How to defend the full social engineering attack chain | Register for the webinar to learn more

General

What Is Impersonation Fraud?

Impersonation fraud uses false identities to steal money or credentials; learn how it works, common types, and defenses.

Doppel TeamSecurity Experts
September 23, 2026
5 min read

What Is Impersonation Fraud?

Impersonation fraud is the use of a false identity (opens in new tab), or a false claim of affiliation with a trusted organization or person, to deceive a target into sending money or disclosing credentials and other sensitive data.

Spoofing falsifies a technical identifier (opens in new tab) such as a domain or caller ID; impersonation fraud is the behavioral act of claiming (opens in new tab) to be someone the target already trusts, and spoofing is one of the tools that makes the claim believable. Attackers can copy the identity of a brand, a government agency, a bank, an executive, a supplier, or an IT help desk.

How impersonation fraud works

Attackers start with reconnaissance. They profile a target from the organization's own website, then fill gaps with social profile data (opens in new tab) so the approach carries accurate names, titles, and context. They also build the false identity's infrastructure: lookalike domains from altered spellings, added prefixes, or a swapped top-level domain (fb-i.gov and thefbi.gov change the spelling; fbi.com swaps the TLD).

From there, attackers use spoofed sender addresses, clone social profiles, and build phishing pages that copy a real login flow.

Contact arrives on whichever channel the target trusts most. Brand impersonation runs through ads, social, and messaging (opens in new tab), email, and phone, and campaigns often open on one channel before pushing the target to an encrypted messaging app (opens in new tab) within minutes. Once engaged, the impersonator applies urgency and authority: in CEO fraud, a senior figure demands an urgent payment and instructs the employee to bypass authorisation procedures (opens in new tab).

A typical case: a finance employee receives an email that appears to come from the CFO about a confidential acquisition, asking for a same-day transfer and framing it as discreet and time-sensitive (opens in new tab), a pattern common to business impersonation scams. The CFO's displayed name alone persuades the employee to authorize payment, no system compromise required.

Why impersonation fraud is hard to stop

The infrastructure behind impersonation fraud often sits outside the perimeter. Brand impersonation rarely touches owned infrastructure (opens in new tab), so SOC tooling scoped to internal traffic never inspects the lookalike domain, the fake support number, the cloned profile, or the scam ad running on someone else's platform.

Detection has to extend past the perimeter, since perimeter-focused controls were never built to see attacker-owned assets. Attackers also register domains rapidly (opens in new tab) and churn through them faster than takedowns keep up.

Synthetic media adds a different problem. AI-generated voices of executives and officials can sound nearly identical (opens in new tab) to the real person, erasing a verification cue people used to rely on.

Types of impersonation fraud

Impersonation fraud categories reflect the identity being copied:

Deepfake voice and video cut across these categories too, including help desk calls and authorizing fraudulent transactions (opens in new tab).

How to defend against impersonation fraud

Defense has to extend to attacker-controlled infrastructure, since the target may never touch your network.

  1. Monitor externally and continuously. Watch domain registrations, social platforms, app stores, and paid ads for brand and executive names, and prioritize newly registered domains.
  2. Pursue takedowns. Accredited registrars must publish an abuse contact and respond to abuse reports (opens in new tab); report an unresponsive registrar to ICANN Contractual Compliance (opens in new tab). This applies to scam ads and cloned profiles, not just domains, so keep watching ad networks and app stores after a takedown.
  3. Authenticate outbound email. Move a DMARC policy from "none" through SPF and DKIM (opens in new tab) to rejecting spoofed mail outright.
  4. Verify out of band. Require a secondary sign-off for any change in vendor payment details, and confirm by phone using previously known numbers (opens in new tab), never ones from the email itself.
  5. Train across channels. Simulations should include vishing with cloned voices, smishing, and deepfake video meetings alongside email lures.
  6. Define prohibited requests. State plainly, as outward-facing policy (opens in new tab), that you never ask for passwords, and require any bank-detail change to be verified through a previously known contact channel.

How Doppel helps

Doppel is the Frontier AI Social Engineering Defense (SED) platform that unifies Digital Risk Protection and Human Risk Management, detecting impersonation across channels and dismantling attacker infrastructure. The Doppel Threat Graph links fake profiles, spoofed domains, and scam ads into a single campaign view.

Doppel's agentic AI correlates signals and executes takedowns through platform APIs while analysts handle escalations, and one-click threat-to-simulation conversion turns a live lure into a training exercise across email, voice, SMS, Teams, Zoom, and Telegram.

Takedown results feed the Threat Graph to sharpen detection on the next campaign, and a product walkthrough maps the fake domains, profiles, and ads targeting your brand. The goal: make impersonating your organization too costly to sustain.

Request a demo to get started.

Frequently asked questions about impersonation fraud

What is impersonation fraud?

Impersonation fraud is deception in which someone falsely claims to be, or to represent, a trusted person or organization to obtain money, credentials, or other personal data. The impersonated party may be a brand, a bank, a government agency, an executive, a supplier, or an IT help desk, and attackers project the false identity through email, phone, text, social media, paid ads, or fake websites — channels that let the claim go unverified. In the US, falsely posing as or misrepresenting affiliation with a government entity or business is unlawful under the FTC's Trade Regulation Rule on Impersonation of Government and Businesses, effective April 1, 2024 (opens in new tab).

What is impersonation fraud in cybersecurity?

Impersonation is a social engineering technique, specifically technique T1656 (opens in new tab) in MITRE ATT&CK: adversaries impersonate a trusted person or organization to persuade a target into acting on their behalf, often in business email compromise. The same technique underlies help desk calls that get an MFA reset, deepfake calls that authorize fraudulent payments, and credential-harvesting pages that copy a corporate login portal.

How is impersonation fraud different from identity theft?

Identity theft is wrongfully obtaining and using (opens in new tab) someone else's personal data through fraud or deception, typically for economic gain. Impersonation fraud is the act of impersonating a trusted person or organization to deceive a third party — the attacker can claim a real executive's identity, a real brand, or an entirely fictional persona. Identity theft often follows a successful impersonation, when criminals reuse harvested data; the same indictment (opens in new tab) can charge both as separate counts.

What is an example of impersonation fraud?

A July 29, 2025 joint #StopRansomware advisory (opens in new tab) from CISA and the FBI documents help-desk social engineering used for initial access throughout 2025, with Scattered Spider activity traced as recently as June 2025. A convincing identity claim is what gives the attacker that first foothold.

Last updated: September 23, 2026