Skip to content
Social EngineeringProduct

The Communication Firewall is Live

Scammers now reach people on every channel they use for work: email, voice, text, WhatsApp, and Telegram. Nearly every major breach starts the same way, with a message or call that looks legitimate on a channel the company already trusts. Here's how it happens, and what we built to stop it.

Common Defense··3 min read
One defense. Every channel. The Common Defense communication firewall.

Scammers are increasingly targeting users across multiple communication channels, costing consumers billions. In 2025, the FTC reported $2.1B in losses to scams on social media, including $425M on WhatsApp, plus $1.1B to fake websites and apps, $1.1B to phone calls, $639M to text messages, and $569M to email.

2025 fraud contact methods, ranked by reported loss


Social Media
$2.1B
Website or App
$1.1B
Phone Call
$1.1B
Text
$639M
Email
$569M

Social media is Facebook $794M, WhatsApp $425M, Instagram $234M, and $599M across all other platforms.

Source: FTC, Consumer Sentinel Network. 2025 top fraud contact methods ranked by total reported loss.

Those are consumer losses, but attackers use the same channels to target some of the world’s largest companies. Every breach below started the same way: with a message or call that looked legitimate on a channel the company already trusted.

Take email, for example, the most heavily defended channel on this list. In January 2026, an attacker socially engineered their way into Betterment’s marketing platform and sent a fraudulent crypto promotion email to 460,000 customers. It bypassed every spam filter because it came from a platform authorized to send emails on Betterment’s behalf.

Sometimes it takes only a phone call. In June 2025, an attacker called a Google employee posing as IT support and convinced them to authorize a rebranded version of Salesforce’s Data Loader tool. That single approval gave the attacker access to one of Google’s corporate Salesforce instances, allowing them to export contact records of businesses before the access was revoked.

In 2022, attackers texted hundreds of Twilio employees while posing as internal IT and directed them to a fake Okta login page on a lookalike domain. Some entered their credentials, allowing the attackers to access internal admin tools and steal data belonging to 209 customers and 93 Authy users.

Email, voice, and text are not the only channels attackers exploit. In web3, finance, and international business, deals often happen through Telegram and WhatsApp, so malicious messages arrive alongside legitimate work.

Some attackers wait months, while others move in just a few days. In April 2026, Drift Protocol lost $285M after DPRK attackers, pretending to be a trading firm, spent six months building relationships with its contributors in person and over Telegram. That trust allowed them to share code and a wallet app containing malware, and from there they collected the signatures they needed to seize admin control of the protocol. That same month, Singapore Police reported that a caller impersonating the chairman of a company’s parent organization reached its CEO on WhatsApp and tricked him into authorizing $36.3M in transfers over four days.

Major Web3 losses that began with social engineering


$1.46B
Bybit, Feb 2025
A developer at Safe Wallet, Bybit's signing-UI provider, was socially engineered into running a malicious Docker project
$540M
Ronin, Mar 2022
A fake job offer on LinkedIn was delivered as a malicious PDF
$308M
DMM Bitcoin, May 2024
A fake recruiter sent a malicious coding test to a developer at Ginco, DMM's wallet provider
$292M
Kelp DAO, Apr 2026
A developer at LayerZero, Kelp's bridge provider, was tricked into cloning a malicious repository
$285M
Drift Protocol, Apr 2026
Contributors were socially engineered over Telegram for six months by a fake trading firm

Losses as reported by victims, their forensic investigators, and on-chain analysis. Ronin is $540M at the time of theft, widely reported as ~$620M at later valuations.

These incidents highlight the need for stronger security tools across modern communication channels. Email has the most mature defenses and monitoring tools, yet the Betterment scam still got through. WhatsApp and Telegram give a security team even less to work with because they cannot inspect incoming messages. We built Common Defense to help close that gap on email and on the channels that never had meaningful protection to begin with.

Common Defense is a communication firewall that protects WhatsApp, Telegram, Slack, SMS, Gmail, and Outlook. It connects to those channels, continuously monitors for suspicious messages, and warns the user in app if something malicious is detected. Security teams also get an administrative dashboard to manage users, check protection coverage, and monitor threat activity in aggregate.

Common Defense is built with accuracy, speed, and privacy in mind. Internal testing demonstrated a 96.7% scam detection rate, with a 0.48% false-positive rate, and decision latency typically under 100ms. To protect privacy, administrators never see users’ messages, and messages determined to be safe are deleted after scanning. Organizations can also self-host Common Defense on their own infrastructure.

Common Defense performance


96.7%
of targeted scams detected
0.48%
false-positive rate
<100ms
typical decision latency
Based on internal testing data.

Every attack here began with an approach that looked like it belonged. Existing defenses often focus on forged senders, malicious links, or suspicious attachments. They struggle when the whole attack is simply a convincing request, and on most communication channels there is little or no monitoring in the first place. If your team relies on WhatsApp, Telegram, or Slack as much as email, we’d like to hear from you. Get started at commondefense.ai.

About Common Defense

Common Defense is an AI cyber lab built by security veterans and AI researchers, whose team has helped protect more than $300B in assets across 1,100+ security engagements. We help AI companies, fintechs, and crypto protocols secure the communication channels and operations that attackers target most.

Related from Common Defense

Close every gap before it becomes an incident.

Get Protected