Impersonation in Cybersecurity and How to Mitigate the Risks

October 7, 2026 / Published by: Admin

Impersonation in cybersecurity is the act of posing as a person or organization the victim trusts in order to deceive them or steal data. The attacker only needs to convince the victim that the other side is genuine.

People reported losing $3.5 billion to imposter scams in 2025, according to data from the US Federal Trade Commission (FTC). Nearly one in three fraud reports were about imposter scams, more than any other fraud category.

For companies, impersonation in cybersecurity is dangerous because the employees who hold access and funds become targets too. The sections below cover how it works, its main types, warning signs, and business impact, then the identity and access controls that prevent it, including one real deepfake case.

What Is Impersonation in Cybersecurity?

In practice, impersonation means faking the identity attributes that make someone trusted, including a name, job title, logo, email address, phone number, or voice. Attackers use those attributes so that the victim complies without checking any further.

The identity being imitated usually carries authority or familiarity, such as a boss, a bank, a vendor, or a government official. MITRE ATT&CK classifies impersonation (T1684.001) as a sub-technique of social engineering, and notes that many business email compromise (BEC) campaigns rely on it.

Phishing often uses impersonation as bait, but the two differ: impersonation centers on faking an identity, while phishing centers on a trap message that steals data. Impersonation also differs from account takeover, because the attacker builds a fake identity, whereas in account takeover the attacker controls the victim’s real account.

From an identity and access management (IAM) point of view, impersonation succeeds when an identity claim is accepted without verification. Zero Trust closes that gap with the principle of never trust, always verify: every request is checked again, even when it comes from a familiar name.

Why Is Impersonation So Effective at Fooling Victims?

Impersonation works because it targets the victim’s trust. Attackers apply pressure through fear or deference to authority, so the victim acts before having time to think.

Data that has leaked or sits openly on social media can make a disguise convincing. When an attacker gets the boss’s name and a live project right, even a tech-savvy employee has a hard time getting suspicious.

The Business Impact of Impersonation

Impersonation can hurt a company on four fronts at once: money, system access, customer data, and reputation. On the money side, the FBI’s Internet Crime Complaint Center (IC3) recorded about $3.05 billion in adjusted BEC losses in 2025 and stresses that time is of the essence in recalling fraudulent transfers.

System access is at risk too: Mandiant’s M-Trends 2026 report found that interactive voice phishing surged to 11% of initial infection vectors in 2025, second only to exploits. The report also describes groups such as UNC3944 that target IT help desks to bypass MFA.

Customer data follows, because the credentials a victim hands over give the attacker access that looks legitimate to applications and the data behind them. Inside the system, the attacker is hard to tell apart from a real employee, and if data leaks, customer trust is at risk too.

How Impersonation Works

Impersonation usually runs in four stages, from gathering information to the victim taking the requested action. The flow is the same whether the disguise arrives by email, phone, text message, or video.

  1. The attacker gathers information on the target: Sources can include social media, company websites, professional profiles, or leaked data.
  2. A fake identity is prepared: It can be a fake social media account, a lookalike email domain, a spoofed phone number, or a synthetic voice.
  3. The attacker pressures the victim: The message is made urgent, for example by claiming an account will be blocked or a transfer must be completed today.
  4. The victim acts: That can mean handing over a password or OTP code, clicking a link, installing an app, or transferring money to the attacker’s account.

Common Types of Impersonation

Impersonation can be grouped into seven types based on who the attacker imitates. The table below summarizes the identity being imitated and an example situation.

TypeIdentity ImitatedExample Situation
Executive or boss (CEO fraud)Director or direct managerA finance team member receives an urgent chat asking to transfer funds to a new account
Employee or IT help deskEmployee or IT staffA caller claims to be an employee locked out of their account and asks the help desk to reset the password and MFA
Vendor or partnerRegular supplier or business partnerA fake invoice with a new bank account number reaches the finance team
Customer service or bankBank or marketplace representativeThe victim is asked to read out an OTP to “verify” their account
Government agencyOfficial or regulator, such as a tax agency or the policeThe victim is threatened with legal trouble and told to transfer money
Family or friendRelative or close friendA message from a new number asks for an urgent money transfer
Fake sites and accountsOfficial company or brandA lookalike domain or fake social media account lures customers into logging in

The same FTC data breaks impersonators down by type. In 2025, people reported losing nearly $1 billion to business impersonators, led by bank impersonators, and about $920 million to government impersonators.

Common Types of Impersonation

AI-Powered Impersonation: The Arup Deepfake Case

AI adds new ways to carry out every type above, because a person’s face and voice can now be imitated in phone and video calls. The FBI’s 2025 IC3 report also counted more than 22,000 complaints that reported AI-related information, with adjusted losses above $893 million.

The 2024 Arup case shows how far AI-powered impersonation can go. As Fortune reported, an employee at Arup’s Hong Kong office joined a video call with deepfakes of the CFO and other staff, then transferred US$25.6 million (HK$200 million) over 15 transactions.

The employee had doubts at first but still made the transfers, and realized the scam only after checking with the company’s UK head office. Arup later confirmed that fake voices and images were used.

Fortune suggests a quick test on video calls: ask the other person to turn their head or use a different light source, because a deepfake face may distort. This simple test helps, but it does not replace verification through a second channel.

Warning Signs of Impersonation to Watch For

The most common sign of impersonation is a request that is urgent and involves money or account access, yet is hard to confirm through an official channel. The seven signs below help you spot it earlier.

  • Time pressure or threats: The attacker pushes the victim to act now, for example by threatening to block an account or take legal action.
  • Requests for an OTP or PIN: Legitimate services do not ask for secret codes over the phone or chat.
  • Access reset requests outside procedure: A password reset or MFA re-enrollment is requested by phone or chat without an official ticket.
  • Lookalike addresses or usernames: Check for swapped letters and email domains that differ by a single character.
  • Invitations to switch channels: The attacker asks to continue on a personal number or account to escape company oversight.
  • Sudden bank account changes: The payment destination changes, or a personal account appears on a company invoice.
  • Refusing verification: The other party dodges when asked to call back on an official number or show identification.

How to Prevent Impersonation at Your Company

Preventing impersonation at a company works on two layers: verification procedures for people, and identity and access controls for accounts. The eight steps below can be rolled out in stages, and the second layer still holds the attacker back when an employee has already been fooled.

  • Require second-channel verification for sensitive requests. Confirm transfer requests or bank detail changes by calling a registered official number, never the number given in the message itself.
  • Tighten identity checks at the help desk. CISA and the FBI warn that Scattered Spider actors convince IT help desk staff to reset passwords and MFA tokens, so verify every requester by calling back a registered number first.
  • Enable MFA on important accounts. Because victims can still be talked into handing over OTP codes, phishing-resistant methods such as FIDO2 give stronger protection.
  • Apply conditional access. Identity, device, location, and login risk are evaluated before access is granted, so credentials obtained through deception are not automatically enough to get in.
  • Limit access rights with the principle of least privilege. If an employee is fooled, the damage stays within the access that person holds, while privileged accounts need extra control through privileged access management.
  • Watch for suspicious logins. Logins from unfamiliar locations or outside working hours should trigger an alert through internal application access monitoring, so a hijacked account is caught quickly.
  • Secure your email domain with SPF, DKIM, and DMARC. Together they authenticate messages sent from your domain, which makes it harder for attackers to spoof company addresses.
  • Train employees with impersonation simulations. Simulated phone, chat, email, and video fakes help finance staff and the help desk get used to double-checking before they act.

Conclusion

Impersonation succeeds because it targets people’s trust, and its face keeps evolving, from fake emails to deepfake video calls. An effective defense combines verification procedures with identity and access controls.

Identity controls such as MFA and conditional access mean credentials obtained by deception may not be enough to get in. The easiest first step is to make sure every sensitive request, including password resets at the help desk, can be verified through a second channel.

FAQ

What is the difference between impersonation and phishing?

Impersonation is faking an identity, while phishing is a trap message designed to steal data or money. The two are often used together, for example in a phishing email that poses as a bank.

Is impersonation the same as social engineering?

Impersonation is one technique within social engineering. Other techniques in the same family include phishing and baiting.

What is an example of impersonation that targets companies?

The most common example is CEO fraud, where an attacker poses as a boss over chat or email and asks for an urgent fund transfer. Another targets the help desk, where a caller claims to be a locked-out employee and asks for a password or MFA reset.

How can I confirm that a chat request from my boss is genuine?

Contact your boss through another channel you already know, such as a call to an official number, and confirm the request. Do not use the number or link shown in the message.

Is MFA enough to prevent impersonation?

Not on its own. MFA protects the account, but attackers can talk victims into handing over an OTP code, so phishing-resistant methods and conditional access need to be paired with verification procedures.

Profil Adaptist Consulting

Adaptist Consulting is a technology and compliance firm dedicated to helping organizations build secure, data-driven, and compliant business ecosystems.

Read Related Post

✕