Impersonation Accounts
What it is
Social-media accounts that pose as a real person, organization, movement, or news outlet — borrowing the target's name, image, and credibility — to speak in their voice, discredit them, or harvest the trust their identity commands.
How it works
Real-world examples
- •The IRA account @TEN_GOP impersonated the Tennessee Republican Party from 2015 to 2017, gained more than a hundred thousand followers, and was retweeted by senior Trump campaign figures; its counterpart Blacktivist impersonated Black activists, and the Peace Data site in 2020 impersonated a left-wing outlet and hired unwitting American freelance writers.
- •On November 10, 2022, an account that had bought a Twitter Blue checkmark and copied Eli Lilly's name and logo tweeted that insulin was now free; the company's shares fell and it paused advertising on the platform, while similar accounts impersonated Lockheed Martin, Nintendo, and politicians.
- •In October 2020, Twitter suspended a set of accounts posing as Black Trump supporters that used stolen or stock photographs and near-identical text, identified by Clemson University researchers; the Identity Evropa account posing as antifa in June 2020 worked the same way from the opposite direction.
- •In May 2023, an AI-generated image of an explosion at the Pentagon spread through accounts impersonating Bloomberg and other news brands, and U.S. stock indexes dipped briefly before the image was debunked.
Ethical guidelines
- ●Speaking in another person's or organization's name without their consent is fraud whatever is said; the harm is to the impersonated party's control over their own voice.
- ●Parody is legitimate only when a reasonable reader can tell it is parody; a label buried in a bio does not meet that standard when the display name and avatar say otherwise.
- ●Platforms that sell identity signals without verifying identity are selling the tool of the fraud.
How to defend against it
- ►Check the handle, not the display name: display names are free text, handles are unique, and impersonators typically differ from the real account by a character, a suffix, or a lookalike letter.
- ►Trace the link from the real source: an organization's official website lists its official accounts, and an account that appears nowhere on it is unverified whatever badge it shows.
- ►Check account age and history — an account created last week speaking for a decades-old institution is the pattern — and reverse-image-search the profile photo.
- ►Before reacting to a screenshot of a shocking post attributed to a known person, find the post on their actual account; if it is not there, it was either deleted or never posted, and a search for the text plus the word fake usually settles which.
- ►Organizations should register their names across platforms, publish a canonical account list, and monitor for lookalikes, because a takedown after the fact never reaches everyone who saw the impersonation.
From the Defense Playbook
A four-move routine for anything you meet online: Stop, Investigate the source, Find better coverage, and Trace claims, quotes, and media to their original context; it takes under a minute and replaces the instinct to study the page itself.
Upload or paste an image (or a video frame) into an image search engine to find where else and when it has appeared, which exposes recycled photos, stolen profile pictures, and images given a false caption.
Before taking an online account's word, or taking a crowd of accounts as public opinion, spend a minute on the profile itself: its age, history, posting rhythm, network, and photo, which together show whether you are looking at a person, a persona, or a coordinated operation.
Expose yourself in advance to a weakened, clearly labelled dose of a manipulation technique together with its refutation, so that when the full-strength version arrives you recognize the move instead of being carried by it.
Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.
Separate the symbols of authority (a title, a uniform, a badge, a confident tone, an official-looking letterhead) from the fact of authority, and check the fact through a source the claimant does not control before you comply.
Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Linvill, D. L., & Warren, P. L. (2020). Troll Factories: Manufacturing Specialized Disinformation on Twitter. Political Communication, 37(4), 447–467The IRA's specialized persona types and their impersonation of specific American communities.
- Mueller, R. S. (U.S. Department of Justice) (2019). Report On The Investigation Into Russian Interference In The 2016 Presidential Election, Volume I. U.S. Department of Justice · linkThe @TEN_GOP and Blacktivist impersonation accounts and their reach.
- DiResta, R., Shaffer, K., Ruppel, B., Sullivan, D., Matney, R., Fox, R., Albright, J., & Johnson, B. (2018). The Tactics & Tropes of the Internet Research Agency. New Knowledge report prepared for the U.S. Senate Select Committee on IntelligenceHow impersonation pages built real audiences before being used, across both sides of the spectrum.
Related Articles
Dark Patterns in UX: How Apps Manipulate Your Behavior
Subscription traps, misleading interfaces, and engineered addiction. Understanding the persuasion techniques built into the apps you use every day.
OSINT for Beginners: Open Source Intelligence Explained
Open Source Intelligence (OSINT) uses publicly available data to gather actionable insights. Here is a beginner-friendly guide to what OSINT is and how it is used.