Blog
Guides

Identity theft and impersonation: types, consequences and how to prevent it

Pretending to be someone else in order to get something is an old fraud with new tools. It happens to the person whose identity documents end up being used by somebody else, and it happens to the company that pays an invoice to a supplier that was not its supplier. Both are searched for with the same words and neither is resolved the same way, so this guide separates what to do in each case: what it is exactly, how impersonation differs from full identity theft, how it reaches a company today, and what to do once it has already happened.

A
Asperis Security
Offensive Security team
3 August 2026
9 min read
Share:
An account-change request passing through three open gates (voice, face and real thread) and stopping at a cross because it came through the same channel, while the only line that reaches accept rises perpendicular from a different channel.

What identity theft and impersonation are

Identity theft and impersonation mean passing yourself off as another person or as an organisation in order to obtain a benefit or cause harm. No document needs to be stolen: it is enough to assemble sufficient data for whoever is on the other side to believe they are talking to you.

That data is almost never stolen in one go. It is assembled: a work email address that is published, an org chart that can be inferred from LinkedIn, a phone number that appears in a signature, a password that leaked somewhere else years ago. That is social engineering, and its raw material is information that is nearly always public, or already out there without anyone having noticed.

There are two different victims and it is worth not mixing them up:

  • The person. Someone takes out contracts in their name, opens accounts, uses their card, or creates a fake profile with their face.
  • The organisation. Someone passes themselves off as a director, as a supplier or as the brand itself so that an employee, a customer or a bank does something: pay, grant access or hand over data.

The rest of this guide covers both, but it dwells on the second, which is the one almost nobody explains and the one that moves the most money per incident.

Impersonation and identity theft: where the line falls

It is the most repeated question and almost nobody answers it, so it goes first.

In everyday use the two terms are used interchangeably, and in most conversations they are. Where a distinction is drawn, it is drawn like this:

  • Impersonation is the broad term: any act of passing yourself off as somebody else, even once and for one thing only. An email signed with the name of the finance director is impersonation.
  • Identity theft is normally reserved for the sustained version: somebody does not imitate a single message, they assume your identity and act as you over time, exercising rights that are yours.

The practical difference, and the one you notice when you report it, is exactly that: an isolated email and somebody living under your name are not investigated the same way and do not leave the same trail.

What this page will not do is tell you how your case is classified in law. That depends on what was done, with which document and with what intent, and it changes from one jurisdiction to another. A lawyer with the facts in front of them decides it. What matters here is the other half: how it is done technically, how it is detected and how it is made difficult.

How it reaches a company: CEO fraud and BEC

This is the form of impersonation that moves the most money in a company and the one that looks least like what people imagine. There is no virus and no red screen: there is a correct email, written in your language, arriving at a plausible moment.

CEO fraud is the well-known version: somebody writes as the chief executive to whoever can authorise a payment, usually with urgency, confidentiality and a deal that justifies skipping the usual circuit.

Business email compromise is the whole family, and its variants are worse because they are more believable:

  • Supplier bank account change. Somebody gets into a real supplier’s mailbox, waits for a real invoice and replies in that same thread asking for the account number to be updated. Everything is genuine except the IBAN.
  • Payroll diversion. An email to HR, in an employee’s name, changing the account the salary is paid into just before the end of the month.
  • Impersonating a lawyer or an adviser in a real transaction the company was already expecting.

The way in is usually spear phishing: not a mass email, but one written for one specific person. Its cousins on other channels are smishing by SMS and vishing by phone, which is the old telephone scam with better scripts.

The control that cuts this off is not technical, it is procedural: no change of bank details is accepted through the same channel it arrived on. It is verified by phone, on a number you already had, not the one in the email signature.

Brand impersonation: when you are the one impersonated in front of your customers

Here the victim who pays is not the company, it is its customers, and the brand is charged for it anyway.

The usual forms are a domain that looks like yours with one letter changed or a different extension, a fake social profile that answers your customers, or emails that go out in your name from servers that are not yours.

That last one has a concrete, measurable defence that many companies still do not have properly in place: the records that authorise who may send email on behalf of your domain, with DMARC on top telling the world what to do with anything that does not line up. Publishing it without ever reaching a reject policy is leaving the door ajar, and that is the state most are in.

The other thing you need is to look: domains registered that resemble yours, profiles opened in your name, and mentions of your brand where access is being sold. That is dark web monitoring, and it is how you find out before an angry customer tells you.

Voice and video: the deepfake is no longer a plot device

Cloning a recognisable voice from public material is a consumer task today, not a laboratory one. And that breaks the informal control half of every company leans on: calling to confirm.

A voice deepfake is used where it has the most effect: a short call, background noise, urgency, and a request that was already half expected. And on video calls, at exactly the quality where the flaws look like the connection.

The practical conclusion is not to distrust everybody, which is not workable. It is this: recognising a voice or a face has stopped being a verification. What verifies is a different channel and a piece of information the attacker cannot have, not that somebody sounds like who they say they are. It is worth saying out loud inside the company, because the people who approve payments still believe that recognising the boss is enough.

Where they really get in: the credentials that are already out

A good share of impersonation does not start with a deception, it starts with a password that is already circulating.

  • An infostealer on somebody’s home laptop takes the passwords saved in the browser and, with them, the session cookies. With a stolen session, the second factor has already been passed.
  • Credential stuffing automatically tries combinations leaked from other services against your own portal. It works because people reuse passwords, not because your site has vulnerabilities.
  • The result of either is an account takeover: the account is legitimate, the person using it is not. That is why the fraudulent email does not look fake, because it is not.

And out of that comes the most useful signal there is to watch: a credential from your domain appearing for sale. When that happens there is nothing left to detect afterwards, because the attacker walks in through the front door.

If it has already happened: what to do and where to report it

In order, and the first two before anything else:

  1. Gather and preserve the evidence before touching anything. Screenshots with the date and time visible, the emails with their full headers (not forwarded, which loses them), URLs, account numbers, transfer receipts. Without that, the report is just a story.
  2. Cut off the access. Change passwords, close open sessions and check for automatic forwarding rules in the affected mailbox, which is what the attacker leaves behind in order to carry on reading.
  3. If money is involved, tell the bank immediately and ask for a recall. The first few hours are what decide whether it comes back.
  4. File a police report. In Spain that means the Policía Nacional or the Guardia Civil, the two national police forces; elsewhere it means whichever body takes reports of cybercrime where you are. Wherever you are, this is the step almost nobody takes and without which there are no proceedings.
  5. If personal data is involved, there is a supervisory authority to notify. In Spain it is the AEPD, the Agencia Española de Protección de Datos, the national data protection authority. If the company affected processes other people’s data, on top of reporting the crime it has notification duties of its own under the GDPR (the RGPD in Spanish) and under the LOPDGDD, the Spanish law that adapts the GDPR to national law and has no direct equivalent elsewhere. Every EU member state has its own supervisory authority, so the GDPR duty is the same and the body you notify is not, and this is a point to have somebody look at with the text in front of them.
  6. INCIBE, Spain’s national cybersecurity institute, runs a public cybersecurity helpline for citizens and businesses, and it is a good place to get your bearings on the steps if this is the first time.
  7. If the impersonation is on a platform, report it inside the platform as well. That is what gets it taken down quickly, although it does not replace any of the above.

For a company there is one more step that gets forgotten: warn whoever might receive the next email. If your finance director is the one being impersonated, the people who are going to get the request are your suppliers and your customers.

How you check that your company holds up against this

All of the above can be written into a policy and still not work. The difference between believing your team would spot CEO fraud and knowing it is having tried.

  • Phishing simulation. Not to catch anybody out, but to measure the two things that are actually useful: how many people report it, and how long the first one takes to do so. That is what we do in phishing simulation.
  • Training for the team that approves payments and changes, which is a small, specific group and not the whole workforce. That goes in training.
  • Credential and brand monitoring, to find out what is already out there: dark web monitoring.
  • And the process, in writing. Double verification on a different channel for any change of bank account, with no exception for seniority. The exception for seniority is exactly what CEO fraud exploits.

If you would rather see the general order of priorities first, the guide to cybersecurity for companies puts it in sequence, and a specific case can be put to us through contact.

A
Asperis Security
Offensive Security team
Share:

If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.

Talk to a senior pentester