How to Respond to a Company Impersonation Scam: A 7-Step Playbook

IN THIS ARTICLE
Table of Contents
Like it? Share it

If your business is being impersonated right now, act in this order: freeze outgoing payments to any recently changed bank details, lock and re-credential the affected accounts, preserve every message as evidence, then report the fraud to the FBI’s IC3 within 72 hours. Speed matters more than certainty: the recall window on a fraudulent wire is measured in hours, not days.

A company impersonation scam is when criminals pose as your business — or as one of your vendors, executives, or banks — to extract payments, credentials, or credit in your name. The financial exposure is real and growing: the FTC reported that people lost nearly $1 billion to business impersonators in 2025, up from $866 million in 2024, while the FBI’s IC3 logged $3.05 billion in business email compromise losses in the same year, 86% of it moved by wire transfer or ACH.

Impersonation only works when nobody verifies who actually owns the bank account receiving the money. That verification gap is exactly what automated vendor identity verification closes, by confirming account ownership and legal entity before a payment leaves your systems rather than after. This guide walks through the first 24 hours, the reporting channels that matter, and the controls that stop the next attempt.

Key Takeaways

  • Contain first, investigate second: stop pending payments, lock compromised accounts, enable MFA, and appoint one incident owner before you start diagnosing.
  • Report to three places minimum: your bank’s fraud desk (by phone, using a number you look up independently), the FBI’s IC3 at ic3.gov, and the FTC at ReportFraud.ftc.gov.
  • Business identity theft is harder to unwind than personal identity theft — there’s no statutory equivalent of the consumer fraud alert for business credit files.
  • The highest-yield red flag is any request to change vendor or payroll bank account information, regardless of how legitimate the sender looks.
  • NACHA’s ACH fraud monitoring rules, effective March 2026, now require every corporate ACH originator to run risk-based fraud detection — manual controls alone no longer meet the bar.

What Should You Do First If Your Company Is Being Impersonated?

Contain the damage in the first hour, then build the evidence file. Work through these seven steps in sequence — resist the urge to investigate before you’ve stopped the bleeding.

  1. Freeze every payment tied to changed details. Halt outgoing wires, ACH batches, and scheduled payments to any account whose details were modified in the last 90 days. If a payment already left, call your bank immediately and request a recall or SWIFT indemnity claim.
  2. Isolate the affected accounts. Disconnect compromised mailboxes, ERP logins, and accounts payable sessions. Don’t delete anything — isolate it.
  3. Reset credentials and enforce MFA. Rotate passwords for every account the attacker could have touched, revoke active sessions and app tokens, and turn on multi-factor authentication across finance, email, and admin accounts.
  4. Appoint a single incident owner. One named person coordinates the response and owns all external communication. Parallel, uncoordinated outreach is how businesses contradict themselves in front of customers and regulators.
  5. Build a timestamped evidence file. Export original emails with full headers, screenshots of spoofed domains or social profiles, invoice copies, payment confirmations, and a chronological timeline. Save messages as .eml or .msg files — forwarding destroys the headers investigators need.
  6. Notify your bank through a verified channel. Call the number printed on your bank statement or card, never a number supplied in the suspicious message. Ask them to flag the beneficiary account, place enhanced monitoring on your business bank accounts, and confirm whether any other payment instructions were altered.
  7. Warn the people who could be defrauded next. Alert customers, vendors, and partners that your identity is being misused, and tell them exactly which channels are legitimate.

Steps 5 through 7 run in parallel once containment is complete. If the impersonation involved a compromised mailbox rather than a lookalike domain, treat it as a full security incident — attackers frequently sit inside an inbox for weeks, observing invoice formats and payment cycles, before they act.

The First 24 Hours: Company Impersonation Response Timeline

WindowPhaseActions
Hour 0–1ContainFreeze outgoing wires and ACH; halt payments to changed details; isolate affected accounts
Hour 1–4SecureRotate credentials; enforce MFA everywhere; name one incident owner
Hour 4–24ReportBank fraud desk on a verified line; FBI IC3 (ic3.gov); FTC (ReportFraud.ftc.gov)
Day 2+Notify and monitorWarn vendors and customers; check Secretary of State filings; check business credit files

Recovery window: wire recall odds fall sharply after 24–72 hours. Source: FBI IC3.

Where Do You Report a Company Impersonation Scam?

Report to your bank, the FBI’s IC3, and the FTC — in that order of urgency. Each channel serves a different purpose, and filing with all of them strengthens both recovery odds and any future insurance claim.

ChannelWhat it’s forWhere
Your bank’s fraud deskPayment recall, beneficiary account freezePhone number from your statement
FBI IC3Federal fraud complaint; triggers the Financial Fraud Kill Chain for qualifying wiresic3.gov
FTCConsumer alert and impersonation reportingReportFraud.ftc.gov
Secretary of State (state of incorporation)Fraudulent or unauthorized business filingsYour state’s business filings division
Local policePolice report number for insurers and banksLocal precinct or online portal
Domain registrar and platform abuse teamsTakedown of spoofed domains, profiles, and ad accountsRegistrar and platform abuse forms
Credit bureaus and credit card providersDispute fraudulent trade lines, inquiries, or accounts opened in your nameD&B, Experian Business, Equifax Business, plus your card issuers

Three practical notes. First, IC3’s Financial Fraud Kill Chain can help freeze fraudulent international wires, but the window is narrow — report the same day. Second, if fraudulent documents were filed with your Secretary of State, request certified copies of those filings. Screenshots are useful internally; certified copies are what courts and banks accept. Third, notify your business insurer early: most crime and cyber policies impose reporting deadlines, and nearly all of them require a police report number before they’ll open a claim.

Impersonation Scam Losses Are Accelerating

Impersonator type2024 reported losses2025 reported lossesChange
Business impersonators$866 millionNearly $1 billion+15%
Government impersonators$789 million$920 million+17%
All imposter scams combined$3.5 billion

Source: FTC Consumer Sentinel Network.

What Is a Business Impersonation Scam?

A business impersonation scam is any fraud in which criminals adopt a company’s identity — its name, domain, branding, executives, or banking relationship — to deceive a third party into sending money or data. The impersonated business may be the victim, the vehicle, or both.

Business impersonation scams pursue one of four objectives:

  • Redirected payments: invoices or bank-detail change requests that route funds to the fraudster’s account. This is the dominant motive, and it maps directly onto the top vendor fraud schemes targeting US finance teams.
  • Credential theft: harvesting logins to email, banking portals, or ERP systems for a larger follow-up attack.
  • Credit and account fraud: opening trade accounts, credit lines, leases, or business bank accounts in the company’s name.
  • Data extraction: stealing sensitive company information — W-2s, customer lists, vendor master files — to sell or reuse in a later attack.

Typical outcomes include unrecoverable wire losses, chargebacks and refund liability, damaged business credit, and regulatory scrutiny. The hidden cost is operational: after an incident, businesses spend valuable time and headcount on forensics, bank correspondence, and filing corrections — weeks of senior finance and IT capacity diverted from actual work.

Small and mid-sized businesses are disproportionately targeted for structural reasons, not because criminals prefer them: they publish the same public filings as large firms but have fewer approval layers, rarely have a dedicated fraud function, often run a single shared accounts payable inbox, and are more likely to have one person able to both change a vendor record and release a payment.

How Is Business Identity Theft Different From Personal Identity Theft?

Business identity theft targets an entity’s commercial identity and credit, and it unwinds far more slowly than personal identity theft because consumer protection statutes largely don’t apply.

DimensionPersonal identity theftBusiness identity theft
Identifiers abusedSSN, date of birth, driver’s licenseEIN, state registration number, DUNS, officer names
Public exposureMostly private dataRegistration, officers, and addresses are public by design
Statutory protectionsFCRA rights, free fraud alerts, credit freezesNo equivalent statutory fraud alert or freeze for business files
Typical loss sizeHundreds to thousandsTens of thousands to millions
Recovery pathBureau dispute processLitigation, state filing corrections, bank claims
Collateral damagePersonal credit scoreCredit lines, vendor terms, contract eligibility, brand trust

The two crimes increasingly overlap. Criminals combine the owner’s personal information — home address, SSN, date of birth — with public business filings to pass verification at banks and lenders, because the pairing looks far more convincing than either data set alone.

As a business identity theft victim, you also get less procedural help. There’s no free statutory fraud alert for a commercial credit file, so the victimized business must find the fraudulent entry itself, dispute it in writing, and prove it. The consequences that hurt most are the second-order ones: a fraudulent trade line can raise borrowing costs, shorten supplier payment terms, or disqualify you from a tender — often months later, when nobody connects the dots.

There’s also a hybrid threat sitting between the two categories. Criminals build fabricated entities from a mix of real and fake identifiers, then cultivate them for months until they resemble established suppliers. This is synthetic identity fraud, and it’s especially dangerous in procurement because roughly 95% of synthetic identities pass standard verification checks (Thomson Reuters). A vendor that clears your onboarding process is not necessarily a vendor that exists.

How Do Scammers Impersonate Your Business Identity?

Criminals impersonate businesses across every channel where trust is assumed rather than verified. Most attacks combine two or three of them.

Which Channels Do Impersonators Use?

  • Email: lookalike domains, display-name spoofing, and reply-chain hijacking. This is the dominant vector, and it’s worth understanding exactly how email spoofing works before you design controls around it.
  • Voice and SMS: caller ID spoofing and smishing, often to “confirm” a bank detail change already sent by email.
  • AI-generated audio and video: synthetic voice or video of a named executive, used to authorize urgent transfers. Deepfake authorization requests are now credible enough that “I heard the CFO say it” is no longer a control.
  • Fake websites and portals: cloned checkout, careers, or vendor onboarding pages built to capture credentials and sensitive company information.
  • Social and marketplace profiles: counterfeit company pages and paid ads using your logo.
  • Paper and postal: forged letterhead for filing changes or credit applications.

How Do They Abuse Your Branding?

Spoofing methods are cheap and effective: registering a domain that swaps one character or changes the TLD, registering an entity name that closely mimics an existing business, copying your email signature and logo lockup verbatim, cloning genuine invoice templates including PO number formats, and reusing real employee names and titles scraped from LinkedIn. Absent SPF, DKIM, and DMARC enforcement on your domain, attackers can also send mail that appears to originate from your actual address.

Which Data Points Do Criminals Exploit?

  • Your EIN and state registration number, both publicly retrievable
  • Officer and registered agent names from state filings
  • Vendor and customer names from press releases, case studies, and job ads
  • Invoice numbering conventions and payment terms
  • Approval thresholds and finance team structure inferred from org charts

Because so much business information is public by design, reconnaissance requires no hacking at all. Note the inverse signal too: fake and synthetic entities are frequently registered to virtual mailboxes or temporary office space, so an address that resolves to a co-working suite or mail-forwarding service deserves a closer look during vendor onboarding — especially for a supplier claiming years of trading history.

What Does the Scam Flow Look Like, Step by Step?

  1. Reconnaissance: the attacker maps your vendors, finance staff, and approval chain from public sources.
  2. Infrastructure: they register a lookalike domain or compromise a mailbox — yours or a vendor’s.
  3. Insertion: they join or replicate a live email thread, often after weeks of silent observation.
  4. The ask: a bank-detail change, an urgent overdue invoice, or a transfer “authorized” by a senior executive whose voice or writing style has been cloned.
  5. The payment: funds land in a mule account and are dispersed within hours.
  6. The exit: the account closes before your reconciliation cycle surfaces the discrepancy.

The gap between step 5 and step 6 is why detection-based controls underperform. By the time a monthly reconciliation flags the anomaly, recovery is largely theoretical.

Why Detection-Based Controls Lose the Race

TimelineWhat the fraudster doesWhat an unprotected finance team sees
Weeks beforeReconnaissance, mailbox access, invoice pattern studyNothing
Day 0Bank-detail change accepted, payment releasedA routine payment run
Day 0–1Funds dispersed through mule accounts, account closedNothing
Day 1–3Already goneRecovery window closing (24–72 hours)
Day 30UntraceableMonthly reconciliation finally flags the discrepancy

Detection gap: 27 days between the fraudster’s exit and the finance team’s discovery.

What Are the Red Flags in Your Records and Communications?

The single highest-value red flag is any inbound request to change bank details. Treat every one as a fraud attempt until independently verified.

Invoice and payment discrepancies to flag:

  • New or changed bank account information, especially pointing to a different country or bank than the vendor’s usual one
  • Invoice amounts just under an approval threshold
  • Duplicate invoice numbers, or numbering that breaks the vendor’s usual sequence
  • A vendor’s payment terms suddenly shortening, or “urgent overdue” framing on a current account
  • Mismatch between the vendor’s legal name and the account holder name
  • Free email domains replacing a corporate domain on correspondence

Unexpected changes to public business filings:

  • A new or changed registered agent you didn’t appoint
  • Address or officer changes you didn’t authorize
  • New DBAs or entity names similar to yours
  • Reinstatement of a dormant entity
  • Unexplained inquiries on your business credit file

Instruct staff to preserve evidence. Anyone who receives a suspicious message should save it as an attachment with full headers, screenshot the sender details, and forward it to the incident owner — without replying, clicking, or deleting. Nine times out of ten, the quality of the evidence file determines whether the bank engages seriously. For the underlying patterns, learn how to detect and prevent invoice fraud, since most impersonation attempts arrive as a document your team already expects to receive.

How Should You Monitor Business Records and Credit Information?

Monitor quarterly at minimum, and treat monitoring as an early-warning system rather than a compliance chore. Fraudulent filings and credit applications typically precede the payment attack — catching them early is the difference between a nuisance and a loss.

How Do You Check Your Public Business Records?

Search your state’s Secretary of State business entity database by exact entity name, then by officer name to catch entities registered in your executives’ names. Repeat in every state where you’re registered or qualified as a foreign entity. Save a certified copy of any filing you didn’t authorize — most states issue these for a small fee, and unlike a screenshot, a certified copy is admissible. Schedule a full business-records audit annually, and check after any leadership or address change.

Which Business Credit Agencies Should You Monitor?

  • Dun & Bradstreet (DUNS number and PAYDEX score)
  • Experian Business
  • Equifax Business
  • Creditsafe

Pull your business credit report from each bureau at least quarterly, and review it line by line against your own records. Paid business credit monitoring services are worth the cost for one reason: they alert you to new trade lines and inquiries in near real time, which is the only way to catch credit fraud before it matures. When an unexpected entry appears, record the date discovered, the reporting creditor, the amount, and the account number; file a written dispute with the bureau; alert the relevant credit card providers or lenders directly; and escalate to the incident owner so it’s linked to any open case.

What Should Long-Term Monitoring Look Like?

Maintain a standing incident log covering every impersonation attempt, successful or not — date, channel, target, amount at risk, outcome, and controls changed as a result. It serves three purposes: it evidences due diligence to auditors and your business insurer, it reveals which vendors or entities are repeatedly targeted, and it justifies control investment to your board. Pair it with quarterly credit file reviews and an annual records audit.

Business Impersonation Monitoring Cadence

FrequencyCheckWhat it catches
Weekly (52× a year)Payment file reviewBank-detail changes made in the last 7 days
Monthly (12× a year)Vendor master auditNew vendors, duplicate records, reactivated dormant accounts
Quarterly (4× a year)Business credit files: D&B, Experian, Equifax, CreditsafeNew trade lines, unexplained inquiries, score movements
Annually (1× a year)Secretary of State filingsRegistered agent, officer, address and DBA changes

Frequency reflects how fast each signal decays: payment data ages in days, state filings in months.

Which Preventive Controls Actually Stop Company Impersonation?

The controls that work remove the fraudster’s opportunity rather than trying to spot their message. Prioritize in this order:

  1. Verify bank details out-of-band, every time. Call the vendor on a number from your own vendor master file — never from the request — and confirm changes with a known contact. This one control blocks the majority of payment-redirect attacks.
  2. Automate bank account validation. Manual callbacks don’t scale past a few dozen vendors and fail silently under volume. Automated validation checks that the account number, the legal entity, and the bank actually correspond, continuously across the vendor lifecycle. This is Trustpair’s core function: validating vendor account ownership at onboarding, on every data change, and before each payment run, so a redirected payment is blocked rather than reported. If you’re building a shortlist, compare identity verification solutions on the features and false-positive benchmarks that matter during an RFP.
  3. Meet the new ACH monitoring bar. Since March 2026, NACHA rules require every corporate entity originating ACH payments to maintain risk-based processes for identifying suspicious entries. If your ACH controls are still a spreadsheet and a second signature, they no longer clear the standard.
  4. Enforce MFA everywhere, with phishing-resistant factors on finance, email, and admin accounts.
  5. Restrict who can update public business records. Limit filing authority to two named officers, lock your registered agent account with MFA, and enable filing notifications where your state offers them.
  6. Harden and monitor your domain estate. Deploy SPF, DKIM, and DMARC at enforcement, register obvious lookalike domains defensively, and monitor for new registrations and fake social handles.
  7. Segregate duties in accounts payable. Nobody who can modify a vendor record should be able to release a payment to it.
  8. Train staff on the specific scenario. Generic security awareness underperforms; run simulations of bank-detail change requests and executive urgency. Walking teams through how third-party fraud plays out inside a finance team makes useful training material, because it shows how ordinary the attack looks from the inside.

Your Next Steps

If you’re in an active incident, work the seven steps above and file your reports today. If you’re reading this to prepare, do three things this week: audit who in your organization can change a vendor’s bank details, verify your Secretary of State filings and business credit report, and pressure-test what would actually happen if a convincing bank-detail change request landed in your accounts payable inbox tomorrow.

Then close the verification gap for good. Trustpair validates vendor and third-party account ownership automatically across 170+ countries — at onboarding, on every data change, and before each payment run — so impersonation attempts are blocked at the payment stage instead of discovered at reconciliation. Book a demo with a fraud expert to see how it fits your existing ERP and P2P workflows.

FAQ
Frequently asked questions
Browse through our different sections and find the answer to your question.

Sometimes, but only if you act within hours. Call your bank’s fraud desk immediately to request a recall, and file with IC3 the same day — its Financial Fraud Kill Chain can help freeze qualifying international wires. Recovery rates fall sharply after the first 24 to 72 hours, once funds have been dispersed through mule accounts.

Report business impersonation to your bank, the FBI’s IC3 at ic3.gov, and the FTC at ReportFraud.ftc.gov. Add your state’s Secretary of State if fraudulent filings were made, local police for a report number your insurer will require, and the relevant registrar or platform abuse team for takedowns.

Yes. Business identity theft is prosecuted under federal statutes including wire fraud, mail fraud, and identity theft provisions, and often under state law as well. Filing with IC3 and local law enforcement is what puts your case into the system, since federal agencies rarely learn of an incident otherwise.

Verify it out-of-band before you pay: call a known contact at the vendor using a number from your own records, not from the request. Confirm the new account holder name matches the vendor’s legal entity, and treat any urgency or secrecy as a red flag. Automated account validation performs this check systematically on every change.

Small businesses are targeted because they combine public visibility with thin controls: their registration data is public, approval chains are short, one person often controls both vendor records and payments, and few have a dedicated fraud function. The attack is identical to the one used on large enterprises; only the defenses differ.

You’d like these articles

Ready to beat the fraudsters? Try our 2-minute game

Ready to beat the fraudsters? Try our 2-minute game