Executive Impersonation Scam Investigations Using OSINT

Executive impersonation turns a leader's name, face or voice into a payment instruction or an investment pitch. We investigate each incident across the channels it used, preserve the evidence before it disappears, trace the accounts, numbers and domains to the operators and help you close the gaps that made the scam believable.

  • CEO fraud against staff and suppliers
  • Cloned voices and fake video calls
  • Fake executive profiles and ads
  • Urgent cases within a business day
Short answer

An executive impersonation investigation looks at a scam that uses a real leader's identity, whether by email, messaging app, cloned voice, fake video call or fake profile, and establishes what happened, which infrastructure the scammers used and what else it connects to. OSINT-S preserves the evidence, traces the operators from open sources and delivers a report your bank, the platforms, police and counsel can act on.

How Executive Impersonation Scams Reach Their Targets

Two audiences, five channels. Inside the company the goal is a payment or data; outside it, the goal is the public's money or trust.

Email

CEO fraud and fake invoices

Urgent requests from a spoofed or look-alike address to finance staff or suppliers, often timed for travel days and quarter ends.

BEC investigations →
Messaging

WhatsApp and SMS from the boss

A new number with the CEO's photo asks a manager to keep a deal confidential and buy gift cards or move funds.

Voice

Cloned voice calls

A short call or voicemail in a leader's voice, built from interviews, earnings calls or conference videos.

Video

Fake video meetings

A meeting invite where the executive and colleagues on screen are synthetic or replayed, used to approve a transfer.

Deepfake detection →
Public

Fake endorsements and profiles

Ads and posts showing a founder recommending an investment, or profiles of executives used to recruit victims.

Investment scam investigations →

Executive Impersonation Losses and the FTC Impersonation Rule

Reported losses to business impersonators reached nearly $1 billion in the US in 2025, and the FTC rule explicitly covers posing as a company's officers.

  • People reported losing $3.5 billion to imposter scams in 2025, with nearly $1 billion lost to scammers posing as businesses, up from $866 million in 2024 (FTC, June 2026).
  • The FTC's Trade Regulation Rule on Impersonation of Government and Businesses, effective April 1, 2024, makes it unlawful to "materially and falsely pose as, directly or by implication, a business or officer thereof" (16 CFR 461.3). The FTC says it has since brought a dozen enforcement actions under the rule.
  • The FBI has warned that criminals use generative AI to "generate videos for real time video chats with alleged company executives, law enforcement" and other authority figures (IC3, December 2024).

The rule gives the FTC a route to civil penalties and redress; it does not give companies a private claim. What a company can do is put a complete, well-sourced file in front of the platforms, banks, police and regulators that can act.

Investigating Voice Deepfakes and Fake Video Calls with OSINT

We work from what the scam left behind: recordings, numbers, meeting links, accounts and the public material the clone was built from.

ArtifactWhat we checkWhy it matters
Voicemail or call recordingPhrases and intonation matched to public interviews and videos of the executiveShows which public material was used, and what to restrict
Caller numberNumber type, carrier, messaging-app profiles and prior scam reportsLinks the call to other incidents and supports a carrier or police request
Meeting invite and linkSender domain, account names, registration dates of linked domainsSeparates a compromised account from an outside look-alike
Video stillsBackground, clothing and framing matched to past public footageIdentifies replayed or synthetic footage and its source
Payment instructionsBeneficiary name, bank, crypto addresses and their public historyGives the bank and police a recall and tracing starting point

Technical analysis of whether audio or video is synthetic runs as deepfake detection; this page covers who ran the scam and what it connects to.

The First 48 Hours: An OSINT Response to CEO Fraud

Stop the money, preserve the evidence, map the infrastructure, warn the right people, then close the gaps.

  1. Call your bank firstIf money moved, your finance team asks the bank to recall the payment immediately and reports to police; speed matters more than anything we do.
  2. PreserveWe capture emails with full headers, messages, call logs, recordings, profiles and ads with timestamps and hashes before accounts are deleted.
  3. Map the infrastructureLook-alike domains, sender accounts, phone numbers, meeting links and payment details are traced and checked for links to earlier incidents.
  4. Find other targetsWe search for the same accounts, domains and scripts aimed at other staff, suppliers, investors or the public.
  5. Warn and reportA short internal alert for staff and suppliers, and evidence packs for platforms, registrars and police.
  6. Reduce the raw materialWe list the public details the scammers relied on, such as travel posts, org charts and long voice recordings, with practical ways to reduce them.

Deliverables, Timelines and Limits

An incident report, an infrastructure map, evidence packs per recipient and a short list of fixes. A single urgent incident can often be documented within a business day.

A single live incident, such as fake messages from the CEO to the finance team this morning, can often be documented within a business day of agreeing scope. A full investigation across several channels and incidents takes from 10 business days, and a campaign targeting the public in several countries up to about a month. Urgent delivery costs 50% more, a senior analyst reviews every report, the quote is fixed after written scoping and the fee goes down if we miss the agreed date.

We use public and lawfully obtained information only. We do not hack scammers' accounts, call them under false identities or buy leaked data, and we handle the executive's and staff's personal data under the GDPR and similar laws. Attribution to a named person is not always possible with organized groups, and the report states the confidence of each link. To shrink what impersonators can copy, pair this work with an organizational OSINT exposure audit; for leaders who also face threats, see executive protection. It is part of the OSINT services for security and legal teams we provide.

Protect the Names People Trust

Tell us which executive was impersonated, through which channels, and whether money moved. We confirm scope the same day where we can and give you a fixed quote.

Executive Impersonation OSINT FAQ

Our finance manager got a WhatsApp voice note that sounded exactly like our CEO asking for an urgent transfer — can an executive impersonation investigation tell us who did it?

We can establish what the scammers used and what it connects to: the number and its history, the messaging profile, the payment details they gave and the public recordings the voice was likely cloned from. Those links often tie the incident to other scams and sometimes to named people. If money moved, ask your bank for a recall and report to police first; our report then supports both.

We nearly approved a payment after a video call where our CFO and two colleagues appeared on screen, but none of them were really there — what evidence should we keep?

Keep the meeting invite with its full email headers, the meeting link and platform account names, any chat messages, recordings or screenshots, the payment instructions and a note of who attended and when. Do not delete the accounts involved. We preserve that material with timestamps and hashes, trace the sender and the linked domains, and identify which public footage the video likely came from.

Scam ads on social media show our founder recommending a crypto platform he has never heard of — can you get them removed and find who is paying for them?

We document each ad and its landing pages, then trace the domains, apps, wallet addresses and advertiser accounts behind them. That evidence supports impersonation reports to the platforms and, where the public lost money, police and regulators. Identifying the people who pay for ads is sometimes possible from public data and sometimes needs platform records through legal process; the report says which applies.

Does the FTC Impersonation Rule mean we can sue the people pretending to be our CEO, or is it something only the government can use against them?

The rule is enforced by the FTC, which can seek civil penalties and redress in federal court; it does not create a private right for companies to sue. It does make clear that posing as a business or its officers is unlawful. Your counsel may still have claims under trademark, fraud or other laws, and a well-documented OSINT report is useful for either route.

How can we make it harder for scammers to impersonate our executives in the first place without taking them completely offline?

Most protection comes from process: a call-back rule on a known number for any payment change, two approvers for urgent transfers and a verification phrase for sensitive requests. On the exposure side, we list the details scammers rely on, such as travel posts, assistant names and long voice recordings, and suggest proportionate changes, so leaders can stay visible without handing over a script.

We're a mid-size company and this happened once — is it worth a full investigation, or should we just warn staff and move on?

If no money moved and the scam stopped, a short documented check is often enough: confirm what was used, whether other staff or suppliers were targeted, and whether the same accounts appear in other scams. A full investigation makes sense when there were losses, repeat attempts, public-facing scams using the executive's name, or a legal or insurance claim that needs evidence.