Threat 05 · Reverse impersonation

Firm impersonation: when your clients receive the fake

A criminal may not impersonate your client to your firm. They may impersonate your firm to the client—borrowing its name, brand and trusted relationship to redirect money, collect documents or capture credentials.

What firm impersonation is

Firm impersonation—sometimes called reverse impersonation—uses a professional organisation's identity against the people who trust it. The contact may appear to come from a lawyer, conveyancer, accountant, broker, property manager or support team.

The imitation can be simple or layered: a copied logo and display name, a one-character domain change, a cloned website, a spoofed phone number, or a call quoting real matter details acquired elsewhere. The client sees familiar context and assumes the firm has authenticated the channel.

The real firm may have no compromised system at all. Public information and a plausible transaction can be enough. But when a mailbox or third-party data source is compromised, private details can make the approach exceptionally convincing.

The reverse angle

Your control boundary extends beyond calls coming in. Clients need a reliable way to test communications that claim to come out of your firm.

How the impersonation kill chain works

The attacker turns the firm's accumulated trust into a shortcut around the client's caution.

  1. 01

    Map the firm and client

    The attacker collects staff names, branding, domains, service language, public matters and transaction clues. Separate data theft may reveal private context.

  2. 02

    Clone the trusted identity

    A lookalike email domain, spoofed display name, copied website, false social profile or call from “the office” presents the firm's familiar face.

  3. 03

    Approach the client

    The impersonator quotes convincing details and introduces a payment, document, credential or verification request at a plausible moment.

  4. 04

    Exploit the relationship

    Urgency and the client's trust in the firm suppress independent checks. The client acts, and the criminal disappears while the firm's name remains attached.

The Australian context

Impersonation sits across scam categories rather than inside one neat total. The National Anti-Scam Centre's Targeting Scams 2025 report records 481,523 reports across participating Australian organisations and $2.18 billion in reported losses in 2025. Payment redirection was among the highest-loss categories, and impersonated organisations and people can be the vehicle for those instructions.

Those combined figures are not a count of professional-firm impersonation and should not be presented that way. They provide honest scale for the surrounding environment. A firm's own exposure depends on its public footprint, client base, transaction patterns and the clarity of its communication controls.

Scamwatch advises people to stop, check and protect: do not act immediately on an unexpected contact; independently verify who is contacting you; and act quickly if information or money has been exposed. Firms can turn that consumer advice into a client experience established before an attack.

Why firms are ideal targets

Trusted relationship. Clients hire professionals to navigate unfamiliar, consequential work. A message carrying the firm's identity starts with credibility that an unknown criminal would not have.

Real transactions. Money and documents legitimately move through legal matters, property, accounting, finance and other professional services. The attacker can imitate an action the client already expects.

Time pressure. Settlements, deposits, tax dates and commercial deadlines create reasons to act quickly. An impersonator uses the real timetable—or invents one—to make verification feel like delay.

Visible expertise. Websites, staff profiles, publications and public records reveal language, roles and relationships. Marketing that helps genuine clients can also help a criminal construct the pretext.

The firm can be harmed without being breached

The client experiences the fraud under the firm's name. Even if every internal system was secure, the first emotional conclusion may be that the firm failed to protect the relationship. Explaining the technical boundary after the loss does not immediately restore trust.

Reputational harm can include client anxiety, public complaints, review activity, media attention and questions from counterparties or insurers. Staff time shifts to warnings, evidence, takedowns and support. Future genuine messages may be treated with suspicion.

A clear pre-incident policy changes the conversation. The firm can point to instructions given at engagement, the channels it committed to use and the verification path available to the client. That does not erase harm or decide legal responsibility, but it creates a practical basis for prevention and response.

Proactive countermeasures

Control 01

Educate at engagement

Give every client a short “we will never…” notice before sensitive work begins. State how the firm sends payment changes, requests documents and verifies identity; tell clients exactly how to report a message that breaks the pattern.

Control 02

Publish a verified-communications policy

Commit to specific domains, numbers, sender names and procedures. Keep the policy simple enough to remember and repeat it before predictable high-risk moments such as settlement or a large transfer.

Control 03

Use mutual verification

Let staff verify clients and let clients verify the firm. A control is stronger when either party can stop an unexpected request and return to a trusted identity record.

Control 04

Prepare the response

Monitor lookalike domains and reports, preserve evidence, warn affected clients through trusted channels, seek takedown assistance and coordinate legal, insurer, bank and ReportCyber responses where appropriate.

What the “we will never…” notice should say

At engagement, tell clients what the firm will never request by an unverified message. Examples may include: “We will never change payment details only by email,” “We will never ask you to read us a password or banking security code,” and “We will never object if you pause and call our published number.” Tailor the promises to controls the firm can consistently keep.

The notice should also explain the positive process. Name the official domains and phone number, identify who may issue payment instructions, state how a change is verified and give a simple reporting path. Repeat the warning before high-risk transactions instead of assuming the engagement document will be remembered months later.

No client-facing one-page template exists in this repository yet, so this page describes the content rather than linking to an unbuilt download. The firm should have legal, risk and operational owners review its version before distribution.

Mutual verification with Vericode

Verification should work in both directions. Staff need to establish that a caller or sender is the expected client. Clients also need a recognisable, trustworthy way to establish that a verification request genuinely comes from Vericode on behalf of the firm.

Vericode sends the possession challenge to the verified phone number held for the real person. Its ACMA-registered VERICODE sender ID makes Vericode's own SMS channel spoofing-resistant. The claim is deliberately narrow: registration strengthens the authenticity of that sender identity; it does not make every message or every wider communication channel immune to fraud.

A code goes to the real person's actual phone, not to the impersonator's lookalike email, cloned website or incoming call. The firm can then tie the result to the sensitive interaction instead of relying on brand familiarity alone.

Firm impersonation red flags

  • A firm contact unexpectedly uses a new domain, number, account or message channel.
  • The message changes payment details or asks for credentials, codes or sensitive documents.
  • The sender quotes real matter details but resists the agreed verification process.
  • A website or email address contains subtle spelling, punctuation or domain differences.
  • The caller creates urgency, secrecy or a reason the usual staff member cannot be contacted.
  • The client is told to ignore earlier written communication or established payment warnings.
  • A message claims to be from the firm but does not follow its stated communication pattern.
General information only. This guide is not legal, reputation-management or incident-response advice. Follow your firm's plan and seek professional advice for an actual impersonation event.

Dedicated vertical pages, a client one-page template and a “Why did I get this code?” page are planned but do not yet exist, so this guide does not create misleading links to them.