#328 Kevin Tian: Exploring Doppel's AI-Native Social Engineering Defense Platform
Episode
48 min
Read time
2 min
Topics
Career Growth, Productivity, Startups
AI-Generated Summary
Key Takeaways
- ✓Attack Kill Chain Framework: Social engineering attacks follow a predictable sequence—preparation, engagement, and asset seizure (money or data). Defenders should map security tools against each stage rather than treating attacks as isolated incidents. Doppel structures its entire platform around disrupting all three phases simultaneously across domains, social media, phone, and ad networks.
- ✓Phone Call Vectors Dominate Enterprise Breaches: Groups like Scattered Spider and Shiny Hunters compromise casinos, banks, airlines, and tech companies primarily through phone calls to customer support, IT helpdesks, and HR lines—not email. Security training programs that focus only on phishing emails miss the highest-impact attack vector currently being exploited against large organizations.
- ✓AI Agent Simulations Run Six-Minute Conversations Undetected: Doppel's offensive AI agent, which it calls Vibe Phishing, conducts deepfake voice calls where targets engage for an average of six minutes without detecting the deception. Organizations should test helpdesk and customer support staff specifically with multichannel simulations—not just phishing emails—because those roles are the primary targets.
- ✓Out-of-Band Verification Reduces Deepfake Risk Without Technology: When verifying someone's identity on a video call, ask them to show their phone's selfie camera view, pose questions about hyper-local topics, or reference fictional places to test for pre-scripted AI responses. Cross-referencing through a second known communication channel—a verified phone number or LinkedIn message—makes simultaneous multi-platform impersonation significantly harder to execute.
- ✓Ground Truth Data Scales Defensively: Doppel's business model—charging enterprises directly rather than monetizing ads—gives it verified ground truth on what legitimate brand activity looks like for each client. This data advantage compounds as more customers onboard, enabling more accurate threat detection. Enterprises should prioritize security vendors whose detection models train on verified organizational data rather than generic threat feeds.
What It Covers
Kevin Tian, cofounder and CEO of Doppel, explains how AI-native social engineering attacks—spanning deepfake phone calls, fake LinkedIn personas, SEO poisoning, and brand impersonation—are scaling faster than human defenses, and how Doppel's platform scans, takes down, and simulates these multichannel threats for hundreds of enterprise customers.
Key Questions Answered
- •Attack Kill Chain Framework: Social engineering attacks follow a predictable sequence—preparation, engagement, and asset seizure (money or data). Defenders should map security tools against each stage rather than treating attacks as isolated incidents. Doppel structures its entire platform around disrupting all three phases simultaneously across domains, social media, phone, and ad networks.
- •Phone Call Vectors Dominate Enterprise Breaches: Groups like Scattered Spider and Shiny Hunters compromise casinos, banks, airlines, and tech companies primarily through phone calls to customer support, IT helpdesks, and HR lines—not email. Security training programs that focus only on phishing emails miss the highest-impact attack vector currently being exploited against large organizations.
- •AI Agent Simulations Run Six-Minute Conversations Undetected: Doppel's offensive AI agent, which it calls Vibe Phishing, conducts deepfake voice calls where targets engage for an average of six minutes without detecting the deception. Organizations should test helpdesk and customer support staff specifically with multichannel simulations—not just phishing emails—because those roles are the primary targets.
- •Out-of-Band Verification Reduces Deepfake Risk Without Technology: When verifying someone's identity on a video call, ask them to show their phone's selfie camera view, pose questions about hyper-local topics, or reference fictional places to test for pre-scripted AI responses. Cross-referencing through a second known communication channel—a verified phone number or LinkedIn message—makes simultaneous multi-platform impersonation significantly harder to execute.
- •Ground Truth Data Scales Defensively: Doppel's business model—charging enterprises directly rather than monetizing ads—gives it verified ground truth on what legitimate brand activity looks like for each client. This data advantage compounds as more customers onboard, enabling more accurate threat detection. Enterprises should prioritize security vendors whose detection models train on verified organizational data rather than generic threat feeds.
Notable Moment
Tian revealed that after Doppel successfully shut down a recurring attack campaign, the threat actors were found complaining on Telegram that the technique was no longer effective—then immediately pivoted to targeting organizations without Doppel coverage, illustrating how deterrence works but never eliminates adversarial adaptation.
You just read a 3-minute summary of a 45-minute episode.
Get Eye on AI summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from Eye on AI
AI Is Reading 15 Million X-Rays a Year With No Human in the Loop | Prashant Warier, Qure.ai
Jun 20 · 41 min
The Indicator
How your phone keeps you scrolling ... even when you want to stop
Jun 19
More from Eye on AI
Only 12% of Companies Generate Value From AI. Here's What They're Doing | Sanjeev Vohra, Genpact
Jun 18 · 59 min
Venture Stories
Parth Patil on Coding Agents, Building Reid AI, and What It Takes to Operate at the Frontier
Mar 5
More from Eye on AI
We summarize every new episode. Want them in your inbox?
AI Is Reading 15 Million X-Rays a Year With No Human in the Loop | Prashant Warier, Qure.ai
Only 12% of Companies Generate Value From AI. Here's What They're Doing | Sanjeev Vohra, Genpact
India Is Becoming an Architect of the Global AI Order | Ivana Bartoletti of Wipro
One Company Now Has More AI Agents Than Human Employees | Ryan Gavin of Slack
AI Is Already Resolving 90% of Customer Service Tickets - and It's Getting Smarter | Shashi Upadhyay, Zendesk
Similar Episodes
Related episodes from other podcasts
The Indicator
Jun 19
How your phone keeps you scrolling ... even when you want to stop
Venture Stories
Mar 5
Parth Patil on Coding Agents, Building Reid AI, and What It Takes to Operate at the Frontier
Unchained
Jan 29
Crypto Sentiment Is Down Bad. The Reality Is Far Different, Says Ryan Watkins
Hard Fork
Jan 13
Can We Build a Better Social Network?
The Genius Life
Dec 29
537: How to Reset Your Nervous System, Heal Chronic Inflammation, and Tame Autoimmunity | Kevin Tracey, MD
Explore Related Topics
This podcast is featured in Best AI Podcasts (2026) — ranked and reviewed with AI summaries.
Read this week's Startups & Product Podcast Insights — cross-podcast analysis updated weekly.
You're clearly into Eye on AI.
Every Monday, we deliver AI summaries of the latest episodes from Eye on AI and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime