower and middle-income countries, lack access to quality and affordable essential medicines. The situation is exacerbated by low-quality or even killer…

Axmed raises $2M from Founderful to streamline drug supply chains in underserved markets

For decades, the Global Positioning System (GPS) has maintained a de facto monopoly on positioning, navigation and timing, because it’s cheap and already integrated into billions of devices around the…

Xona Space Systems closes $19M Series A to build out ultra-accurate GPS alternative

Bankruptcy lawyers representing customers impacted by the dramatic crash of cryptocurrency exchange FTX 17 months ago say that the vast majority of victims will receive their money back — plus interest. The…

FTX crypto fraud victims to get their money back — plus interest

Google on Wednesday launched its digital wallet in India with local integrations, nearly two years after the app was relaunched as a digital wallet platform in the U.S. As TechCrunch exclusively reported last month,…

Google Wallet is now available in India

Bluesky has launched a new product roadmap for the coming months. The decentralized social network said on Tuesday that it is planning to introduce direct messages, support for videos, improved…

Bluesky to add DMs, video support and in-app custom feed curation

Samsung Medison, a medical device unit of Samsung Electronics that specializes in developing diagnostic imaging devices, said on Wednesday it plans to acquire Sonio, a Paris-based startup that makes AI-powered software…

Samsung Medison to acquire French AI ultrasound startup Sonio for $92.7M

Kyle Kuzma is a lot of things. He’s a forward for the Washington Wizards NBA team and a 2020 NBA champion. He’s also a style icon — depending on who…

NBA champion Kyle Kuzma looks to bring his team mentality to Scrum Ventures

Ofcom is cracking down on Instagram, YouTube and 150,000 other web services to improve child safety online. A new Children’s Safety Code from the U.K. Internet regulator will push tech…

Ofcom to push for better age verification, filters and 40 other checks in new online child safety code

Lipids are fatty, waxy or oily compounds that, for instance, typically come in the form of fats and oils. As a result they are heavily used in the production of…

After a $20M Series A funding, Germany’s Insempra plans eco-friendly lipid production

Tesla CEO Elon Musk has said that lidar sensors are a “crutch” for autonomous vehicles. But his company has bought so many from Luminar that Tesla is now the lidar-maker’s…

Tesla is Luminar’s largest lidar customer

U.S. realty trust giant Brandywine Realty Trust has confirmed a cyberattack that resulted in the theft of data from its network. In a filing with regulators on Tuesday, the Philadelphia-based…

Brandywine Realty Trust says data stolen in ransomware attack