Imagine getting an email from your boss asking for a quick wire transfer, or a "bank" text asking you to confirm your account number. It looks right. It feels urgent. But it's spoofing — an attack where hackers disguise their identity to impersonate a coworker, executive, or trusted business, using classic phishing tools like fake websites, malicious links, and social engineering to make it convincing.
Since attackers are skilled at recreating a brand's look and feel, spotting the specific scam tactic matters less than spotting the facade itself. The strongest clue is usually a mismatch in behavior: a request for information a company or coworker wouldn't normally ask for, sent through a channel they wouldn't normally use. A bank might need certain details, but only through its official website, never by email.
Ahead, we're covering the nine most common spoofing scenarios and the red flags that expose each one.
Coworker Impersonation
Hackers that use this method will gather a lot of personal information about their victims, where they work, and even their coworkers to make their emails so convincing that the target willingly shares information with the hackers.
Since the information in the email all checks out, victims are less likely to double-check the provenance of the email. Like other social engineering attempts, the email address will not have the correct affix, and spelling mistakes might be present.
The best way to counter these attacks is to have users double-check with their coworkers in person or on work platforms like Teams before sharing information.
Fake Invoice
The same way people receive hundreds of emails every day, accounts payable departments in large companies receive hundreds of invoices daily, often from companies they don’t know directly.
These attacks are hard to detect because they’ll often come from the same domain or company name present on the invoice but be for goods or services that were never delivered.
Attacks like these emphasize why it’s crucial to implement a multi-factor authentication (MFA) process for all invoices. One person prepares the invoice, and a second verifies the information on the invoice with the concerned department to ensure the invoice is genuine.
Malicious Extension
One of the sneakiest phishing tactics involves tricking victims into downloading a malicious file, quietly infecting their machine with malware. Attackers pair this with social engineering to make the file look like something completely routine — an invoice, a report, a document you'd expect to see in your inbox.
A classic move is disguising an executable file with an innocent-sounding name like "Q3 Earnings Report," banking on the victim not noticing it's actually a .exe rather than an Excel file. More deceptive versions stack extensions to bury the truth even further, such as Q3EarningsReport.bat.pdf designed to make the file appear safe at a glance.
Train employees to always check the full file extension before downloading anything, and to never open a file type they don't recognize. As a rule, no file from an unknown sender should be downloaded without running it through antivirus scanning first.
Even more advanced attackers skip the fake extension altogether, instead embedding executable code directly inside seemingly harmless files like PDFs. This is exactly why file-scanning software for all incoming company email is essential.
Facial Spoofing
As facial recognition has become the default way to unlock smartphones and laptops — no password required — it's opened the door to a new kind of attack. Hackers have found ways to bypass this convenience using photos, videos, and even 3D renderings of a victim's face to trick the sensor into unlocking a device.
The catch: this attack only works if the hacker has extended physical access to the device itself. That's why a clear, well-enforced policy for lost or stolen hardware is one of the best defenses available. Configuring devices to require a PIN or password after a period of inactivity, rather than relying on facial recognition alone, adds another critical layer of protection.
In most cases, a hacker would need to steal the device first and attempt facial spoofing later. But that gap in time works in your favor: it's usually enough to trigger the inactivity timeout, forcing a PIN entry and rendering the stolen device useless without it.
Fake Fines
Typically combined with vishing or email phishing, hackers present themselves as officials from the city the victim resides in or a collections agency and ask for an immediate fine payment.
The hackers will usually have gathered information on the victim to increase their chances of success. They’ll often know the person’s full name and information like the make and model of their car or license plate. The victim is then pressured to pay the fine over the phone via credit card.
These often work because they sound realistic, and the victim bends under pressure. Remind your users that such fines are always paid via official means such as a bank transfer or a credit card payment on a secure website, never over the phone. If they get pressured for payment, tell them to ask to see the fine in question and for it to be paid securely.
Malicious Social Media Profiles
This attack thrives on the public nature of social media. Hackers create fake company pages or "tech support" accounts, then scan platforms for users publicly venting about issues with a particular service. Posing as that company, they slide into the conversation offering to help and the victim, feeling like they're getting special attention, takes the bait.
From there, the victim either hands over their password directly or enters it into a convincing fake password-reset page controlled by the attacker. What makes this especially dangerous is how closely these fake profiles mirror the real thing — matching bios, branding, and tone almost word for word, making them tough to spot at a glance.
The defense is simple but essential: remind users to never share passwords or account details over social media, and to only reset passwords through official, verified websites, never through a link sent by a "support" account.
Search Engine Phishing
These attacks have only gotten more sophisticated. Where scammers once had to painstakingly build convincing fake storefronts, AI-powered website builders now let them spin up a realistic, fully-functional fake shopping site — complete with generated product images and copy — in as little as 60 seconds. Once live, these sites get pushed into search results through traditional SEO manipulation, black-hat techniques, and increasingly, paid search ads and malvertising designed to outrank or mimic the legitimate brand.
The endgame hasn't changed: these fraudulent "companies" sell products and services that don't exist, prompting victims to enter bank or credit card details at checkout. That financial information is then stolen outright or used to fuel deeper identity theft down the line.
The clearest red flag remains the same as it's always been: legitimate online retailers process payments through recognized, secure processors. If a site skips major platforms like Shopify, Stripe, or PayPal in favor of unfamiliar or informal payment methods, that's a signal to stop and verify before entering any information. Remind users to stick to retailers they know and trust, double-check the URL for subtle misspellings or lookalike domains, and treat unfamiliar search ads for "too good to be true" deals with extra scrutiny
Awareness is Key
Spoofing attacks succeed for one simple reason: people don't realize they're happening until it's too late. The good news? Catching them usually comes down to small, second-long checks —verifying a sender, double-checking a URL, or pausing before entering credentials. The challenge isn't complexity; it's building the habit.
That's where consistent training makes the difference. Running a varied phishing simulation program gives employees hands-on experience recognizing these attacks in a safe environment, rather than learning the hard way. Fortra Security Awareness Training helps organizations build exactly that kind of program, combining realistic simulations with targeted education so employees develop the instincts to spot a spoof before they ever click, reply, or enter information.
Spoofing isn't going away. If anything, it will keep evolving alongside every new platform and communication channel that emerges. But when your users stay alert, your organization's data stays protected.