When a customer has a problem with a product or service, they might start by calling a phone number, using a helpdesk portal, or visiting a brand’s official website. But just as often they go where they already are, posting messages on Instagram, TikTok, X, Facebook, or Reddit.
By posting a public complaint and tagging the brand or support handle, they expect speed and a human response.
Cybercriminals understand that expectation just as well as brands do.
As social platforms become customer service channels, impersonation is becoming a customer experience problem, and a security threat.
The same channels brands use to deliver convenient customer experiences are increasingly being exploited by fraudsters impersonating customer support teams, executives and trusted brands. What begins as a customer service interaction can quickly become a sophisticated social engineering attack, with victims persuaded to hand over sensitive information.
Fake support accounts, spoofed brand profiles, cloned executives, lookalike handles, AI-written scam replies and fraudulent “customer care” pages are exploiting the moment when customers are particularly vulnerable—when they are frustrated, seeking help and inclined to trust whoever appears to be solving their problem.
Fraud Starts Long Before Payment
A white paper on authorized push payment (APP) fraud by the Payments Association in the U.K. illustrates the shift in the attack surface, as 66 percent of reported APP fraud cases in the first half of 2025 began on online platforms, including social media and messaging services, while 17 percent originated via telecoms channels.
The report argues that fraud frequently begins well before a payment is initiated, often through interactions on social media, messaging apps or online marketplaces. By the time a scammer requests payment details or credentials, victims often believe they are communicating with a legitimate organization.
The Payments Association notes that reimbursement rules and banking controls only address the final stage of the fraud lifecycle. The initial compromise typically occurs elsewhere, placing greater responsibility on digital platforms, social networks and organizations whose brands are being impersonated.
AI Is Accelerating Impersonation
Impersonation scams are not new, but GenAI has fundamentally changed their speed, scale, and realism.
Vyntra's 2026 Anatomy of Modern Banking Fraud report describes today's environment as one of "industrialized AI," where fraudsters combine automation, hyper-personalization, and real-time monetization to operate at unprecedented scale. Global scam losses reached an estimated $442BN over the past year, while 70 percent of adults experienced at least one scam attempt and almost one in four lost money.
The report also indicates that AI has reduced the time criminals need to produce convincing phishing campaigns from more than 16 hours to less than five minutes, enabling them to generate highly personalized messages, cloned identities, deepfake videos and spoofed communications that they can proliferate widely.
This creates a significant challenge for customer experience teams, as cybercriminals no longer rely on poorly written messages or obviously fake accounts. They can reproduce a brand's tone of voice, customer service language, visual identity and even the communication style of individual executives with a high level of accuracy.
"Our daily digital habits are no longer as safe as we expected them to be," Darius Belejevas, CEO of Incogni, told CX Today.
"We see data breaches occurring at an alarming rate and with significant impact, which understandably makes respondents feel that their personal data is almost inevitably going to be exposed at some point. If a user's data is breached elsewhere, scammers can easily triangulate it with what that person shares on social media and use it to spearhead more convincing AI-powered attacks."
Belejevas pointed to US Federal Trade Commission data showing that losses from social media scams have increased sharply since 2020, with consumers reporting $2.1BN in losses during 2025 alone. "Social media has become a honey pot for scammers," Belejevas said.
Customer Trust Is the Newest Attack Surface
The Payments Association concludes that APP fraud can no longer be viewed solely as a banking problem because the customer journey typically begins elsewhere.
The same observation applies to customer experience. Every public customer complaint represents an opportunity for either a genuine service recovery or a fraudster posing as the brand.
Organizations should view privacy as a strategic trust issue rather than simply a regulatory obligation, Belejevas said. "Users have every right to be concerned about how their data is handled by Big Tech and by the brands they interact with online."
"The fact that more than half of respondents say privacy or security risks could push them to delete their social media accounts should be a clear warning: Privacy has moved beyond compliance. It is now central to the trust users place in platforms, brands and the AI-powered experiences they are asked to engage with."
As organizations expand customer service across social and messaging platforms, delivering fast responses is only part of the challenge.
Protecting customers from convincing impersonation has become equally important. In an era of AI-generated identities, cloned brand voices and increasingly sophisticated social engineering, customer trust has become one of the most valuable—and vulnerable—assets a business possesses.




