Social Media Impersonation Tops Expected Cyber Threats as AI Reshapes Domain Trust
TechRadar reports social media impersonation and defamation have become the top expected cyber threat over the next three years, while AI makes deepfakes and lookalike domains harder to detect and businesses rethink domain strategy.
The findings, cited by TechRadar, also show employee and executive impersonation, including deepfakes, entering the top five areas of risk for the first time. A senior director of technology for brand protection at CSC said the results point to a wider challenge: criminals still try to compromise systems, but increasingly exploit the trust that legitimate brands have built through their social media presence, customer service accounts, domain names, websites, and leaders' online profiles.
For security leaders, that means the attack surface is no longer limited to infrastructure they own and control. It also includes the public-facing channels where customers, employees, and partners interact with the company every day. A threat may begin with a fake profile, TechRadar reported, but it rarely stays there.
Fake profiles and fraudulent customer service accounts are not new, but they are becoming more common and are being used as entry points for phishing, fraud, counterfeit sales, and broader brand abuse. This is happening while cybersecurity teams are already under pressure. Recent research cited by TechRadar found that 72% of senior technology leaders said the level of cybersecurity threats their organization faced in 2025 was either critical or very critical.
On social media, criminals can reach potential victims where they already engage with brands. Fake accounts can share malicious links, promote fraudulent schemes, spread false information, or pose as legitimate support channels. Attackers may then direct users to a second location, such as a lookalike website, fake login portal, or phishing page, where victims are encouraged to enter account credentials, payment information, or other sensitive data.
A related risk is counterfeiting. Fraudulent social media accounts can impersonate legitimate brands to advertise fake goods and send customers to websites that present counterfeit products as genuine. In both phishing and counterfeiting, criminals use the trust associated with a recognized brand to make the next step of an attack appear credible. Impersonation can also spread false or defamatory claims about a company or its employees, damaging reputation and customer confidence even when no direct financial fraud occurs. TechRadar reported that social media abuse, domain impersonation, and identity-based fraud should be treated as part of the same threat landscape.
AI is making impersonation faster and more convincing. Criminals can use AI tools to imitate a brand's tone of voice, generate convincing customer messages, produce realistic imagery, or create credible fake profiles at speed. Deepfakes, synthetic audio, and AI-generated content can strengthen employee or executive impersonation, particularly when combined with information gathered from multiple sources. For example, an attacker could create a fake executive profile and use AI-generated messages that mimic how that person communicates, making requests or links appear more credible.
AI is only one part of the threat. Attackers also use established techniques to build the infrastructure behind impersonation campaigns. Domain generation algorithms, for instance, can produce large numbers of plausible lookalike web addresses to support phishing and impersonation. Although DGAs are not inherently AI-powered, 86% of respondents in the research cited by TechRadar viewed them as a threat. These domains can be combined with fake social media profiles to create a more convincing digital presence: a fake executive account may point to a fraudulent landing page, and a counterfeit product post may direct customers to a lookalike domain. For customers and employees, the signs of fraud may be subtle, and by the time an impersonation attempt is reported, the campaign may already have moved to another account, page, or domain.
TechRadar also reported how the same pressures are reshaping domain strategy. Launching a business has become easier because AI tools can generate brand names, build websites, create logos, and produce marketing copy in hours. But the same technology makes it easier for cybercriminals to create convincing digital impersonations at scale. TechRadar cited recent allegations by Google that cybercriminals used AI to generate 1.5 million malicious URLs designed to mimic legitimate organizations. As AI lowers the cost of creating convincing websites, businesses face a new challenge: proving they are real.
The conversation around domains is changing. The hardest part of launching a business is no longer getting online; it is establishing a distinctive brand that customers can recognize, trust, and confidently return to. For decades, securing a .com domain was considered the first milestone of establishing an online presence because it was familiar, widely recognized, and trusted. That has not changed, but availability has. According to The Domain Name Industry Brief's latest quarterly report, more than 166 million .com domains are registered with domain registrars. Many short, memorable .com domains are already registered, held defensively, or owned by investors. Businesses launching today may find their ideal domain has long been taken, forcing them to choose longer names, additional words, or unconventional spellings that can make brands harder to remember.
TechRadar reported that this does not signal the decline of .com. Instead, it is encouraging organizations to become more intentional about their online identity. Rather than focusing only on securing a .com address, businesses are evaluating whether their domain reflects their brand, communicates what they do, and supports long-term recognition. Some are exploring domain extensions that better align with their brand, industry, or audience. A technology startup may choose an .ai domain, while an ecommerce retailer might adopt a .store extension. Creative agencies, consultants, and online communities are similarly exploring domain names that better align with their industries and audiences.
Domains have evolved from web addresses into brand assets. A domain shapes the first impression customers have of a business and appears in search results, LLM citations, email addresses, advertisements, social media profiles, and digital marketing campaigns. It is one of the few digital assets a business owns. Businesses invest heavily in building audiences on social media platforms, but those platforms ultimately control the experience; algorithms change, policies evolve, and visibility can change overnight. A domain provides a stable identity that remains under the business's control. A well-chosen domain can communicate something meaningful before a visitor reaches the homepage.
Digital identity is also becoming a competitive advantage. AI has made it easier to imitate legitimate organizations by simplifying the creation of convincing fake websites with professional-looking branding, realistic copy, and cloned user experiences. As a result, businesses face growing pressure to make their digital presence unmistakably authentic. A customer who lands on the wrong website may not have another opportunity to determine which business is genuine. TechRadar reported that business owners should think beyond individual websites and consider their entire domain portfolio, including relevant brand variations, country-specific domains, and campaign domains. Forgotten domains, expired microsites, or unmanaged registrations can create opportunities for phishing, typosquatting, and brand impersonation.
Editor's Summary Social media impersonation and defamation have become the top expected cyber threat businesses face over the next three years, with AI making deepfakes, fake accounts, and lookalike domains harder to detect. At the same time, domain strategy is shifting as companies treat domains as brand and trust assets rather than simple web addresses. The two trends show that protecting digital identity now requires monitoring public-facing channels and domain portfolios as part of cybersecurity.