Impersonation scams are among the most common forms of fraud, and they are getting harder to spot. The premise is simple: a criminal pretends to be someone you trust — your bank, a well-known company, a delivery firm, even a family member — to persuade you to hand over money or personal information. Knowing how these scams work, and the handful of habits that defeat most of them, is the best protection you have. This is general information, not security or financial advice.
What an impersonation scam is
An impersonation scam is a fraud in which someone disguises themselves as a trusted person or organisation to trick you into acting against your own interests — usually sending money, sharing login details, or installing something harmful.
The disguise can be remarkably convincing. Scammers copy logos, spoof phone numbers so a call appears to come from a real company, and clone websites down to the small print. Because the appearance is so polished, the safest mindset is to focus not on how genuine something looks, but on what it is asking you to do.
Impersonation scams reach you through several channels:
- Phishing — scam emails.
- Smishing — scam text messages.
- Vishing — scam phone calls.
- Fake websites and adverts — pages designed to look like a real brand.
- Social media and messaging — including the "hi mum/dad" scam, where a fraudster poses as a relative.
The channel changes; the playbook does not.
The warning signs
Most impersonation scams share the same handful of tells. If you learn to spot these, you will catch the great majority.

The golden rule: a genuine organisation will never mind you stopping to check. A scammer needs you to act before you think.
- Urgency and pressure. "Your account will be closed," "act within the hour," "your payment failed." Manufactured panic is designed to stop you pausing.
- Unexpected contact. A message or call you were not expecting, especially about money, deserves extra suspicion.
- Requests for codes, passwords or PINs. No legitimate bank or company will ask you to share a one-time passcode, full password or PIN. This request is almost always a scam.
- Links that ask you to "log in" or "verify". A link in a message can lead to a convincing fake. Type the address yourself instead.
- Requests to move money "to keep it safe". Banks do not ask you to transfer funds to a "safe account." This is a well-known scam.
- Odd payment methods. Demands for gift cards, cryptocurrency or unusual transfers are red flags.
- Small inconsistencies. Slightly wrong web addresses, odd phrasing or a sender address that does not match the brand.
How to verify a contact
The single most powerful habit is to verify independently. Whenever a message or call asks you to do something, assume the contact details it gives you might be fake.
To check whether something is genuine:
- Find the contact details yourself. Use the number on the back of your bank card, on a statement, or on the organisation's official website you navigate to directly — not a link or number from the suspicious message.
- Call back on a trusted line, and if you have just had a "bank" call, wait a few minutes or use a different phone if you can, in case the line is still held open.
- Ask the organisation to confirm whether they contacted you and whether the request is real. A legitimate firm will be happy to.
- Check official guidance. Many companies publish advice on how they will and will not contact you, which makes spotting fakes easier. UK lender Credicorp, for example, explains how to stay safe from impersonation and confirm a contact is genuinely from them — the kind of "here is how we will really get in touch" guidance worth reading for any company you deal with.
Slowing down to verify costs a minute. Falling for an impersonation scam can cost far more.
How to protect yourself day to day
Beyond verifying individual contacts, a few standing habits make you a harder target.
| Habit | Why it helps |
|---|---|
| Use strong, unique passwords | One leaked password cannot unlock everything |
| Turn on two-factor authentication | Stops criminals logging in with a password alone |
| Keep devices and apps updated | Closes security holes scammers exploit |
| Never share one-time codes | These are the keys to your accounts |
| Pause before acting on urgency | Defeats the core scammer tactic |
Two of these deserve emphasis. Two-factor authentication adds a second step to logging in, so even a stolen password is not enough — it is one of the most effective protections available; the broader principles are covered in our guide to identity verification and how companies confirm it's really you. And never sharing one-time passcodes matters because those codes are exactly what a scammer needs; a request to read one out is a request to hand over your account.
It also helps to understand why organisations sometimes verify your identity or record calls — legitimate security steps that scammers try to imitate. Our explainers on why companies record calls and on spotting loan scams cover related ground.
How to report a scam
Reporting fraud helps you and helps others, because it feeds the intelligence used to shut scams down. If you have been targeted — whether or not you lost money:
- If money or card details are involved, contact your bank immediately. Speed matters; banks have processes for suspected fraud.
- Change exposed passwords and turn on two-factor authentication where you have not already.
- Report it to Action Fraud (the UK's national reporting centre for fraud and cybercrime; in Scotland, report to Police Scotland on 101).
- Forward suspicious messages. Suspicious texts can be forwarded to 7726 (free), and suspicious emails can be reported to the National Cyber Security Centre's reporting service.
If you have lost money, do not be embarrassed — these scams are designed by professionals to deceive. Citizens Advice can help with next steps, and your bank should investigate.
The bottom line
Impersonation scams succeed by looking trustworthy and creating urgency, whether they arrive as a phishing email, a smishing text or a spoofed call. The defences are simple and reliable: be suspicious of unexpected contact, never share passwords or one-time codes, and always verify a request using contact details you find yourself rather than ones a message hands you. Add strong passwords and two-factor authentication, report anything suspicious to Action Fraud, and you take away almost everything these scams rely on.
Frequently asked questions
What is an impersonation scam?
It is a fraud in which a criminal pretends to be a trusted organisation or person, such as your bank, a delivery company or a family member, to trick you into sending money or revealing personal details. This is general information, not advice.
What is the difference between phishing and smishing?
Phishing usually refers to scam emails, while smishing refers to scam text messages. Both try to get you to click a link, enter details or call a number. The tactics are the same; only the channel differs.
How can I check whether a message is genuine?
Do not use the contact details in the message. Instead, contact the organisation using a number or website you find independently, such as on a statement or the back of your bank card, and ask them to confirm.
What should I do if I think I have been scammed?
Contact your bank immediately if money or card details are involved, change any exposed passwords, and report it to Action Fraud (or Police Scotland in Scotland). Acting quickly improves the chance of help.
Join in — free. Comments on Daily Junction are for members, so real names stay rare and bots stay out.
One field. We email you a 6-digit code — no password needed. Your comment is kept while you do it.
Under 13? You’ll need a parent’s OK first — it takes them one click.