How does convincing impersonation happen?
A scammer can copy photographs and a name into a new profile, compromise the genuine account, or use generated or altered voice, image and video. A deepfake is synthetic or manipulated media that can make it appear that a real person said or did something.
Do not rely on spotting unusual blinking, facial edges or sound artefacts. Such clues are not always present. Check the request, channel and reason you are being asked to act.
Signals in the request itself
- an unexpected change to payment details;
- a request to skip normal approval or keep the action secret;
- urgent demand for money, a document, password or code;
- a familiar account behaving differently;
- an attempt to keep all verification in the same chat or call.
Verify through another channel
Contact the person through a number or address you held before the suspicious message. Ask a specific question whose answer is not easy to find in public posts. For business payments, follow the existing dual-approval process and verify supplier account changes.
Limit public visibility of your phone number, email, location, travel plans and job details. This will not prevent every scam, but reduces material for targeted impersonation. Protect social accounts with a unique password and 2FA.
If someone is impersonating you
- Preserve the profile address, messages and time.
- Report the fake profile to the platform. If your real account was taken over, follow the account recovery guide.
- Warn contacts through another channel not to open links, share codes or send money.
- If money was sent or banking information exposed, contact the bank immediately. For a work account, include IT, security and finance teams.