Impersonation fraud in the workplace
One cited estimate suggests that nearly 30% of companies report some form of employee impersonation or identity fraud each year. Prevalence figures vary according to the sector, sample and definition used, but impersonation fraud is a relevant concern in increasingly digital and hybrid workplaces. It can lead to financial loss, legal or regulatory exposure, operational disruption and reputational harm.
Impersonation fraud is not the same as identity theft, although the two can overlap. Impersonation fraud involves someone pretending to be a trusted person or organisation to influence another person’s actions. Identity theft involves obtaining and using someone’s personal information without permission. In the workplace, incidents can range from email spoofing and stolen accounts to false identities, manipulated calls and AI-generated audio or video.
Hybrid working can complicate both prevention and detection. Employees may have fewer opportunities to confirm a colleague’s identity informally, while fraudsters have more digital channels through which to make contact. At the same time, established verification procedures and well-configured security tools can help organisations manage the risk.
This article explains common forms of workplace impersonation fraud, why they matter, the warning signs to watch for and practical steps that HR teams, managers and employees can take.
What is employee impersonation?
Employee impersonation occurs when someone pretends to be an employee, or fraudulently uses an employee’s identity, within a business context. It can happen physically, such as when a person poses as a member of staff, or digitally, for example when someone sends messages from a spoofed address, accesses systems using stolen credentials, or imitates a person’s voice or appearance.
Common examples include:
- Email spoofing: A message is made to look as though it came from a genuine employee, often to obtain sensitive information or secure approval for a payment.
- Credential theft: Stolen login details are used to access company systems, data or communications. This may support impersonation fraud, data theft or operational disruption.
- Physical impersonation: Someone poses as an employee, contractor, courier or official to enter a restricted area, attend a confidential meeting or obtain information.
- Deepfake attacks: AI-generated audio, video or images imitate a real person and may be used to request data, approve a transaction or damage a professional relationship. These incidents remain less common than conventional phishing, but the technology is developing quickly. An often-cited forecast suggested a threefold increase in deepfake-based fraud by 2026. Separately, Gartner predicted that, by 2026, 30% of enterprises would consider identity verification and authentication unreliable when used alone because of AI-generated deepfakes.
Quick question: Have you encountered any of these tactics? Impersonation incidents may be reported late or not reported at all, particularly when the initial contact appears routine or the consequences are not immediately visible.
Hybrid and remote working extend impersonation risks beyond the physical office, so verification procedures should apply across email, messaging, phone calls, video meetings and in-person interactions.
Why is employee impersonation a serious threat?
Impersonation fraud can undermine trust, but its effects may also be financial, legal and operational:
- Financial loss: Fraudulent payments, diverted invoices and data theft can cause substantial losses.
- Legal and compliance risk: An impersonation incident may contribute to a data breach or control failure. Depending on the circumstances, this could create obligations or exposure under frameworks such as the Sarbanes-Oxley Act (SOX) or the UK GDPR and EU GDPR.
- Reputational damage: A security failure or fraud incident can affect relationships with customers, suppliers and employees.
- Operational disruption: An attacker may spread false instructions, leak confidential information, interfere with projects or disrupt access to systems.
- Loss of trust: A single incident can reduce employees’ confidence in internal communications and security processes.
The risk can be particularly significant in finance, HR and executive roles because people in these functions may be able to approve payments, change employee or supplier details, or access sensitive information.
In one reported case, a large multinational company lost $1.7 million after a fraudster allegedly impersonated its chief financial officer and requested an urgent wire transfer. The example illustrates the potential impact of a convincing request, but the source and circumstances should be checked before the figure is used as a benchmark.
Warning signs of impersonation fraud at work
Impersonation fraud can be difficult to identify because fraudsters may sound knowledgeable and use websites, documents or branding that closely resemble genuine materials. If a call, email, text message or in-person request seems unusual, pause and consider the following questions:
- Was the contact unexpected? Fraudsters may make contact by phone, email, text, post, social media or in person without prior notice.
- Are you being pressured to act quickly? A person may claim that a payment, account change or decision is urgent. In consumer, investment or employee-benefit contexts, they may also offer a bonus or discount, or say that an opportunity is available only for a limited period.
- Does the offer seem too good to be true? Some fraudsters promise unusually attractive rewards, including high investment returns.
- Are they claiming the offer is exclusively for you? You may be told that you have been specially selected or instructed to keep the opportunity secret.
- Are they trying to flatter you or build a personal connection? A fraudster may try to establish trust so that a request feels less suspicious.
- Are they trying to make you worried or excited? Emotional pressure can be used to encourage a quick response and discourage careful checking.
- Are they presenting themselves as an authority? They may claim to be authorised, refer to internal details or demonstrate knowledge of financial products, company procedures or professional terminology.
A single warning sign does not prove that a request is fraudulent. However, if you answer “yes” to any of these questions, or are unsure whether the contact is genuine, verify the request independently before taking action.
Different forms of impersonation fraud at work
Impersonation fraud can operate through email, phone calls, text messages, social media, websites, networks and face-to-face contact. Some of the techniques below are direct forms of impersonation, while others are technical methods that can enable or strengthen an impersonation attempt.
Phishing
Fraudulent emails are designed to look as though they come from a bank, employer, retailer or online service. Their purpose is often to steal login details or install malicious software.
Spear phishing
A targeted phishing attempt that uses personal or organisational information to make the message appear more credible.
Business email compromise
A fraudster pretends to be an executive, colleague or supplier and asks for payments, confidential information or changes to account details.
Email spoofing
he sender address displayed in an email is falsified, making the message appear to come from a legitimate source.
Account takeover
A criminal uses stolen login credentials or session tokens to control a genuine account, making the impersonation difficult to detect.
Caller ID spoofing and vishing
A phone call appears to come from a trusted number, while the caller claims to represent a bank, government body or technical support provider.
Smishing
Fraudulent text messages impersonate banks, delivery companies, tax authorities or other organisations, often directing recipients to a malicious website.
Social media impersonation
Fake or compromised accounts imitate friends, executives, public figures or brands to obtain money or personal information.
Website and domain impersonation
Lookalike domain names, cloned websites and deceptive characters are used to make fraudulent pages resemble genuine ones.
Brand impersonation
Criminals copy logos, designs, advertisements and customer support identities to create a convincing but fraudulent presence.
Technical support impersonation
A fraudster claims that a device or account has been compromised and asks the victim to install remote-access software or reveal security details.
Physical impersonation
Someone poses as an employee, contractor, courier or official to gain access to a restricted area or obtain sensitive information.
Deepfake impersonation
Artificially generated voices, videos or images imitate a real person, often to create urgency or secure approval for a payment.
Network impersonation
Fraudulent Wi-Fi access points, DNS manipulation and person-in-the-middle attacks make a malicious network or service appear trustworthy.
Device or identity spoofing
Criminals falsify phone numbers, IP addresses, MAC addresses, certificates or other identifiers to bypass weak security controls.
Other warning signs include unusual payment instructions, changed bank details, requests to bypass normal procedures, subtle misspellings in domain names, and requests for passwords or one-time security codes.
Independent verification is one of the most effective safeguards. Contact the person or organisation through a known phone number, a bookmarked website or a separate communication channel. Multi-factor authentication, payment approval controls, password managers, staff training and email authentication measures such as SPF, DKIM and DMARC provide additional protection.
Educate staff
Education should reflect the audience. Workplace training should focus on the requests and channels employees encounter in their roles.
Guidance for employees
- Explain how impersonation fraud can affect payments, payroll, supplier records, personal data and access to company systems.
- Require employees to verify unusual or sensitive requests through a separate, trusted channel, even when the request appears to come from a senior colleague.
- Train staff never to disclose passwords or one-time security codes and to report suspicious contact promptly.
- Reinforce payment approval procedures and make clear that urgency or seniority is not a reason to bypass them.
- Use realistic examples covering email, phone, text, video calls, social media and in-person approaches.
Consistent training, proportionate controls and a culture in which employees feel comfortable questioning unusual requests can reduce the risk of impersonation fraud without creating unnecessary alarm.
What to do after an impersonation attack at the office
If your organisation has been targeted by impersonation fraud;
- Stop all communication with the suspected fraudster and immediately report the incident to your IT or cybersecurity team, line manager and relevant internal departments.
- Do not delete emails, messages, call records or payment instructions, as this evidence may support the investigation.
- If login details were disclosed, change the affected passwords from a secure device, revoke active sessions and enable multi-factor authentication.
- Contact your bank or payment provider immediately if money was transferred or financial details were changed.
- The organisation should secure affected systems, identify what information was accessed, warn employees about related messages and follow its incident-response, reporting and data-breach procedures.
- Depending on the circumstances, the incident may also need to be reported to law enforcement, insurers, regulators, customers or other affected parties.
Prevention controls for an impersonation attack
Organisations should combine employee awareness with controls that prevent a convincing impersonation attack from succeeding. Key measures include:
- Use call-back procedures: Verify requests involving payments, payroll details, account access or sensitive information through a separate, trusted channel. Contact the person using a telephone number already held in company records, not one supplied in the suspicious message.
- Require dual approval: High-value payments, changes to supplier bank details and other sensitive transactions should require approval from two authorised employees. Approvers should independently verify the request and supporting information.
- Strengthen joiner, mover and leaver controls: Grant new employees only the access required for their roles. Review permissions when employees change positions and remove access promptly when they leave. Shared accounts and unused credentials should also be identified and disabled.
- Apply least-privilege access: Employees should have access only to the systems, data and functions necessary for their work. Privileged access should be limited, monitored and reviewed regularly to reduce the potential impact of a compromised account.
- Use stronger multi-factor authentication: MFA provides additional protection when passwords are stolen. Where possible, organisations should use phishing-resistant methods such as security keys or passkeys instead of relying solely on text-message codes. Employees should never approve an unexpected authentication request or share a one-time security code.
These controls should be supported by clear reporting procedures, regular access reviews and role-specific training. Employees must also understand that urgency, confidentiality or a request from a senior colleague is never a valid reason to bypass established security procedures.
Optimise cyber in case of impersonation attack at the office
Optimise Cyber Solutions helps offices reduce the risk of impersonation fraud through practical cybersecurity training and awareness programmes. We teach employees how to recognise suspicious emails, calls, payment requests, account changes and deepfake communications, while reinforcing safe verification and reporting procedures. By using realistic examples and role-specific guidance, we help teams identify an impersonation attack early, respond confidently and protect sensitive information, business systems and company finances.