For a long time, the cybersecurity industry has framed social engineering as a psychological problem. We treat it as a battle of wits between a charismatic con artist and an unsuspecting employee. The prevailing wisdom says that if we just train our people to better identify scams or tear down malicious infrastructure slightly faster, we can stay ahead of scammers.

But looking at the threat landscape from a purely threat-intelligence perspective tells us something entirely different: Modern social engineering is more than a psychological game. It's a highly optimized, industrialized deception economy.

Attackers run campaigns like hyper-efficient businesses. They have Customer Acquisition Costs, operational budgets, and strict Return on Investment (ROI) targets.

This is the part the industry doesn't like to sit with: If we want to truly break the social engineering attack chain, we have to stop focusing exclusively on building higher walls or executing reactive takedowns. We must target the one metric the adversary cares about most: their profit margin.

The industrialization of the attack chain

Generative AI, agentic workflows, and automated infrastructure deployment have dramatically collapsed the cost of running a cybercriminal enterprise.

A few years ago, orchestrating a highly personalized, multi-channel spear-phishing campaign required significant manual labor, native language fluency, and time. Today, an attacker can use specialized Large Language Models (LLMs) and automated orchestration platforms to deploy thousands of tailored campaigns simultaneously across email, SMS, LinkedIn, and collaboration tools for pennies on the dollar.

By some published estimates, the cost of producing a convincing lure has fallen by 95 percent. That reduction means attackers can send more messages and test more personas, channels, and narratives, then rapidly concentrate resources on whichever approach generates the highest return.

This shift has changed the nature of the attack chain. When infrastructure is cheap and automated, playing "whack-a-mole" with lookalike domains and fake social media profiles only gets you so far. It costs an adversary next to nothing to spin up a fresh typosquatted domain and an AI persona. Forcing them to spin up another one tomorrow is merely an inconvenience, not a deterrent.

With the median time to click a lure sitting at just 21 seconds, you're not looking at a control you can tune. Treating people as your last line of defense is a cost center the attacker is counting on. To achieve real disruption, defenders must exploit the structural vulnerabilities inherent in automated, industrialized attack chains.

Exploiting the vulnerabilities of automated pipelines

Industrialized attack pipelines rely heavily on two things to stay profitable: clean target data and predictable feedback loops. When you look closely at the modern threat lifecycle, these dependencies represent significant operational vulnerabilities.

1. Disrupting the reconnaissance ROI

Before an attacker ever sends a message, they spend resources gathering intelligence on your organization. They scrape public repositories, ingest corporate design languages, map out organizational hierarchies on LinkedIn, and buy leaked credential datasets.

Instead of trying to hide this data (an increasingly impossible task), forward-leaning threat intel teams are beginning to seed environments with defensive disinformation. By polluting the open-source intelligence (OSINT) pools that attackers use to train their target models, defenders go on the offense and inject friction directly into a malicious attacker's setup phase.

When an adversary's automated system builds a campaign based on poisoned or intentionally flawed data, the resulting lures fail instantly upon deployment, destroying the attacker's upfront capital investment.

2. Turning AI against itself: The compute drain

One of the most consequential shifts in modern social engineering is the use of AI conversational agents to engage victims over chat, voice, and text. Attackers use these bots to handle objections, build rapport, and guide victims through multi-factor authentication (MFA) bypass steps in real time. According to recent CISA cybersecurity guidance updates on emerging automated threats, these AI-driven interactions allow attackers to scale their operations exponentially.

But running these AI models requires compute power, and compute power costs money.

Defenders can exploit this by deploying specialized defensive conversational honeypots, or tarpits, designed to look like high-value internal targets. When an attacker's AI bot attempts to engage, the defender's AI engages back, dragging the malicious agent into an endless, circular, highly realistic conversation.

By keeping the attacker's automated infrastructure locked in a compute-heavy dialogue for hours or days, we actively drain their operational budget. We flip the economics: the attacker is forced to spend significant compute dollars interacting with a machine, netting them an absolute zero ROI.

3. Poisoning the attacker's telemetry

Modern threat actors rely heavily on telemetry. They track click-through rates, open rates, and successful credential harvests to optimize their campaigns dynamically. If a specific lure isn't converting, their automated systems automatically swap it out for a different angle.

If our security tools immediately block an inbound lure or show a loud "Access Denied" page on a credential harvesting site, we provide the attacker with clean telemetry. They know instantly that their asset has been burned, allowing them to pivot immediately to a new vector.

An intel-driven approach does the opposite, feeding the attacker's platform false validation signals. By letting the automated attack infrastructure believe it's succeeding (while safely isolating the interaction within a sandbox or virtualized workspace), we pollute their dataset. The attacker wastes time attempting to exploit a "successful" compromise that doesn't actually exist, blinding their telemetry and stalling their momentum.

Shifting from incident response to economic warfare

Breaking the social engineering attack chain requires threat intelligence and security operations teams to adopt the mindset of an economic adversary. In my 25-plus years on the receiving end of these threats, I have watched us win the technical-cost arms race and slowly lose the human-cost one. The encouraging part is that the lever has not changed: You win by making the cheap path expensive again.

When evaluating your defensive posture, ask yourself: Are we making it more expensive for the attacker to target us tomorrow than it was today?

That requires measuring more than alerts blocked or domains removed. Teams should also examine how much attacker time was wasted, how quickly infrastructure was forced to rotate, and whether repeated campaigns became less frequent or effective.

This is the exact philosophy that guides our research at Doppel. While traditional defensive tools focus strictly on the point of impact, true modern defense requires a comprehensive understanding of the threat actor's business model. By combining global cross-channel visibility with automated, API-driven disruption, we can systematically dismantle the profitability of the campaigns targeting them.

Tearing down a malicious site is a tactical win. But forcing an attacker to burn through their infrastructure budget, pollute their target databases, and waste their compute resources is a strategic victory. When you make targeting your organization an unprofitable venture, the adversary will simply take their business elsewhere.

To learn more about how to weaponize threat intelligence against automated adversary infrastructure, explore the Doppel Economics of Social Engineering analysis.

About the author: Josh Bartolomie is Vice President and Global Head of Threat Intelligence at Doppel, where he leads threat intelligence strategy across the full social engineering attack chain. With more than 26 years in IT and cybersecurity, he has built and led security operations centers, incident response teams, and threat intelligence programs for global organizations including ITT Inc., Exelis, and Cognizant, and most recently served as Chief Security Officer and VP of Global Threat Services at Cofense. At Doppel, he is focused on advancing the real-time curation and actioning of threat intelligence that disrupts social engineering attackers.

Josh Bartolomie — VP, Global Head of Threat Intelligence at Doppel https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpErQEMFqooQhzxa_QQZHjLIBHgbXTAnBk0JmpqUJU0TPkEXsnseXOEZRQnOw0BX1f827IQf-mvrqYuQ-UMa65iZ55rlgmN2EkZgU3vCCFYyJnHK1v73u6viJ-MBf-A0EQ0rt1Hjf5J5yQUClXoNydt75UOKmERrka4hu_Cx4NFwde77feZWvVxg8XMCg/s1700-e365/Josh.png
Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Twitter and LinkedIn to read more exclusive content we post.