Join Doppel at Black Hat USA 2026 to win The Bigger Carry-On suitcase from Away
Research

15 Real Social Engineering Attack Examples and How to Spot Them

See 15 real social engineering attack examples across email, voice, text, and the web, plus the red flags that catch them before damage is done.

How AI Agents Track Multi-Channel Phishing Attacks

An accounts payable specialist opens an email from a supplier she has paid for years. The message carries updated banking details for an outstanding invoice. Minutes later, a caller who knows the invoice number and names the supplier's account manager confirms the change. She updates the record. The next payment lands in an attacker's account.

That is what social engineering looks like when it works. Social engineering examples across email, voice, text, the web, and the physical world share the same pattern: trusted context turns routine action into the attack path.

Spotting them by sight is getting harder as attackers clone brands and personalize lures at scale. In 2024, phishing and spoofing topped the cybercrime charts, with 193,407 complaints, and the 2025 DBIR traced a human element to 60% of breaches.

Key takeaways

  • Social engineering works by turning trusted context into the attack path, so the same lure succeeds across email, voice, text, web, and physical channels.
  • This guide breaks down 15 real-world attack examples across every channel attackers use, anchored in real, recent campaigns where they sharpen the picture.
  • The same red flags recur across every channel: manufactured urgency, requests that route around normal controls, contact points that can't be independently verified, and pressure tactics that target emotion or authority.
  • Recognition alone no longer scales against AI-generated lures and multi-channel campaigns, so modern defense pairs employee training with multi-channel detection and infrastructure takedowns that disrupt the attack at its source.

What is a social engineering attack?

A social engineering attack manipulates a person into sharing credentials or taking an action that exposes money or access. It tricks someone into revealing information through a trusted channel that makes the request feel routine.

Firewalls inspect packets. MFA checks credentials. Neither inspects the fabricated context that convinces an employee to act. Attackers pull the same psychological levers: authority makes a request hard to refuse, a false sense of urgency short-circuits evaluation, fear pushes compliance, and the instinct to be helpful turns a favor into an opening.

The payoff rarely requires a technical exploit. A single believable instruction can reroute a wire or surrender a credential.

Email-based social engineering attacks

Email remains a high-volume channel because it reaches employees at scale while letting an attacker impersonate a trusted brand or colleague. These four plays range from a mass blast that nets whoever clicks to a single wire-fraud email aimed at one finance approver.

1. Mass phishing email

A brand-spoofed message blasts thousands of inboxes and routes anyone who clicks to a cloned login page. A SharePoint-spoofing campaign used a "shared document" lure to route recipients through a Tycoon2FA CAPTCHA page that intercepts session tokens in real time and defeats MFA.

2. Spear-phishing email

Attackers research one named person and reference a real project or vendor so the message feels trusted, then ask the target to open a weaponized attachment or click a tailored link. A Star Blizzard campaign invited a target to join a WhatsApp group, then served a QR code that links a WhatsApp account to an attacker-controlled device once scanned.

Catching it depends on the same phishing red flags that apply to mass campaigns, only tuned to one person.

3. Business email compromise

An email impersonating the CEO or a known supplier instructs finance to send an urgent payment or update banking details, with no link or malware to flag. In the vendor variant, accounts payable pays an invoice that looks real except the remittance details point to an attacker account; in one documented case, a homebuyer wired a substantial sum on a spoofed email from a supposed attorney.

BEC remains among the costliest reported cybercrime categories and is the canonical targeted email attack on businesses.

4. Quishing (QR-code phishing)

An email embeds a QR code that moves the attack onto the target's phone, beyond corporate email filters. Tax-themed emails carrying a personalized W-2 attachment with a QR code routed targets to a Microsoft 365 sign-in clone on the SneakyLog platform.

Voice and phone-based social engineering attacks

A phone call adds the pressure of a live human voice, which is why attackers use voice when they need real-time persuasion or want to defeat a control a written message cannot. These three plays range from a scripted pretext call to an AI-cloned executive voice.

5. Vishing (voice phishing)

A caller posing as the bank's fraud team, IT support, or a government agency uses urgency to talk the target into reading back a one-time code or approving an account action. Scattered Spider has run help desk reset calls for years, a playbook tied to high-impact ransomware incidents.

6. Deepfake voice fraud

An AI clone of an executive's voice, built from a short sample of public audio, calls an employee to authorize an urgent transfer. In a historical enterprise case, an executive took a call from someone who sounded exactly like his parent-company boss and wired roughly $243,000 to the caller's account, growing suspicious only when the same voice called back asking for a second payment.

7. Callback phishing (TOAD)

An email about a fake charge prompts the target to call a number, where a live agent walks them into installing remote-access software. Silent Ransom Group emails a link to remote access software when the victim calls to cancel. TOAD stands for telephone-oriented attack delivery, and the structure works because the phone call feels like the resolution.

Text- and chat-based social engineering attacks

A text or chat message lands on a personal device people check quickly and strips away much of the context an inbox would surface. These two examples span consumer-style SMS scams and the executive-impersonation plays increasingly run inside work messaging apps.

8. Smishing (SMS phishing)

A text impersonating a courier, toll authority, or bank pushes the target to a cloned page that captures payment details and one-time codes. Attackers run platforms such as Lucid smishing kits to impersonate couriers and major banks at scale through channels carrier spam filters cannot easily inspect. The same playbook drives most SMS phishing seen against enterprise brands today.

9. Messaging-app executive impersonation

A WhatsApp or Telegram message from someone claiming to be an executive asks an assistant to buy gift cards or push a quick payment before a fabricated deadline. An unexpected message from a "boss" asks an urgent favor and instructs the target to send gift-card numbers back. The same pattern shows up across WhatsApp scam activity, where authority and urgency carry the lure on their own.

Web and device-based social engineering attacks

Some attacks wait where the target already goes or leave bait for the target to pick up. These three examples turn a trusted website, a search result, or a found device into the lure.

10. Watering hole attack

Attackers compromise a legitimate website a target group already visits so that simply browsing it serves malware. In one South Korean watering-hole campaign, employees visited media portals seeded with scripts that redirected profiled targets to a fake software-vendor site that delivered a backdoor.

11. Malvertising and poisoned search results

Attackers buy ads or game search rankings so a poisoned result for common software sits at the top, sending a target to a fake download page. Users searching for VPN software hit spoofed sites near the top of results that redirected to a trojanized installer, and separate campaigns have pushed fake KeePass and Google Authenticator downloads through paid search.

12. Baiting

A curiosity or freebie hook gets the target to introduce malware themselves. Attackers have delivered first-stage malware through encrypted cloud archives hosted on trusted services, and removable media remains another baiting vector.

Social platform and in-person social engineering attacks

Attackers also work channels where people may drop their guard, including a social feed, a job inbox, or the front door of the building. These three examples round out the surface, from a hijacked support reply to someone walking in behind an employee.

13. Angler phishing

Attackers run a fake brand support account that intercepts a customer's public complaint, then sends a direct-message "fix" link that harvests login or payment details. A fake support account replies fast to a frustrated customer and asks for booking references or account credentials, the kind of customer impersonation fraud brand teams now track across social.

14. Fake recruiter and job-offer scam

A message from a fake recruiter on a professional network extends a too-good offer, then uses an "onboarding" step to plant malware through a poisoned assignment file. Attackers have used fictitious LinkedIn job messages as the social pretext for compromise.

15. Tailgating and physical pretexting

An attacker posing as a delivery driver, contractor, or new hire follows an employee through a secure door. Physical access becomes the foothold. Tailgating pretexts include delivery covers, fake documentation, and observation of visitor policies that exploit the impulse to be helpful.

How a social engineering attack unfolds

Different as these 15 examples look, most move through the same five-stage social engineering attack chain:

  1. Reconnaissance. Attackers harvest names from LinkedIn, press releases, and data broker sites, then map who holds the access worth targeting. A short audio sample can become voice-clone material.
  2. Weaponization. That reconnaissance becomes infrastructure: lookalike domains, pixel-perfect cloned login pages, and fake support and recruiter profiles, all built before any lure goes out. Typosquatting and combosquatting variants are the most common domain plays.
  3. Delivery. The lure reaches the target through whichever channel carries the most trust: email, text, phone, or QR code.
  4. Persuasion. Impersonated authority and a manufactured deadline push the target to decide before they verify, and a multi-channel handoff reinforces the story.
  5. Execution. The target wires the money, reads back the one-time code, installs the remote-access tool, or holds the door.

The chain explains why the 15 examples above look different on the surface but follow the same script underneath.

How to spot a social engineering attack

Across all 15 examples, the same handful of tells give the attack away. Work through these four checks before acting on any unexpected request.

1. Check for manufactured urgency

Urgency over a routine stake is the most durable tell. A false sense of urgency is a primary red flag, and the fix is to slow down. If the request would normally allow time for review, treat the rush itself as the signal.

2. Check whether the request routes around a normal control

Any request that asks you to bypass a standard step deserves suspicion. Financial institutions and government agencies do not call or text to ask a client to change sensitive details, and legitimate workflows rarely require sharing a password or sidestepping an approval.

3. Verify the contact point independently

A contact point you cannot independently verify is the tell: attackers spoof caller ID and alter a sender address by a single character to imitate the real one. Discard the contact information in the suspicious message itself and reach the supposed sender through a website you know is real or a number on file.

4. Watch for emotional or authority-based pressure

A lure that targets emotion is engineered. Messages that make you panic or feel fearful or that lean on the authority of someone official are distinct scam indicators, and recognizing the pressure tactic is often enough to break it.

Why spotting social engineering by sight no longer scales

A single alert employee in one moment cannot carry an organization. AI generates flawless, personalized lures faster than people learn the tells: the grammar errors training taught people to spot are gone now that AI helps attackers write perfectly written emails. AI-automated phishing emails hit click-through rates of 54%, compared to 12% for standard attempts.

The campaign behind any one lure also fragments across channels, so any one employee only ever sees a slice of it. Attackers design the handoff that way, and they route through channels that strip away the cues recognition depends on: QR codes obscure destinations, voice carries fewer written cues, and a single-channel security tool sees only its own slice of the multi-stage chain. That gap is the case for multi-channel, graph-driven defense.

How Doppel defends against social engineering attacks

The AI-native Social Engineering Defense platform unifies Digital Risk Protection and Human Risk Management on one intelligence layer to disrupt the attack before it reaches the employee.

Doppel DRP finds and dismantles the lookalike domains, spoofed support profiles, cloned login pages, scam ads, and malicious numbers seen across these attacks, spanning brand and impersonation protection across domains, social, ads, app stores, messaging, telco, dark web, and crypto.

Legacy takedown workflows most often miss the telco channel; direct provider relationships pull it down in the same action as the rest of the infrastructure, closing the SMS and voice legs that feed vishing, smishing, and deepfake-voice campaigns. The Doppel Threat Graph maps an attacker's connected infrastructure into a single campaign-level view so a takedown disrupts the entire campaign in one action.

Doppel HRM builds the recognition reflex employees need. Dynamic Simulation runs multi-channel exercises across email, voice, SMS, Microsoft Teams, and WhatsApp, including deepfake voice scenarios, and one click converts any threat DRP detects into an employee simulation.

Voice agents navigate IVR trees and hold queues to test the help desk reset path Scattered Spider has run for years, and they can pivot mid-call to an email or SMS handoff so simulations mirror how live campaigns actually chain channels.

By April 2026, email had emerged as a leading source of attacker activity against financial services and fintech brands alongside social and messaging.

Make social engineering harder to run against your organization

Dismantle the impersonation infrastructure attackers build, drill the workforce against live tactics, and every attempt costs more than it returns. The attackers already crossed into multi-channel, AI-scale campaigns. The defense has to follow.

Request a demo to see it in action.

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.