#328 Kevin Tian: Exploring Doppel's AI-Native Social Engineering Defense Platform
Episode
48 min
Read time
2 min
Topics
Career Growth, Productivity, Startups
AI-Generated Summary
Key Takeaways
- ✓Attack Kill Chain Framework: Social engineering attacks follow a predictable sequence—preparation, engagement, and asset seizure (money or data). Defenders should map security tools against each stage rather than treating attacks as isolated incidents. Doppel structures its entire platform around disrupting all three phases simultaneously across domains, social media, phone, and ad networks.
- ✓Phone Call Vectors Dominate Enterprise Breaches: Groups like Scattered Spider and Shiny Hunters compromise casinos, banks, airlines, and tech companies primarily through phone calls to customer support, IT helpdesks, and HR lines—not email. Security training programs that focus only on phishing emails miss the highest-impact attack vector currently being exploited against large organizations.
- ✓AI Agent Simulations Run Six-Minute Conversations Undetected: Doppel's offensive AI agent, which it calls Vibe Phishing, conducts deepfake voice calls where targets engage for an average of six minutes without detecting the deception. Organizations should test helpdesk and customer support staff specifically with multichannel simulations—not just phishing emails—because those roles are the primary targets.
- ✓Out-of-Band Verification Reduces Deepfake Risk Without Technology: When verifying someone's identity on a video call, ask them to show their phone's selfie camera view, pose questions about hyper-local topics, or reference fictional places to test for pre-scripted AI responses. Cross-referencing through a second known communication channel—a verified phone number or LinkedIn message—makes simultaneous multi-platform impersonation significantly harder to execute.
- ✓Ground Truth Data Scales Defensively: Doppel's business model—charging enterprises directly rather than monetizing ads—gives it verified ground truth on what legitimate brand activity looks like for each client. This data advantage compounds as more customers onboard, enabling more accurate threat detection. Enterprises should prioritize security vendors whose detection models train on verified organizational data rather than generic threat feeds.
What It Covers
Kevin Tian, cofounder and CEO of Doppel, explains how AI-native social engineering attacks—spanning deepfake phone calls, fake LinkedIn personas, SEO poisoning, and brand impersonation—are scaling faster than human defenses, and how Doppel's platform scans, takes down, and simulates these multichannel threats for hundreds of enterprise customers.
Key Questions Answered
- •Attack Kill Chain Framework: Social engineering attacks follow a predictable sequence—preparation, engagement, and asset seizure (money or data). Defenders should map security tools against each stage rather than treating attacks as isolated incidents. Doppel structures its entire platform around disrupting all three phases simultaneously across domains, social media, phone, and ad networks.
- •Phone Call Vectors Dominate Enterprise Breaches: Groups like Scattered Spider and Shiny Hunters compromise casinos, banks, airlines, and tech companies primarily through phone calls to customer support, IT helpdesks, and HR lines—not email. Security training programs that focus only on phishing emails miss the highest-impact attack vector currently being exploited against large organizations.
- •AI Agent Simulations Run Six-Minute Conversations Undetected: Doppel's offensive AI agent, which it calls Vibe Phishing, conducts deepfake voice calls where targets engage for an average of six minutes without detecting the deception. Organizations should test helpdesk and customer support staff specifically with multichannel simulations—not just phishing emails—because those roles are the primary targets.
- •Out-of-Band Verification Reduces Deepfake Risk Without Technology: When verifying someone's identity on a video call, ask them to show their phone's selfie camera view, pose questions about hyper-local topics, or reference fictional places to test for pre-scripted AI responses. Cross-referencing through a second known communication channel—a verified phone number or LinkedIn message—makes simultaneous multi-platform impersonation significantly harder to execute.
- •Ground Truth Data Scales Defensively: Doppel's business model—charging enterprises directly rather than monetizing ads—gives it verified ground truth on what legitimate brand activity looks like for each client. This data advantage compounds as more customers onboard, enabling more accurate threat detection. Enterprises should prioritize security vendors whose detection models train on verified organizational data rather than generic threat feeds.
Notable Moment
Tian revealed that after Doppel successfully shut down a recurring attack campaign, the threat actors were found complaining on Telegram that the technique was no longer effective—then immediately pivoted to targeting organizations without Doppel coverage, illustrating how deterrence works but never eliminates adversarial adaptation.
You just read a 3-minute summary of a 45-minute episode.
Get Eye on AI summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from Eye on AI
Why People Are Paying 10x More for AI | Sid Sheth, d-Matrix
Aug 6 · 50 min
Cognitive Revolution
1000 Designs a Day: Neural Concept's Thomas von Tschammer on AI-Native Engineering
Jul 1
More from Eye on AI
AI Agents Fixing Your IT Before You Even Know Something Broke | Erhan Giral & Ryan Manning, BMC Helix
Aug 3 · 59 min
The Indicator
How your phone keeps you scrolling ... even when you want to stop
Jun 19
More from Eye on AI
We summarize every new episode. Want them in your inbox?
Why People Are Paying 10x More for AI | Sid Sheth, d-Matrix
AI Agents Fixing Your IT Before You Even Know Something Broke | Erhan Giral & Ryan Manning, BMC Helix
"According to NASA's Definition of Life, I'm Not Alive" - Why Nobody Can Define Life | Dr. Kate Adamala
"According to NASA's Definition of Life, I'm Not Alive" - Why Nobody Can Define Life | Dr. Kate Adamala
6 in 10 Enterprises Can't Find the Root Cause When Their AI Workloads Fail | Paul Appleby, Virtana
Similar Episodes
Related episodes from other podcasts
Cognitive Revolution
Jul 1
1000 Designs a Day: Neural Concept's Thomas von Tschammer on AI-Native Engineering
The Indicator
Jun 19
How your phone keeps you scrolling ... even when you want to stop
Venture Stories
Mar 5
Parth Patil on Coding Agents, Building Reid AI, and What It Takes to Operate at the Frontier
Unchained
Jan 29
Crypto Sentiment Is Down Bad. The Reality Is Far Different, Says Ryan Watkins
Hard Fork
Jan 13
Can We Build a Better Social Network?
Explore Related Topics
This podcast is featured in Best AI Podcasts (2026) — ranked and reviewed with AI summaries.
Read this week's Startups & Product Podcast Insights — cross-podcast analysis updated weekly.
You're clearly into Eye on AI.
Every Monday, we deliver AI summaries of the latest episodes from Eye on AI and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime