Editorial

5 min read

Brand impersonation during campaigns: why attention attracts imitators

Brand impersonation during campaigns: why attention attracts imitators

Impersonation spikes when brand attention spikes. Learn why campaign launches draw fake accounts, and how to turn detection into evidence and action.

Handles Newsroom Team

Written by

·

Editorial cover

On 10 November 2022, a fake account impersonating Eli Lilly, made to look official with a paid blue-tick verification,  tweeted that insulin was free. The next day the company's shares fell more than 6%, wiping billions from its market value, and Lilly paused its Twitter advertising, as FiercePharma reported. A single fraudulent account, taken for genuine, had moved a listed company in hours.

The incident is extreme, but the mechanism is ordinary: impersonation works by borrowing attention that already exists. That is why it concentrates around campaigns. When a brand spikes interest with a launch, a sponsorship or a sale, it also raises the value of pretending to be that brand, and lowers the effort, because customers are already primed to engage.

Why campaigns attract impersonators

A campaign does three things at once that favour an impersonator. It increases the volume of brand mentions, so a fake account is easier to hide in the noise. It heightens customer intent, so a scam offer or fake checkout link converts more readily. And it compresses time, so a brand has hours, not days, to respond before the moment passes.

For brand, marketing and social teams, the operational point is that the same attention the campaign is designed to create is the attention impersonators exploit. Planning for the upside without planning for the imitators leaves the most valuable window unguarded.

The scale behind this is not marginal. Reported losses to scams that start on social media reached $2.1 billion in 2025, around eight times the 2020 figure, and more than for any other method scammers use to reach people, according to the US Federal Trade Commission. Much of that runs on impersonation: fake profiles and ads dressed in a brand's identity. A campaign is precisely when a brand puts the most recognisable version of that identity into circulation for attackers to copy. The exposure is twofold — customers defrauded in the brand's name, and the trust those customers placed in the brand spent on a fake.

The types of account risk to separate

Not every unofficial account is fraud, and treating them all the same wastes effort during the period when speed matters most. The useful distinctions are impersonation (accounts built to pass as official), misuse (unauthorised use of brand assets that may not be malicious), fan accounts (unofficial but benign) and legacy accounts (old or dormant official-adjacent profiles).

The distinction matters because each type calls for a different response. A fake checkout ad is an enforcement priority; a long-standing fan account may need nothing more than monitoring. Naming the risk clearly, rather than reacting to every unofficial mention, is what keeps a campaign response proportionate.

How to turn detection into action

The aim during a campaign is not to remove all risk, which no programme can promise, but to make the response faster, better evidenced and more consistent. A repeatable cycle helps: monitor, classify, evidence, remediate, review.

Monitoring should run continuously and tighten around campaign dates. A verified account map, a clear record of which accounts are official and who controls them, gives the team a baseline, so new or anomalous accounts stand out against what is known rather than being assessed from scratch each time. Our Radar solution can support this automated risk monitoring and infringement detection, which matters when a campaign generates more mentions than a team can review by hand.

Classification comes next: sorting what monitoring surfaces into impersonation, misuse, fan and legacy accounts, and prioritising by harm. From there, the work is building the evidence each platform needs for review. A strong takedown workflow is organised around that evidence, because platform outcomes depend on policy, ownership and context, not on the assumption of guaranteed removal. Where the right route is reclaiming or consolidating a handle rather than enforcement, a managed Handle Acquisition service can help; where trademark enforcement applies, IP Claims supports the takedown process. Repeat-offender tracking then closes the loop, so the same actors are recognised quickly when the next campaign begins.

Building campaign impersonation into the plan

The aim during a campaign is not to remove all risk, but to make the response faster, better evidenced and more consistent. A repeatable cycle helps: monitor, classify, evidence, remediate, review.

Monitoring should run continuously and tighten around campaign dates. A verified account map, a clear record of which accounts are official and who controls them, gives the team a baseline, so new or anomalous accounts stand out against what is known rather than being assessed from scratch each time. Our Radar solution can support this automated risk monitoring and infringement detection, which matters when a campaign generates more mentions than a team can review by hand.

Classification comes next: sorting what monitoring surfaces into impersonation, misuse, fan and legacy accounts, and prioritising by harm. From there, the work is building the evidence each platform needs for review. A strong takedown workflow is organised around that evidence, because platform outcomes depend on policy, ownership and context, not on the assumption of guaranteed removal. Where the right route is reclaiming or consolidating a handle rather than enforcement, a managed Handle Acquisition service can help; where trademark enforcement applies, our IP Integrity solution supports the takedown process. Repeat-offender tracking then closes the loop, so the same actors are recognised quickly when the next campaign begins.

On 10 November 2022, a fake account impersonating Eli Lilly, made to look official with a paid blue-tick verification,  tweeted that insulin was free. The next day the company's shares fell more than 6%, wiping billions from its market value, and Lilly paused its Twitter advertising, as FiercePharma reported. A single fraudulent account, taken for genuine, had moved a listed company in hours.

The incident is extreme, but the mechanism is ordinary: impersonation works by borrowing attention that already exists. That is why it concentrates around campaigns. When a brand spikes interest with a launch, a sponsorship or a sale, it also raises the value of pretending to be that brand, and lowers the effort, because customers are already primed to engage.

Why campaigns attract impersonators

A campaign does three things at once that favour an impersonator. It increases the volume of brand mentions, so a fake account is easier to hide in the noise. It heightens customer intent, so a scam offer or fake checkout link converts more readily. And it compresses time, so a brand has hours, not days, to respond before the moment passes.

For brand, marketing and social teams, the operational point is that the same attention the campaign is designed to create is the attention impersonators exploit. Planning for the upside without planning for the imitators leaves the most valuable window unguarded.

The scale behind this is not marginal. Reported losses to scams that start on social media reached $2.1 billion in 2025, around eight times the 2020 figure, and more than for any other method scammers use to reach people, according to the US Federal Trade Commission. Much of that runs on impersonation: fake profiles and ads dressed in a brand's identity. A campaign is precisely when a brand puts the most recognisable version of that identity into circulation for attackers to copy. The exposure is twofold — customers defrauded in the brand's name, and the trust those customers placed in the brand spent on a fake.

The types of account risk to separate

Not every unofficial account is fraud, and treating them all the same wastes effort during the period when speed matters most. The useful distinctions are impersonation (accounts built to pass as official), misuse (unauthorised use of brand assets that may not be malicious), fan accounts (unofficial but benign) and legacy accounts (old or dormant official-adjacent profiles).

The distinction matters because each type calls for a different response. A fake checkout ad is an enforcement priority; a long-standing fan account may need nothing more than monitoring. Naming the risk clearly, rather than reacting to every unofficial mention, is what keeps a campaign response proportionate.

How to turn detection into action

The aim during a campaign is not to remove all risk, which no programme can promise, but to make the response faster, better evidenced and more consistent. A repeatable cycle helps: monitor, classify, evidence, remediate, review.

Monitoring should run continuously and tighten around campaign dates. A verified account map, a clear record of which accounts are official and who controls them, gives the team a baseline, so new or anomalous accounts stand out against what is known rather than being assessed from scratch each time. Our Radar solution can support this automated risk monitoring and infringement detection, which matters when a campaign generates more mentions than a team can review by hand.

Classification comes next: sorting what monitoring surfaces into impersonation, misuse, fan and legacy accounts, and prioritising by harm. From there, the work is building the evidence each platform needs for review. A strong takedown workflow is organised around that evidence, because platform outcomes depend on policy, ownership and context, not on the assumption of guaranteed removal. Where the right route is reclaiming or consolidating a handle rather than enforcement, a managed Handle Acquisition service can help; where trademark enforcement applies, IP Claims supports the takedown process. Repeat-offender tracking then closes the loop, so the same actors are recognised quickly when the next campaign begins.

Building campaign impersonation into the plan

The aim during a campaign is not to remove all risk, but to make the response faster, better evidenced and more consistent. A repeatable cycle helps: monitor, classify, evidence, remediate, review.

Monitoring should run continuously and tighten around campaign dates. A verified account map, a clear record of which accounts are official and who controls them, gives the team a baseline, so new or anomalous accounts stand out against what is known rather than being assessed from scratch each time. Our Radar solution can support this automated risk monitoring and infringement detection, which matters when a campaign generates more mentions than a team can review by hand.

Classification comes next: sorting what monitoring surfaces into impersonation, misuse, fan and legacy accounts, and prioritising by harm. From there, the work is building the evidence each platform needs for review. A strong takedown workflow is organised around that evidence, because platform outcomes depend on policy, ownership and context, not on the assumption of guaranteed removal. Where the right route is reclaiming or consolidating a handle rather than enforcement, a managed Handle Acquisition service can help; where trademark enforcement applies, our IP Integrity solution supports the takedown process. Repeat-offender tracking then closes the loop, so the same actors are recognised quickly when the next campaign begins.

© 2026 Handles.ai. All Rights Reserved.