Doppel’s Kevin Tian on Combating AI-Powered Threats with Smarter Identity Verification
Kevin Tian, co-founder and CEO at Doppel, discusses how the rise of AI-driven social engineering and multi-channel attacks demands stronger identity verification. New investments aim to scale services and drive innovation in cybersecurity defense.
Transcript
Hey guys, thanks for the throw. We're here with Kevin Teen, who's the CEO of Doppel, and we're talking about a social engineering defense framework. 'cause these attacks are changing and they are, of course, are coming off, raising 35 million in additional funding.
But let's dive into what's going on here. Kevin, welcome to show. Thank you for having me, Mike.
Well, let's get started with the simple thing. What exactly is a social engineering defense framework? 'cause I feel like we've been fighting this fight for a long time.
So what's changing here? Absolutely. It's a great question.
Um, well, you know, first of all, right, it starts off with the premise of framework, right? Like what, what, what's different today, like you said, you know, we've been battling social engineering for many decades now. Um, and, you know, and the quick TLDR, there's ai, right?
With ai, it's easier than effort to not only do, you know, deep fakes and synthetic content, but to personalize these complex social engineering campaigns at scale. And so, you know, taking a step back even further, right? If you look at how, uh, companies in the Fortune 500, or even more specifically in the Fortune 100 have been breached in the past 18 to 24 months, it's been due to a social engineering attack.
And, you know, and again, to make it even more concrete, right? Like the whole idea is that, look, if I'm gonna go attack your organization today, I've got much more weapons at my disposal today than just the traditional phishing email. And so that's where this framework comes from.
So what do those attacks look like? 'cause I mean, we all hear about deep fakes, but we also hear about how they're kind of multi-pronged and yeah. Multiple phases, and they're good at like tacking you through your phone, but then getting you to move over to a Zoom account and it all feels exactly more natural.
Exactly. I mean, it's just, you know, how, how we like to think about it, right? Everything's multi-channel, multi-pronged, multi-touch, right?
Almo almost just like a marketing team would, right? If they're trying to reach a certain account. Um, but you know, what we've seen in these past 18 to 24 months with the largest enterprises in the world, um, a lot of these phishing attacks, these credential theft, you know, they go beyond the email.
They, you know, sometimes orchestrate through SMS attacks. Sometimes they're orchestrated through, you know, uh, certain encrypted chats like, you know, WhatsApp or Telegram. Um, you know, mal advertising has been an interesting attack vector as well with SEO poisoning.
So basically, if I go Google, you know, my company's login page, right? How do, how do you make sure that a phishing site doesn't show up as the number one result from Google? Um, so there are things like that where, you know, it may seem, you know, in retrospect like, Hey, you know, how could someone fall for this?
But it happens, um, all the time, and it happens with increasing sophistication due to ai, right? How easy it is now to have AI spoof these attacks, you know, run these multichannel campaigns, do it in a very personalized manner, you know, change the language, right? And o oftentimes a lot of these attacks attack, uh, a lot of these attacks are targeting global organizations.
So again, AI is really a big accelerant there to, um, enable global attack. Are the bad guys further down the path of using AI than we are? That's a good, good question.
I mean, you know, in some ways, yes, some ways no, right? Like, I actually think in terms of what the good guys have access to, um, you know, obviously there's a lot of cutting edge AI stuff coming out when it comes to sales and marketing, advertising, things like that. And so almost every single modern business today, right, is taking advantage of AI for those different campaigns, those different efforts, um, and in a lot of ways those may even be more cutting edge than what some of these bad guys are using.
Um, but at the same time, right, bad guys are using these tools for different purposes. Um, and so those, for those different purposes, they're, you know, um, they're doing stuff that we wouldn't necessarily do with ai, right? As a company at Doppel.
So, um, you know, ultimately, you know, the, the bigger question, right? Is how is this translating into results and outcomes? And you know, again, just from what we've seen over the, you know, the lifespan of the company, um, these attacks have grown rapidly in terms of velocity, in terms of volume, and in terms of the variety that we're seeing.
So the three vs there, So the framework itself, is it using AI to combat ai? Are we involved in some sort of AI arms race here? Yeah, I mean, AI is certainly critical because specifically for that volume and velocity piece of that three vs framework, right?
Like, um, you know, if bad guys can now spin up these attacks and it just costs them a few cents to spin them up, we gotta make sure that, you know, our response capabilities, you know, whether it's mitigation internally or whether it's a full disruption of the threat active framework, uh, can also scale to that same unit economics. Um, and so a lot of our job, you know, on the good guys side, right, is how do we just make sure that we can keep raising that cost for the bad guys and, and make it, you know, a lot less economically feasible for them to target our clients. Um, and so that's why the AI piece is critical on the defense side.
It's because, again, if the bad guys are using AI to, you know, significantly reduce the cost of these attacks, we need to make sure that we can keep up from the unit economics perspective. As I think about it, the attacks themselves are increasing in both volume and sophistication, but it also seems like, um, they're not necessarily smashing grab anymore. They are stealing credentials and then kind of watching and see how workflow emerges and then inserting themselves into almost like they're part of the team and then striking.
So, um, you know, has the nature of this whole game just changed? I'd, I'd say yes, right? I mean, you know, not necessarily, again, social engineering of course has always existed.
Um, you know, these threat actors have always existed for many decades now. Um, but in terms of what has changed, um, in terms of, you know, how we need to think about these attacks again, it's just the fact that if you do have the capability now with AI to automate a lot of these multi-channel, multi-touch attacks, how does that change? You know, how we need to defend.
And, and so, you know, our perspective from doppel side, right? Is that we gotta make sure that we can cover all these different channels now, um, and go beyond the email. So we need to cover the SMS channels, we need to cover, uh, the social media channels, we need to cover, you know, the, uh, paid ads channels, the search engine channels, things like that.
Um, and just because they're not considered traditional, you know, corporate channels doesn't mean that the threat actors won't take advantage of that. And so, um, and so again, you know, in terms of what we've seen change and what we've seen be different, um, and this is again, just based off the data from, you know, what we've seen in the industry, um, just again, the velocity and the sophistication of these attacks are just on another level. And there, the multi-channel really is the key piece there.
So how do I verify somebody who's who they say they are? Because, you know, essentially we're reaching a point now where I have to assume that everybody who is reaching out to me is not who they are until proven otherwise. So how do I verify who's who and what's legit?
Yeah, no, it's a great question. I mean, it's certainly something that, you know, we're all paranoid about with the LinkedIn connections coming in and things like that is, you know, is this really a real person? Um, or is this a fake persona that's gotten enough people to accept their LinkedIn connections to make them look like a credible profile online?
Um, in terms of how to verify, uh, you know, it's, it's the same sort, you know, of course it depends on the context of the situation, um, but it just comes down to the same principles, right? Of, you know, we also need to be multi-channel in our verification, right? So whether it's your finance team making sure to not just, you know, validate the email, but make sure to do the, you know, phone call, the known phone call with the known number to the, um, you know, particular vendor or whether it's, you know, with these job applicants, right?
Where we're seeing, you know, fake personas come in through the job, uh, applicant market, especially with, um, a lot of what North Korea is orchestrating, even seeing folks in person, right? And, and then really doing your back channels, references, things like that because, um, you know, a lot of the identity verification's just not enough anymore, um, for a lot of those sorts of, um, interactions. Um, again, TLDR, you gotta go multi-channel and your verification process as well.
So does that mean we have to get to the point where, um, someone vouches for us? I mean, I've never met you before today, so for all I know, you're not actually who you are, but Right, somebody I do know introduced us and said, you are you. So, um, and of course I am, me theoretically, um, right?
Is that what we're kind of getting to at this point? Uh, yes. Um, but even then it's not foolproof, right?
Like if someone had compromised, um, you know, the person who had introduced us, right, Mike, and it turns out you're not actually, you know, who you say you are, things like that. Even though I have what I think is a social reference on you, um, even that may not be enough. And so a lot of it is, you know, everything is within context.
Everything is about collecting as many signals as you can from as many channels. And, um, you know, so of course before I hopped on this, you know, double check the LinkedIn, double check the email, double checked, um, you know, just seeing this video right now and looking for signals of deep fakes, things like that, um, everything is within context. Um, but yeah, even, even the social references and even a foolproof solution just given what we're seeing with some of these social engineering attacks.
So theoretically, if I have a social media footprint that didn't exist prior to five years ago, that might be a dead giveaway if I'm supposed to be in my fifties and have been in the business for 25 years, right? Yeah, I mean, this morning someone did a great post, they're actually automatically rejecting, uh, LinkedIn applicants who created their profile within the past, uh, six months. Um, but claim to have multiple years of experience.
And so very similar to what you just described, right? They, you know, of course there's probably gonna be a couple false negatives there. You know, some folks who are just coming online, LinkedIn, um, you know, maybe more, uh, latent in their career.
But, um, but just the, the, the hit rate of how many fake accounts are out there, they're finding it to be, you know, well over 90%. And so that's why they've implemented that policy. So you raised additional capital, what's the plan for that money?
What are you thinking and what needs to be done? It's doubled down, right? It's doubled down and scaling what, what's already working.
So we've got a lot of work to do on our go-to-market side to, you know, just continue to expand our service delivery right to as many clients as possible. Um, on the core r and d side, it's, you know, a lot of in invest in our core products, continue to scale it, continue to fine tune the AI models that we do have, um, keep up with the latest there. Um, and then of course, from the RD side, think about potential new bets and product expansions from our core platform.
Um, you know, we collect data that almost no other security company collects, right? CrowdStrike's not collecting fake LinkedIn profiles or, uh, mal advertising campaigns, or s smashing telephone numbers, things like that. And so with that unique social engineering threat graph that we have underneath the hood, how do we provide additional products to help our customers protect their businesses?
So at the core of the framework is essentially a social graph that you guys are tracking and helping me figure out what the relationship is between all these people who may or may not be real Social graph or, you know, we, we frame it as a threat graph because of course it's not necessarily people, but, you know, just these identities or these sorts of indicators, right? Um, but yeah, that's, you know, that's basically our unique, um, you know, unique differentiation in this market is, um, we're actually, we actually just shipped a new threat graph feature that shows how, you know, of course, again, a lot of traditional security companies will show you how email addresses are tied together, or IP addresses are tied together. We'll take that traditional framework and tie it to the new world framework where we're connecting it to telephone numbers, we'll, we're connecting it to the social accounts, uh, and we're connecting it to the advertiser IDs, things like that.
And so, again, whether it's about protecting your customers, whether it's about protecting your executives and your VIPs, or protecting your business, we just wanna make sure you have the most data possible to combat these threats. So, what's your best advice to folks? 'cause I think a lot of folks are so overwhelmed by all of this that they just give up and they hope for the best.
So is, is there some more rational way of approaching this? I mean, well, number one is don't give up, right? I think, uh, you know, there, there's a lot of work that's being done by multiple parties, right?
And the ecosystem to continue to innovate, continue to improve, um, what we can do from a capabilities perspective. Um, and that comes from both, you know, startups that are, you know, rapid growth innovators like us. And, and then of course the larger, uh, bigger companies as well are, you know, shipping new capabilities as well.
And then, of course, internal teams, right? And what, what we're seeing change in terms of security posture and security programs for a lot of our clients. So, um, cybersecurity, you know, always rapidly evolving, always, um, rapidly changing.
Um, but yeah, I mean, step one, don't give up, right? There's a lot that we continue to do to, um, improve our defenses and make sure that we're, we're doing what's right for, you know, our businesses. Alright, folks, you're heard in here.
Well, sadly we can't trust anyone, but the good news is, hey, we're working on it in this hole. Hey, Kevin, thanks for being on the show. Thank you for having me, Mike.
All right. And back to you guys in the studio.