Impersonation is a core social engineering technique in which an attacker poses as a trusted person, authority figure, or recognized brand to bypass victim skepticism and extract information or access. Understanding how these tactics work is essential for recognizing and defending against them.
Impersonation in Social Engineering
If we're carrying out a social engineering attack, somehow we're going to need to gain trust quickly, and one way to do that is through impersonation.
In order to carry out a successful social engineering attack, an adversary is going to need to trick the victim into making whatever they say believable, with a certain amount of trust in it. As soon as the victim starts questioning, really, is this true, is this a scam, at that point in time there's going to be the seed of a doubt that's going to make the social engineering tactic much less successful. If an adversary impersonates another person, maybe a person that the victim already knows, then the victim is going to put the same level of trust in this adversary as they would in this other person. So it can be a very successful technique.
A common impersonation would be some sort of authority figure. Maybe it's a CEO of the company, or an executive, or somewhere in management, somebody that oversees other people. Immediately they have a certain amount of authority, and people are going to listen to that authority within a company. So a good person to emulate is somebody of authority within the company.
Another effective method is to emulate tech support. When you call up and say, "Hey, I'm IT support," then immediately the person on the other side has a certain amount of trust in that IT support.
It doesn't necessarily have to be impersonating another person. For instance, it could be impersonating a brand or a website. When it comes to brand impersonation, maybe you're claiming that you're part of some sort of company that's well recognized, like Microsoft. This is a common one where scammers will say, "This is Microsoft. We've noticed that you've been hacked and we're trying to help you fix that." So brand impersonation can be an effective way to trick the victim into divulging information or getting access into their system. Maybe you're impersonating some sort of website. Maybe the website has some sort of misspelling in it. This is what's called typosquatting, and it's a type of impersonation.
Here's the 2025 global threat report by CrowdStrike. In this report it outlines some of the techniques that Curly Spider, Chatty Spider and Plump Spider use to carry out their social engineering attacks. In the case of Curly Spider, they call the victim posing as IT support after spam bombing them. They claim that they are there to fix their spam bombing problem, and so it gives some legitimacy to who they are. In this one, Plump Spider calls the victim posing as IT support. So in both cases it's called vishing, where you're calling in and doing a voice attack. That's called vishing, and in this case they're claiming that they're IT support.
Here's our attack card for impersonation. It's when you're pretending to be someone else, or maybe it's another entity like some sort of company. Some examples might be the adversary pretending to be a part of management or an executive within the company, or maybe it's IT support, or maybe it's just claiming some sort of other brand or mimicking a website.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →