Latest News

Brand Impersonation in AdTech: How Trusted Brands Are Exploited

s

When Trusted Brands Become Targets: Brand Impersonation in AdTech

A recognisable brand name carries real value in advertising. It signals quality to consumers, credibility to job seekers, and reliability to other businesses in the supply chain.

That same value can make a trusted name attractive to people looking to impersonate it.

Across advertising and AdTech, impersonation can take several forms: fake job offers, fraudulent social media accounts, phishing emails, lookalike websites, spoofed publisher domains and communications that appear to come from legitimate companies.

The underlying tactic is simple: borrow an identity people already recognise and trust.

This does not mean the companies being impersonated are responsible for the activity. In many cases, they are themselves targets of fraud and spend significant effort warning customers, candidates and partners about it.

This article looks at the different forms brand impersonation can take across advertising and AdTech, the broader costs associated with digital fraud, and the verification practices being used to reduce exposure.

What Brand Impersonation Looks Like in Advertising and AdTech

Brand impersonation is not limited to a fake logo or a copied website. In an industry that connects advertisers, publishers, platforms, employees and consumers across digital channels, it can appear in several different ways.

Recruiter and job impersonation

Scammers can pose as recruiters or employees of legitimate companies to run fake hiring processes, often using company names, logos and job descriptions taken from real organisations.

This is increasingly relevant as fraudulent recruiters can use polished emails, professional-looking profiles and AI-generated content to make an opportunity appear genuine.

The same pattern is explored in greater detail in a companion article on AI-enabled job scams in AdTech: a familiar company name is used to reduce suspicion before the target is asked to take the next step.

Publisher and domain spoofing in programmatic advertising

This is a different form of identity misrepresentation, specific to how digital advertising inventory is bought and sold.

In a programmatic auction, a fraudulent or low-quality website can misrepresent the domain associated with an ad impression, making inventory appear to come from a legitimate publisher.

Because programmatic buying operates at considerable scale and speed, manual verification of every transaction is impractical. Automated verification, authorised-seller records and supply-chain transparency therefore play an important role in identifying questionable inventory.

One of the clearest documented examples is the Methbot and 3ve ad fraud cases investigated by the U.S. Department of Justice. The schemes allegedly spoofed thousands of domains and generated fabricated advertising activity designed to make advertisers believe they were reaching genuine audiences on legitimate websites.

Fake social media accounts impersonating a brand

Fraudulent accounts can copy a company’s name, logo and visual identity to appear legitimate.

These accounts may be used to promote fake giveaways, fraudulent offers, investment schemes, fake jobs or phishing links.

For someone encountering the account for the first time, the visual similarity can create enough familiarity to encourage engagement before the account’s authenticity is checked.

Spoofed customer and partner communications

Fake emails, messages and lookalike websites can imitate a company’s branding and communication style to target customers, partners or suppliers.

The objective may be to collect login credentials, personal information, payments or other sensitive data.

The message does not need to be technically sophisticated if the recipient already recognises and trusts the company name.

Counterfeit or fraudulent advertising using real brand assets

Fraudulent advertisers can also copy legitimate brand creative, logos or messaging and use them to promote unrelated products or services.

Here, the brand itself may have nothing to do with the advertisement. Its identity is simply being borrowed to create credibility.

Why These Scams Can Scale

Several characteristics of today’s digital advertising ecosystem can make impersonation harder to detect at scale.

Programmatic advertising operates at high speed

Programmatic advertising is designed to make buying and selling digital inventory more efficient. Campaigns can reach large numbers of websites, with buying decisions taking place automatically in milliseconds.

That efficiency also means that manually checking every transaction is unrealistic. Automated standards and verification systems become essential when activity happens at this scale.

Digital-first communication is now normal

Recruitment, sales conversations, customer support and business partnerships can all begin digitally.

An introductory message may arrive through email, LinkedIn or another messaging platform without an initial face-to-face interaction.

That is convenient for legitimate businesses, but it can also give impersonators more opportunities to create a convincing first interaction.

Generative AI lowers the effort required to create convincing material

Generative AI can produce polished text, images, profiles, documents and outreach messages quickly.

It does not create the underlying scam technique, but it can make fraudulent material easier to produce and customise at scale.

For a target, this means that spelling mistakes, awkward copy and obviously poor graphics are no longer reliable indicators on their own.

The industry depends on trust between parties

An advertiser trusts that inventory information accurately represents where an ad will run. A job seeker trusts that a recruiter claiming to represent a company is genuine. A customer trusts that a message carrying a familiar logo actually came from the brand.

Impersonation works by exploiting that assumption.

The answer is not to distrust every digital interaction. It is to build independent verification into important decisions.

Real Brands, Real Impersonation Warnings

It is important to be precise here. In the examples below, the companies are the parties whose identities have been used or imitated. They are not being presented as responsible for the fraudulent activity.

The Trade Desk

The Trade Desk publishes guidance for candidates about recruiting fraud. Its guidance states that the company will never request payment in exchange for employment or provide pre-hire compensation through a check or money order. It also advises candidates to verify that recruiter communications originate from an official @thetradedesk.com address.

The warning illustrates a broader point: even established technology companies can have their names used to make fraudulent recruitment approaches appear credible.

Xapads

Xapads addresses recruitment fraud directly on its careers page, advising candidates to use its official Careers page and verified @xapads.com email addresses when evaluating recruitment opportunities.

The company also states that it does not ask candidates to make payments or pay recruitment fees.

These precautions reflect a wider industry issue rather than an issue unique to any individual company.

Criteo

Criteo maintains guidance on phishing campaigns that impersonate the company. Its published examples include fraudulent recruitment communications, fake urgency and outreach through channels such as Telegram, Signal, Teams and personal email accounts.

The guidance highlights an important verification principle: a professional-looking communication is not sufficient evidence that the sender is legitimate.

AppLovin

AppLovin has also published recruitment-fraud warnings, including alerts about fake app-optimisation roles and fraudulent approaches made through platforms such as WhatsApp and Telegram.

Its guidance directs candidates toward the company’s official careers channels and warns against requests for payments or suspicious downloads.

Taken together, these examples show that brand impersonation can affect companies across different parts of the advertising and technology ecosystem.

The Broader Cost of Digital Impersonation and Ad Fraud

There is no single figure that captures the financial cost of brand impersonation across AdTech. Different forms of fraud are measured separately, and the available datasets use different definitions and methodologies.

The broader data nevertheless shows why verification matters.

Impersonation scams are becoming more costly

The U.S. Federal Trade Commission’s analysis of 2023 data recorded more than 330,000 reports of business impersonation and nearly 160,000 reports of government impersonation. Combined reported losses exceeded $1.1 billion, compared with $310 million reported in 2020.

The FTC also reported that impersonation complaints overall had increased roughly fivefold since 2020.

These figures cover impersonation scams broadly, rather than AdTech specifically, but they demonstrate the scale of the wider problem.

Programmatic inefficiency adds another layer

The Association of National Advertisers’ 2023 Programmatic Media Supply Chain Transparency Study found that only around 36 cents of every dollar entering a demand-side platform effectively reached the consumer.

The study identified transaction costs, non-viewable inventory, invalid traffic, non-measurable inventory and made-for-advertising sites among the factors affecting media efficiency, and estimated a potential $22 billion efficiency opportunity for marketers.

Importantly, this is not a measure of brand impersonation. It reflects broader challenges in programmatic transparency and media supply-chain efficiency.

The distinction matters because not every inefficient or fraudulent ad transaction involves a brand being impersonated.

Anti-fraud efforts are producing measurable savings

There is also a significant countertrend: the industry has invested heavily in fraud detection, verification and transparency.

The Trustworthy Accountability Group’s 2024 U.S. Ad Fraud Savings Report estimated that cross-industry anti-fraud efforts saved advertisers approximately $10.8 billion in U.S. display and video advertising in 2023.

The report estimated that these measures reduced invalid-traffic-related losses by around 92% compared with what losses would have been without those protections, while still estimating approximately $979 million in remaining fraud losses.

TAG’s 2025 analysis also reported continued progress in Europe, including an estimated €3.45 billion in ad fraud savings.

The takeaway is not that fraud has disappeared. It is that coordinated standards, verification and shared intelligence can materially reduce its impact.

How the Industry Is Building Defences

Several established practices help advertisers, publishers and platforms verify the identity of participants in the digital advertising supply chain.

Ads.txt

Ads.txt allows publishers to publicly declare which companies are authorised to sell their digital advertising inventory.

Buyers can use this information to compare the seller identified in an advertising transaction with the publisher’s authorised seller list.

A mismatch does not automatically prove fraud, but it can indicate that the inventory or supply path requires further investigation.

Sellers.json

Sellers.json provides buyers with information about the organisations participating in the selling of advertising inventory.

It helps buyers understand who is actually selling or reselling inventory rather than relying solely on the domain associated with an impression.

SupplyChain object

The SupplyChain object provides information about the entities involved in the transaction path of a programmatic impression.

Together, these standards provide greater visibility into who is authorised to sell inventory and which intermediaries are involved.

Shared industry intelligence

Individual companies can publish fraud warnings and security guidance, but industry-wide collaboration can identify patterns that may cross company boundaries.

Organisations such as the Trustworthy Accountability Group facilitate collaboration and shared anti-fraud initiatives across the advertising ecosystem.

That matters because an impersonation attempt rarely respects organisational boundaries.

How Individuals and Businesses Can Verify What’s Real

The most useful defence is often surprisingly simple: verify through a channel the person contacting you does not control.

For job seekers

  • Go directly to the company’s official careers page rather than relying on a link sent by a recruiter.
  • Check whether the recruiter’s email address matches the company’s official domain.
  • Search for the recruiter’s employment history independently rather than relying only on the profile provided.
  • Be cautious if the entire hiring process is pushed onto WhatsApp, Telegram or another messaging platform while the sender avoids official company channels.
  • Never pay a recruitment fee, equipment deposit or training charge simply to secure a job.
  • Do not share financial or identity information merely because someone claiming to be a recruiter requests it. Verify the employer, role and recruiter first, then provide information through the legitimate hiring or onboarding process.
  • Be particularly cautious when a message creates artificial urgency or asks you to act before you have independently verified the opportunity.

For advertisers

  • Work with authorised and well-vetted sellers where possible.
  • Check publisher and seller relationships using ads.txt and sellers.json.
  • Review the SupplyChain information associated with programmatic transactions.
  • Use independent verification and fraud-detection tools where appropriate.
  • Be cautious about inventory that appears inconsistent with the publisher, audience or supply path being presented.

For publishers and partners

  • Monitor for unauthorised use of your domain, logo, creative assets and company identity.
  • Maintain accurate authorised-seller information.
  • Publish clear fraud or impersonation warnings when fraudulent activity is identified.
  • Give customers, candidates and partners a reliable way to verify suspicious communications.

For consumers and social media users

  • Check the account’s history, established contact details and previous posts.
  • Treat platform verification indicators as one signal, not proof of authenticity.
  • Avoid clicking unsolicited links simply because they use a familiar logo or brand name.
  • Go directly to the company’s official website when you need to confirm a promotion, customer-service request or offer.
  • Report suspected impersonation to the relevant platform.

What to Do If Something Doesn’t Look Right

If you suspect that a communication or opportunity is fraudulent, stop engaging until you can verify it.

Do not send additional information or payments. Save relevant messages, email addresses, profile links, payment details and screenshots.

Then contact the organisation through an independently sourced official channel and report the suspicious account or communication to the relevant platform or authorities where appropriate.

The most important step is to avoid allowing the urgency of the message to dictate the verification process.

A legitimate opportunity can withstand a verification check.

The Bigger Picture

Brand impersonation in advertising and AdTech is not one single problem. It includes fake recruiters, fraudulent social accounts, phishing communications, publisher and domain spoofing, and other forms of digital identity misuse.

The techniques may differ, but the underlying mechanism is similar: a recognisable identity is used to create confidence before the target has independently verified the interaction.

Documented cases involving companies such as The Trade Desk, Xapads, Criteo and AppLovin show that trusted brands themselves can become targets. The Methbot and 3ve cases demonstrate how identity and inventory misrepresentation can operate at programmatic scale. Broader data from the FTC, ANA and TAG shows both the financial significance of digital fraud and the measurable impact of industry countermeasures.

The presence of impersonation does not mean that a job offer, ad placement or business communication is automatically suspicious. The useful question is whether the identity and transaction can be independently verified.

For a job seeker, that may mean checking a careers page.

For an advertiser, it may mean validating sellers and supply paths.

For a consumer, it may mean going directly to a company’s website rather than following an unsolicited link.

A familiar name can create trust. Verification is what should confirm it.

 

Comments

TechBullion

FinTech News and Information

Copyright © 2026 TechBullion. All Rights Reserved.

To Top

Pin It on Pinterest

Share This