Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

Insight

Practical Guide to Impersonation Defenses: How to Counter Evolving Threats from Social Media, AI Voice Scams, and Spoofed Domains

Impersonation of your brand is no longer limited to search ads and fake landing pages. It now spans multiple channels, including fake accounts and ads on TikTok and Instagram, DMs on messaging apps, and even AI-generated voice cloning over phone calls. The US FTC reported that fraud losses reached a record $12.5 billion in 2024, with online scams driving the sharp increase. Regulators are also tightening telecom controls: the US FCC has clarified that robocalls using AI-generated voices are illegal, and the UK's Ofcom now requires carriers to block spoofed international CLIs. Consequently, brand protection can no longer be managed by the IT department alone; it requires a company-wide operation uniting legal, PR, and customer support. As generative AI slashes attack costs, the frequency of attempts is growing exponentially. Yagura addresses this structural shift head-on, leveraging a combination of AI and human operations to bolster corporate defense. This report examines the reality of attackers armed with crawling and OSINT, and proposes countermeasures that work across domains, social media, and phone channels. Finally, we outline key operational SLAs and customer education strategies that directly impact executive decision-making.

AI SOCとは? 仕組み・従来型SOCとの違い

1. The Modern Impersonation Landscape (SNS, AI Voice, Domains)

Attackers begin by scraping brand assets from public websites and social media. They gather fragmented information—such as logos, executive names, hiring data, event photos, locations, and titles—and enrich this context through OSINT. Using these assets, they quickly deploy fake profiles, fake landing pages, and fake call scripts across TikTok and Instagram via ads, short-form videos, and live streams. They exploit cognitive blind spots through visual authenticity and sheer volume. Phishing has become chronic, with over 1 million incidents detected quarterly, alongside a notable rise in QR code-based redirection (Quishing).

A particularly challenging trend is the misuse of AI voice calls linked to social media and fake landing pages. For instance, an attacker redirects a victim from a fake social media ad to an in-app DM, initiates an AI voice call pretending to perform identity verification, and directs them via SMS to a fake domain to submit KYC details. This multi-stage social engineering is no longer rare. At major UK engineering firm Arup, a video conference-based deepfake resulted in a loss of approximately $25 million. This case proves that visual or auditory "authenticity" alone can no longer guarantee the legitimacy of decisions.

In the domain space, typo and combo squatting—which exploit typos, prefixes, and suffixes to create legitimate-looking URLs—remain persistent. When attackers use TLS certificates and CDNs to project outward security, expecting everyday users to distinguish real from fake becomes unrealistic. This media convergence, starting on social media and routing users to fake domains, continues to broaden the scope of victim exposure.

Yagura's Perspective
Attackers are leveraging generative AI for mass production and optimization, achieving speed, low cost, and high sophistication simultaneously. To counter this, defenders must implement AI-driven coverage, speed, and repetition.

2. The Impact of Impersonation on Businesses (Brand, Finance, Regulation)

The damage caused by impersonation goes beyond isolated incidents. First is brand degradation. Fake ads generate high impression volumes in short timeframes, establishing a false sense of legitimacy. According to the UK Finance Annual Report (2025), total fraud losses in 2024 exceeded £1 billion, with incident volume rising year-over-year, driven by the expansion of social media-originated fraud.

The impact is not limited to reputation. As the Arup case shows, pressure applied through highly convincing voice or video impersonations leads to faulty wire transfers and authorization errors, resulting in direct financial loss. Without out-of-band verification mechanisms, preventing high-value losses is extremely difficult.

Regulatory scrutiny is also intensifying. In Japan, the Financial Services Agency (2025) issued warnings and requested threat disclosures and strong authentication in response to the surge in fraudulent trading and fake websites impersonating securities firms. Allowing this trend to grow unchecked will inevitably erode trust among regulators and investors.

3. Mitigation Strategies (A Unified Approach: Management, IT, and PR)

3-1. Enforcing Domain-Centric Technical Controls

The foundation for mitigating email impersonation lies in SPF, DKIM, and DMARC. Since 2024, Google and Yahoo have required bulk senders to implement DMARC, provide one-click unsubscribe options, and keep spam rates below 0.3%. Failure to comply directly impacts email deliverability. Organizations should aim to graduate policies to "p=reject". Deploying BIMI (VMC/CMC) to verify logo authenticity is also essential. For domain strategies, defensive domain registration—preemptively registering major TLDs and common typos—is highly effective. Organizations must also monitor CT logs and employ look-alike domain detection to catch new fraudulent URLs early, extending constant monitoring to landing URLs linked to social media ads.

3-2. Social Media Defense: Proactive Protection on TikTok and Instagram

Start by securing official account verification (blue badges). TikTok provides dedicated verification and reporting workflows, and Meta continues to enhance its Brand Rights Protection tools. PR, Legal, and IT departments must establish shared SLAs to manage the daily lifecycle of detection, evidence preservation, reporting, takedown, and recurrence prevention. Customer education should also live on these platforms. Pinning posts or detailing official domains on profiles, explicitly stating that "we never request payment details via DM," and keeping reporting links accessible are critical. This is not ad optimization; it is security UX designed to minimize victim impact.

3-3. Voice Channels: Systemic Defense Against AI Voice Calls

Auditory and visual authenticity can no longer serve as proof of identity. The US FCC has classified AI-generated robocalls as illegal calls, and the UK's Ofcom requires telecom providers to block CLI spoofing from international sources. Organizations must codify three key practices: callbacks to verified numbers, the use of codewords, and out-of-band authorization for high-value or urgent requests. Contact centers must mandate procedures that do not rely solely on voice to confirm identity.

3-4. AI-Powered Defense (Operational Requirements Supported by Yagura)

Managing these defenses manually is no longer viable. Automated crawling must be used to detect fake ads, fake accounts, and look-alike domains across platforms, with generative AI-based scoring evaluating visual cues like logo misuse, text similarity, and redirection patterns. The time from detection to evidence logging, reporting, and takedown should be tracked on dashboards using KPIs like fake ad detection volume, time-to-takedown, look-alike domains detected, and report counts, all managed under clear SLAs. Customer education templates, such as pinned posts and dedicated alerts, should not be static assets but treated as dynamic content kept constantly up to date.

Yagura's Commitment
We standardize AI-driven defense, enabling broad, rapid, and repetitive security operations. Through process automation and cross-functional SLAs, we transform brand protection into a measurable business KPI.

Conclusion: Win Through Operations. Ensure Coverage, Speed, and Repetition with AI.

Impersonation has expanded into social media and AI voice calls; domain-only defenses are no longer sufficient. Beyond core infrastructure like DMARC and BIMI, organizations must integrate official TikTok and Instagram tools into daily operations. Treating customer education as a continuous service through pinned posts, alerts, and clear reporting channels is essential. Finally, to counter AI voice threats, companies must institutionalize callbacks and out-of-band authorization, ending reliance on voice or video appearance for critical decisions. These three areas form the core of modern corporate defense.

Generative AI-driven attacks will continue to advance, and falling costs will exponentially increase attack frequency. Defenders must adopt generative AI to keep pace. Fake accounts and ads appear daily; look-alike domains emerge weekly. While complete eradication is impossible, shrinking the window between detection and takedown and keeping customer channels updated will materially reduce the impact. As regulatory frameworks from the FCC and Ofcom tighten, the deciding factor will be whether organizations can sustain a "broad, rapid, and repetitive" baseline supported by AI. Yagura is built to partner with you in executing this strategy.

Related Services: Learn more about how "Yagura Takedown" continuously monitors social media impersonations using AI and automates takedown requests.

References and Sources

This article references the following reports and disclosures: The FTC report on $12.5 billion in fraud losses in 2024 (highlighting online-originated fraud expansion); the FCC Declaratory Ruling clarifying AI-generated robocalls as illegal; Ofcom's updated guidance requiring telecom operators to block international CLI spoofing; APWG observations of over 1 million phishing incidents in Q1 2025 and rising QR code abuse; the UK Finance Annual Report (2025) noting fraud losses exceeding £1 billion and increased incident volume (analyzed by KPMG); the Financial Services Agency (2025) warnings and calls for strong authentication amid rising fake websites and illicit transactions; and the Arup case, which resulted in a $25 million loss due to a video conference-based deepfake.

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化や

サービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。