DigitalMANIPULATIVE

Impersonation Accounts

What it is

Social-media accounts that pose as a real person, organization, movement, or news outlet — borrowing the target's name, image, and credibility — to speak in their voice, discredit them, or harvest the trust their identity commands.

How it works

Identity is the fastest credibility check people make: a familiar name and logo settle who is speaking before any content is read. Impersonation exploits that shortcut and the platforms' weak identity guarantees — a display name, an avatar, and a plausible handle are enough, and paid verification badges, introduced by Twitter in 2022, briefly made the disguise purchasable. Linvill and Warren (2020) showed that the Internet Research Agency's most effective accounts were not generic trolls but specialized personas that impersonated specific communities — a state Republican party, Black activists, a left-wing news site — and built real followings before deploying them. The technique serves three purposes: speaking as the target, discrediting the target, and harvesting the target's audience for later use. Detection rests on provenance rather than content, because content is the disguise: account age, handle history, follower composition, whether the target's verified channels link to it, and whether the profile image returns matches elsewhere. The tell is a familiar identity saying something its real owner would not, on an account nobody can trace to that owner.

Real-world examples

  • The IRA account @TEN_GOP impersonated the Tennessee Republican Party from 2015 to 2017, gained more than a hundred thousand followers, and was retweeted by senior Trump campaign figures; its counterpart Blacktivist impersonated Black activists, and the Peace Data site in 2020 impersonated a left-wing outlet and hired unwitting American freelance writers.
  • On November 10, 2022, an account that had bought a Twitter Blue checkmark and copied Eli Lilly's name and logo tweeted that insulin was now free; the company's shares fell and it paused advertising on the platform, while similar accounts impersonated Lockheed Martin, Nintendo, and politicians.
  • In October 2020, Twitter suspended a set of accounts posing as Black Trump supporters that used stolen or stock photographs and near-identical text, identified by Clemson University researchers; the Identity Evropa account posing as antifa in June 2020 worked the same way from the opposite direction.
  • In May 2023, an AI-generated image of an explosion at the Pentagon spread through accounts impersonating Bloomberg and other news brands, and U.S. stock indexes dipped briefly before the image was debunked.

Ethical guidelines

  • Speaking in another person's or organization's name without their consent is fraud whatever is said; the harm is to the impersonated party's control over their own voice.
  • Parody is legitimate only when a reasonable reader can tell it is parody; a label buried in a bio does not meet that standard when the display name and avatar say otherwise.
  • Platforms that sell identity signals without verifying identity are selling the tool of the fraud.

How to defend against it

  • Check the handle, not the display name: display names are free text, handles are unique, and impersonators typically differ from the real account by a character, a suffix, or a lookalike letter.
  • Trace the link from the real source: an organization's official website lists its official accounts, and an account that appears nowhere on it is unverified whatever badge it shows.
  • Check account age and history — an account created last week speaking for a decades-old institution is the pattern — and reverse-image-search the profile photo.
  • Before reacting to a screenshot of a shocking post attributed to a known person, find the post on their actual account; if it is not there, it was either deleted or never posted, and a search for the text plus the word fake usually settles which.
  • Organizations should register their names across platforms, publish a canonical account list, and monitor for lookalikes, because a takedown after the fact never reaches everyone who saw the impersonation.

From the Defense Playbook

The SIFT Methodminutes

A four-move routine for anything you meet online: Stop, Investigate the source, Find better coverage, and Trace claims, quotes, and media to their original context; it takes under a minute and replaces the instinct to study the page itself.

Reverse Image Searchminutes

Upload or paste an image (or a video frame) into an image search engine to find where else and when it has appeared, which exposes recycled photos, stolen profile pictures, and images given a false caption.

Account Forensicsminutes

Before taking an online account's word, or taking a crowd of accounts as public opinion, spend a minute on the profile itself: its age, history, posting rhythm, network, and photo, which together show whether you are looking at a person, a persona, or a coordinated operation.

Prebunking (Self-Inoculation)takes practice

Expose yourself in advance to a weakened, clearly labelled dose of a manipulation technique together with its refutation, so that when the full-strength version arrives you recognize the move instead of being carried by it.

Out-of-Band Verificationminutes

Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.

Verify, Then Trust (for Authority Claims)minutes

Separate the symbols of authority (a title, a uniform, a badge, a confident tone, an official-looking letterhead) from the fact of authority, and check the fact through a source the claimant does not control before you comply.

Multi-Factor Authentication and Passkeysminutes

Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Linvill, D. L., & Warren, P. L. (2020). Troll Factories: Manufacturing Specialized Disinformation on Twitter. Political Communication, 37(4), 447–467
    The IRA's specialized persona types and their impersonation of specific American communities.
  2. Mueller, R. S. (U.S. Department of Justice) (2019). Report On The Investigation Into Russian Interference In The 2016 Presidential Election, Volume I. U.S. Department of Justice · link
    The @TEN_GOP and Blacktivist impersonation accounts and their reach.
  3. DiResta, R., Shaffer, K., Ruppel, B., Sullivan, D., Matney, R., Fox, R., Albright, J., & Johnson, B. (2018). The Tactics & Tropes of the Internet Research Agency. New Knowledge report prepared for the U.S. Senate Select Committee on Intelligence
    How impersonation pages built real audiences before being used, across both sides of the spectrum.
Last reviewed
Suggest a correction

Detect Impersonation Accounts in any text

Paste any message, email, or article into our free Manipulation Detector to see if Impersonation Accounts or other techniques are being used on you.

Related Articles