Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
Learn why deepfakes, lookalike domains, and synthetic identities require security teams to extend assume-breach thinking to impersonation.

‘Assume breach’ (opens in new tab) is a useful operating principle for enterprise security: Build as if an attacker will eventually get past the perimeter. That mindset led teams to adopt Zero Trust (opens in new tab), stronger endpoint controls, network segmentation, and tighter identity and access management.
The premise still holds in 2026, but the gap is that many of today's most effective attacks don't begin with an intruder forcing their way into a system. They begin with someone borrowing a trusted identity and persuading a legitimate employee to act.
An attacker can imitate an executive's voice, recreate a familiar face on video, register a nearly identical domain, or write in a colleague's style. Nothing has to look technically compromised. The request only has to feel credible long enough for someone to approve a payment, share credentials, reset an account, or bypass a control.
That's why ‘assume breach’ needs a companion principle: ‘assume impersonation.’
The Arup deepfake fraud case (opens in new tab) is a useful example. In 2024, an employee in Hong Kong received a message that appeared to come from the company's CFO and joined a video conference with people who appeared to be senior colleagues. The participants were deepfakes. The employee ultimately authorized 15 transfers totaling HK$200 million, or roughly US$25.6 million.
The case wasn't a story about malware slipping past endpoint detection. It was a story about a real employee using legitimate access, responding to a request engineered to look and sound authentic.
That distinction matters. Authentication can confirm that the employee is allowed to initiate a transaction. It can't confirm that the person instructing them is really the CFO. Network segmentation can limit lateral movement, but it can't evaluate the legitimacy of a face on a video call. An email gateway may inspect a message, but it can't protect a process that treats a familiar voice as proof.
The attacker didn't need to defeat every control. They found the point where technical trust became human trust and built the attack around it.
Most internal security controls answer technical questions.
That request may travel through a sanctioned channel and land on a managed device. It may contain perfect grammar, accurate company context, and a convincing explanation for its urgency. It may even come from a compromised account or a domain that differs from the real one by a single character.
This is how the social engineering attack chain moves through the seams between controls. Attackers establish infrastructure, launch the lure across one or more channels, engage the target, and push toward compromise. A tool that sees only the email, the domain, or the user action gets one fragment of the campaign rather than the whole operation.
Assume impersonation doesn't replace Zero Trust. It extends the same skepticism from network access to identity signals, business context, and high-impact requests.
An assume-impersonation model treats every identity cue as a claim that may need verification. A known display name is a claim. A familiar voice is a claim. A video feed, writing style, caller ID, and corporate logo are all claims. The higher the stakes, the stronger the proof should be.
This isn't a request to make employees suspicious of every ordinary interaction. It's a way to design safer defaults around the moments attackers value most: payment changes, password resets, MFA enrollment, payroll updates, sensitive data transfers, and exceptions to established policy.
The goal is to remove the burden of improvisation. Employees shouldn't have to decide, under pressure, whether a realistic voice clone is real. The process should tell them when a second check is required, which channel to use, and who must approve the action.
The principle becomes useful when it changes day-to-day controls. Four practices matter most:
These controls work best as a system. External monitoring can reveal what attackers are preparing. Email and phishing defenses can catch the lure when it arrives. Reporting, simulation, and training can strengthen the human response when an attacker reaches a person.
The original ‘assume breach’ model concentrated on what happens inside the environment. Impersonation often begins outside it, where attackers register domains, build fake profiles, gather public content, stage ads, and prepare synthetic identities.
Security teams need visibility across both sides of that boundary. They also need signals that connect them. A lookalike domain shouldn't sit in one dashboard while a related phishing email, employee report, and fake executive profile appear as unrelated events elsewhere.
Doppel’s platform is built around that connection. It links digital risk protection, human risk management, and email security through shared intelligence, while the threat graph maps domains, profiles, messages, and other artifacts into the campaigns behind them.
That changes what the organization can do with a signal. A threat discovered externally can inform simulation and training. An employee-reported message can sharpen detection and remediation. Email evidence can reveal infrastructure to disrupt before the campaign reaches more people.
Instead of asking each tool to win a separate fight, social engineering defense coordinates the response across the attack chain.
Attackers have learned that imitating trust can be cheaper and faster than breaking a technical control. Security architecture has to account for both paths.
Continue to assume that credentials can be stolen, devices can be compromised, and an adversary can gain access. Also assume a voice, face, account, domain, or message can be fabricated well enough to influence a legitimate user.
The practical answer isn't permanent distrust. It's better verification at high-risk moments, earlier visibility into attacker infrastructure, and connected defenses that can follow a campaign across channels. ‘Assume breach’ protects the environment after access is challenged. ‘Assume impersonation’ helps stop the attacker from borrowing trust in the first place.
See how Doppel helps security teams detect, disrupt, and defend against impersonation across the attack chain.
BLOG
Modern social engineering is a relentless, AI-orchestrated lifecycle. Learn how to map the five-stage attack chain—from setup to contact—and why a unified defense platform is the only way to outpace AI-driven social engineering attacks.
by Bobby Ford, Rahul Madduluri, and Alvin Lin