What is impersonation fraud?¶
Impersonation fraud involves an offender pretending to be another person, organisation or authority to influence the victim’s decision.
Avoid the dangerous assumption¶
The dangerous assumption is that impersonation depends on technically taking over the genuine account.
It may use:
- a lookalike email address
- a copied social profile
- a spoofed telephone number
- a compromised account
- a fake website
- a forged document
- a familiar display name
- information taken from genuine communications.
The offender may impersonate a senior manager, supplier, bank, government body, police officer, family member or technical-support provider.
Investigators should identify what representation was made and what action it was intended to cause.
Was the victim asked to pay money, reveal information, approve access, install software, change account details or bypass normal controls?
Preserve every communication channel involved. Impersonation schemes often move between email, telephone, messaging and websites to increase credibility.
Check how the victim verified the request and whether the offender discouraged independent contact or created urgency.
The impersonated identity may also be a victim. Their account, brand or contact details may have been misused without their knowledge.
Evidence of impersonation can help establish deception and method. It does not automatically identify the offender behind the communication.
The apparent account may have been compromised, shared or automated. Infrastructure may have been rented or controlled through another service.
Reporting should distinguish between “a message purporting to be from” and “a message sent by” unless authorship is established.
Operational takeaway¶
Identify the false representation, the action it was designed to cause and the channels used, while keeping the impersonated identity separate from the offender.