Executive impersonation uses a leader's identity to lend false authority to accounts, messages, calls, or websites. Verify requests through a trusted channel, preserve evidence, trace connected assets, and confirm what each enforcement action changed.
What executive impersonation looks like
The attacker does not have to break into an executive's inbox. They can create a new social profile with a real photograph, register a lookalike domain, spoof a display name, or place a call that sounds familiar. The identity becomes a shortcut to trust with employees, partners, customers, and the executive's contacts.
In a 2025 warning, the FBI described text and AI-generated voice messages impersonating senior US officials. Those messages attempted to move recipients to another messaging platform and gain access to accounts. The example concerns public officials, but the verification lesson applies whenever a familiar name or voice arrives through an unexpected channel.
Executive impersonation overlaps with brand impersonation, but the trust cue is a specific person's perceived authority. The goal may be payment diversion, access to sensitive information, credential theft, or harm to a trusted relationship. The visible fake may be only one part of a larger campaign.
Signals worth investigating
A single typo or unfamiliar profile is not proof of fraud. Compare the identity, contact path, request, and any linked infrastructure before prioritizing a case.
Identity
A copied portrait, name, title, biography, or familiar writing style on an account the organization has not verified.
Contact path
A new phone number, messaging handle, reply-to address, or lookalike domain that differs from a known channel.
Request
An urgent transfer, confidential document, credential, sign-in code, or switch to a different messaging application.
Connection
The same avatar, link, callback number, domain, or message template appearing across several accounts or posts.
The FBI advises checking addresses, phone numbers, URLs, and spelling, then independently contacting the person. Visual or audio imperfections can be clues, but convincing media can also be fake. Build the decision around a trusted callback, not around whether an image looks real.
Verify the identity, not the message
Use a previously confirmed phone number, company directory entry, or established contact to check a sensitive request. If a message asks you to change channel, obtain the new contact details independently.
The FBI's business email compromise guidance recommends a secondary channel when account information changes. The same check helps when a purported executive requests a transfer, document, or sign-in code.
A response workflow for the first report
The immediate goal is to protect the recipient, preserve the signal, and discover whether it connects to more assets. These steps are an operational sequence, not a promise that every provider can remove every asset.
Pause the requested action
If money, credentials, access, or sensitive information is involved, stop that workflow while the request is checked. Do not use a number or link supplied in the suspicious message as the verification channel.
Confirm through an established channel
Contact the executive or their authorized delegate through a number or account already on record. Record who confirmed the request, when, and through which channel. A familiar photo or plausible voice is not proof of identity.
Preserve and scope the evidence
Capture the profile, full URL, handle, message, timestamps, destination links, and any affected recipients. Check for connected accounts, domains, or messages before treating the first report as the entire operation.
Contain and report
Notify the internal security owner and affected teams. Report the fake account to its platform, a malicious page to its host or other responsible provider, and fraud to relevant authorities. If a transfer was made, contact the financial institution immediately about a recall.
Verify the result and watch for return
Recheck the account, page, and related assets after a provider responds. Log what changed: a warning, removed post, disabled account, inaccessible page, or suspended domain. Keep monitoring for replacements and alert affected people through an official channel.
The FTC advises businesses facing impersonation to warn customers promptly through official channels and report suspected scams. For a fraudulent transfer, the FBI advises contacting the financial institution immediately about a recall and filing a complaint with IC3.
Evidence to preserve before it changes
Collect enough to support both internal investigation and the provider-specific report. Preserve what you can observe safely. Do not enter real credentials, payment information, or personal data into a suspected fake.
What removal actually changes
The right report depends on the asset and the provider with control over it. Record the outcome rather than treating a submitted takedown request as a completed takedown.
| Outcome | What changed | What may remain |
|---|---|---|
| Post or profile removal | The specific content or account is disabled | Other accounts and linked sites may remain |
| Page or hosting removal | Hosted content becomes unavailable | The domain or social account may still exist |
| Warning or block | Some visitors see a warning or cannot reach the asset | The underlying content may remain online |
| Domain suspension | The named domain stops operating | A replacement domain may appear |
A successful report can reduce exposure without ending the campaign. Check the precise account, page, and domain again after enforcement, and watch for related or replacement assets.
Prepare before the next case
Maintain an approved list of executive accounts, domains, and contact routes. Assign the security owner and the person who can reach each executive. Decide which requests require an independent callback, and rehearse what finance, legal, communications, and support should do when one arrives.
For owned domains, email authentication is part of the baseline. The FTC recommends it to help receiving servers distinguish authorized messages from spoofed ones. It does not make fake social profiles or lookalike domains disappear, so monitoring and a provider-specific response path still matter.
Outtake's digital risk protection approach connects suspicious identities, infrastructure, and distribution into a wider case rather than treating each reported account as a separate ticket. Teams can investigate and route action with control over enforcement preferences. See the phishing takedown guide for more detail on evidence, escalation, and verification.
Frequently asked questions
What is executive impersonation?
It is the false presentation of a person as a company leader or other executive in an account, message, call, site, or other channel to exploit that person's authority or relationships. It does not require the executive's real account to be compromised.
Is a convincing voice or video enough to confirm identity?
No. The FBI has warned that malicious actors use AI-generated voice messages in impersonation campaigns. Verify unusual requests through a previously established channel, especially when the request concerns money, credentials, or a new contact path.
Who should own the response?
Name one accountable security or fraud owner and a clear path to the executive's office, legal, communications, and any affected finance or customer teams. Platform enforcement and customer warnings often require several teams, but the case should have one record and an agreed outcome.
Does taking down one fake account end the incident?
Not necessarily. A copied identity may also point to a lookalike domain, message campaign, or replacement profile. Verify the reported account is gone, search for related assets, and continue monitoring for recurrence.