Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.

The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
See 15 real social engineering attack examples across email, voice, text, and the web, plus the red flags that catch them before damage is done.
by Alvin Lin

An accounts payable specialist opens an email from a supplier she has paid for years. The message carries updated banking details for an outstanding invoice. Minutes later, a caller who knows the invoice number and names the supplier's account manager confirms the change. She updates the record. The next payment lands in an attacker's account.
That is what social engineering looks like when it works. Social engineering examples across email, voice, text, the web, and the physical world share the same pattern: trusted context turns routine action into the attack path.
Spotting them by sight is getting harder as attackers clone brands and personalize lures at scale. In 2024, phishing and spoofing topped the cybercrime charts, with 193,407 complaints, and the 2025 DBIR traced a human element to 60% of breaches.
A social engineering attack manipulates a person into sharing credentials or taking an action that exposes money or access. It tricks someone into revealing information through a trusted channel that makes the request feel routine.
Firewalls inspect packets. MFA checks credentials. Neither inspects the fabricated context that convinces an employee to act. Attackers pull the same psychological levers: authority makes a request hard to refuse, a false sense of urgency short-circuits evaluation, fear pushes compliance, and the instinct to be helpful turns a favor into an opening.
The payoff rarely requires a technical exploit. A single believable instruction can reroute a wire or surrender a credential.
Email remains a high-volume channel because it reaches employees at scale while letting an attacker impersonate a trusted brand or colleague. These four plays range from a mass blast that nets whoever clicks to a single wire-fraud email aimed at one finance approver.
A brand-spoofed message blasts thousands of inboxes and routes anyone who clicks to a cloned login page. A SharePoint-spoofing campaign used a "shared document" lure to route recipients through a Tycoon2FA CAPTCHA page that intercepts session tokens in real time and defeats MFA.
Attackers research one named person and reference a real project or vendor so the message feels trusted, then ask the target to open a weaponized attachment or click a tailored link. A Star Blizzard campaign invited a target to join a WhatsApp group, then served a QR code that links a WhatsApp account to an attacker-controlled device once scanned.
Catching it depends on the same phishing red flags that apply to mass campaigns, only tuned to one person.
An email impersonating the CEO or a known supplier instructs finance to send an urgent payment or update banking details, with no link or malware to flag. In the vendor variant, accounts payable pays an invoice that looks real except the remittance details point to an attacker account; in one documented case, a homebuyer wired a substantial sum on a spoofed email from a supposed attorney.
BEC remains among the costliest reported cybercrime categories and is the canonical targeted email attack on businesses.
An email embeds a QR code that moves the attack onto the target's phone, beyond corporate email filters. Tax-themed emails carrying a personalized W-2 attachment with a QR code routed targets to a Microsoft 365 sign-in clone on the SneakyLog platform.
A phone call adds the pressure of a live human voice, which is why attackers use voice when they need real-time persuasion or want to defeat a control a written message cannot. These three plays range from a scripted pretext call to an AI-cloned executive voice.
A caller posing as the bank's fraud team, IT support, or a government agency uses urgency to talk the target into reading back a one-time code or approving an account action. Scattered Spider has run help desk reset calls for years, a playbook tied to high-impact ransomware incidents.
An AI clone of an executive's voice, built from a short sample of public audio, calls an employee to authorize an urgent transfer. In a historical enterprise case, an executive took a call from someone who sounded exactly like his parent-company boss and wired roughly $243,000 to the caller's account, growing suspicious only when the same voice called back asking for a second payment.
An email about a fake charge prompts the target to call a number, where a live agent walks them into installing remote-access software. Silent Ransom Group emails a link to remote access software when the victim calls to cancel. TOAD stands for telephone-oriented attack delivery, and the structure works because the phone call feels like the resolution.
A text or chat message lands on a personal device people check quickly and strips away much of the context an inbox would surface. These two examples span consumer-style SMS scams and the executive-impersonation plays increasingly run inside work messaging apps.
A text impersonating a courier, toll authority, or bank pushes the target to a cloned page that captures payment details and one-time codes. Attackers run platforms such as Lucid smishing kits to impersonate couriers and major banks at scale through channels carrier spam filters cannot easily inspect. The same playbook drives most SMS phishing seen against enterprise brands today.
A WhatsApp or Telegram message from someone claiming to be an executive asks an assistant to buy gift cards or push a quick payment before a fabricated deadline. An unexpected message from a "boss" asks an urgent favor and instructs the target to send gift-card numbers back. The same pattern shows up across WhatsApp scam activity, where authority and urgency carry the lure on their own.
Some attacks wait where the target already goes or leave bait for the target to pick up. These three examples turn a trusted website, a search result, or a found device into the lure.
Attackers compromise a legitimate website a target group already visits so that simply browsing it serves malware. In one South Korean watering-hole campaign, employees visited media portals seeded with scripts that redirected profiled targets to a fake software-vendor site that delivered a backdoor.
Attackers buy ads or game search rankings so a poisoned result for common software sits at the top, sending a target to a fake download page. Users searching for VPN software hit spoofed sites near the top of results that redirected to a trojanized installer, and separate campaigns have pushed fake KeePass and Google Authenticator downloads through paid search.
A curiosity or freebie hook gets the target to introduce malware themselves. Attackers have delivered first-stage malware through encrypted cloud archives hosted on trusted services, and removable media remains another baiting vector.
Attackers also work channels where people may drop their guard, including a social feed, a job inbox, or the front door of the building. These three examples round out the surface, from a hijacked support reply to someone walking in behind an employee.
Attackers run a fake brand support account that intercepts a customer's public complaint, then sends a direct-message "fix" link that harvests login or payment details. A fake support account replies fast to a frustrated customer and asks for booking references or account credentials, the kind of customer impersonation fraud brand teams now track across social.
A message from a fake recruiter on a professional network extends a too-good offer, then uses an "onboarding" step to plant malware through a poisoned assignment file. Attackers have used fictitious LinkedIn job messages as the social pretext for compromise.
An attacker posing as a delivery driver, contractor, or new hire follows an employee through a secure door. Physical access becomes the foothold. Tailgating pretexts include delivery covers, fake documentation, and observation of visitor policies that exploit the impulse to be helpful.
Different as these 15 examples look, most move through the same five-stage social engineering attack chain:
The chain explains why the 15 examples above look different on the surface but follow the same script underneath.
Across all 15 examples, the same handful of tells give the attack away. Work through these four checks before acting on any unexpected request.
Urgency over a routine stake is the most durable tell. A false sense of urgency is a primary red flag, and the fix is to slow down. If the request would normally allow time for review, treat the rush itself as the signal.
Any request that asks you to bypass a standard step deserves suspicion. Financial institutions and government agencies do not call or text to ask a client to change sensitive details, and legitimate workflows rarely require sharing a password or sidestepping an approval.
A contact point you cannot independently verify is the tell: attackers spoof caller ID and alter a sender address by a single character to imitate the real one. Discard the contact information in the suspicious message itself and reach the supposed sender through a website you know is real or a number on file.
A lure that targets emotion is engineered. Messages that make you panic or feel fearful or that lean on the authority of someone official are distinct scam indicators, and recognizing the pressure tactic is often enough to break it.
A single alert employee in one moment cannot carry an organization. AI generates flawless, personalized lures faster than people learn the tells: the grammar errors training taught people to spot are gone now that AI helps attackers write perfectly written emails. AI-automated phishing emails hit click-through rates of 54%, compared to 12% for standard attempts.
The campaign behind any one lure also fragments across channels, so any one employee only ever sees a slice of it. Attackers design the handoff that way, and they route through channels that strip away the cues recognition depends on: QR codes obscure destinations, voice carries fewer written cues, and a single-channel security tool sees only its own slice of the multi-stage chain. That gap is the case for multi-channel, graph-driven defense.
The AI-native Social Engineering Defense platform unifies Digital Risk Protection and Human Risk Management on one intelligence layer to disrupt the attack before it reaches the employee.
Doppel DRP finds and dismantles the lookalike domains, spoofed support profiles, cloned login pages, scam ads, and malicious numbers seen across these attacks, spanning brand and impersonation protection across domains, social, ads, app stores, messaging, telco, dark web, and crypto.
Legacy takedown workflows most often miss the telco channel; direct provider relationships pull it down in the same action as the rest of the infrastructure, closing the SMS and voice legs that feed vishing, smishing, and deepfake-voice campaigns. The Doppel Threat Graph maps an attacker's connected infrastructure into a single campaign-level view so a takedown disrupts the entire campaign in one action.
Doppel HRM builds the recognition reflex employees need. Dynamic Simulation runs multi-channel exercises across email, voice, SMS, Microsoft Teams, and WhatsApp, including deepfake voice scenarios, and one click converts any threat DRP detects into an employee simulation.
Voice agents navigate IVR trees and hold queues to test the help desk reset path Scattered Spider has run for years, and they can pivot mid-call to an email or SMS handoff so simulations mirror how live campaigns actually chain channels.
By April 2026, email had emerged as a leading source of attacker activity against financial services and fintech brands alongside social and messaging.
Dismantle the impersonation infrastructure attackers build, drill the workforce against live tactics, and every attempt costs more than it returns. The attackers already crossed into multi-channel, AI-scale campaigns. The defense has to follow.
Request a demo to see it in action.