Doppel is the Official Social Engineering Defense Partner of the San Francisco 49ers

Company

Some Assembly Required: Verifying What's Real in 2026

Threats got more believable this year. See why familiar voices and faces no longer prove identity, and how to build verification into every communication.

Some Assembly Required: Verifying What's Real in 2026

The hard truth about fooling someone is that it takes so little nowadays: three seconds of audio. A good photo. A few sentences of your writing.

That's the reality we're confronting for this year's Cybersecurity Awareness Month. Every October, the industry uses this moment to take stock of how the threat landscape has shifted and what it means for how we protect ourselves.

This year, one shift stands above the rest: The threats have become more believable.

AI has made the fake indistinguishable from the real thing, across every channel a person might use to reach you: email, phone, video, text, a Teams call, or a LinkedIn message.

The numbers back up what most security teams already sense:

The thing you were trained to trust, like a familiar voice, a known face, or a signature writing style, is no longer proof of anything.

That's the problem this month is built to address, and it's why we're spending October the way we are: not with another round of generic phishing tips, but with a full month of content built around one question. In a world where you can't tell the real from the fake, what do you do instead?

Why traditional trust signals are breaking

Security awareness training has spent two decades teaching people to watch for tells: bad grammar, a slightly off email address, a caller ID that doesn't match, or an unnatural cadence in a voice. Those tells worked because convincingly faking a human used to take real skill.

That floor has collapsed. Generative AI erases the signals we used to rely on almost by design:

  • Perfect grammar and tone: LLMs don't make typos. The stilted, obviously-translated phishing email is a relic.
  • Voices that pass for real: Cloning no longer requires a skilled impressionist or hours of source audio. It just takes a few seconds pulled from a voicemail greeting, a podcast clip, or a company town hall to impersonate your voice.
  • Faces that move and respond: Real-time deepfake video can now hold a conversation, not just play back a static clip.
  • Correct-looking metadata: Spoofed numbers, lookalike domains, and cloned signature blocks make the "channel" itself look legitimate.

None of this is theoretical. Companies have lost tens of millions to help desk calls, deepfakes of company executives, and impersonated interactions. Not one of these started with malware. Each started with a human being convinced that they were talking to someone they trusted.

The old model of "spot the fake" assumed fakes would always carry some detectable flaw. In 2026, that assumption doesn't hold. If detection is your only line of defense, you're playing a game you've already lost, because the average person still clicks a phishing link in under 60 seconds (opens in new tab) of receiving it, and training alone barely moves that number.

Trust needs a process, not a feeling

When you can no longer tell the human from the fake by looking or listening, verification has to become a structured and repeatable process, not a gut check.

That’s the core idea behind social engineering defense (SED). You treat impersonation as a coordinated, multi-stage attack chain that starts with infrastructure (a lookalike domain, a cloned profile, a scraped voice sample) well before it ever reaches a human being.

By the time that "urgent" call or email lands, the attacker has already done the setup work. Trying to catch it purely at the moment of contact (e.g., by training someone to just notice something's off) puts all the weight on the least reliable control in the chain: a person's split-second judgment under intense pressure.

For example, it takes organizations an average of 260 days (opens in new tab) to identify and contain a social engineering attack. That’s the longest dwell time of any threat type, largely because tools and teams operate in silos and nothing connects the external infrastructure to what actually lands in an inbox or on a phone screen.

The fix is a verification protocol that doesn't depend on instincts at all. Instead, the protocol should assume any voice, face, or message could be synthetic and require proof before high-risk action, every time, regardless of how convincing the request feels.

What we're doing about it this month

Each week in October, we’ll release new resources built around this same premise: detection alone won't save you. Verification will.

Some will help you build the habit of verification into your own day-to-day communications. Some will help you see exactly where your organization's defenses are thinnest, so you know what to fix first instead of guessing.

And some of it, honestly, is just going to be fun. The best way to make a habit stick is to make it memorable, not mandatory.

Learn how Doppel can protect your brand from social engineering attacks

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.