Doppel Email Security is now generally available! | Register for the webinar to learn more
General

What Is Online Fraud?

Online fraud uses the internet to trick victims into handing over money, credentials, or access. Learn how it works, its main types, and how to defend against it.

Doppel TeamSecurity Experts
August 10, 2026
5 min read

Online fraud is the use of internet technology to deceive a victim into voluntarily handing over money, property, credentials, or access. It is a cyber-enabled crime (opens in new tab): a traditional deception offense that the internet lets attackers conduct at greater scale and reach.

Cyber-dependent crimes (opens in new tab), such as malware attacks, cannot exist without digital infrastructure. Fraud depends on a voluntary transfer (opens in new tab); the victim complies because the request looks legitimate.

How online fraud works

Many online fraud schemes run on manufactured trust (opens in new tab), which attackers can build as infrastructure before contacting a victim. Attackers register lookalike domains through typosquatting and cybersquatting (opens in new tab). They stand up spoofed social profiles and scam ads (opens in new tab), while phishing-as-a-service (opens in new tab) kits support credential captures (opens in new tab) at scale.

One China-linked syndicate delivers its lures over iMessage and RCS, bypassing mobile carrier networks entirely.

The engagement stage converts that infrastructure into a loss. A victim may type credentials into a lookalike login page or pay a redirected invoice. Other victims follow instructions from an impersonated executive.

Generative AI (opens in new tab) has compressed this stage by helping attackers build sites rapidly (opens in new tab). One deepfake-payment scenario illustrates the risk: attackers use AI-generated deepfakes (opens in new tab) to impersonate a CFO and other video-conference participants.

The impersonation leads a finance employee to authorize multiple wire transfers before verification with headquarters exposes the fraud. The final stage moves the proceeds through money mule networks (opens in new tab).

Why online fraud matters

Brand impersonation (opens in new tab) campaigns often operate outside the victim organization's network on attacker-owned infrastructure (opens in new tab) that SOC tooling watching internal telemetry can miss. The brand absorbs the damage anyway: diverted revenue (opens in new tab) and eroded customer trust, even though the fraud never touches its own systems.

Cyber-enabled fraud accounted for 83% of all losses (opens in new tab) reported to IC3 in 2024: $13.7 billion across 333,981 complaints. Regulators are now pricing that damage. The FTC's Impersonation Rule (opens in new tab) gives the agency a federal enforcement lever against anyone materially posing as a business or government entity, including authority to seek civil penalties.

In the UK, payment service providers must reimburse eligible victims (opens in new tab) of authorized push payment fraud, subject to a regulatory cap, which moves the cost of impersonation-enabled scams directly onto regulated firms.

AI-enabled social engineering (opens in new tab) presents one of the most significant threats to the financial services sector, a risk addressed in an October 2024 industry letter (opens in new tab) from NYDFS.

Types of online fraud

Online fraud falls into recurring scheme types (opens in new tab), many of which involve impersonation at some stage:

How to defend against online fraud

Start outside your own perimeter. Monitoring new domain registrations (opens in new tab) identifies misleading lookalike domains (opens in new tab) before attackers weaponize them, and suspending malicious domains (opens in new tab) disrupts phishing campaigns before more victims encounter them. Speed decides the outcome here, because phishing sites (opens in new tab) can steal credentials soon after launch (opens in new tab).

Establish takedown paths before you need them. Decide when to engage (opens in new tab) a takedown provider, and map registrar and hosting abuse contacts before an incident.

Harden the channels fraud travels on. Set DMARC to "reject" (opens in new tab) alongside SPF and DKIM on all corporate email infrastructure, and use phishing-resistant MFA (opens in new tab) on the highest-risk accounts. For payments, verify significant transactions through a second channel (opens in new tab) that both parties establish early in the relationship and keep outside the email environment.

Use the live tactics targeting those channels to build training. Generic embedded training barely moves outcomes (opens in new tab), which is why effective programs build simulations from the attacks actually hitting your organization.

How Doppel helps

Doppel is the AI-native Social Engineering Defense (SED) platform that unifies Digital Risk Protection (DRP) (opens in new tab) and Human Risk Management (HRM) (opens in new tab) to detect and dismantle online fraud campaigns. The Doppel Threat Graph (opens in new tab) links spoofed domains, fake social profiles, scam ads, phone numbers, and dark web mentions into campaign-level views.

Its agentic AI (opens in new tab) correlates and prioritizes those signals and executes takedowns across registrars, hosts, social platforms, and ad networks. Analysts can turn threats the platform detects into employee simulations (opens in new tab) in one click. Signals from campaigns the platform dismantles strengthen the Threat Graph's infrastructure correlation. Request a demo (opens in new tab) to get started.

Frequently asked questions about online fraud

What is online fraud?

Online fraud is any scheme that uses internet technology to deceive victims into voluntarily handing over money, property, or sensitive information. Common forms include phishing, business email compromise, investment scams, brand impersonation, and fake online storefronts. The deception is what distinguishes it from theft: victims transfer the money or data themselves because the request appears to come from someone they trust.

What is online fraud in cybersecurity?

In cybersecurity, online fraud falls under cyber-enabled crime (opens in new tab): a deception offense that predates the internet but now scales far wider because of it. Cyber-dependent crimes (opens in new tab), such as malware or data breaches, rely entirely on digital systems. Online fraud reaches organizations through social engineering across email, SMS, voice, social media, and paid ads instead of technical exploitation alone. Security teams therefore defend two surfaces at once: the external infrastructure impersonating the brand and the employees and customers that infrastructure targets.

What is the difference between online fraud and cybercrime?

Cybercrime is the umbrella category (opens in new tab) covering all crime committed in or through cyberspace, including hacking, ransomware, espionage, and fraud. Online fraud is a subset of cybercrime defined by deception for financial gain rather than by technical intrusion. A ransomware attack that encrypts servers is cyber-dependent; a spoofed supplier email that redirects a legitimate invoice payment is online fraud. Many schemes combine the two (opens in new tab). They use stolen credentials or compromised accounts to make the deception more convincing.

What is an example of online fraud?

A deepfake-payment scenario can involve a finance employee at a multinational firm authorizing substantial wire transfers after attackers use AI-generated deepfakes to impersonate the chief financial officer and other video-conference participants. A more routine example is invoice fraud, where a criminal poses as a known supplier and redirects a legitimate payment to an account they control. In a customer-facing case, scammers have impersonated an airline's support accounts (opens in new tab) on social media during mass flight cancellations to intercept stranded customers.

Last updated: August 10, 2026

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.