What Is Impersonation Fraud?
Impersonation fraud is the use of a false identity (opens in new tab), or a false claim of affiliation with a trusted organization or person, to deceive a target into sending money or disclosing credentials and other sensitive data.
Spoofing falsifies a technical identifier (opens in new tab) such as a domain or caller ID; impersonation fraud is the behavioral act of claiming (opens in new tab) to be someone the target already trusts, and spoofing is one of the tools that makes the claim believable. Attackers can copy the identity of a brand, a government agency, a bank, an executive, a supplier, or an IT help desk.
How impersonation fraud works
Attackers start with reconnaissance. They profile a target from the organization's own website, then fill gaps with social profile data (opens in new tab) so the approach carries accurate names, titles, and context. They also build the false identity's infrastructure: lookalike domains from altered spellings, added prefixes, or a swapped top-level domain (fb-i.gov and thefbi.gov change the spelling; fbi.com swaps the TLD).
From there, attackers use spoofed sender addresses, clone social profiles, and build phishing pages that copy a real login flow.
Contact arrives on whichever channel the target trusts most. Brand impersonation runs through ads, social, and messaging (opens in new tab), email, and phone, and campaigns often open on one channel before pushing the target to an encrypted messaging app (opens in new tab) within minutes. Once engaged, the impersonator applies urgency and authority: in CEO fraud, a senior figure demands an urgent payment and instructs the employee to bypass authorisation procedures (opens in new tab).
A typical case: a finance employee receives an email that appears to come from the CFO about a confidential acquisition, asking for a same-day transfer and framing it as discreet and time-sensitive (opens in new tab), a pattern common to business impersonation scams. The CFO's displayed name alone persuades the employee to authorize payment, no system compromise required.
Why impersonation fraud is hard to stop
The infrastructure behind impersonation fraud often sits outside the perimeter. Brand impersonation rarely touches owned infrastructure (opens in new tab), so SOC tooling scoped to internal traffic never inspects the lookalike domain, the fake support number, the cloned profile, or the scam ad running on someone else's platform.
Detection has to extend past the perimeter, since perimeter-focused controls were never built to see attacker-owned assets. Attackers also register domains rapidly (opens in new tab) and churn through them faster than takedowns keep up.
Synthetic media adds a different problem. AI-generated voices of executives and officials can sound nearly identical (opens in new tab) to the real person, erasing a verification cue people used to rely on.
Types of impersonation fraud
Impersonation fraud categories reflect the identity being copied:
- Brand impersonation. The attacker uses a company's name, logo, domain, or visual identity to deceive that company's customers. Materially and falsely posing as a business, or misrepresenting affiliation with one, is prohibited under the FTC's rule (opens in new tab), which reaches misleading uses of a business name and other tactics implying false affiliation.
- Executive impersonation. Also called CEO fraud, a business email compromise variant where the attacker poses as a senior leader to direct finance or HR toward urgent wire transfers (opens in new tab) or payroll changes, sometimes seeking W-2 disclosures.
- Vendor impersonation. The attacker poses as an existing supplier and asks accounts payable to redirect future payments to a new account — invoice and mandate fraud (opens in new tab), not CEO fraud.
- IT help desk and employee impersonation. The attacker calls a service desk posing as an employee to get a password or MFA reset; actors who pose as company IT (opens in new tab) routinely talk help desk staff into resetting MFA tokens.
- Government and law enforcement impersonation. Attackers pose as agencies and threaten license suspension or fines (opens in new tab), sometimes trademark loss, using a badge number or case ID to manufacture urgency. The FTC's definition of government (opens in new tab) spans agencies at every level, federal and tribal included, plus their officers and agents.
Deepfake voice and video cut across these categories too, including help desk calls and authorizing fraudulent transactions (opens in new tab).
How to defend against impersonation fraud
Defense has to extend to attacker-controlled infrastructure, since the target may never touch your network.
- Monitor externally and continuously. Watch domain registrations, social platforms, app stores, and paid ads for brand and executive names, and prioritize newly registered domains.
- Pursue takedowns. Accredited registrars must publish an abuse contact and respond to abuse reports (opens in new tab); report an unresponsive registrar to ICANN Contractual Compliance (opens in new tab). This applies to scam ads and cloned profiles, not just domains, so keep watching ad networks and app stores after a takedown.
- Authenticate outbound email. Move a DMARC policy from "none" through SPF and DKIM (opens in new tab) to rejecting spoofed mail outright.
- Verify out of band. Require a secondary sign-off for any change in vendor payment details, and confirm by phone using previously known numbers (opens in new tab), never ones from the email itself.
- Train across channels. Simulations should include vishing with cloned voices, smishing, and deepfake video meetings alongside email lures.
- Define prohibited requests. State plainly, as outward-facing policy (opens in new tab), that you never ask for passwords, and require any bank-detail change to be verified through a previously known contact channel.
How Doppel helps
Doppel is the Frontier AI Social Engineering Defense (SED) platform that unifies Digital Risk Protection and Human Risk Management, detecting impersonation across channels and dismantling attacker infrastructure. The Doppel Threat Graph links fake profiles, spoofed domains, and scam ads into a single campaign view.
Doppel's agentic AI correlates signals and executes takedowns through platform APIs while analysts handle escalations, and one-click threat-to-simulation conversion turns a live lure into a training exercise across email, voice, SMS, Teams, Zoom, and Telegram.
Takedown results feed the Threat Graph to sharpen detection on the next campaign, and a product walkthrough maps the fake domains, profiles, and ads targeting your brand. The goal: make impersonating your organization too costly to sustain.
Request a demo to get started.
Frequently asked questions about impersonation fraud
What is impersonation fraud?
Impersonation fraud is deception in which someone falsely claims to be, or to represent, a trusted person or organization to obtain money, credentials, or other personal data. The impersonated party may be a brand, a bank, a government agency, an executive, a supplier, or an IT help desk, and attackers project the false identity through email, phone, text, social media, paid ads, or fake websites — channels that let the claim go unverified. In the US, falsely posing as or misrepresenting affiliation with a government entity or business is unlawful under the FTC's Trade Regulation Rule on Impersonation of Government and Businesses, effective April 1, 2024 (opens in new tab).
What is impersonation fraud in cybersecurity?
Impersonation is a social engineering technique, specifically technique T1656 (opens in new tab) in MITRE ATT&CK: adversaries impersonate a trusted person or organization to persuade a target into acting on their behalf, often in business email compromise. The same technique underlies help desk calls that get an MFA reset, deepfake calls that authorize fraudulent payments, and credential-harvesting pages that copy a corporate login portal.
How is impersonation fraud different from identity theft?
Identity theft is wrongfully obtaining and using (opens in new tab) someone else's personal data through fraud or deception, typically for economic gain. Impersonation fraud is the act of impersonating a trusted person or organization to deceive a third party — the attacker can claim a real executive's identity, a real brand, or an entirely fictional persona. Identity theft often follows a successful impersonation, when criminals reuse harvested data; the same indictment (opens in new tab) can charge both as separate counts.
What is an example of impersonation fraud?
A July 29, 2025 joint #StopRansomware advisory (opens in new tab) from CISA and the FBI documents help-desk social engineering used for initial access throughout 2025, with Scattered Spider activity traced as recently as June 2025. A convincing identity claim is what gives the attacker that first foothold.


