Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is impersonation fraud?

Impersonation fraud uses a false claimed identity or authority to persuade somebody to do something they otherwise would not do.

That might be:

  • make a payment;
  • disclose information;
  • approve an account change;
  • install software;
  • bypass a control;
  • hand over credentials.

The core evidence is the false representation and the action it was designed to trigger.

Impersonation can use many channels

The offender may use:

  • email;
  • text message;
  • phone call;
  • social-media profile;
  • fake website;
  • forged document;
  • lookalike account.

The same incident may move across several channels.

It does not require account takeover

A convincing impersonation can be built from:

  • spoofed number;
  • lookalike email address;
  • copied logo;
  • fake profile;
  • false website;
  • familiar display name.

A genuine compromised account is only one possible route.

Preserve the representation exactly

Record:

  • who or what the communication claimed to be;
  • exact wording;
  • channel;
  • time;
  • requested action;
  • links/files/numbers supplied;
  • what the victim did next.
Example impersonation sequence
Claim: “Northmere Finance Director”Channel: WhatsAppRequest: urgent supplier paymentPayment destination: account ending 4219Victim action: payment approved at 15:42 UTC

That captures the core fraud mechanism before you even know the offender's identity.

The impersonated person may also be a victim

If somebody pretends to be a real director or supplier, do not collapse that person into the suspect simply because their name appears in the communication.

Use wording such as:

“A message purporting to be from…”

until the sending account/session/device is properly attributed.

The practical point is: prove the false identity and requested action first. Then attribute the communication and resulting payment or account change through separate technical and financial evidence.

Reference: CIM-039Cyber Incidents & Offender Methods