Skip to main content

Brand impersonation

Brand impersonation is any attempt to pose as a legitimate brand, through fake websites, domains, social profiles, ads, or emails, to deceive that brand’s customers or partners.

How it works

Attackers copy the elements people trust, such as the logo, name, colours, and tone, and attach them to infrastructure they control. The goal is to convert your reputation into clicks, credentials, or payments before anyone notices.

Impersonation spans channels: a lookalike domain, a cloned login page, a fake support account on social media, or a spoofed sender in the inbox.

How it relates to brand impersonation

Brand impersonation is the parent category for nearly every threat in this glossary. It is the strategy; phishing, squatting, and fake profiles are the tactics.

How nebty helps

nebty is built for exactly this: continuous monitoring across domains, social media, ads, and search, plus on-demand takedowns to remove what we find. See our brand impersonation protection overview.

Brand Impersonation Protection

Where it shows up

Brand impersonation rarely stays on one channel. The same operator might register a lookalike domain, clone your site on it, run search ads that point at it, and back the whole thing with a fake support profile that answers your customers with a scam link. Because the pieces sit on different platforms, an internal team often sees only one at a time and treats each as isolated. The pattern becomes obvious when you watch domains, social, ads, and search together and tie them to the same campaign. That cross-channel view is also what lets you take the whole operation down instead of playing whack-a-mole with one fake at a time. Catching the lookalike domain early often exposes the rest before the campaign reaches your customers.

A concrete example

Customers of the fintech Solara Finance complain on Instagram about a delayed payout. Within minutes an account called @solarafinance.help replies, apologises in the brand voice, and asks them to continue in direct messages. There it sends a "refund portal" link that leads to solara-finance-refund.com, a clone of the real login page. The profile, the domain, and the search ad pointing at it were registered by the same operator within one week. Seen together, they are one campaign; seen separately, each looks like a minor nuisance.

How to spot and stop it

  1. Claim and verify your official profiles and register the obvious domain variants, so the real presence is easy to tell apart from fakes.
  2. Monitor domains, social platforms, ads, and search results together. Impersonation campaigns span channels, and the lookalike domain usually appears first.
  3. When you confirm a fake, act on every piece at once: platform reports for the profiles, takedowns for the domains, and a warning to customers if the campaign is already live.

Frequently asked questions

Is brand impersonation a crime?

The impersonation itself usually amounts to trademark infringement, and the fraud it enables is criminal in most jurisdictions. In practice you rarely need a court: platform policies and abuse rules already ban impersonation, and takedowns run on those.

What is the difference between brand impersonation and brand abuse?

Impersonation means pretending to be the brand: fake sites, profiles, or senders that claim to be you. Brand abuse is the wider category and also covers counterfeits, unauthorized resellers, and reputation attacks that do not claim your identity.

What should we do first when we find an impersonation?

Preserve evidence before you report anything: screenshots, URLs, and message samples. Fakes often disappear and reappear elsewhere, and the evidence is what makes the platform report and the takedown stick.

See who is impersonating your brand

The free nebty report scans the web for lookalike domains and fake profiles targeting your brand, with no obligation.

Get your free report