Attack technique

Brand Impersonation

A phishing tactic where attackers mimic a well known company's branding, tone, and communication style to make fraudulent messages appear legitimate.

Definition

Brand impersonation is a tactic in which an attacker copies the logo, visual identity, email format, and tone of voice of a well known and trusted company to make a fraudulent email, website, or message appear genuine. It relies on the target's existing trust in the impersonated brand to lower their guard against the deception.

Attackers commonly impersonate banks, government agencies, shipping companies, and popular technology platforms, since these brands already have widespread name recognition and a plausible reason to contact almost anyone. A convincing impersonation copies genuine logos, color schemes, and email templates closely enough that a quick glance does not reveal anything wrong, and pairs it with a typosquatted domain or a spoofed sender name to complete the illusion. These fraudulent messages typically drive the target toward a fake login page, a fraudulent payment request, or a malicious attachment disguised as an official document.

Brand impersonation matters because it damages two parties at once: the customer or employee who is deceived, and the legitimate brand whose reputation suffers when victims associate the fraud with the real company. Banks and government services in Indonesia are frequently impersonated because they are widely used and trusted institutions, making a fraudulent message referencing them immediately credible to a large population of potential victims. The rise of AI tools has made it easier for attackers to produce polished, error-free impersonations that closely mirror genuine corporate communication.

Organizations can reduce impersonation risk by implementing email authentication standards such as SPF, DKIM, and DMARC, which make it harder for attackers to send email that appears to come from the legitimate domain. Customers and employees should be taught to verify unexpected communications through official channels, such as typing a known web address directly rather than clicking a link, and to check sender domains carefully rather than trusting a display name alone. Monitoring for impersonating domains and social media accounts allows a brand to request takedowns before large numbers of people are deceived.

At a glance

Severity
High
Prevalence
Very common
Primary targets
Customers and employees of well-known banks, government services, and technology platforms

How it works

  1. 1

    Brand selection: the attacker chooses a widely trusted brand, such as a bank, government agency, or well-known company.

  2. 2

    Visual copying: they replicate the logo, color scheme, email template, and tone of voice closely enough to pass a quick glance.

  3. 3

    Supporting infrastructure: a typosquatted domain or spoofed sender name completes the illusion.

  4. 4

    Deceptive message: the fraudulent communication drives the target toward a fake login page, payment request, or malicious attachment.

  5. 5

    Dual harm: the victim is deceived, and the real brand's reputation suffers when victims associate the fraud with the genuine company.

Warning signs

  • A message using a familiar logo and tone but requesting something unusual
  • Sender domain that is slightly different from the brand's real domain
  • A link that leads to a page not hosted on the brand's official domain
  • Urgency or threats that a well-known brand would not normally use
  • Minor inconsistencies in formatting, colors, or wording compared to genuine communications

How to defend

  • Verify unexpected communications through official channels, such as typing a known web address directly
  • Check sender domains carefully rather than trusting a display name alone
  • Implement SPF, DKIM, and DMARC to make it harder for attackers to spoof your domain
  • Monitor for impersonating domains and social media accounts and request takedowns promptly
  • Train customers and employees to recognize subtle inconsistencies in impersonated brand communications

Real-world example

A customer receives an email that appears to come from a major Indonesian bank, complete with the correct logo and color scheme, warning that their account will be frozen unless they verify their details. The link leads to a lookalike domain built to capture banking credentials, which the customer nearly enters before noticing the sender's email address does not match the bank's real domain.

How Claro helps

Claro's simulation library includes brand impersonation templates modeled on common Indonesian and global companies, helping employees practice spotting subtle inconsistencies in a safe setting.

Frequently asked questions

What is Brand Impersonation?

Brand impersonation is a phishing tactic where attackers copy the logo, visual identity, and tone of a well-known company so that fraudulent emails, websites, or messages look genuine.

What is the difference between brand impersonation and typosquatting?

Typosquatting is a specific technique of registering a lookalike domain. Brand impersonation is broader, covering the full imitation of a brand's logo, tone, and communication style, often paired with a typosquatted domain to complete the deception.

Why are banks and government services frequently impersonated?

They are widely used and trusted institutions, so a fraudulent message referencing them is immediately credible to a large population of potential victims.

How can I verify a message claiming to be from a trusted brand?

Type the organization's known web address directly into your browser rather than clicking a link, and check the sender's actual email domain carefully rather than trusting the display name.

Does DMARC stop brand impersonation?

It significantly reduces email spoofing of your exact domain, but attackers can still use typosquatted domains or display name tricks, so employee and customer awareness remains necessary alongside technical controls.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo