S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T14.7
CATEGORY Social Engineering
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Authority Impersonation

Human Vector · Borrowed Rank · Very High
Red Flag
How It WorksSEC 01

Authority impersonation poses as a person or institution with legitimate power over the target — an executive, IT administrator, government agency, bank, or police force — so their claimed rank compels action that bypasses normal scrutiny. It is a high-yield specialization of pretexting: rather than merely inventing a plausible reason to make contact, the attacker adopts a role the target is conditioned to obey.

Three ingredients recur — a claimed powerful role, a request that role could plausibly make, and urgency or intimidation that discourages checking. The impersonation is reinforced with borrowed signals: a spoofed domain or caller ID, a copied logo, real executive names, jargon, and increasingly synthetic voice or video of a known leader. A message “from the CEO” demanding an urgent confidential wire, a caller “from IT” who needs your password, a “tax agency” threatening arrest — each substitutes the appearance of authority for its substance.

Because compliance is driven by the hierarchy rather than any suspicious artifact, the attack often succeeds even against people who would spot a crude phishing link. AI voice and video cloning have sharpened it — a widely reported 2024 case saw a finance employee wire funds after a video call populated with deepfaked executives — but the underlying lever is unchanged: the target obeys a role they did not verify.

Warning SignsSEC 02
  • A "do it now" from someone senior — urgency, threats, or a hard deadline.
  • Authority you can't confirm through the directory or a known official number; contact via an unusual channel (personal email, text, new number).
  • Heavy reliance on rank and secrecy — "don't loop anyone in."
  • Intimidation, name-dropping, or flattery ("I trust you with this").
  • A request that breaks normal process — an irregular payment path, or a credential/MFA reset by voice.
  • Tell: real officials never demand gift cards, crypto, or wires under threat, and never ask for passwords or one-time codes.
Frequently Paired WithSEC 03
  • Pretexting · T14.1
    Parent frame; this is the role-specific case
  • Institutional Mimicry · T2.13
    Impersonating the organization's look and voice
  • Phishing · T14.2
    Common delivery channel
  • Vishing · T14.8
    The voice channel this rides on
How the Attack UnfoldsSEC 04
  • Stage 01 · Claim
    The attacker asserts a powerful role — exec, IT, agency, bank — reinforced with spoofed IDs, logos, or a cloned voice.
  • Stage 02 · Pressure
    An urgent, confidential request the role could plausibly make arrives, with intimidation or a deadline that discourages verification.
  • Stage 03 · Compliance
    The target obeys the hierarchy — wiring funds, disclosing a password, resetting MFA — before confirming who is really asking.
Counter-ProtocolSEC 05
Defense: Rank plus urgency is a stop signal, not a go signal — verify authority out-of-band.
  • Confirm the person independently. Use the internal directory, a known-good number, or a second channel — never the contact details supplied in the request.
  • Unhook and escalate. Name the intimidation to restore judgment; route unusual "executive," "IT," or "official" requests to a manager or security.
  • Enforce process. Dual authorization and callback verification for payments and credential/MFA resets.
  • Publish the norms. Leadership will never demand secret urgent wires, and IT will never ask for your password.
  • Defeat deepfakes. Register a verification code word for high-value transactions; treat voice and video instructions as spoofable and confirm separately.