If your business is being impersonated right now, act in this order: freeze outgoing payments to any recently changed bank details, lock and re-credential the affected accounts, preserve every message as evidence, then report the fraud to the FBI’s IC3 within 72 hours. Speed matters more than certainty: the recall window on a fraudulent wire is measured in hours, not days.
A company impersonation scam is when criminals pose as your business — or as one of your vendors, executives, or banks — to extract payments, credentials, or credit in your name. The financial exposure is real and growing: the FTC reported that people lost nearly $1 billion to business impersonators in 2025, up from $866 million in 2024, while the FBI’s IC3 logged $3.05 billion in business email compromise losses in the same year, 86% of it moved by wire transfer or ACH.
Impersonation only works when nobody verifies who actually owns the bank account receiving the money. That verification gap is exactly what automated vendor identity verification closes, by confirming account ownership and legal entity before a payment leaves your systems rather than after. This guide walks through the first 24 hours, the reporting channels that matter, and the controls that stop the next attempt.
Key Takeaways
- Contain first, investigate second: stop pending payments, lock compromised accounts, enable MFA, and appoint one incident owner before you start diagnosing.
- Report to three places minimum: your bank’s fraud desk (by phone, using a number you look up independently), the FBI’s IC3 at ic3.gov, and the FTC at ReportFraud.ftc.gov.
- Business identity theft is harder to unwind than personal identity theft — there’s no statutory equivalent of the consumer fraud alert for business credit files.
- The highest-yield red flag is any request to change vendor or payroll bank account information, regardless of how legitimate the sender looks.
- NACHA’s ACH fraud monitoring rules, effective March 2026, now require every corporate ACH originator to run risk-based fraud detection — manual controls alone no longer meet the bar.
What Should You Do First If Your Company Is Being Impersonated?
Contain the damage in the first hour, then build the evidence file. Work through these seven steps in sequence — resist the urge to investigate before you’ve stopped the bleeding.
- Freeze every payment tied to changed details. Halt outgoing wires, ACH batches, and scheduled payments to any account whose details were modified in the last 90 days. If a payment already left, call your bank immediately and request a recall or SWIFT indemnity claim.
- Isolate the affected accounts. Disconnect compromised mailboxes, ERP logins, and accounts payable sessions. Don’t delete anything — isolate it.
- Reset credentials and enforce MFA. Rotate passwords for every account the attacker could have touched, revoke active sessions and app tokens, and turn on multi-factor authentication across finance, email, and admin accounts.
- Appoint a single incident owner. One named person coordinates the response and owns all external communication. Parallel, uncoordinated outreach is how businesses contradict themselves in front of customers and regulators.
- Build a timestamped evidence file. Export original emails with full headers, screenshots of spoofed domains or social profiles, invoice copies, payment confirmations, and a chronological timeline. Save messages as .eml or .msg files — forwarding destroys the headers investigators need.
- Notify your bank through a verified channel. Call the number printed on your bank statement or card, never a number supplied in the suspicious message. Ask them to flag the beneficiary account, place enhanced monitoring on your business bank accounts, and confirm whether any other payment instructions were altered.
- Warn the people who could be defrauded next. Alert customers, vendors, and partners that your identity is being misused, and tell them exactly which channels are legitimate.
Steps 5 through 7 run in parallel once containment is complete. If the impersonation involved a compromised mailbox rather than a lookalike domain, treat it as a full security incident — attackers frequently sit inside an inbox for weeks, observing invoice formats and payment cycles, before they act.
The First 24 Hours: Company Impersonation Response Timeline
| Window | Phase | Actions |
|---|---|---|
| Hour 0–1 | Contain | Freeze outgoing wires and ACH; halt payments to changed details; isolate affected accounts |
| Hour 1–4 | Secure | Rotate credentials; enforce MFA everywhere; name one incident owner |
| Hour 4–24 | Report | Bank fraud desk on a verified line; FBI IC3 (ic3.gov); FTC (ReportFraud.ftc.gov) |
| Day 2+ | Notify and monitor | Warn vendors and customers; check Secretary of State filings; check business credit files |
Recovery window: wire recall odds fall sharply after 24–72 hours. Source: FBI IC3.
Where Do You Report a Company Impersonation Scam?
Report to your bank, the FBI’s IC3, and the FTC — in that order of urgency. Each channel serves a different purpose, and filing with all of them strengthens both recovery odds and any future insurance claim.
| Channel | What it’s for | Where |
|---|---|---|
| Your bank’s fraud desk | Payment recall, beneficiary account freeze | Phone number from your statement |
| FBI IC3 | Federal fraud complaint; triggers the Financial Fraud Kill Chain for qualifying wires | ic3.gov |
| FTC | Consumer alert and impersonation reporting | ReportFraud.ftc.gov |
| Secretary of State (state of incorporation) | Fraudulent or unauthorized business filings | Your state’s business filings division |
| Local police | Police report number for insurers and banks | Local precinct or online portal |
| Domain registrar and platform abuse teams | Takedown of spoofed domains, profiles, and ad accounts | Registrar and platform abuse forms |
| Credit bureaus and credit card providers | Dispute fraudulent trade lines, inquiries, or accounts opened in your name | D&B, Experian Business, Equifax Business, plus your card issuers |
Three practical notes. First, IC3’s Financial Fraud Kill Chain can help freeze fraudulent international wires, but the window is narrow — report the same day. Second, if fraudulent documents were filed with your Secretary of State, request certified copies of those filings. Screenshots are useful internally; certified copies are what courts and banks accept. Third, notify your business insurer early: most crime and cyber policies impose reporting deadlines, and nearly all of them require a police report number before they’ll open a claim.
Impersonation Scam Losses Are Accelerating
| Impersonator type | 2024 reported losses | 2025 reported losses | Change |
|---|---|---|---|
| Business impersonators | $866 million | Nearly $1 billion | +15% |
| Government impersonators | $789 million | $920 million | +17% |
| All imposter scams combined | — | $3.5 billion | — |
Source: FTC Consumer Sentinel Network.
What Is a Business Impersonation Scam?
A business impersonation scam is any fraud in which criminals adopt a company’s identity — its name, domain, branding, executives, or banking relationship — to deceive a third party into sending money or data. The impersonated business may be the victim, the vehicle, or both.
Business impersonation scams pursue one of four objectives:
- Redirected payments: invoices or bank-detail change requests that route funds to the fraudster’s account. This is the dominant motive, and it maps directly onto the top vendor fraud schemes targeting US finance teams.
- Credential theft: harvesting logins to email, banking portals, or ERP systems for a larger follow-up attack.
- Credit and account fraud: opening trade accounts, credit lines, leases, or business bank accounts in the company’s name.
- Data extraction: stealing sensitive company information — W-2s, customer lists, vendor master files — to sell or reuse in a later attack.
Typical outcomes include unrecoverable wire losses, chargebacks and refund liability, damaged business credit, and regulatory scrutiny. The hidden cost is operational: after an incident, businesses spend valuable time and headcount on forensics, bank correspondence, and filing corrections — weeks of senior finance and IT capacity diverted from actual work.
Small and mid-sized businesses are disproportionately targeted for structural reasons, not because criminals prefer them: they publish the same public filings as large firms but have fewer approval layers, rarely have a dedicated fraud function, often run a single shared accounts payable inbox, and are more likely to have one person able to both change a vendor record and release a payment.
How Is Business Identity Theft Different From Personal Identity Theft?
Business identity theft targets an entity’s commercial identity and credit, and it unwinds far more slowly than personal identity theft because consumer protection statutes largely don’t apply.
| Dimension | Personal identity theft | Business identity theft |
|---|---|---|
| Identifiers abused | SSN, date of birth, driver’s license | EIN, state registration number, DUNS, officer names |
| Public exposure | Mostly private data | Registration, officers, and addresses are public by design |
| Statutory protections | FCRA rights, free fraud alerts, credit freezes | No equivalent statutory fraud alert or freeze for business files |
| Typical loss size | Hundreds to thousands | Tens of thousands to millions |
| Recovery path | Bureau dispute process | Litigation, state filing corrections, bank claims |
| Collateral damage | Personal credit score | Credit lines, vendor terms, contract eligibility, brand trust |
The two crimes increasingly overlap. Criminals combine the owner’s personal information — home address, SSN, date of birth — with public business filings to pass verification at banks and lenders, because the pairing looks far more convincing than either data set alone.
As a business identity theft victim, you also get less procedural help. There’s no free statutory fraud alert for a commercial credit file, so the victimized business must find the fraudulent entry itself, dispute it in writing, and prove it. The consequences that hurt most are the second-order ones: a fraudulent trade line can raise borrowing costs, shorten supplier payment terms, or disqualify you from a tender — often months later, when nobody connects the dots.
There’s also a hybrid threat sitting between the two categories. Criminals build fabricated entities from a mix of real and fake identifiers, then cultivate them for months until they resemble established suppliers. This is synthetic identity fraud, and it’s especially dangerous in procurement because roughly 95% of synthetic identities pass standard verification checks (Thomson Reuters). A vendor that clears your onboarding process is not necessarily a vendor that exists.
How Do Scammers Impersonate Your Business Identity?
Criminals impersonate businesses across every channel where trust is assumed rather than verified. Most attacks combine two or three of them.
Which Channels Do Impersonators Use?
- Email: lookalike domains, display-name spoofing, and reply-chain hijacking. This is the dominant vector, and it’s worth understanding exactly how email spoofing works before you design controls around it.
- Voice and SMS: caller ID spoofing and smishing, often to “confirm” a bank detail change already sent by email.
- AI-generated audio and video: synthetic voice or video of a named executive, used to authorize urgent transfers. Deepfake authorization requests are now credible enough that “I heard the CFO say it” is no longer a control.
- Fake websites and portals: cloned checkout, careers, or vendor onboarding pages built to capture credentials and sensitive company information.
- Social and marketplace profiles: counterfeit company pages and paid ads using your logo.
- Paper and postal: forged letterhead for filing changes or credit applications.
How Do They Abuse Your Branding?
Spoofing methods are cheap and effective: registering a domain that swaps one character or changes the TLD, registering an entity name that closely mimics an existing business, copying your email signature and logo lockup verbatim, cloning genuine invoice templates including PO number formats, and reusing real employee names and titles scraped from LinkedIn. Absent SPF, DKIM, and DMARC enforcement on your domain, attackers can also send mail that appears to originate from your actual address.
Which Data Points Do Criminals Exploit?
- Your EIN and state registration number, both publicly retrievable
- Officer and registered agent names from state filings
- Vendor and customer names from press releases, case studies, and job ads
- Invoice numbering conventions and payment terms
- Approval thresholds and finance team structure inferred from org charts
Because so much business information is public by design, reconnaissance requires no hacking at all. Note the inverse signal too: fake and synthetic entities are frequently registered to virtual mailboxes or temporary office space, so an address that resolves to a co-working suite or mail-forwarding service deserves a closer look during vendor onboarding — especially for a supplier claiming years of trading history.
What Does the Scam Flow Look Like, Step by Step?
- Reconnaissance: the attacker maps your vendors, finance staff, and approval chain from public sources.
- Infrastructure: they register a lookalike domain or compromise a mailbox — yours or a vendor’s.
- Insertion: they join or replicate a live email thread, often after weeks of silent observation.
- The ask: a bank-detail change, an urgent overdue invoice, or a transfer “authorized” by a senior executive whose voice or writing style has been cloned.
- The payment: funds land in a mule account and are dispersed within hours.
- The exit: the account closes before your reconciliation cycle surfaces the discrepancy.
The gap between step 5 and step 6 is why detection-based controls underperform. By the time a monthly reconciliation flags the anomaly, recovery is largely theoretical.
Why Detection-Based Controls Lose the Race
| Timeline | What the fraudster does | What an unprotected finance team sees |
|---|---|---|
| Weeks before | Reconnaissance, mailbox access, invoice pattern study | Nothing |
| Day 0 | Bank-detail change accepted, payment released | A routine payment run |
| Day 0–1 | Funds dispersed through mule accounts, account closed | Nothing |
| Day 1–3 | Already gone | Recovery window closing (24–72 hours) |
| Day 30 | Untraceable | Monthly reconciliation finally flags the discrepancy |
Detection gap: 27 days between the fraudster’s exit and the finance team’s discovery.
What Are the Red Flags in Your Records and Communications?
The single highest-value red flag is any inbound request to change bank details. Treat every one as a fraud attempt until independently verified.
Invoice and payment discrepancies to flag:
- New or changed bank account information, especially pointing to a different country or bank than the vendor’s usual one
- Invoice amounts just under an approval threshold
- Duplicate invoice numbers, or numbering that breaks the vendor’s usual sequence
- A vendor’s payment terms suddenly shortening, or “urgent overdue” framing on a current account
- Mismatch between the vendor’s legal name and the account holder name
- Free email domains replacing a corporate domain on correspondence
Unexpected changes to public business filings:
- A new or changed registered agent you didn’t appoint
- Address or officer changes you didn’t authorize
- New DBAs or entity names similar to yours
- Reinstatement of a dormant entity
- Unexplained inquiries on your business credit file
Instruct staff to preserve evidence. Anyone who receives a suspicious message should save it as an attachment with full headers, screenshot the sender details, and forward it to the incident owner — without replying, clicking, or deleting. Nine times out of ten, the quality of the evidence file determines whether the bank engages seriously. For the underlying patterns, learn how to detect and prevent invoice fraud, since most impersonation attempts arrive as a document your team already expects to receive.
How Should You Monitor Business Records and Credit Information?
Monitor quarterly at minimum, and treat monitoring as an early-warning system rather than a compliance chore. Fraudulent filings and credit applications typically precede the payment attack — catching them early is the difference between a nuisance and a loss.
How Do You Check Your Public Business Records?
Search your state’s Secretary of State business entity database by exact entity name, then by officer name to catch entities registered in your executives’ names. Repeat in every state where you’re registered or qualified as a foreign entity. Save a certified copy of any filing you didn’t authorize — most states issue these for a small fee, and unlike a screenshot, a certified copy is admissible. Schedule a full business-records audit annually, and check after any leadership or address change.
Which Business Credit Agencies Should You Monitor?
- Dun & Bradstreet (DUNS number and PAYDEX score)
- Experian Business
- Equifax Business
- Creditsafe
Pull your business credit report from each bureau at least quarterly, and review it line by line against your own records. Paid business credit monitoring services are worth the cost for one reason: they alert you to new trade lines and inquiries in near real time, which is the only way to catch credit fraud before it matures. When an unexpected entry appears, record the date discovered, the reporting creditor, the amount, and the account number; file a written dispute with the bureau; alert the relevant credit card providers or lenders directly; and escalate to the incident owner so it’s linked to any open case.
What Should Long-Term Monitoring Look Like?
Maintain a standing incident log covering every impersonation attempt, successful or not — date, channel, target, amount at risk, outcome, and controls changed as a result. It serves three purposes: it evidences due diligence to auditors and your business insurer, it reveals which vendors or entities are repeatedly targeted, and it justifies control investment to your board. Pair it with quarterly credit file reviews and an annual records audit.
Business Impersonation Monitoring Cadence
| Frequency | Check | What it catches |
|---|---|---|
| Weekly (52× a year) | Payment file review | Bank-detail changes made in the last 7 days |
| Monthly (12× a year) | Vendor master audit | New vendors, duplicate records, reactivated dormant accounts |
| Quarterly (4× a year) | Business credit files: D&B, Experian, Equifax, Creditsafe | New trade lines, unexplained inquiries, score movements |
| Annually (1× a year) | Secretary of State filings | Registered agent, officer, address and DBA changes |
Frequency reflects how fast each signal decays: payment data ages in days, state filings in months.
Which Preventive Controls Actually Stop Company Impersonation?
The controls that work remove the fraudster’s opportunity rather than trying to spot their message. Prioritize in this order:
- Verify bank details out-of-band, every time. Call the vendor on a number from your own vendor master file — never from the request — and confirm changes with a known contact. This one control blocks the majority of payment-redirect attacks.
- Automate bank account validation. Manual callbacks don’t scale past a few dozen vendors and fail silently under volume. Automated validation checks that the account number, the legal entity, and the bank actually correspond, continuously across the vendor lifecycle. This is Trustpair’s core function: validating vendor account ownership at onboarding, on every data change, and before each payment run, so a redirected payment is blocked rather than reported. If you’re building a shortlist, compare identity verification solutions on the features and false-positive benchmarks that matter during an RFP.
- Meet the new ACH monitoring bar. Since March 2026, NACHA rules require every corporate entity originating ACH payments to maintain risk-based processes for identifying suspicious entries. If your ACH controls are still a spreadsheet and a second signature, they no longer clear the standard.
- Enforce MFA everywhere, with phishing-resistant factors on finance, email, and admin accounts.
- Restrict who can update public business records. Limit filing authority to two named officers, lock your registered agent account with MFA, and enable filing notifications where your state offers them.
- Harden and monitor your domain estate. Deploy SPF, DKIM, and DMARC at enforcement, register obvious lookalike domains defensively, and monitor for new registrations and fake social handles.
- Segregate duties in accounts payable. Nobody who can modify a vendor record should be able to release a payment to it.
- Train staff on the specific scenario. Generic security awareness underperforms; run simulations of bank-detail change requests and executive urgency. Walking teams through how third-party fraud plays out inside a finance team makes useful training material, because it shows how ordinary the attack looks from the inside.
Your Next Steps
If you’re in an active incident, work the seven steps above and file your reports today. If you’re reading this to prepare, do three things this week: audit who in your organization can change a vendor’s bank details, verify your Secretary of State filings and business credit report, and pressure-test what would actually happen if a convincing bank-detail change request landed in your accounts payable inbox tomorrow.
Then close the verification gap for good. Trustpair validates vendor and third-party account ownership automatically across 170+ countries — at onboarding, on every data change, and before each payment run — so impersonation attempts are blocked at the payment stage instead of discovered at reconciliation. Book a demo with a fraud expert to see how it fits your existing ERP and P2P workflows.