Card listing six impersonation cases and where each could have been stopped. Where could each of these six impersonation cases have been stopped?
Image: Privacy Scam Verification

Guides

Part of Impersonation runs both ways: protecting your name and your trust in others

Where could each of these six impersonation cases have been stopped?

Six composite impersonation situations, each stopped at the point a decision was still available, with what the person did next and what it cost them.

The useful thing about a case is not the story. It is the moment where the outcome was still open.

The six situations below are composites, written to show shape rather than to report any real incident, and no real person or organization appears in them. Each is set out the same way: what arrived, where the decision sat, and what the response looked like afterwards. Read the middle part of each. That is where the page is.

One real, named case is set out after the sixth, and it is sourced.

What to take away

  • A code sent to you proves you are you to the service that sent it, and it is never proof to another person.
  • In every one of these, the decision point arrives before the loss, and it is quieter than the loss.
  • The people who did best were the ones who broke the channelthey went and used a number they already had.
  • Recovering the account matters less than telling the people who were contacted.

One: the copied profile that asked for a small favor

A copy of somebody's social account, built from public photos, messaged around forty of their contacts. It asked for a small loan, with a family reason and a deadline that afternoon.

Fake profile contact flow

  1. Copied profile built from public photos
  2. Messaged around forty contacts
  3. Asked for small loan, family reason
  4. Two contacts checked real account
  5. One sent the money

Where the decision sat. With the contacts, not with the person copied. Two of them replied to the real account to check. One sent the money.

What happened next. The person copied posted once, plainly, from the real account: this is my only account, I will never ask you for money, anything else is not me. That single message reached more people in an hour than the platform report reached in a week.

The contact who had paid reported the payment to their bank the same afternoon, which is the step that decides whether a payment method has any route at all.

What it cost. One payment, not recovered. The fake account stayed up for nine days.

Where the report goes. On Instagram, open the profile, tap the three dots, then Report, then Something about this account, then Pretending to be someone. Then ReportFraud.ftc.gov. In Canada, the Canadian Anti-Fraud Centre is at 1-888-495-8501.

Two: the message from a senior name at work

A short email, in-house tone, from a name everybody knew, asking a junior member of staff to arrange an urgent payment before a meeting and to keep it quiet for now.

Where the decision sat. In the instruction not to check. That is the load-bearing part of this shape: the request cannot survive a callback, so it has to discourage one.

What happened next. The member of staff called the internal number they already had, rather than replying. The request evaporated in ten seconds. They reported it anyway, which is the part that is usually skipped and the part that protected the next four people who received it.

What it cost. Nothing, because a callback rule existed and nobody was punished for using it.

Where the report goes. The FBI's Internet Crime Complaint Center at ic3.gov, and your bank's fraud line the same day.

Three: the delivery notice with a small fee

A text about a parcel, with a link, asking for a small redelivery charge. The recipient was expecting a parcel, which is why it worked.

Delivery notice decision

Reach address from message or elsewhere?

Yes

From message -> enter card on fake page

No

Elsewhere -> avoid card entry, no charge

Where the decision sat. In whether the address was reached from the message or from somewhere else. A card was entered on a page that looked ordinary.

What happened next. The small charge was followed by a call, days later, from somebody claiming to be the bank's fraud team, referring to that exact charge and asking them to move money to a safe account. That second call is the real event in this shape. They hung up and called the number on the back of the card.

What it cost. The small charge, and an afternoon. The second, larger loss did not happen because the callback happened.

Where the report goes. Forward the text to 7726 and call the number on the back of your card.

Four: the code request during a sale

Somebody selling an item was asked by a buyer to confirm they were a real seller by reading back a code that was about to arrive by text.

Where the decision sat. With the seller, at the moment the request arrived.

What happened next. The seller sent it. Within minutes an account of theirs was being used to message other people. They changed the password on the account and on the email behind it, ended every other session, and checked the recovery phone number, which had already been changed. Resetting the recovery details is what made the reset stick.

What it cost. Two days of clean-up, and messages sent in their name that they had to explain. The sequence they followed is the one in account security.

Where the report goes. The platform's account security team, then the FTC at ReportFraud.ftc.gov.

Five: the quiet copy that only posted

An account using somebody's name and photographs that never messaged anybody. It posted for several weeks, gathering followers who assumed it was real.

Where the decision sat. In whether a copy that had done nothing yet counted as a problem.

What happened next. The followers it collected were later messaged with investment offers, which is the harm a dormant copy can do. Losses that begin on social media are a large share of reported fraud, according to the FTC's Consumer Sentinel data.

What it cost. Nothing directly to the person copied, and something to strangers who believed a name. The exposure map for that gap between nuisance and harm is in impersonation risks.

Where the report goes. The platform's impersonation report, and the SEC's tips line at sec.gov/tcr once investment offers appear.

Six: the offer of help after the incident

Two days after a public impersonation, a message arrived offering to get the fake account removed and to trace whoever was behind it, for a fee paid upfront.

Where the decision sat. In noticing that the offer arrived unprompted, and that the fee came before any result.

What happened next. They declined, filed the platform report themselves, and reported the fraud through the Federal Trade Commission's advice on what to do after a scam. Nobody legitimate approaches you first and charges before anything happens.

What it cost. Nothing, which is unusual for this shape.

Where the report goes. The FTC at ReportFraud.ftc.gov, and your state attorney general's consumer protection office.

How to reduce the risk

General hardening that makes each less likely is in CISA's cybersecurity best practices. Recognition patterns for the message that starts them are in phishing scams examples.

A real case, and the figures behind the six

On 15 July 2020, attackers took over the Twitter accounts of Barack Obama, Joe Biden, Elon Musk and Bill Gates and posted a bitcoin scam. Twitter locked the affected accounts and removed the posts within hours.

The US Department of Justice put the take at about $118,000. Court records show Graham Ivan Clark pleaded guilty in a Florida court in 2021, and two others pleaded guilty in federal court. That is the one real, named case on this page, and it sits beside the six composites, not among them.

The FTC counted $10 billion in consumer fraud losses for 2023, with $2.7 billion of that from imposter scams. The FBI's Internet Crime Complaint Center reported $12.5 billion in total 2023 losses, including $2.9 billion from business email compromise.

Recovery has no reliable public rate. What exists is a mechanism: the FBI's Recovery Asset Team asks banks to freeze funds, and it tells victims to file within 72 hours. Money still in an account can be frozen. Money already withdrawn usually cannot.

Takedown times are not published in a form worth quoting. The wait depends on the report path you use, how many recipients report as well, and whether the copy is monetized. In the 2020 case above the posts came down within hours.

Common questions

Are these real cases?

No. The six numbered cases are composites written to show the shape of a situation, deliberately with no identifying detail, because a page like this should teach a decision rather than report on anybody. The Twitter case near the end is real, named and sourced.

Why does the same callback advice appear in all of them?

Because it is the only step that works regardless of how convincing the approach was. It does not depend on you spotting anything.

In the fourth case, was the seller careless?

No more than most people. The code request is designed to sound administrative, and it is the single most effective request in this whole area, which is why it gets its own line everywhere on this site.

What would have changed the outcome in the first case?

A private contacts list, and warning people faster. Neither prevents the copy, and both shrink what it can do.

Does reporting to a platform ever work?

Yes, unevenly and slowly, and it works better when several recipients report as well as the person impersonated. Treat it as a background process rather than the response, and use reporting and recovery for the parts that are time-sensitive.

More in Guides

Latest from Review Desk