Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.

The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
Modern attacks reach targets via SMS, LinkedIn, and voice calls, not just email. Explore Contact, the third stage of the social engineering attack chain.

Somewhere in your organization today, an attack crossed the perimeter, and there is a good chance it did not come through email. It came as a text to a personal phone, a LinkedIn message, a WhatsApp note, or a call to the help desk, and the first voice in the exchange may not have been a person at all. This piece walks through Contact, the third stage of the social engineering attack chain: how modern attacks reach their target across channels your security stack cannot see, how one channel is used to make the next one believable, and what changes when you treat the pattern of contact, rather than any single message, as the thing to catch.
The perimeter most security programs defend is the one the attack no longer bothers with. Two decades of investment taught attackers exactly where our inspection points sit: the email gateway, the web proxy, the managed endpoint. The response was not to fight through those points. It was to go around them, to the target’s phone, their LinkedIn inbox, their WhatsApp, the help desk that answers for them. The attack still reaches the same person. It just crosses a perimeter no one is standing on.
That crossing is Contact, the third stage of the chain, and the first moment the attack depends on someone other than the attacker. Setup builds the conditions. Launch puts them in motion. Now a human enters the loop, and everything staged before this point was built for one purpose: earning that person’s trust.
The first piece in this series (opens in new tab) argued that social engineering is a chain, not an event. The second (opens in new tab) followed the money, and the third (opens in new tab) and fourth walked the buildout and the moment it went live. This piece follows the attack the rest of the way to its intended victim.
In the five-stage model, Contact is when the attack reaches the target and crosses whatever perimeter stands between the two. The definition is deliberately broader than “the phishing email arrives,” because the perimeter in question is no longer one boundary. It is the sum of every channel that can put a message, a call, or a request in front of your people: corporate email, personal SMS, social platforms, collaboration tools, messaging apps, paid ads, and the phone line at your help desk.
Contact is also where the pretext (opens in new tab) goes to work. The persona built during Setup (i.e., the recruiter, the vendor, the executive, the IT technician) stops being staged material and becomes the identity the target actually meets. Whether the target believes that identity for the thirty seconds it takes to click, or the thirty minutes it takes to reset a credential, is what this stage is for.
They pick the channel where you are weakest, not where you look hardest. Email still carries volume, but the growth is everywhere your controls are not: vishing calls (opens in new tab) that arrive with a caller ID and a script, smishing to personal devices, and outreach on WhatsApp (opens in new tab), where a message from a cloned profile lands with no gateway, no banner, and no reporting button in sight.
They target the people whose job is to be reached. The help desk exists to take calls from strangers and solve their problems quickly, which is exactly the posture an impersonator needs. Groups like Scattered Spider (opens in new tab) made a specialty of it: call the service desk as the employee, pass the weak verification, and have someone else’s credentials reset for you. The same logic finds every role that is rewarded for being fast and accommodating: support, recruiting, accounts payable, admissions and financial aid offices (opens in new tab).
They chain the channels. The modern contact is rarely one message on one surface. It is a sequence: an email that mentions a follow-up text, a text that references the email, a call that cites both. Each touch arrives on a different channel, so no single control sees more than one of them, and each touch quietly vouches for the last. Repetition across channels manufactures legitimacy. The target is not fooled by one convincing message; they are worn into confidence by a pattern that behaves the way real business behaves.
They no longer place every call themselves. The first turn of the exchange is increasingly automated: platforms sold to attackers for a few thousand dollars (opens in new tab) will run the opening conversation with a synthetic voice at scale, and hand the call to a human operator only when a target bites. The adversary economics covered earlier in this series apply here with full force. When the first contact costs nothing and sounds like a person, the attacker can afford to contact everyone.
The structural problem at this stage is coverage. Your inspection points sit on the channels you manage, and Contact increasingly happens on the ones you do not. A WhatsApp message to a personal phone never touches your mail gateway. A LinkedIn DM never crosses your proxy. A voice call to an employee’s cell exists, from your security stack’s point of view, nowhere at all. These are not exotic edge cases; they are the growth channels precisely because they are unwatched.
The subtler problem is that even the watched channels are watched one message at a time. A gateway scores the email on its own merits, and a well-built lure standing on aged, warmed, trusted infrastructure can score clean. What the gateway cannot see is that the same target got a text an hour later and a call the next morning, all citing each other, all from one operation. Message-level inspection was built for a world where the attack was a message. At Contact, the attack is a pattern, spread across channels on purpose so that no one control ever sees enough of it to judge.
There is one detection surface that does span every channel the attacker uses: the person being targeted. The employee who gets the email, the text, and the call is the only point in your enterprise where the whole contact pattern converges. Most programs treat that fact as the problem. Handled right, it is the best sensor you have.
The employee’s job at Contact is not to adjudicate whether the message is malicious; the adversary economics behind these attacks (opens in new tab) already make out-detecting an industrialized deception a race no employee can win. Their job is to report the odd contact fast. The program’s job is everything after: correlating that report with the lookalike domain flagged at Setup and the sending pattern seen at Launch, so one thirty-second report resolves an operation potentially aimed at hundreds of employees. Reported contacts, correlated at the campaign level (opens in new tab), are how the unwatched channels become watched: your tooling does not sit inside WhatsApp, but the people being contacted there already do.
Contact ends when the target responds, and an exchange begins. The reply is sent, the link is followed, the caller is engaged in conversation. That handoff is Engagement, the stage where the modern attack does its real work and the subject of the next piece. The boundary is worth marking because most of a defender’s mental model stops at Contact: message arrives, message is judged, done. The attacker’s model is just getting started. For them, Contact is not the attempt; it is the opening move of a conversation built to end in a payout.
The common mistake at this stage is judging each contact instead of recognizing the targeting behind them. A reported phishing email is scored, blocked, and closed. A suspicious text is ignored because it hit a personal device. The help desk logs an odd call and moves on. Each verdict may well be correct on its own terms. What gets lost is the question that matters most at this stage: is someone actively targeting this person, or this team, across channels?
No single message can answer that. Three clean-scoring contacts that cite each other are a campaign. One employee reporting a strange call likely means others were called and stayed silent. Contact-stage defense is not a better filter. It is the discipline of connecting contacts that look harmless on their own and seeing the operation behind them.
Contact is where the attack meets your people, on channels chosen because your controls are not on them, in sequences built so no single touch looks like much. The instinct this stage punishes is judging each contact on its own. The posture that works inverts the usual model: expect the perimeter to be crossed, make reporting the odd contact effortless, and put your investment into recognizing the pattern of targeting rather than perfecting the verdict on any one message. The attacker is counting on your channels staying siloed. The chain stops being invisible the moment they are not.
The next piece in the series enters the conversation itself: Engagement, the stage where the payload stops being a thing you can scan and becomes the exchange, and where much of our existing defensive logic quietly comes apart.
BLOG
Modern social engineering is a relentless, AI-orchestrated lifecycle. Learn how to map the five-stage attack chain—from setup to contact—and why a unified defense platform is the only way to outpace AI-driven social engineering attacks.
by Bobby Ford, Rahul Madduluri, and Alvin Lin