Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
How account takeover attacks get assembled on surfaces you do not operate, why your first record opens at the login, and the four moves that shrink the surface.
by Jordan Evers

A caller asks a service desk to reset a password and transfer multi-factor authentication (MFA) to a new phone number. Once the desk approves the request, the caller operates as one of your people through a session your own controls approved. That session appears authorized (opens in new tab) to downstream systems, which is what makes the takeover hard to catch.
Every social-engineering (opens in new tab) route into an account gets assembled somewhere you do not operate, and two of those surfaces cannot function without announcing themselves. A lookalike name has to resolve through a new registration (opens in new tab), and a scam support number has to be reachable through the fake sites and profiles (opens in new tab) that promote it.
External providers add a third point of exposure when they issue or restore access on your behalf, and third-party involvement in breaches (opens in new tab) keeps climbing.
This article covers what an account takeover is worth, how one unfolds across five stages, what three recent cases came in through, why login-side defense arrives late, and the four moves that shrink the surface.
An account takeover (opens in new tab) is an attacker authenticating as one of your people and inheriting that account's permissions, so what follows looks like work. This article follows the takeovers that run through the people and infrastructure around your brand, so credential theft by malware on a managed device and abuse by someone who already holds access (opens in new tab) reach the same outcome by a different route.
What the account can reach decides the price of the compromise.
A mailbox with no approval rights is a nuisance. Finance approval rights can move money, and IT administrative rights include granting access. A support agent who can reset other people's credentials can create new takeovers.
Each of these accounts is itself an authentication authority, even though the entry usually ran through ordinary credential harvesting (opens in new tab). Severity is a property of the role, so rank a compromised approver above a compromised mailbox.
A password reset does not touch active sessions or consented applications. A live session can persist (opens in new tab) after a password change, and a consented application can retain access (opens in new tab) after normal password or MFA remediation.
The attacker keeps operating through an artifact the reset did not revoke, and from there the access travels into connected SaaS through island hopping (opens in new tab).
An account takeover runs the same five stages as any other social engineering campaign. Doppel maps them as the social engineering attack chain (opens in new tab), and the stages below are where attackers build the pieces.
Three recent cases point the same way: in each, the step that decided the outcome ran through someone you would not operate.
Third parties do not always secure their own access: fewer than a quarter have fully remediated (opens in new tab) missing or improperly secured MFA on their own cloud accounts.
Your identity platform is doing its job when it checks the factors presented and flags anomalous tokens (opens in new tab). Defense still arrives late for two reasons that sit outside it: sequence and ownership.
Your own first record of the takeover begins at the moment someone signs in. Your mail gateway may log the lure in transit, but everything else in the buildup ran on infrastructure you do not operate.
Two of those pieces still surface on their own: a name has to resolve before anyone can visit it, and the certificate issued to that name gets published to a public log (opens in new tab) where anyone can watch it appear.
Your identity platform does raise those detections for anomalous sessions and stolen session cookies, and they fire at sign-in.
The verification step attackers aim at is frequently run by someone whose policies you do not write. A service desk you contract completes the reset, a contractor holds the session, and a carrier holds the number that receives the code.
Designing that step (opens in new tab) is its own discipline.
Harden the sign-in and attackers move to the paths that transfer or reset a factor. Phishing-resistant authentication (opens in new tab) takes away the relay's credential-capture path, so enrollment and recovery become the target instead.
Device-bound session protections (opens in new tab) cover specific client scenarios today, so check what your own stack covers for browser sessions.
These four moves strengthen factor recovery, expose lookalike infrastructure, identify post-login abuse, and test reset decisions. Together they reduce how often a takeover succeeds and shorten how long an attacker keeps access, without ending the category.
Enrollment and recovery are where a strong factor gets swapped for a weak one, through MFA re-enrollment, a recovery email or phone standing in as a second factor, or self-service reset. Treat any change to an authentication method as a high-risk action that needs a second, stronger verification before it goes through.
Weigh device-swap indicators (opens in new tab) such as SIM changes or number porting before a one-time code goes to a phone number at all. Password reset fraud (opens in new tab) runs through exactly these paths.
Two of these surfaces cannot operate without showing themselves. A lookalike name has to resolve, and its certificate gets logged as it is issued, the signal behind lookalike domain monitoring (opens in new tab): what you act on is the moment a permutation goes active.
A spoofed support number (opens in new tab) has to be reachable to work, so any number that starts answering in your name is part of your authentication path. Exposed credentials are the exception. They do not announce themselves; they get traded, so you watch for the moment a set surfaces outside your walls.
Three post-login signals point to a live compromise: a new authentication method (opens in new tab) added, an unrecognized third-party application granted consent (opens in new tab), and one session identifier showing up from a second address.
When you see them, revoke the active session (opens in new tab) as well as resetting the password, because a relayed session (opens in new tab) keeps working after the credential changes.
The people who approve a reset or return a callback are making an authentication decision. The rehearsal has to apply the same multi-channel pressure (opens in new tab) a real attempt applies, including the pivot to email or SMS when the first pretext stalls.
Help desk vishing exercises (opens in new tab) recreate that pressure, whoever answers the phone.
Doppel is the AI-native Social Engineering Defense (opens in new tab) (SED) platform, unifying Digital Risk Protection (opens in new tab) (DRP) with Human Risk Management (opens in new tab). Against account takeover, it works the stage that runs before your identity platform has anything to authenticate.
The Doppel Threat Graph (opens in new tab) correlates one lookalike sign-in page or one spoofed support number into the operator's whole infrastructure (opens in new tab), and agentic takedown acts on that estate while analysts take the complex escalations. Brand Protection (opens in new tab) detects and dismantles it at campaign scale (opens in new tab).
Two populations decide how the human paths hold. Executive Protection (opens in new tab) detects credential and personal-data exposure for prominent individuals, whose approval and reset rights make a takeover worth the most, and extends to the family and data-broker exposure (opens in new tab) attackers build pretexts from.
Simulation (opens in new tab) rehearses the reset decision with everyone who can approve one, including outsourced desks and contractors, through its Helpdesk Mode, so the person a real attacker calls has already taken that call.
The login is where an account takeover becomes your problem, and the pieces that produced it were assembled on surfaces that had to announce themselves to work. Ask who is watching the registrations and certificates standing up against your brand, and whether that coverage reaches the numbers answering in your name.
Reaching that part of the sequence while it is still being built shortens the next campaign's window before it gets to your login. Request a demo (opens in new tab) to see the infrastructure already mapped in the Doppel Threat Graph.