Picture this: 

A finance employee joins a video call with the CFO and several colleagues. Everything on the call seems normal, as everyone looks and sounds like it’s any working day. The call is efficient, straight to the point. On the advice of several colleagues, the CFO authorizes the finance employee to submit certain wire transfers. So, the employee does as they’re told. 

They have no idea that everyone on that call is fake.

This is exactly the deepfake scam that led to $25.6 million in theft from a British engineering firm in early 2024. It’s a preview of where digital impersonation is headed for everyone, from individuals dealing with a cloned social profile to finance teams wiring money on the strength of a trusted face. And with each passing day, the technology behind these scams grows more sophisticated.

The growing problem of digital impersonation

AI has made impersonation faster, cheaper, and more convincing than at any point in the history of fraud. Cloning a voice used to require hours of recorded audio and real technical skill. Now it takes a few minutes of a public earnings call, a LinkedIn profile photo, and an off-the-shelf tool. 

So, how do you identify synthetic media scams and avoid becoming the target of digital impersonation? How do corporations protect their assets and high-access employees? How do high-risk individuals protect their personal assets and families?

This guide breaks down what digital impersonation has looked like in recent months, the major trending scams, and practical steps to reduce the threat, whether you’re looking to protect your company, a brand, or yourself. 

Impersonation attacks are now common

The video-call scenario from Arup is no longer rare. Recent findings from the Ponemon Institute indicate that 42% of executives and board members have been targeted by a fake image or video at least once. Most (59%) security leaders admit these deepfake attacks are very or highly difficult to detect.

What’s even more troubling is that these attacks are also targeting high-access employees’ families. In a recent Techstrong PulseMeter report, over a third of respondents said a family member had been targeted by social engineering attacks.

In the case mentioned above, the scammers’ opening move was a standard phishing email that the Hong Kong employee correctly flagged as suspicious. However, his doubts faded once he joined a video call and saw his CFO and colleagues, all convincing deepfakes built from public video and audio of Arup executives.

In another case, a bank manager in the United Arab Emirates got a call from a voice he recognized, a company director he’d spoken with many times before. The director said his company was about to close an acquisition and needed $35 million transferred immediately. The manager could see supporting emails in his inbox, confirming the accounts. Everything lined up, but the voice was cloned. The stolen money was scattered across more than a dozen accounts before anyone realized.

These attacks work because they target human judgment. Judgment is much harder to patch than software, especially since, with impersonation attacks, there are three techniques scammers use to support the AI deception: 

  • Presumed authority
  • Personal familiarity
  • The illusion of urgency  

What this means

For executives, CISOs, board members, and high-profile individuals alike: educate yourself, your family, and your team. 

In all digital exchanges, ask yourself, “Is this person leaning on authority, familiarity that feels performed, or urgency that doesn’t match the stakes?” 

Then, always confirm before you act.

Digital impersonation: 6 trending scams in 2027

Digital impersonation is a family of techniques built around the single goal of making someone believe they’re dealing with a real, trusted person when they’re not. Here are the most common attacks we’ve been tracking in recent months—and how they work.

1. Deepfake video scams

“Anyone can be manipulated, even the best of us.” 

That’s a direct quote from a CISO when specifically discussing deepfake attacks. Other CISOs have called them “phishing on steroids,” with some reporting as many as 4-5 significant targeted deepfake attacks this year alone.

Deepfake video scams rank at the top of this list for potential financial damage, mostly because they use the strongest form of proof most people trust: a live face on a call. 

Detecting these in real time is hard even for trained staff, since the tells that used to give deepfakes away (flat blinking, lag, waxy skin, or a “mask-like” appearance) have mostly been engineered out of current AI tools. 

Portrait picture of a 2 men side by side with subtle differences

The identifying traits of deepfakes are subtle—slightly smoother skin, blemishes filtered out—and the technology continues to improve.

This is why so much of the advice on how to prevent deepfake video scams now focuses less on spotting artifacts and more on authentication habits, including: 

  • Confirming a request through a second channel before acting
  • Treating any urgent financial ask on video as unverified until proven otherwise 
  • Building protocols that make an out-of-nowhere request stand out 

For more in-depth deepfake protection strategies, jump ahead: 

How to protect against digital impersonation attacks in 2027

2. AI voice scams: Voice cloning and voice spoofing

Voice cloning, sometimes called vishing, is the use of deepfakes in a phone scam. A short clip from a podcast, an earnings call, or a conference talk is often enough to produce a convincing clone. 

While the UAE bank fraud above is a high-profile example, these same techniques now show up in everything from corporate fraud to domestic cyberattacks. Common techniques include:

  • A “CEO” looking to approve an urgent payment
  • A high-authority “employee” requesting access to a locked-out account
  • An “IT professional” requesting login credentials
  • A “medical/authority figure” requesting personally identifiable information
  • A “family member” calling in distress, requesting funds 

The common thread is that the voice sounds right, so the listener stops applying the scrutiny they’d use on a text or email. It’s increasingly a threat within the corporate perimeter and for personal lives beyond.

3. Business email compromise and email impersonation

Business email compromise, or BEC, is the oldest technique on this list, yet it remains one of the most costly because AI has made the emails themselves harder to detect. The grammatical mistakes and awkward phrasing that used to flag a phishing email are gone. 

AI-written BEC emails now match the tone and structure of the person being impersonated, sometimes trained on that person’s actual sent messages if they’ve been exposed in a prior breach. Combine a clean BEC email with a follow-up deepfake voice call, and you get a scam that clears almost every traditional red flag.

That’s why best practices for BEC cybersecurity remain even more important:

  • Carefully examine the email address and URL used in any correspondence.
  • Call the company to ask if the request is legitimate. Look up the company’s phone number on your own. Never use anything a potential scammer provides. 
  • Don’t click on anything in an unsolicited email or text message asking you to update or verify account information. 
  • Verify any changes to the account number or payment procedures with the person making the request. 

4. Online impersonation and social media impersonation

Social media and online impersonation are usually the versions of digital impersonation most people encounter in their everyday lives. By exploiting lapses in social media companies’ authentication protocols, scammers create fake accounts of individuals or even brands. 

What to do if someone is impersonating you

Impersonation scams on social media targeting execs and other high-profile individuals: Recent trends show an increase in spear-phishing attacks on individual high-value targets and their networks. Scammers build a convincing social profile using a person’s real name and photos, often pulled from a corporate page or a public LinkedIn profile, and use it to contact that person’s connections under false pretenses. 

A new deception trend worth noting: Bot networks are increasingly used to create the illusion of a robust friend network, helping the fake account appear legitimate. Throughout 2027, we expect this trend to continue growing.

3. Brand and infrastructure spoofing

Brand and infrastructure spoofing uses deceptive online pages to harvest data from their targets. While often less personal than the scams above, it feeds the same pipeline of impersonation. The credentials and personal details harvested through spoofed infrastructure often become the raw material for a more targeted impersonation later.

This typically includes:

  • Lookalike domains that mimic a company’s real site
  • Fake login pages that capture credentials when someone types them in
  • Fake customer service numbers that may even outrank the real ones in search results or ads
  • Spoofed sender emails that look like they came from a known brand

One attacker can spin up dozens of lookalike domains and fake support numbers in a day. Prevention comes down to education and good cybersecurity habits:

  • Bookmark real login pages and financial sites 
  • Verify customer service numbers through the company’s official app
  • Check the sender’s actual domain on any email from a “known” brand
  • Report fake websites and spoofed numbers to the company being impersonated

4. Executive and CEO impersonation

This scam overlaps with many of the above techniques, but recent, increasing trends push it into its own category. Executive and CEO impersonation attacks will include deepfake video, voice cloning, BEC, fake social profiles, and more—all aimed at a company’s most senior, highest-access people.

It’s because executives, board members, and high-net-worth individuals make unusually good targets. Why?

  • Large public footprint: Earnings calls, keynotes, interviews, press coverage, and even LinkedIn activity hand attackers an extensive research trail.
  • Undermatched personal security: Highly secure corporate networks do nothing for a home Wi-Fi router or a personal phone, even as executives’ personal accounts may hold the same sway over corporate decisions.
  • High exposure: Home addresses and travel itineraries are often a few simple searches away.
  • High authority: They can approve the wires and deals that make impersonation worth the effort.

As a result, executives are increasingly getting impersonated over WhatsApp, LinkedIn, SMS, phone, email, and video, often at once. 

We find that attack patterns are constant but often cluster around moments of publicly monitored change: M&A, leadership transitions, executive travel, wire approvals, product launches, and/or public controversy. 

Looking to defend the digital vulnerabilities where executives are getting targeted the most? Jump ahead to:    

For executives and high-profile individuals: The growing importance of a circle of trust

How to protect against digital impersonation attacks in 2027

AI deception technology is rapidly advancing, but certain strategies can significantly reduce exposure and limit the potential threats. 

1. Follow best practices for protecting your online identity

These basic hygiene tips aren’t groundbreaking, but even in 2027, they’re too often overlooked. These best practices are no longer optional for anyone with a public profile, especially those who appear on company website leadership pages, have a significant net worth, or have a large social following.

How to protect your identity online: 3 places to start

Step 1. Know what personal information is publicly findable 

    • Check for old accounts and cached posts you forgot existed.
    • Google your name plus city, employer, and old usernames. 
    • Run a reverse image search on your profile photo.
    • Search your email on Have I Been Pwned to see what breaches you’ve been part of.
  • Are your social accounts public? If so, scammers can easily discover everything from your daily routines and personal network to your upcoming travel plans.

Step 2. Use strong, unique authentication everywhere, particularly on email and financial accounts. These are the accounts an attacker wants most.

Step 3. Enlist data broker removal services to address the hundreds of sites that collect and sell your personal information. This is essential to remove instances of home addresses, personal information, and family details.

2. Monitor for false accounts, mentions, or content

Fake profiles, cloned websites, and deepfake videos can spread quickly. Set up monitoring to watch for fake accounts reaching out to your employees, investors, or family.

With a free tool like Google Alerts, you can receive updates on posts that include your name, common misspellings, and any businesses you’re associated with. Other paid services can provide more in-depth narrative intelligence to help you understand what’s being said about you and why.

What to watch for:

  • Fake profiles on LinkedIn, X, Instagram, and Facebook using your name or photo.
  • Lookalike domains that swap a letter or add a word to your name or company.

For high-profile individuals and companies: Consider monitoring services that also watch for mentions on cybercriminal forums, Telegram channels, and the dark web, where stolen data and cloned identities circulate. 

3. Implement future-proof deepfake protection (not detection

Deepfake detection is the piece most people think of when it comes to digital impersonation cybersecurity. This usually means some combination of technical analysis (checking video or audio for signs of AI) paired with education (teaching people what to watch for and, more importantly, what not to trust anymore). 

But unfortunately, AI deception tools are advancing too quickly for detection to work on its own. Just as bad, even when detection tools are working, they often rely on a probability score that gives an estimate of how likely a call or video is fake. It may sound helpful, but in practice, CISOs and others have found the service impractical. After all, a 2% chance of a deepfake is still extremely high when millions or more are at stake, even if the percentage is technically low. 

That’s why, in general, security leaders are opting for Impersonation Protection tools that completely sidestep the threat posed by advancing deepfake technology. By providing a practical, future-proof way to validate a communication before acting on a request, these tools have become the most reliable way to prevent deepfake scams.

4. Understand the link between impersonation and identity theft

Especially for those in the cybersecurity sphere, it may seem like a simple distinction, and yet too often the gap highlights one of the biggest ongoing threats to at-risk individuals. Digital impersonation and identity theft build off one another, as each instance compounds the danger of the other.

Identity theft vs. impersonation

Impersonation is a scam in which a person impersonates another to deceive a specific target, usually for a single payoff: a wire transfer, a leaked document, a damaged reputation, etc. 

Identity theft is broader: using someone’s personal information, stolen or scraped, to open accounts, file claims, or access financial systems in their name, often without any live deception at all.

Why this distinction actually matters

Enough impersonation attempts, successful or not, can add up to identity theft, because each attempt is also a reconnaissance exercise. At the same time, identity theft can lead to more convincing digital impersonation attempts, as scammers now have access to troves of PII for training AI models.

Even a failed BEC email can confirm a phone number, an internal process detail, or a real relationship an attacker didn’t have before. Data doesn’t disappear once the scam attempt is over. It circulates among scammers or data brokers, gets bundled with other exposed information, and becomes raw material either for a better-targeted impersonation attempt or for identity theft down the line.

All cyberattacks, successful or not, can be a compounding threat. That means each and every incident should be closely reviewed to learn exactly what new information may have been revealed to scammers. If new personal details are revealed, expect them to reappear and be leveraged in future attacks.

5. Have a plan in place for response

Prevention is ideal, but a response plan is necessary, even though most corporations and individuals don’t build one until they need it.

For businesses, plan for both threat isolation and reputation protection: For social media impersonation, this typically means effective monitoring where fake accounts and manipulated content tend to surface, and a fast path to getting damaging content taken down before it spreads. For compromised employee identities/accounts, set up secure, out-of-band channels in advance through which in-house teams can be notified of the ongoing threat, even before it’s shut down. 

For individuals, particularly the high-net-worth and their families, your plan can include a verification method that doesn’t exist anywhere digitally, like a code word or phrase, agreed on in person, used to confirm identity before acting on an urgent request for money or sensitive information. Remember that if it’s written in an email, text, or shared drive, anyone with access to your accounts can find it, too. Another downside to this method is if those with that information end up leaving that inner circle, a new code word or phrase needs to be created. 

For executives and high-profile individuals: The growing importance of a circle of trust

Recent trends have shown that executives and high-profile individuals require one more layer of defense because of who they talk to, because of how much a single successful impersonation can cost, and because of the increasing frequency and intensity of the attacks targeting them.

A circle of trust is a confirmed network, usually family, assistants, advisors, and board members, that any message claiming to come from inside the circle can be checked against. With it, any odd request gets flagged before anyone has to make a judgment call under pressure.

It’s a strategy built for the people whose exposure runs highest. It’s a part of a three-pillared cyberdefense structure designed to protect executives, HNWIs, and high-profile individuals from all developing impersonation threats outside the corporate perimeter, which includes:

  • Impersonation Protection lets members confirm a communication, using out-of-band biometric and location checks instead of trusting that a voice or video looks convincing. Impersonation protection with circle of trust extends that authentication to anyone in a BlackCloak member’s inner circle, such as family, friends, advisors, and household staff, closing the exploit of going around the member rather than through them.
  • Exposure Intelligence adds continuous monitoring across all targeted digital vectors, with pattern detection that catches coordinated campaigns a single flagged post would miss. 
  • Personal cybersecurity protection reduces the amount of personal information available online that a deepfake or cloned voice would otherwise be built from. It extends corporate-grade cybersecurity to the executives’, HNWIs’, and high-profile individuals’ personal devices and home networks that have become prime targets.

Learn more about BlackCloak’s enhanced Impersonation Protection and personal cybersecurity features that make up the Digital Executive Protection Platform. featuring circle of trust.

What to do if someone is impersonating you

Here’s what to do the moment something is already happening.

Someone is impersonating me on Facebook 

Report the account through Facebook’s impersonation reporting form, document it with screenshots before it disappears, and alert your real contacts directly, since the fake account is likely already messaging them.

Someone is impersonating me on Instagram or Threads 

Use Instagram’s in-app reporting for impersonation, save evidence first, and warn people in your network separately, since a message from the fake account may already be sitting in their inbox.

Someone is using one of my old email accounts 

Change the password if you can still get in, check what’s still linked to it (recovery emails, old financial accounts, forgotten subscriptions), and report it to the provider as compromised. If you can’t log in at all, use the provider’s official recovery flow, and expect to prove you’re the original owner.

I’m locked out of one of my accounts 

Go straight to the provider’s official recovery process, not a link from an email offering to help, since that’s a common way attackers compromise the account you’re trying to save. 

There are deepfake videos of me online 

Screenshot and save the URLs before you report anything, since platforms sometimes remove content faster than you can document it. Use the platform’s specific synthetic media or deepfake reporting path rather than general abuse reporting. 

If the video is being used for fraud or harassment, that’s worth involving law enforcement, too.

Someone knows my password 

Change it everywhere you’ve reused it, not just the account where it leaked, and turn on multifactor authentication anywhere you haven’t already. Check that account’s recent login history and connected devices for anything unfamiliar.

Someone is using a false email address that resembles mine 

Warn your real contacts before the impersonator does, since a lookalike address only works if people aren’t looking closely. 

Report the address or domain to the email provider, and if it’s spoofing a company domain instead of a personal one, loop in that company’s security team as well.

BlackCloak: Elite digital protection for those most at risk

Impersonation only has to work once. See how BlackCloak protects executives, high-profile individuals, families, and reputations before an attack happens. 

Talk to our team or request a demo today.