Authority impersonation poses as a person or institution with legitimate power over the target — an executive, IT administrator, government agency, bank, or police force — so their claimed rank compels action that bypasses normal scrutiny. It is a high-yield specialization of pretexting: rather than merely inventing a plausible reason to make contact, the attacker adopts a role the target is conditioned to obey.
Three ingredients recur — a claimed powerful role, a request that role could plausibly make, and urgency or intimidation that discourages checking. The impersonation is reinforced with borrowed signals: a spoofed domain or caller ID, a copied logo, real executive names, jargon, and increasingly synthetic voice or video of a known leader. A message “from the CEO” demanding an urgent confidential wire, a caller “from IT” who needs your password, a “tax agency” threatening arrest — each substitutes the appearance of authority for its substance.
Because compliance is driven by the hierarchy rather than any suspicious artifact, the attack often succeeds even against people who would spot a crude phishing link. AI voice and video cloning have sharpened it — a widely reported 2024 case saw a finance employee wire funds after a video call populated with deepfaked executives — but the underlying lever is unchanged: the target obeys a role they did not verify.