Industry

Impersonation: risks, safeguards and decisions

Impersonation covers both directions: someone using an organization's name on you, and someone using yours on the people who trust you. What to do in each.

Impersonation works by borrowing something you already trust (an agency, a bank, an employer, a relative, a brand), so that a request you would normally question arrives pre-approved. The claim is never proved. It is asserted, and then the conversation moves so quickly that the assertion is never revisited.

Everything below is organized around one question: for this kind of claim, what is the independent route that settles it? Every claimed identity has one. Knowing it in advance is what lets you use it under pressure.

What to take away

  • Caller ID can be set to any number, including the real one belonging to the organization being impersonated.
  • A government agency, tax, police, courts, immigration, benefits.
  • A cloned profile, a fake account using your photos, a business page copying yours, or your name attached to something you never said.
  • Turn on the strongest sign-in available on the accounts that carry your name publicly: a passkey or a security key rather than text codes.

Why the usual signals do not help

  • Caller ID can be set to any number, including the real one belonging to the organization being impersonated.
  • A display name is free text. So is a sender name on a message, and so is the name on a profile.
  • Logos, formatting, and reference numbers are trivially copied. So are letters and printed notices.
  • A real address can send a fake message if that mailbox has been taken over. A message genuinely from your colleague's account is still hostile if someone else is in it.
  • A voice is not identification. Short samples of speech are enough to produce a convincing imitation, so treat a familiar voice on an unexpected call as a claim, not a confirmation.

What none of these can fake is you starting a fresh contact through a route you already had.

Who gets impersonated, and how to settle it

A government agency, tax, police, courts, immigration, benefits. The pitch is a debt, a warrant, a compromised identity number, a visa problem, an investigation. Common shape: a threat with an immediate deadline, an instruction not to discuss it, and a demand for payment by an unusual method. Settle it: hang up and contact the agency using the number or the account portal you find yourself. Agencies write to you, they do not demand payment in gift cards or cryptocurrency, and no real investigation requires you to keep it from your bank or your family.

Your bank's fraud team. The strongest version of this scam, because the caller appears to be protecting you. They say your account is under attack and ask you to move money to a "safe account", read out codes, approve a login, or install software so they can help. Settle it: end the call and dial the number printed on your card. No bank moves your money to keep it safe, and no bank needs a code sent to you.

Platform or tech support. Reached through a search result, a pop-up warning, an ad, or a reply to your public complaint. They want remote access or a payment for a subscription you never bought. Settle it: support is reached from inside the app or from a bookmarked page, never through a number or link that found you. Support never contacts you first about a problem you have not reported.

Your employer, a manager, or payroll. An urgent request while someone is "in a meeting": buy gift cards, pay an invoice, change bank details, send a staff list, approve a login. Bank-detail changes for a supplier are the expensive version. Settle it: verify through an internal channel you already use, a phone number in the directory, a walk to their desk, a message in the company's own system. Do this even when it feels awkward, and especially when the request says not to.

A relative or friend in trouble. A new number, a bad connection, an accident, an arrest, a phone that broke. Urgency plus a request for money or for secrecy from the rest of the family. Settle it: call the person on the number you already have, and call another family member. Agreeing a simple question that only your family could answer is cheap and works even against a convincing voice.

A delivery company, utility, or subscription. A small fee, a redelivery, an expiring card, an over-payment refund. The amount is deliberately trivial, because the aim is the card details, not the fee. Settle it: open the company's own app or account page. Deliveries and refunds are visible there or they are not real.

A brand's support account on social media. You post a complaint, and something that looks like the company replies within minutes from a near-identical handle, moving you to a private message and then to a link or a payment. Settle it: start from the brand's verified profile or its own website, and never follow a support account that approached you first.

A public figure or a well-known company, offering something. Giveaways, investment opportunities, recovery services, job offers. Often built on a copied profile or an advert using a real person's face and voice without permission. Settle it: the person did not message you, and no genuine giveaway asks you to send money or personal data first.

The verification anchors, in one place

The claim The route that settles it
Your bank The number printed on your card
A government agency The agency's own site or portal, found yourself
Platform support Inside the app, or a bookmark
Your employer The internal directory, or in person
A relative The number already in your contacts
A delivery or utility That company's own app or account page
A brand's social account Its verified profile, reached from its website

Two habits make the table work under pressure. Never use the contact details the message supplies, that is the whole attack. And give yourself the pause: say you will call back. Nothing genuine collapses in the ninety seconds that takes, and every impersonation depends on it not happening.

The requests that are always wrong

Regardless of who is asking or how convincing they are:

  • A one-time code that was sent to you. It is arriving because someone is logging in as you.
  • A payment in gift card codes, cryptocurrency, or a wire to a new account, especially framed as a fee, a fine, a tax, or a release.
  • Remote access to your device, or installing software so someone can "help".
  • Moving your money to a "safe" or "protection" account.
  • Secrecy from your bank, your family, or your colleagues.
  • A change of bank details for an existing payee, arriving by message.

Any one of these is enough on its own. You do not need to work out who is really calling. The first item is also the most common request made to private sellers, and the buying and selling version of it is in marketplace scams.

When you are the one being impersonated

A cloned profile, a fake account using your photos, a business page copying yours, or your name attached to something you never said.

Gather it first. Profile URLs and handles, screenshots showing the account and its content, dates, and any messages sent to people in your name. Save it before you report, because successful reports remove the evidence.

Report it through the impersonation route specifically. Most platforms have a dedicated form separate from ordinary abuse reporting, and it usually moves faster. Expect to be asked to prove who you are; that is normal in this one case, and only through the platform's own reporting flow.

Tell your circle before the fake account does. A short post ("someone has copied my account, I am not asking anyone for money"), is the fastest way to stop losses among people who trust you. Ask them to report the account rather than to engage with it.

Do not contact the impersonator. It confirms the account is worth running and can escalate into harassment.

Close the doors that made the copy easy. A copied profile is built from what was public: photos, friend lists, and posts. Reviewing visibility and friend-list exposure reduces how convincing the next attempt can be, and the walkthrough is in privacy settings.

If it was a takeover rather than a copy (your actual account, now controlled by somebody else), that is a different job, and the recovery sequence is in account security.

If money moved because of it, whether yours or someone else's, work through scam reporting and recovery and report it. In the US, that means the Federal Trade Commission for consumer fraud, whose guidance on what to do if you were scammed is organized by payment method, and the FBI's Internet Crime Complaint Center for internet-enabled crime.

Making yourself harder to impersonate

  • Turn on the strongest sign-in available on the accounts that carry your name publicly: a passkey or a security key rather than text codes.
  • Keep your recovery email and phone current, and check them occasionally. Stale recovery details are how accounts get taken permanently.
  • Agree a family verification question now. It costs nothing and it is the only defense that survives a convincing voice.
  • Treat any message that pressures you to act at once as unverified, whoever it appears to come from, which is the rule the whole of phishing scams is built on.
  • Reduce the raw material. Publicly visible friend lists, birthdays, employers, and photo archives are what make a copy convincing.
  • At work, insist on a callback rule for payment changes, and make it a policy rather than a personal habit, so that no individual has to be the awkward one. CISA's guidance on recognizing and reporting phishing is a usable starting point for the messaging side.

Common questions

The number that called me really is my bank's number. How?

The number shown to you is supplied by the caller's system and is not verified end to end. Matching caller ID is common in this scam and proves nothing. Hang up, wait for the line to clear or use another phone, and dial the number on your card.

A verified badge means the account is genuine, doesn't it?

It depends entirely on the platform, and on several of them a badge can be purchased. Treat it as weak evidence. The stronger check is reaching the account from the organization's own website.

They knew my address, my account, and a recent transaction.

Personal detail is easy to obtain from breaches, receipts, and public posts, and it is used specifically to open the conversation. It makes a call convincing; it does not make it genuine.

Someone is using my photos on a dating profile. Can I get it removed?

Report it through the platform's impersonation route with the evidence saved first, and tell anyone likely to be contacted. Do not engage with the account. If the profile is being used to defraud people, report it to the authorities as well as to the platform.

More in Industry

Industry

Phishing scams risks: warning signs and safer responses

Phishing risk sized by what you actually gave away, what surfaces in the first week, and the follow-up offer that takes more money than the original.