Multi-Stage Attacks — When Trust Is Built Over Time
Learn how attackers build trust gradually through multiple interactions before making their move.
In this lesson, you will learn to:
- Recognize the pattern of trust-building in multi-stage attacks and identify at least one warning sign in a sequence of communications.
Multi-Stage Attacks — When Trust Is Built Over Time
This lesson examines sophisticated attacks that unfold over days or weeks. You’ll learn to recognize the pattern of trust-building and spot when a seemingly harmless conversation is actually a setup.
Trust That Builds Over Time — And the Trap That Follows
Not all attacks happen quickly. Some of the most sophisticated social-engineering attacks unfold over days, weeks, or even months. Attackers build a relationship with you first — establishing trust through a series of innocuous conversations — before they make their real request.
This is called a “long con” or business email compromise (BEC) campaign. The attacker might start by asking a simple question about a project, then follow up with a document request, then eventually ask for something sensitive or valuable. Each step feels reasonable because trust has been established incrementally.
How to protect yourself:
- Be suspicious of any request, even from someone you’ve been talking to, if it feels out of pattern.
- Trust your gut: if something feels slightly off, it probably is.
- Verify significant requests through a separate, independent channel — even if you’ve spoken before.