Your CEO's name is in a channel you don't have access to. Now what?
Impersonation, doxxing and lookalike infrastructure are assembled in the open, out of material that leaked somewhere else: a personal inbox in a stealer log, a home address in a fullz listing, a voice sample from a conference keynote. The assembly is visible before the attack is.
The four places the current answer runs out
The exposure is personal, not corporate
The leaked account is a private inbox on a home laptop, and it is where the mortgage, the family and the travel plans live. It is entirely outside your estate, and entirely usable against you.
The impersonation is built where you cannot look
Lookalike domains get advertised, executive dossiers get traded and voice samples get swapped in channels that are invite-only, non-English, and closed to the tooling most brand-protection vendors run.
By the time it is public, it has already worked
A takedown request is a response to a live campaign. The registration, the kit purchase and the target research all happened weeks earlier, in venues that were never hiding.
Comms and security find out from different places
The security team sees a domain; the comms team sees a Telegram post; nobody sees the thread that connects them, because the two live in different tools and neither is the record.
How impersonation became infrastructure
The raw material for each era is harvested in the era before it. What is being collected about your executives now is the input to the next line on this rail.
THREAT EVOLUTION
EACH ERA STACKED ON THE LAST
2014-2019
The typosquat
A near-miss domain, a spoofed sender and a wire-transfer request written in workmanlike English. Detectable by a human reading carefully, and often caught by one.
2020-2023
Impersonation at scale
Phishing kits with tenant-aware login pages, lookalike domains registered in bulk, and executive profiles reconstructed from leaked personal accounts. The tell-tale typos are gone, because a kit wrote it.
YOU ARE HERE
2024-2026
Synthetic authority
A cloned voice on a call and a face in a video meeting, backed by real internal detail bought from a stealer log. The fraud is no longer asking you to believe an email; it is asking you to disbelieve your own CFO.
Next
Persistent synthetic identity
Not a single call but a maintained persona: a fake vendor contact with history, a plausible inbox and months of correspondence, built to be trusted long before it asks for anything.
Six plays, and the window each one runs in
Every play names the module that does the work. Nothing here is a capability we describe without shipping.
Watch the thing being built
Executive names, personal domains and brand strings, monitored as full-text queries across forums, marketplaces and leak sites, in every language they surface in, with attachments and screenshots preserved.
DRAGNETThe dossier is advertised where the buyers are
Fullz listings, lookalike-domain adverts and executive dossiers are sold to subscriber channels rather than posted in a forum thread, and often in a language your brand-protection tool does not read. The same name is searchable there as it is on the forums. It is a second query against a second corpus rather than one result, and running it is the difference between reading the advert and never seeing it.
TELEPATHYThe personal account is the way in
When an executive's private credentials surface in a stealer log, you can find it as an incident, with the log's own context and the cookies beside it, rather than as a line in a breach digest six months later.
SHERLOGFind the face wearing the name
Impersonation does not stop at a lookalike domain; it wears a name, a title and a photo on the professional networks your staff trusts. Baitback searches a name, and the same name at your company, and groups the profiles so the handful claiming to work there stand apart from the crowd of genuine namesakes, with the link and photo to report the one nobody recognises.
BAITBACKEvidence that survives deletion
Impersonation posts get pulled the moment they are reported. The archived copy, with its timestamp and screenshot, is what your lawyers, your registrar and your regulator will actually accept.
DRAGNETAnd the signal we do not publish
There is one collection surface that shows attacker attention rather than attacker output: who is researching whom. Its public, anonymized shadow is the Hunt Scene; the rest is a closed briefing.
SOURSAlso searchedJabbernautGuildwire
The call that almost worked
A stealer log surfaces containing an executive assistant's personal Gmail, its cookies, and in the autofill records the travel itinerary for the board offsite.
A lookalike domain for your finance portal is registered and advertised in a fraud channel. On its own it is one of thousands; against the log, it is the second half of a plan.
Nothing correlates them for you. An analyst holding both, the log from one query and the domain from another, writes the brief; comms, security and the CFO read the same one, with both artefacts in it.
The call comes during the offsite, in the CFO's voice, referencing the itinerary. It is refused in nine seconds, because the person answering had read the brief.
The move, stated plainly
No customer logos and no invented percentages: we have not deployed long enough to have honest ones. What we can state is what the workflow becomes.
Brand monitoring watches the clear web
The same query runs in the closed venues, in the languages the material is traded in
Executive exposure is a personal problem
Executive exposure is an incident with an evidence chain and an owner
The post is deleted before legal sees it
The archived copy, timestamped, is in the case file
Brand & executive exposure, honestly answered
The other four
Credential exposure
We do not stop the login. We hold the record that would have made it work, and you can search it today.
Ransomware early warning
The ransom note is the last message in the thread. We read the earlier ones.
Vulnerability triage
Your backlog is sorted by severity. The attacker's is sorted by price.
Fraud & abuse
The chargeback is the symptom. The breach that caused it happened somewhere upstream.
Your competitors will learn about the leak from the invoice.
Learn about it from the log batch.
NDA-friendly briefings · global coverage · no slideware