What is brand impersonation?
Brand impersonation is the use of a company's name, logo, website or app identity to pose as that company and deceive the people who trust it: a copied sign-in page, a fake support portal, a listing wearing your icon, or a lookalike domain sending mail in your name.
Updated
- Phishing attacks observed in 2025
- 3.8 million (APWG)
- US imposter scam losses, 2025
- $3.5 billion (FTC)
- Reported BEC losses, 2025
- $3.05 billion (FBI IC3)
Where typosquatting borrows a name and cybersquatting borrows a trademark, impersonation borrows the whole identity. The domain may differ by a character or an extension, but what the visitor sees is designed to be indistinguishable: your logo, your layout, your sign-in form, on infrastructure you do not control. The FBI defines a spoofed website as one “designed to impersonate a legitimate website,” and in September 2025 it had to warn the public that criminals were running spoofed copies of IC3.gov itself, the very site victims use to report the crime.
MITRE ATT&CK catalogs the underlying technique as Impersonation (T1684.001): pretending to be a trusted person or organization to persuade a target into acting. Depending on which layer carries it, the same conduct gets called website impersonation, domain impersonation or brand spoofing. On the web that pretense has a concrete footprint: domains, sites, apps and mail. That is what this page covers. Impersonation on social media, fake accounts on platforms like X, Instagram or Discord, is a related problem with its own reporting channels; notolens monitors domains, trademark registers and app stores, not social handles.
Brand impersonation vs. typosquatting vs. cybersquatting
The three terms describe different layers of the same attack and are easy to conflate:
| Typosquatting | Cybersquatting | Brand impersonation | |
|---|---|---|---|
| What it borrows | The spelling of your name | Your trademark in a registration | Your identity: logo, layout, sign-in page |
| Where it happens | In the domain name | At the registrar | On the page the visitor sees |
| Typical payoff | Mistyped traffic, ad revenue | Resale, a blocked name | Harvested credentials or payments |
| Caught by | Name matching | Registration records | Checking what the site shows and does |
In practice the layers stack: a lookalike or combosquatted domain supplies the plausible address, and the impersonating site it hosts does the damage. Watching the registration stream catches the first layer; only visiting the site catches the second.
The shapes impersonation takes
Fake login pages
The most direct shape: a page that clones a sign-in screen and posts what the visitor types to the attacker, often to a different domain entirely or to a messaging bot. A 2014 Google study of real phishing pages (Bursztein et al., ACM IMC 2014) found that once visitors reached a fake page, 14% submitted their information on average and up to 45% did on the most convincing ones; when the researchers planted decoy credentials, criminals tried to access roughly a fifth of those accounts within 30 minutes. The payoff keeps the shape popular: Verizon’s 2026 Data Breach Investigations Report found credential abuse somewhere in the attack path of 39% of breaches, still the top vector on that measure, even though vulnerability exploitation (31%) has overtaken it as the most common first step and credential abuse now starts only 13%.
Spoofed websites
A broader costume than the login form alone: cloned storefronts that take orders never shipped, fake checkout and account portals, or a near-perfect copy of the brand’s whole site. The domain is the prop and the page is the costume, which is why the FBI’s advice after IC3.gov was spoofed was to type known addresses directly into the browser rather than trusting links or search results.
Copycat support portals
Fake help desks intercept customers at their most credulous: mid-problem, actively looking for official support. IC3 logged 47,794 tech support scam complaints in 2025 with $2.13 billion in reported losses, part of more than $2.9 billion lost to call-center scams overall. On the consumer side, people told the FTC they lost nearly $1 billion to business impersonators in 2025, with bank impersonators causing the highest reported losses.
Spoofed apps
The same costume worn as a store listing: your name and icon published under someone else’s developer account. Google prevented more than 1.75 million policy-violating apps from being published on Play in 2025. Apple’s 2025 transparency report counts 166,899 removed apps, including 90,608 taken down for fraud and 279 under its copycat rule. App store monitoring covers this surface in depth.
The domains behind email impersonation
Email impersonation splits into two techniques that look identical in an inbox.
The first forges your exact domain in the From field. That is what SPF, DKIM and DMARC exist to stop, and the bar rose in February 2024 when Google and Yahoo began requiring bulk senders to authenticate; Gmail says an earlier authentication requirement alone cut unauthenticated mail by 75%. An enforced DMARC policy on your real domain closes that door.
The second sends from a cousin domain: a lookalike registration carrying its own mail records. dmarc.org, which maintains the standard’s documentation, is explicit that DMARC “does not address cousin domain attacks” or display-name abuse, because a lookalike domain authenticates as itself. The FBI calls the same move spoofing on the sending side, an email address or URL altered by a single letter, symbol or number, and counts it among the key parts of business email compromise. IC3 counted $55 billion in exposed BEC losses between October 2013 and December 2023 and $3.05 billion in reported BEC losses in 2025 alone, and APWG measured an average of $61,732 requested in wire-transfer BEC attacks in the second quarter of 2026.
The tell lives in DNS, not spelling. A lookalike domain with MX records can receive mail, and one that sends with no DMARC enforcement of its own passes fewer checks while wearing your name. Both show up in DNS as soon as they are configured, which can be the day the domain registers or months later.
How impersonation gets caught
Name matching alone is not the test. A phishing domain earns that label from what it serves, not from how its name is spelled. Measurement research that crawled more than 50,000 live phishing sites (PhishInPatterns, ACM IMC 2022) found that modern phishing pages often impersonate a brand without closely cloning its design, so a pure visual comparison misses them. The checks that matter look at what the site does:
- Whether the domain resolves to a live site at all, or is parked or dormant.
- Whether the page carries a sign-in or password form, and where that form posts. A login form that submits to a different domain, a chat bot or a mail endpoint is harvesting credentials no matter how the page looks.
- How closely the rendered page resembles your real site: layout, logo, copy.
- Whether the domain can send and receive mail, and whether it enforces DMARC.
- For app listings, whether the name, developer identity and store details line up with the real publisher.
The scale of brand abuse is why this has to be systematic. APWG counted 3.8 million phishing attacks in 2025, and Palo Alto’s squatting detector was already finding roughly 450 lookalike registrations a day in December 2019, about a fifth of them already malicious. Nobody reviews that stream by hand; the workable pattern is to check each new registration against your brand, then check the site that answers.
What to do when someone impersonates your brand
The response runs on parallel tracks, and the right order is evidence first:
- Capture the facts before anything changes. Timestamped captures of the site, the DNS answers, the registration record and any correspondence are what every later step consumes. The evidence package guide covers exactly what to collect.
- Report the content. Registrar and hosting abuse reports can suspend an impersonating site in days at no cost, though they leave the domain in the impersonator’s hands. See reporting domain abuse and reporting hosting abuse.
- Take the name. A UDRP complaint transfers or cancels the domain itself, typically within 45 to 60 days, and US courts under the ACPA can award damages on top.
- Report the fraud. Consumer-facing impersonation can be reported to IC3 and the FTC. The FTC’s Impersonation Rule, in force since April 2024, lets the agency act against impersonators directly; it shut down 13 websites impersonating the FTC itself in the rule’s first year.
Sources
- MITRE ATT&CK T1684.001: Social Engineering, Impersonation
- FBI IC3: threat actors spoofing the IC3 website (September 2025)
- FBI: spoofing and phishing, definitions and guidance
- FBI IC3: 2025 Internet Crime Report
- FBI IC3: Business Email Compromise, the $55 billion scam (September 2024)
- APWG: Phishing Activity Trends Report, Q4 2025
- APWG: Phishing Activity Trends Report, Q2 2026
- FTC: imposter scam losses reported in 2025 (June 2026)
- FTC: actions to protect consumers from impersonation scams (April 2025)
- Verizon: 2026 Data Breach Investigations Report
- Bursztein et al., Handcrafted Fraud and Extortion: Manual Account Hijacking in the Wild (ACM IMC 2014)
- Google: how Google Play was kept safe in 2025 (February 2026)
- Apple: 2025 App Store Transparency Report
- Unit 42: cybersquatting detector findings (September 2020)
- PhishInPatterns: measuring modern phishing site design (ACM IMC 2022)
- dmarc.org: FAQ, what DMARC does not address
- Google: new Gmail sender authentication requirements (October 2023)
Frequently asked questions
Often yes, though the framework depends on the conduct. Phishing and credential theft are criminal. Using a mark in commerce in a way likely to confuse consumers can be trademark infringement, and a lookalike domain registered in bad faith can be recovered through the UDRP or sued over under the ACPA. In the US, the FTC's Government and Business Impersonation Rule, in force since April 2024, makes business impersonation unlawful and lets the FTC act against impersonators directly. Which lever applies depends on what the impersonator is doing, so documenting the facts comes first. For anything beyond procedure, consult qualified counsel.
Typosquatting is a naming trick: a domain that differs from yours by a character or two, built to catch mistyped traffic or lend a scam a plausible address. Brand impersonation is about behavior: a site, app or sender that wears your identity, your logo, your sign-in page, your name, wherever it lives. A typo domain hosting a cloned login page is both; the same clone on an unrelated domain is impersonation without the typo.
Mostly through links rather than navigation: phishing emails, text messages, malicious ads, posts and QR codes deliver visitors straight to a spoofed page, and APWG tracked SMS-based phishing rising through 2025. Some impersonating domains also harvest mistyped traffic directly, which is where impersonation overlaps typosquatting. After its own website was spoofed, the FBI's advice was to type known addresses into the browser directly rather than following links or search results.
No. Fake accounts on social platforms are the most visible form of impersonation and a large share of reported scams, but each platform runs its own impersonation reporting and enforcement channel. notolens watches the web layer: domain registrations, trademark filings and app store listings.
Document first, then act. Capture the site, its DNS answers and its registration record before reporting anything, since impersonating sites change or vanish once reported. Then report it to the hosting provider and registrar, whose abuse teams can suspend it quickly and at no cost, though that leaves the domain in the impersonator's hands. To recover the name itself, a UDRP complaint is the standard route for trademark holders, and US courts can award damages under the ACPA.
Related tools and resources
Domain Watch
Lookalike registrations of your brand from the last 30 days, ranked by pattern and TLD.
Domain Monitoring
Daily monitoring for lookalike registrations, with every match checked and explained.
How to Report Domain Abuse to a Registrar
Collect the required evidence and submit a suspension report that registrars act on.
Daily checks of new registrations for impersonating domains.
notolens checks new registrations across covered TLDs against your brand, visits what answers, flags sign-in forms posting off your domain, and keeps the dated records a report or dispute needs. Clear monthly pricing, no sales calls.
Start monitoring in 3 minutes