Join Doppel at Black Hat USA 2026 to win The Bigger Carry-On suitcase from Away
Research

IDC Examines Social Engineering Defense: From Infrastructure to Inbox

IDC validates Doppel's framework: To stop modern social engineering, defenders must dismantle attack infrastructure across email, SMS, and voice instead of chasing messages.

IDC Examines Social Engineering Defense: From Infrastructure to Inbox

Doppel called the social engineering threat before the market had words for it: velocity, volume, and variety.

A new IDC Spotlight, sponsored by Doppel, From Infrastructure to Inbox: Defending the Full Social Engineering Attack Chain, now reaches the same conclusion in the same words: defenders need to match attacker velocity, volume, and variety by dismantling the infrastructure behind the operation, not chasing individual messages. When an analyst firm arrives at the language a vendor coined, that’s a category taking shape.

The picture IDC draws is stark. Attackers no longer work one channel at a time. AI lets them coordinate campaigns across email, SMS, voice, and social media with consistent messaging and no canned responses. The grammar mistakes and visual tells that employees and filters were trained to catch are gone. Voice cloning takes seconds of audio. Phishing infrastructure spins up in minutes from a single prompt.

And the costs are no longer abstract. The IDC Spotlight cites survey data showing that social engineering accounts for up to 24% of ransomware incidents, and FBI figures put cyber-enabled fraud losses at $17.7 billion in 2025, with business email compromise second only to investment fraud.

The research grounds this in attacks you already know: a vished help desk that ended in one of the most public casino breaches in history. An outsourced IT desk and a SIM swap. A $25 million wire transfer authorized on a video call where every executive on screen was a deepfake. Different channels, different entry points, same playbook.

The gap attackers count on

To us, the IDC’s Spotlight's sharpest observation is structural. Most organizations buy messaging security, digital risk protection, and human risk management as three separate products from three separate vendors. Each tool sees its own slice. None sees the campaign.

IDC puts it plainly: When a phishing email is reported and removed, the solution addresses one message, not the thousands or millions more the attacker will send from the same infrastructure. The attack chain stays intact. Only the symptom got treated.

A framework built for conversations, not payloads

Traditional kill chain models track malicious code. But in social engineering, as the IDC Spotlight notes, the payload is a conversation. That is why the IDC's Spotlight walks through the social engineering attack chain, the five-stage framework Doppel developed to map how these attacks unfold: set up the infrastructure, launch the communication, contact the target, engage the victim, compromise.

Every stage is an opportunity to break the chain:

  1. Find the lookalike domain before the first email is sent.
  2. Tie an inbox detection back to the infrastructure behind it and take it down.
  3. Turn the real attack into the training simulation, so employees learn from what is actually targeting them.

Where this goes next

We believe the IDC Spotlight's conclusion looks forward, and it should get your attention: The trend is moving toward agent-to-agent interaction, where attack messages are generated, delivered, and even answered with no human on either side. That is the fight Doppel is built for, and it is why social engineering defense stands as its own category.

Click here to read the full analysis, including the IDC Spotlight

profile of how Doppel defends across the entire chain.

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.