Impersonation is pretending to be a specific person or role to win the trust or access that identity commands. It is the engine beneath many of the costliest frauds — business email compromise, executive and agency-official scams, tech-support and bank impersonation, and grandparent/relative-in-distress schemes. The tactic exploits trust transfer and authority: we extend to a recognized identity a level of compliance we would never grant a stranger, and impersonation simply borrows that recognition.
The mechanism pairs a stolen persona with authority and urgency. Richard Dawkins and John Krebs framed signaling between organisms as manipulation exploiting a receiver’s response system; impersonation is the human case — it counterfeits the identity cues we use as shortcuts for “safe to comply.” Spoofed sender names, look-alike numbers, cloned accounts, and (increasingly) synthetic voice or video make the persona convincing, while a time-critical, keep-it-quiet request suppresses the verification that would expose it. Authorized role-play exists in sanctioned security testing; malicious impersonation is distinguished by its refusal to be verified.
Because the persona can be faked but the person can be reached, the defense is out-of-band authentication. Call back on a known number, enforce dual-approval process for money and access regardless of who is asking, agree on a shared code phrase for urgent requests, and treat the combination of urgency plus secrecy plus resistance to verification as the reliable signature. A genuine contact welcomes the callback; an impersonator needs you to skip it.