What you'll learn in this article
- An email impersonation attack is a type of fraud where attackers pose as a trusted person to trick employees into sending money, sharing data, or giving up credentials.
- These attacks are often malware-less and rely on social engineering, urgency, and familiarity rather than obvious technical red flags.
- Common forms include CEO fraud, business email compromise, payroll scams, and requests involving gift cards or wire transfers.
- Warning signs include urgent tone, secrecy, unusual payment requests, and email addresses or links that do not fully match the trusted sender.
- Mimecast helps stop impersonation attacks by scanning email for anomalies, social engineering signals, malicious links, and risky attachments.
Stopping an impersonation attack requires strong security policies and vigilance on the part of employees. But because these attacks are designed to take advantage of human error, you also need solutions that can automatically scan email and block any potential attack. That's where Mimecast can help.
What is an email impersonation attack?
Email impersonation attacks are a type of phishing attack where the attacker impersonates a legitimate sender in order to trick the recipient into clicking on a malicious link or attachment.
During an email impersonation attack, attackers pose as a known or trusted person to dupe an employee into transferring money to a fraudulent account, sharing sensitive information (such as intellectual property, financial data or payroll information), or revealing login credentials that attackers can use to hack into a company’s computer network. CEO fraud , business email compromise and whaling are specific forms of impersonation attacks where malicious individuals pose as high-level executives within a company.
Why they are hard to detect
Email impersonation attacks can be difficult to detect, as the attacker will often use a fake email address that is similar to the legitimate sender's address. If you receive an email from an unknown sender, or if the email contains grammar or spelling errors, these may be signs that it is a suspicious email or part of an impersonation attack.
If you are unsure whether an email is legitimate, you can always contact the supposed sender directly to verify its authenticity. Remember, never click on any links or attachments in an email unless you are certain that they are safe.
Email impersonation vs email spoofing
Email impersonation is the broader attack in which a cybercriminal pretends to be a trusted person or brand to manipulate the recipient, while email spoofing is one tactic used to support that deception by forging the sender address or making the message appear to come from a legitimate source. In other words, spoofing can help make an impersonation attack more convincing, but impersonation attacks can also rely on social engineering, look-alike domains, or other trust-based tactics even without exact sender spoofing.
How does an impersonation attack work?
Email impersonation attacks follow a series of steps designed to make the recipient believe they are interacting with a trusted source. Common stages in these attacks include:
- Select a target: Attackers choose an employee who can send payments, share sensitive data, or approve requests, often in finance, HR, legal, or executive support roles.
- Research the target: They gather details about the target’s role, contacts, and communication habits through company websites, directories, and social media.
- Choose someone to impersonate: The attacker decides which identity will be most convincing, such as an executive, coworker, vendor, or business partner.
- Create the deception: They use a spoofed address, look-alike domain, or compromised account to make the message appear legitimate.
- Send the message: The email is crafted to match the tone, style, and urgency the target would expect from the impersonated sender.
- Push for action: The attacker asks for something that serves their goal, such as a wire transfer, payroll change, credential submission, or release of confidential information.
These attacks work because they combine research, trust, and urgency to make fraudulent requests seem believable.
In some cases, the attacker may also rely on email spoofing to make the message look even more convincing.
What are common types of email impersonation attacks?
Email impersonation attacks can take several forms, but most follow the same pattern: they use trust, urgency, or familiarity to push the recipient toward a risky action. Some of the most common types include:
- Urgent, short-notice requests that involve the transfer of money or sensitive information such as bank account information or login credentials.
- Purchase requests to be completed on behalf of the CEO, often gift cards.
- Employees abruptly requesting changes to direct deposit information.
- Creating emails with slight name deviations such as writing the letter "m" as "rn".
- Using language that induces urgency and a sense of fear.
These patterns matter because impersonation attacks often do not look obviously malicious at first. The more familiar teams are with these tactics, the easier it becomes to pause, verify, and avoid acting on a fraudulent request.
Real-world examples of email impersonation attacks
Email impersonation attacks can lead to major financial loss, data exposure, and wider security consequences when employees trust a message that appears legitimate. Some notable cases include:
- Ubiquiti Networks: Attackers impersonated senior executives and sent fraudulent wire transfer requests, resulting in a reported $46.7 million loss.
- Facebook and Google: Cybercriminals posed as a legitimate hardware vendor in a long-running BEC scam that reportedly stole more than $100 million.
- Toyota subsidiary: Attackers impersonated a company executive and sent a fraudulent payment request that led to a reported $37 million loss.
These incidents show that email impersonation attacks can affect even well-resourced organizations when trust, urgency, and deception are used effectively.
How to recognize an impersonation attack
Unlike common phishing attacks, which are often unspecific and filled with grammar or spelling mistakes, impersonation attacks are highly targeted and well-crafted to appear realistic and authentic. There are a few things, however, that point to a potentially fraudulent email:
- An urgent and possibly threatening tone. Most impersonation attacks request or demand that the recipient act immediately. Some impersonation emails may threaten negative consequences if the recipient doesn't act quickly enough. This is intended to prevent the employee from taking time to double check before acting.
- An emphasis on confidentiality. Some impersonation attacks will suggest that the action is part of a confidential development or secret program that should not be discussed with colleagues or immediate superiors.
- A request to send money or share sensitive information. Any request to transfer money or to release sensitive financial data, payroll information or intellectual property should be corroborated through multiple channels.
- A problem with email addresses or links. Often, the email impersonating an executive will be a slightly altered version of a legitimate email account. Additionally, the reply-to address may be different than the sender's address, or the actual links to URLs within the email don't match the text in the hyperlinks in the body of the email copy.
- Unusual requests or accounts. Impersonation attacks frequently request recipients to send money to bank accounts or vendor accounts that have different numbers than the employee has used in the past.
How to avoid an impersonation attack?
Scams involving an impersonation attack pose a significant danger to companies of every size. Rather than using malicious URLs or attachments, an impersonation attack uses social engineering and personalization to trick an employee into unwittingly transferring money to a fraudulent account or sharing sensitive data with cyber criminals.
How these attacks usually appear
An impersonation attack typically involves an email that seems to come from a trusted source. Sometimes the email attack may start with a message that looks like it comes from a CEO, CFO or another high-level executive – these scams are also called whaling email attacks. An impersonation attack may also involve a message that appears to be from a trusted colleague, a third-party vendor or other well-known Internet brands.
The message may request that the recipient initiate a transfer to a bank account or vendor that later proves to be fraudulent, or it may ask the recipient to send along information like W-2 files, bank information or login credentials that give hackers access to business finances and systems. A single phishing email can also become the starting point for a larger cyber attack if the attacker succeeds in gaining trust or access.
How to reduce the risk
Stopping an impersonation attack requires strong security policies and vigilance on the part of employees. But because these attacks are designed to take advantage of human error, you also need solutions that can automatically scan email and block any potential attack. That's where Mimecast can help.
Combating an impersonation attack with Mimecast
Mimecast makes email safer for business by combining solutions for email security, email continuity and email data protection into a single cloud-based service. By streamlining administration and providing a single cloud platform that covers all email functions, Mimecast reduces the cost and complexity of business email management.
Mimecast's SaaS email security services include protection against all major threats. In addition to stopping an impersonation attack, Mimecast can help prevent a ransomware attack, spear-phishing attack and insider attack as well as threats from viruses and malware. In addition to threat response solutions, Mimecast security offerings also include solutions for sending messages and large files securely, and for content control and data loss prevention.