Generative AI hasn't invented new ways to attack organizations. It has removed the friction from the oldest one: pretending to be someone you trust.
Impersonation has always been a favorite tool for cybercriminals. It is cheaper than building malware, faster than finding a zero-day, and it exploits something every organization depends on to function: trust. What has changed is the economics. AI is making impersonation attacks faster to launch, more convincing, and easier to scale, and the financial toll shows it. The FBI's Internet Crime Complaint Center (IC3) reported $3.046 billion in business email compromise (BEC) losses in 2025 alone, the second-costliest cybercrime category in the U.S. behind investment fraud. Add phishing and government-impersonation losses to that figure and the total tied to attacks that exploit trust in email crosses $4 billion, up 46% year over year.
01 The new math of impersonation risk
For most of the last decade, BEC losses climbed steadily and predictably. Then AI entered the picture at scale, and the curve stopped being predictable.

Business email compromise losses reported annually to the FBI's Internet Crime Complaint Center. Source: FBI IC3 Annual Internet Crime Reports, 2020–2025.
The FBI's 2025 Internet Crime Report introduced an “AI-related fraud” category for the first time in the Bureau's 25-year history, logging more than 22,000 complaints and $893 million in losses tied directly to AI-enabled schemes. Phishing emails increasingly contain AI-generated text, and AI-driven elements, including cloned voices, synthetic video, and AI-written scripts, are becoming a bigger part of business email compromise attempts.
The pattern behind these numbers is consistent: attackers are not inventing new tactics so much as removing the friction from old ones. Domain spoofing, lookalike domains, and compromised supplier accounts, the same tactics that have driven impersonation losses for years, are exactly what AI is now accelerating.
02 How AI is rewriting the attack playbook

A composite pattern based on publicly reported AI-assisted impersonation and BEC incidents.
- GenAI removes the tells. Legacy defenses like spam filters and security-awareness training were built to catch grammatical errors, generic greetings, and clumsy formatting, the fingerprints of an attacker writing in a language or register they don't know well. Generative AI erases those fingerprints. A lure written by a large language model reads like it was written by the person it's impersonating, because in a very real sense, it was trained to.
- Lookalike domains, at industrial scale. Registering a single lookalike domain used to take manual work: finding the right character substitution, checking availability, standing up hosting. Attackers now pair domain-generation algorithms with generative AI to produce and launch hundreds of convincing lookalikes at once, each with AI-written content tailored to the brand or supplier it targets. Because these domains are attacker-owned, they pass SPF, DKIM, and DMARC checks cleanly. Authentication was never designed to catch a domain that isn't yours to begin with.
- Deepfakes close the loop. Text-based impersonation used to be the whole attack. Now it's often just the opener. In one widely reported case , a finance employee at engineering firm Arup joined a video call in early 2024 with people who appeared to be the company's CFO and several colleagues. Every person on that call was an AI-generated deepfake built from public footage. The employee approved 15 transfers totaling roughly $25.6 million before anyone realized the meeting had never been real.
03 Why legacy defenses fall short
Most email security stacks were built to catch malicious payloads: bad links, infected attachments, known-bad senders. Impersonation attacks often contain none of these. A well-crafted BEC email has no link to sandbox and no attachment to scan, just a request, phrased convincingly, from someone the recipient already trusts. And authentication protocols like DMARC, while essential, only protect domains you actually own; they do nothing to stop a lookalike domain an attacker registered themselves, or a legitimate supplier account that has been quietly compromised.
That's the real challenge with impersonation. It isn't one problem with one fix. It's several overlapping problems, spoofed domains, lookalike domains, unauthenticated application email, compromised trusted accounts, that all converge on the same outcome: an attacker borrowing your trust to get someone to act.
04 The case for layered impersonation protection
Meeting that challenge takes a strategy built in layers, not a single control:
Authenticate what you own — Strong DMARC enforcement, backed by SPF and DKIM, closes the door on attackers spoofing your exact domain.
Monitor what you don't own — Continuous lookalike-domain detection catches attacker-registered domains built to imitate your brand, or your suppliers, before they're weaponized at scale.
Watch trusted third parties — Suppliers and partners are attractive targets precisely because your systems already trust them. Visibility into supplier risk and compromised-account behavior closes that blind spot.
Secure what you automate — Application email, transactional messages, and now AI agents sending email autonomously all need the same authentication and policy control as human-sent mail, or they become the easiest domain to abuse.
05 How Proofpoint can help
Proofpoint takes a layered approach to impersonation because the risk itself is layered, spanning the domain, the account, and the message, whether that message was written by a person or generated by a machine.
- Hosted SPF, DKIM, and DMARC services with expert-guided rollout, so you can enforce strong authentication without your team owning the entire DMARC learning curve alone.
- Continuous scanning across hundreds of millions of domains to detect malicious lookalikes targeting your brand or your suppliers, combined with rapid takedown support.
- Extends authentication and policy control to application, transactional, and AI-agent-generated email, so automated messages don't become the gap attackers walk through.
- Behavioral AI and threat intelligence alert you of compromised supplier accounts and hijacked communications and automate actions to keep you protected.
Explore Proofpoint Impersonation Protection or Collaboration Security Prime, which includes Impersonation Protection, to learn more or contact a representative today for a deeper discussion.
Sources: FBI IC3 Annual Internet Crime Reports (2020–2025); FBI IC3 2025 AI-related fraud data; publicly reported deepfake BEC incidents. Statistics current as of publication and subject to change as new reports are released.