Brand Monitoring
AI Impersonation Attacks: How Attackers Clone Brands and Executives, and How to Respond
Meredith Gray · · 6 min read

Key Takeaways
- AI impersonation uses deepfake video, cloned voices, fake social profiles, and spoofed websites to pose as trusted people and brands.
- Generative AI makes impersonation faster and more convincing, and removes many of the errors that used to give fraud away.
- In the Arup case, a deepfake video call with a fake CFO led an employee to send about US$25.6 million across 15 transactions.
- Most impersonation infrastructure is built outside your network, so internal security tools rarely see it before someone acts.
- Verify high-risk requests through a separate channel, monitor for impersonating assets, and take them down quickly.
Summarize this article with:ChatGPTGeminiPerplexityClaudeGrok
AI impersonation is the use of generative AI to pose as a trusted person or organization, such as an executive, a brand, or an authority figure, to steal money, credentials, or data. Attackers use AI to produce convincing fake video, cloned voices, spoofed websites, and fake social profiles faster and at higher quality than they could by hand. Most of that infrastructure is built and deployed outside your network, so internal security tools rarely see it before someone acts on it.
What is an AI impersonation attack?
An AI impersonation attack is social engineering where the trust signal is synthetic. Instead of a clumsy email from an unknown sender, the target sees a familiar face on a video call, hears a known voice, or lands on a website that looks like the real one.
The attacker's goal hasn't changed: get someone to approve a payment, share credentials, hand over personal data, or click a malicious link.
What has changed is cost: AI has made believable impersonation much cheaper.
What generative AI changed for attackers
The FBI warned in a December 2024 public service announcement that generative AI reduces the time and effort criminals need to deceive targets, and that it can correct the human errors that used to give fraud away. The same announcement describes criminals using AI to:
- Generate large numbers of fictitious social media profiles.
- Write content for fraudulent websites.
- Embed AI chatbots on fraudulent websites to push visitors toward malicious links.
- Clone voices to impersonate individuals, including to access bank accounts.
- Generate video for real-time chats with people posing as executives, law enforcement, or other authority figures.
For security teams, that adds up to three practical shifts:
- Volume. Fake profiles, pages, and messages can be produced in bulk.
- Quality. Spelling mistakes, awkward translation, and low-effort graphics are no longer dependable warning signs.
- Channel spread. A single campaign can combine email, social media, spoofed websites, messaging apps, and live video.
Common types of AI impersonation attacks
| Attack type | What the attacker creates | Where it shows up | Typical target |
|---|---|---|---|
| Deepfake video | Synthetic video of an executive, official, or public figure, live or pre-recorded | Video calls, social media posts and ads | Finance staff, employees, the public |
| Voice cloning | AI-generated audio that mimics a known person | Phone calls, voice messages | Finance teams, account holders |
| Fake social profiles | AI-generated photos and personas posing as executives, staff, or officials | Social networks, messaging apps | Customers, members, employees |
| Spoofed websites | Lookalike pages with AI-written content, sometimes with embedded chatbots | Lookalike domains, sponsored search results | Customers, members, the public |
| AI-written phishing | Fluent, tailored messages with fewer obvious errors | Email, SMS, direct messages | Employees, customers |
Two documented AI impersonation cases
Arup: a deepfake video call and US$25.6 million
In early 2024, a finance employee in engineering firm Arup's Hong Kong office joined a video call with people he believed were the company's chief financial officer and other colleagues. All of them were deepfakes. He went on to send HK$200 million, about US$25.6 million, across 15 transactions, according to CNN's reporting of Hong Kong police statements.
The employee had first suspected the request, a message about a secret transaction, was phishing. The video call is what removed his doubt. Hong Kong police investigators later determined the deepfakes were built from videos of the executives that were already available online.
FBI: deepfake officials promoting a spoofed IC3 website
In July 2026, the FBI updated its warning about criminals impersonating its Internet Crime Complaint Center (IC3). In one variant, AI-generated videos showing a senior FBI leader circulated on social media and directed viewers to a spoofed IC3 website. The fake site mirrored the real site's structure but only collected a name, phone number, email address, scam type, and estimated loss.
In another variant, scammers built fake social media profiles and pages impersonating FBI personnel, then contacted victims through Facebook Messenger and Telegram. The FBI also advised the public to avoid sponsored search results for IC3, noting they are usually paid imitators.
What the two cases share: both attacks ran on assets the targeted organization did not own or control, including public video, social media accounts, spoofed websites, and third-party messaging apps.
Why internal security controls miss AI impersonation
Email filtering, endpoint detection, and log monitoring watch what happens inside your environment. AI impersonation is mostly assembled somewhere else:
- A deepfake of an executive can be trained on publicly available video.
- A fake support or executive account lives on a social platform.
- A spoofed login or complaint page sits on a domain you don't own.
- The conversation moves to a messaging app or a personal phone.
None of that raises an alert internally until someone acts on it. By then, the payment may already be sent or the credentials entered.
See what attackers can find about you
Get a free report on your organization's external exposure: lookalike domains, impersonation accounts, and leaked data.
Get your Free Risk ReportHow to respond to AI impersonation
1. Stop treating sight and sound as proof
The Arup employee used a video call to settle his doubts, and the call was the attack. Payment approvals, credential resets, and sensitive data requests need confirmation through a channel the requester did not provide, such as a known phone number, an internal ticketing system, or a second approver.
2. Know what raw material attackers have
Inventory what is publicly available about executives and high-risk roles: video and audio, personal contact details, and exposed personal data. You won't remove all of it, but you will know what an attacker can work with.
3. Monitor where impersonation is built
Watch for newly registered lookalike domains, social profiles using your brand or executive names, spoofed login and support pages, and ads that use your brand or your leaders' likeness.
4. Take impersonation down quickly
Fake profiles, sites, and ads keep working until they are removed. Have a takedown process ready for registrars, hosting providers, and social platforms, and track how long removal takes.
5. Tell people what you will never do
The FBI's IC3 guidance is a useful model. It states plainly that IC3 has no social media presence and will never contact individuals through phone, email, social media, or messaging apps. Publish the equivalent for your customers, members, and staff.
6. Report it
Report impersonation to the platform hosting it. If fraud has occurred, US organizations and individuals can file a complaint at ic3.gov.
Where digital risk protection fits, and where it doesn't
Digital risk protection (DRP) covers the external layer of AI impersonation: the domains, websites, social accounts, and exposed data attackers use to build and deliver the attack. DRP won't stop a live deepfake call that is already in progress. That is the job of verification controls and trained staff.
Styx Intelligence monitors for brand impersonation, impersonation accounts targeting your leadership, leaked personal data, and exposed credentials, pairing AI-powered detection with dedicated analysts. Teams can initiate takedowns of impersonating domains, phishing sites, and fraudulent social accounts directly from the platform. For lean security teams, that means finding and removing the infrastructure behind impersonation campaigns without building an in-house monitoring function.
Frequently asked questions
Can you spot a deepfake by looking closely?
Sometimes, but you can't rely on it. The FBI lists clues such as distorted hands, irregular faces, inaccurate shadows, and voice lag, and it also notes that AI-generated content is often difficult to identify. Treat visual clues as a bonus, not a control.
Is AI impersonation the same as phishing?
No. Phishing is one delivery method. AI impersonation also includes cloned voices, deepfake video, fake social profiles, and spoofed websites, and a single campaign often combines several of them.
Who do AI impersonation attacks target?
Employees who can move money or grant access are frequent targets, as the Arup case shows. Customers, members, and the public are targeted too, through fake profiles and spoofed websites that borrow a trusted organization's identity.
Want this visibility for your own footprint?
Book a demoRelated articles

What Is Smishing? How to Spot a Scam Text in 2026
What is Smishing? Smishing is phishing by text message. The word combines “SMS” and “phishing.” The goal is the same as email phishing: get you to tap a link, hand over information, or send money. Attackers usually prete
May 28, 2026 · 9 min read

Lookalike Domain Attacks by Industry: Why Every Sector Faces Rising Digital Risk
How Lookalike Domains Damage Businesses Lookalike domains and phishing websites disrupt trust, slow operations, and yes, they cost a lot of money. One impersonated site or phishing email can set off a chain reaction acro
Oct 30, 2025 · 9 min read

Lookalike Domains and Phishing Websites: How to Find, Block, and Take Them Down
Cyber threats are getting harder to spot. Lookalike domains sit at the center of modern phishing attacks, costing businesses over $100 billion globally in 2024. These attacks don’t look suspicious anymore. They use prope
Oct 3, 2025 · 12 min read
