General Intels
SOLUTION 04 · For the CISO, comms and the protective-security team

Your CEO's name is in a channel you don't have access to. Now what?

Impersonation, doxxing and lookalike infrastructure are assembled in the open, out of material that leaked somewhere else: a personal inbox in a stealer log, a home address in a fullz listing, a voice sample from a conference keynote. The assembly is visible before the attack is.

01Why it keeps happening

The four places the current answer runs out

The exposure is personal, not corporate

The leaked account is a private inbox on a home laptop, and it is where the mortgage, the family and the travel plans live. It is entirely outside your estate, and entirely usable against you.

The impersonation is built where you cannot look

Lookalike domains get advertised, executive dossiers get traded and voice samples get swapped in channels that are invite-only, non-English, and closed to the tooling most brand-protection vendors run.

By the time it is public, it has already worked

A takedown request is a response to a live campaign. The registration, the kit purchase and the target research all happened weeks earlier, in venues that were never hiding.

Comms and security find out from different places

The security team sees a domain; the comms team sees a Telegram post; nobody sees the thread that connects them, because the two live in different tools and neither is the record.

02How it got here

How impersonation became infrastructure

The raw material for each era is harvested in the era before it. What is being collected about your executives now is the input to the next line on this rail.

THREAT EVOLUTION

EACH ERA STACKED ON THE LAST

  1. 2014-2019

    The typosquat

    A near-miss domain, a spoofed sender and a wire-transfer request written in workmanlike English. Detectable by a human reading carefully, and often caught by one.

  2. 2020-2023

    Impersonation at scale

    Phishing kits with tenant-aware login pages, lookalike domains registered in bulk, and executive profiles reconstructed from leaked personal accounts. The tell-tale typos are gone, because a kit wrote it.

  3. YOU ARE HERE

    2024-2026

    Synthetic authority

    A cloned voice on a call and a face in a video meeting, backed by real internal detail bought from a stealer log. The fraud is no longer asking you to believe an email; it is asking you to disbelieve your own CFO.

  4. Next

    Persistent synthetic identity

    Not a single call but a maintained persona: a fake vendor contact with history, a plausible inbox and months of correspondence, built to be trusted long before it asks for anything.

03What we do about it

Six plays, and the window each one runs in

Every play names the module that does the work. Nothing here is a capability we describe without shipping.

Watch the thing being built

Executive names, personal domains and brand strings, monitored as full-text queries across forums, marketplaces and leak sites, in every language they surface in, with attachments and screenshots preserved.

DRAGNET

The dossier is advertised where the buyers are

Fullz listings, lookalike-domain adverts and executive dossiers are sold to subscriber channels rather than posted in a forum thread, and often in a language your brand-protection tool does not read. The same name is searchable there as it is on the forums. It is a second query against a second corpus rather than one result, and running it is the difference between reading the advert and never seeing it.

TELEPATHY

The personal account is the way in

When an executive's private credentials surface in a stealer log, you can find it as an incident, with the log's own context and the cookies beside it, rather than as a line in a breach digest six months later.

SHERLOG

Find the face wearing the name

Impersonation does not stop at a lookalike domain; it wears a name, a title and a photo on the professional networks your staff trusts. Baitback searches a name, and the same name at your company, and groups the profiles so the handful claiming to work there stand apart from the crowd of genuine namesakes, with the link and photo to report the one nobody recognises.

BAITBACK

Evidence that survives deletion

Impersonation posts get pulled the moment they are reported. The archived copy, with its timestamp and screenshot, is what your lawyers, your registrar and your regulator will actually accept.

DRAGNET

And the signal we do not publish

There is one collection surface that shows attacker attention rather than attacker output: who is researching whom. Its public, anonymized shadow is the Hunt Scene; the rest is a closed briefing.

SOURS

Also searchedJabbernautGuildwire

04In practice

The call that almost worked

Week 1

A stealer log surfaces containing an executive assistant's personal Gmail, its cookies, and in the autofill records the travel itinerary for the board offsite.

Week 2

A lookalike domain for your finance portal is registered and advertised in a fraud channel. On its own it is one of thousands; against the log, it is the second half of a plan.

Week 3

Nothing correlates them for you. An analyst holding both, the log from one query and the domain from another, writes the brief; comms, security and the CFO read the same one, with both artefacts in it.

Week 3

The call comes during the offsite, in the CFO's voice, referencing the itinerary. It is refused in nine seconds, because the person answering had read the brief.

05What changes

The move, stated plainly

No customer logos and no invented percentages: we have not deployed long enough to have honest ones. What we can state is what the workflow becomes.

Brand monitoring watches the clear web

The same query runs in the closed venues, in the languages the material is traded in

Executive exposure is a personal problem

Executive exposure is an incident with an evidence chain and an owner

The post is deleted before legal sees it

The archived copy, timestamped, is in the case file

Questions

Brand & executive exposure, honestly answered

Your competitors will learn about the leak from the invoice.

Learn about it from the log batch.

NDA-friendly briefings · global coverage · no slideware