Real-World Attack Scenarios

Multi-Stage Attacks — When Trust Is Built Over Time

Learn how attackers build trust gradually through multiple interactions before making their move.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Recognize the pattern of trust-building in multi-stage attacks and identify at least one warning sign in a sequence of communications.

Multi-Stage Attacks — When Trust Is Built Over Time

This lesson examines sophisticated attacks that unfold over days or weeks. You’ll learn to recognize the pattern of trust-building and spot when a seemingly harmless conversation is actually a setup.

Trust That Builds Over Time — And the Trap That Follows

Not all attacks happen quickly. Some of the most sophisticated social-engineering attacks unfold over days, weeks, or even months. Attackers build a relationship with you first — establishing trust through a series of innocuous conversations — before they make their real request.

This is called a “long con” or business email compromise (BEC) campaign. The attacker might start by asking a simple question about a project, then follow up with a document request, then eventually ask for something sensitive or valuable. Each step feels reasonable because trust has been established incrementally.

How to protect yourself:

  • Be suspicious of any request, even from someone you’ve been talking to, if it feels out of pattern.
  • Trust your gut: if something feels slightly off, it probably is.
  • Verify significant requests through a separate, independent channel — even if you’ve spoken before.