Brand Impersonation Scams: What to Do When Fraudsters Pose as Your Company

  • 4 min read
Security and compliance illustration with a glass shield and a cyan verification scan ring

Pretending to be someone else online costs a scammer almost nothing, and the tactics keep getting more convincing. B2B iGaming is an attractive target: deals involve significant payments, integration credentials and personal documents, and many conversations happen on messaging apps. If fraudsters start posing as your company, a fast and structured response limits the damage to your clients and your reputation.

How impersonation scams usually work

In a typical case, criminals pose as employees of a real company and target its existing or prospective clients. Common approaches include:

  • fake staff profiles on messengers and social networks that contact clients directly;
  • emails that spoof your domain or come from an address that looks almost the same;
  • lookalike websites that copy your branding;
  • invoices or "updated bank details" that redirect payments;
  • requests for passports, company documents or login details under the pretext of onboarding.

The aim is nearly always the same: get money or sensitive data from people who believe they are dealing with you.

Step 1: Warn clients and prospects straight away

Your first move should be an official notice to everyone who has shared an email address with you, from current clients to recent enquiries. Keep it clear and practical:

  • explain what is happening and how the scam works, for example strangers adding clients on a messaging app and asking for payments or personal data;
  • list the channels and domains your team genuinely uses;
  • say what you will never ask for, such as payment to a new account through a chat message;
  • tell recipients how to verify a request and where to report suspicious contact.

Publish the same notice on your website so people who search for your name find it.

Step 2: Secure your email domain

Send all official communication from your own domain and configure the standard email authentication records:

  • Sender Policy Framework (SPF) lists the servers allowed to send mail for your domain.
  • DomainKeys Identified Mail (DKIM) adds a digital signature that proves a message was not altered.
  • DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving servers what to do with mail that fails those checks and sends you reports about it.

These measures will not stop every fraud attempt, since they cannot prevent a scammer from registering a similar domain. They do make it much harder to spoof your exact address and help recipients tell genuine messages from fakes.

Step 3: Find and remove lookalike domains and profiles

Typosquatting is one of the most common impersonation tricks. Fraudsters register a domain that is almost identical to yours and wait for someone to miss the difference. Watch for:

  • Deliberate typos: a swapped, missing or doubled letter in your brand name.
  • Different endings: your name on .org or .net when you use .com.
  • Homoglyphs: characters from another alphabet that look the same. A Cyrillic "а" or "м" is almost impossible to tell apart from the Latin letter in most fonts.

Set up monitoring for new registrations that resemble your brand, consider registering the most obvious variants yourself, and report fake sites to the registrar and hosting provider. For persistent cases, the UDRP dispute process can transfer an infringing domain. Report fake profiles to the social network or messaging platform concerned.

Step 4: Keep educating your clients

A single warning helps today; ongoing education stops clients falling for the next variation. Publish short security guides on your blog, include tips in newsletters and remind contacts regularly:

  • check the sender's full email address, not just the display name;
  • confirm any change of payment details through a known channel;
  • be wary of urgency, unusual requests or new contact methods;
  • never share passwords or one-time codes.

Even experienced, tech-savvy people make mistakes, so repeat the message.

Step 5: Record and report every incident

Keep screenshots, email headers, domain names and payment details used by the fraudsters. Report incidents to the police or national cybercrime unit, and alert the banks and payment providers involved. If personal data may have been exposed, check whether data protection rules require you to notify authorities or the people affected.

You cannot stop every scam, but you can limit the damage

As long as people trust brands online, someone will try to abuse that trust. The companies that come through best know the common tactics, respond quickly and make verification easy for clients. For the record, genuine emails from our team only ever come from addresses ending in @igamingsoftwaresolutions.com. If in doubt, check through our contacts page.

Written and reviewed by the iGaming Software Solutions Editorial Team.

Ready to launch your online casino?

iGaming Software Solutions builds turnkey, white label and self-service casino platforms, a unified casino games API, sportsbook, payments and bonus tooling for online gambling operators.

Talk to our team

Tell us what you are building

Share a few details about your project (platform, games, sportsbook, payments or licensing) and the right specialist will reply by email.

Prefer email? Write to the team that fits your request.