Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
Black Hat 2026 key takeaways: Learn how AI deception, multi-channel attacks, and agentic infrastructure disruption are reshaping social engineering defense.

The expo hall at the Mandalay Bay Convention Center is always a masterclass in market noise and buzzwords, and while the hospitality in Las Vegas is top-tier, Black Hat 2026 made one thing clear: the cybersecurity threat landscape has changed, and organizations need to adapt…and fast. Synthetic media, hyper-personalized text, AI voice clones, and automated multi-channel lures are the operational baseline for everyday cybercriminals.
It’s no secret that SOC teams are drowning in manual queues, CISOs are under intense board pressure to show quantifiable risk reduction, and attackers are weaponizing human trust across channels faster than inbox-only tools can generate alerts.
This recap shares the core takeaways, practitioner insights, and executive discussions from Black Hat 2026. From the lobby of the Doppel Hotel to the presentation stage, we detail why inbox-only security is obsolete, how agentic infrastructure disruption replaces passive email scoring, why automation is mandatory to survive machine-speed deception, and how human risk management must evolve to combat generative AI threats.
A primary topic of conversation among CISOs at the show was the dissolution of the traditional security perimeter. Modern adversaries don’t limit their campaigns to email. They bypass the concierge entirely and execute orchestrated, multi-surface campaigns, simultaneously deploying lookalike domains, launching malicious mobile apps, weaponizing executives' identities on social media, and initiating AI-vishing calls to corporate help desks.

In conversations at the Doppel Hotel and around the event, practitioners shared that siloed monitoring tools are failing because attackers channel-hop. An analyst might quarantine a phishing email in Microsoft 365, but if the underlying lookalike domain, malicious Telegram channel, and fake LinkedIn persona remain active, the attacker can simply pivot to SMS or WhatsApp to compromise the same user.
Seeing email security, digital risk protection, and dark web monitoring as isolated functions leaves massive blind spots. Security teams must adopt a unified social engineering defense (SED) architecture that correlates cross-channel telemetry into a single intelligence layer. When you map the entire campaign instead of analyzing isolated alerts, you close the operational gaps adversaries exploit.
For decades, the email security market has focused on scoring the message in front of the user. Whether relying on native filters, secure email gateways, or behavioral machine learning, traditional tools evaluate a message, assign a risk score, and place it in a junk or quarantine folder.
Quarantining an email stops one message, but it acts like a simple "Do Not Disturb" sign: The malicious infrastructure remains completely intact. The domain stays live, the payload remains hosted, and the attacker continues retargeting your enterprise seconds later.

Modern security requires moving from passive detection to active infrastructure disruption. By leveraging external threat graph intelligence, advanced security teams now trace inbox lures back to their external hosting providers, domain registrars, and ad networks.
Evaluating your email defense requires asking a simple question: Does your system merely hide bad emails, or does it actively take down the malicious domains and sending infrastructure behind them?
During his Black Hat session, Breaking the AI-Driven Social Engineering Attack Chain, Bobby Ford highlighted how generative AI tools have dropped the cost of producing hyper-personalized attack assets significantly, driving phishing volume up exponentially.
When adversaries deploy autonomous agents to generate targeted lures, synthetic video, and deepfake audio in seconds, SecOps teams manually reviewing abuse inboxes are fighting machine speed with human scale.
Without proper operational support, analysts are left managing a non-stop room service order of alerts, leading to analyst burnout, high dwell times, and a loss in operational efficiency.

To outpace modern adversaries, organizations must implement agentic SOC automation. By using multimodal AI agents to automate detection, correlation, and takedown workflows, security teams can reduce manual workloads by over 80%. This shifts analysts away from constant alert triage and enables them to focus on strategic risk reduction.
The traditional approach to employee awareness (i.e., annual compliance videos paired with predictable monthly phishing templates) is ineffective against generative AI. Studies show that 99.9% of individuals cannot distinguish a state-of-the-art AI voice clone from a real person, and over 62% of enterprises have already been targeted by deepfake-driven social engineering.
This vulnerability was underscored on the show floor at the Doppel Hotel during our Phish or Fact challenge. Even seasoned security professionals struggled to differentiate real communications from AI-generated voice clones and synthetic media.
The takeaway for security leaders: Click-through rates on generic email tests are a vanity metric. If an employee resists ten basic email lures but falls for a single, hyper-realistic AI voice clone impersonating their CISO, your enterprise remains vulnerable.
Organizations must transition from static, check-the-box security awareness training to human risk management:
Black Hat 2026 confirmed that the era of treating social engineering as a simple inbox problem or a user training issue is over. Attackers operate across channels, weaponize trust using generative AI, and scale infrastructure in seconds.
Missed our sessions at the Doppel Hotel in Las Vegas? Request a guided platform tour to learn how to break the social engineering attack chain before it reaches your workforce.