Online fraud is the use of internet technology to deceive a victim into voluntarily handing over money, property, credentials, or access. It is a cyber-enabled crime (opens in new tab): a traditional deception offense that the internet lets attackers conduct at greater scale and reach.
Cyber-dependent crimes (opens in new tab), such as malware attacks, cannot exist without digital infrastructure. Fraud depends on a voluntary transfer (opens in new tab); the victim complies because the request looks legitimate.
How online fraud works
Many online fraud schemes run on manufactured trust (opens in new tab), which attackers can build as infrastructure before contacting a victim. Attackers register lookalike domains through typosquatting and cybersquatting (opens in new tab). They stand up spoofed social profiles and scam ads (opens in new tab), while phishing-as-a-service (opens in new tab) kits support credential captures (opens in new tab) at scale.
One China-linked syndicate delivers its lures over iMessage and RCS, bypassing mobile carrier networks entirely.
The engagement stage converts that infrastructure into a loss. A victim may type credentials into a lookalike login page or pay a redirected invoice. Other victims follow instructions from an impersonated executive.
Generative AI (opens in new tab) has compressed this stage by helping attackers build sites rapidly (opens in new tab). One deepfake-payment scenario illustrates the risk: attackers use AI-generated deepfakes (opens in new tab) to impersonate a CFO and other video-conference participants.
The impersonation leads a finance employee to authorize multiple wire transfers before verification with headquarters exposes the fraud. The final stage moves the proceeds through money mule networks (opens in new tab).
Why online fraud matters
Brand impersonation (opens in new tab) campaigns often operate outside the victim organization's network on attacker-owned infrastructure (opens in new tab) that SOC tooling watching internal telemetry can miss. The brand absorbs the damage anyway: diverted revenue (opens in new tab) and eroded customer trust, even though the fraud never touches its own systems.
Cyber-enabled fraud accounted for 83% of all losses (opens in new tab) reported to IC3 in 2024: $13.7 billion across 333,981 complaints. Regulators are now pricing that damage. The FTC's Impersonation Rule (opens in new tab) gives the agency a federal enforcement lever against anyone materially posing as a business or government entity, including authority to seek civil penalties.
In the UK, payment service providers must reimburse eligible victims (opens in new tab) of authorized push payment fraud, subject to a regulatory cap, which moves the cost of impersonation-enabled scams directly onto regulated firms.
AI-enabled social engineering (opens in new tab) presents one of the most significant threats to the financial services sector, a risk addressed in an October 2024 industry letter (opens in new tab) from NYDFS.
Types of online fraud
Online fraud falls into recurring scheme types (opens in new tab), many of which involve impersonation at some stage:
- Business email compromise (BEC): Attackers compromise or spoof email (opens in new tab), phone numbers, or meeting applications to trigger unauthorized fund transfers. Common variants are CEO and invoice fraud (opens in new tab).
- Phishing and spoofing: Unsolicited email, texts, or calls (opens in new tab) purporting to come from a legitimate company to harvest personal, financial or login data (opens in new tab); phishing and spoofing drew 193,407 complaints in 2024 and were the most reported cybercrime type to IC3.
- Brand and executive impersonation: Typosquatted domains (opens in new tab), lookalike URLs, fake social profiles (opens in new tab), and scam ads that trade on an organization's trust (opens in new tab) to reach its customers.
- Account takeover: A criminal gains control of a customer's account (opens in new tab) at a financial institution to remove funds or information (opens in new tab).
- Authorized push payment (APP) fraud: A fraudster tricks the victim into sending money (opens in new tab) while posing as a genuine payee, including through invoice and mandate redirection.
- Investment and romance fraud: Cryptocurrency investment fraud (opens in new tab) is especially prevalent; "pig butchering" schemes build a fictitious relationship (opens in new tab) over weeks before extraction.
- Non-payment and non-delivery fraud: Victims pay for goods or services they never receive, often through counterfeit storefronts.
How to defend against online fraud
Start outside your own perimeter. Monitoring new domain registrations (opens in new tab) identifies misleading lookalike domains (opens in new tab) before attackers weaponize them, and suspending malicious domains (opens in new tab) disrupts phishing campaigns before more victims encounter them. Speed decides the outcome here, because phishing sites (opens in new tab) can steal credentials soon after launch (opens in new tab).
Establish takedown paths before you need them. Decide when to engage (opens in new tab) a takedown provider, and map registrar and hosting abuse contacts before an incident.
Harden the channels fraud travels on. Set DMARC to "reject" (opens in new tab) alongside SPF and DKIM on all corporate email infrastructure, and use phishing-resistant MFA (opens in new tab) on the highest-risk accounts. For payments, verify significant transactions through a second channel (opens in new tab) that both parties establish early in the relationship and keep outside the email environment.
Use the live tactics targeting those channels to build training. Generic embedded training barely moves outcomes (opens in new tab), which is why effective programs build simulations from the attacks actually hitting your organization.
How Doppel helps
Doppel is the AI-native Social Engineering Defense (SED) platform that unifies Digital Risk Protection (DRP) (opens in new tab) and Human Risk Management (HRM) (opens in new tab) to detect and dismantle online fraud campaigns. The Doppel Threat Graph (opens in new tab) links spoofed domains, fake social profiles, scam ads, phone numbers, and dark web mentions into campaign-level views.
Its agentic AI (opens in new tab) correlates and prioritizes those signals and executes takedowns across registrars, hosts, social platforms, and ad networks. Analysts can turn threats the platform detects into employee simulations (opens in new tab) in one click. Signals from campaigns the platform dismantles strengthen the Threat Graph's infrastructure correlation. Request a demo (opens in new tab) to get started.
Frequently asked questions about online fraud
What is online fraud?
Online fraud is any scheme that uses internet technology to deceive victims into voluntarily handing over money, property, or sensitive information. Common forms include phishing, business email compromise, investment scams, brand impersonation, and fake online storefronts. The deception is what distinguishes it from theft: victims transfer the money or data themselves because the request appears to come from someone they trust.
What is online fraud in cybersecurity?
In cybersecurity, online fraud falls under cyber-enabled crime (opens in new tab): a deception offense that predates the internet but now scales far wider because of it. Cyber-dependent crimes (opens in new tab), such as malware or data breaches, rely entirely on digital systems. Online fraud reaches organizations through social engineering across email, SMS, voice, social media, and paid ads instead of technical exploitation alone. Security teams therefore defend two surfaces at once: the external infrastructure impersonating the brand and the employees and customers that infrastructure targets.
What is the difference between online fraud and cybercrime?
Cybercrime is the umbrella category (opens in new tab) covering all crime committed in or through cyberspace, including hacking, ransomware, espionage, and fraud. Online fraud is a subset of cybercrime defined by deception for financial gain rather than by technical intrusion. A ransomware attack that encrypts servers is cyber-dependent; a spoofed supplier email that redirects a legitimate invoice payment is online fraud. Many schemes combine the two (opens in new tab). They use stolen credentials or compromised accounts to make the deception more convincing.
What is an example of online fraud?
A deepfake-payment scenario can involve a finance employee at a multinational firm authorizing substantial wire transfers after attackers use AI-generated deepfakes to impersonate the chief financial officer and other video-conference participants. A more routine example is invoice fraud, where a criminal poses as a known supplier and redirects a legitimate payment to an account they control. In a customer-facing case, scammers have impersonated an airline's support accounts (opens in new tab) on social media during mass flight cancellations to intercept stranded customers.
