Skip to main content
Exposure · Impersonation across surfaces

Finding the impersonators is the easy half. The other half is telling them from your own partners.

ShadowMap watches the surfaces a customer would plausibly mistake for you — social platforms, app stores, executive identity and the marks themselves — and matches what it finds against a model of your real properties. Detection is the commodity. What decides whether brand protection is worth owning is disposition: whether the account trading on your name is an impersonator, a reseller you authorised, or something only you can settle.

Unlimited
Takedowns, subject to fair use
Deepfakes
And cloned voices of named executives, watched where they are published
1,430

Accredited agencies legitimately trading under one brand

One distribution network, where every accredited agency ran its own local pages, its own logo treatment and its own microsite — all of it permitted, most of it encouraged. On the surfaces those agencies appeared on, an authorised partner and an account trading on the brand without permission are indistinguishable. The count is not the achievement. Separating the two is the work this page is about.

What this covers

Impersonation is a surface problem, not a domain problem

A brand gets impersonated wherever a customer might reasonably look for it. That is rarely one place, and it is usually not the place being watched.

The registered-domain layer — permutations, homoglyphs and look-alike registrations caught as they appear in a registration feed — is a discipline of its own, and it lives on Domain Monitoring. This page is about everything that is not a domain string: the LinkedIn page recruiting in your name, the Telegram channel running a support desk you never opened, the store listing shipping your icon, the payment request from someone carrying your CFO’s photograph and something close to their voice. None of those has a WHOIS record or a registration feed behind it. They are found by matching what you actually look like — your marks, your imagery, your site copy, your naming conventions — against what is being published in your name. And once found, most of them are ambiguous until somebody decides whether they are yours.

The hard part

Every match carries a disposition, including the one that is a question for you

Detection produces candidates. A candidate is not a finding until something has decided what it is, and across a network of resellers, franchisees and regional offices part of that decision is genuinely yours to make. We publish the state rather than guessing and calling the guess a detection.

Every match carries a disposition, including the one that is a question for you
StateWhat it meansWhat follows
Impersonation confirmed Trading on your identity with no authorisation — a cloned profile, a store listing reusing your icon and publisher name, a page lifted from your own site. Where a live site is behind it and probing is authorised, the hosted kit is fingerprinted, including known families such as 16Shop and EvilProxy. Evidence pack assembled against whoever controls the listing, ready for you to authorise the filing.
Authorised partner A reseller, agency, franchisee or distributor you have permitted to use the mark. On the surface it looks identical to the row above; the difference is contractual, not technical, and no amount of image matching can see it. Suppressed for your tenant, and the pattern retained so the same agency does not resurface next month as a new candidate.
Unclear — pending your confirmation The signals are genuinely ambiguous. A regional office nobody told marketing about looks exactly like a franchise nobody authorised, and from outside there is no honest way to tell. Held with the evidence attached and one question: is this yours? Your answer becomes part of the signature.
Out of scope Terminal A coincidental name collision in an unrelated sector, editorial coverage, an enthusiast account, or a mark we have no basis to act on for you. Closed with the reason recorded. A queue padded to look busy helps nobody.
Key
  • File for removal
  • Known and permitted
  • Needs your answer
  • Closed, with reason
  • TerminalNo state follows this one

Surfaces

Where the brand is watched, and what is matched there

Each surface fails differently, so each is matched differently — and each has a limit worth stating. The limits sit in the rows, because a boundary declared three sections later is a boundary nobody read.

SurfaceWhat is matchedWhere a confirmed case goes
Social platforms LinkedIn, X, Instagram, Facebook and Telegram. Handle and display-name proximity, profile and cover imagery against your registered marks, and copy lifted verbatim from your own site or job posts. The platform impersonation channel.
Boundary: only what is publicly visible is detectable. A closed group, or an operation that lives entirely in direct messages, leaves no public artefact to match — so it is not covered, and we would rather say that than imply reach we do not have.
App stores Play Store, App Store and third-party or side-load markets. Package and publisher names, icon and screenshot similarity, and listing copy reusing your product descriptions. The store developer-infringement process.
Boundary: side-load markets differ in whether any removal route exists. Where none does, the case still reaches you with the distribution URL and the listing evidence, because your legal team may have a route through the platform that we do not.
Executive identity Named executives: profile spoofs, recruitment and payment lures sent in their name, and synthetic media — deepfake video and cloned voice — published where it can be seen. The platform channel, plus a briefing note written for the named individual.
This is monitoring of an executive digital identity. It is not physical protection, and nothing here should be read as a close-protection or personal-security service.
Marks and imagery Image similarity against your logos and wordmarks, so a visually identical page is caught even when the domain string, the handle and the body copy are all innocent. The host or platform, on a trademark basis.
The cheapest convincing impersonation to build is a pixel-perfect copy published under a name with nothing to do with you — which anything matching on strings alone misses by construction. In the partner network above, 38 of the 47 sites eventually confirmed unauthorised carried the brand name correctly, on ordinary domains. There was no misspelling to catch on any of them.
Customer-facing leaks Branded material naming your customers where it should not be: dump posts, paste sites, and offers using your name as the hook. Host abuse process; the underlying exposure routes to Data Exposure Monitoring.
The overlap is deliberate. One post can be both a brand problem and a data problem, and it is worked once rather than twice in two products.

Social platforms

What is matched
LinkedIn, X, Instagram, Facebook and Telegram. Handle and display-name proximity, profile and cover imagery against your registered marks, and copy lifted verbatim from your own site or job posts.
Where a confirmed case goes
The platform impersonation channel.

Boundary: only what is publicly visible is detectable. A closed group, or an operation that lives entirely in direct messages, leaves no public artefact to match — so it is not covered, and we would rather say that than imply reach we do not have.

App stores

What is matched
Play Store, App Store and third-party or side-load markets. Package and publisher names, icon and screenshot similarity, and listing copy reusing your product descriptions.
Where a confirmed case goes
The store developer-infringement process.

Boundary: side-load markets differ in whether any removal route exists. Where none does, the case still reaches you with the distribution URL and the listing evidence, because your legal team may have a route through the platform that we do not.

Executive identity

What is matched
Named executives: profile spoofs, recruitment and payment lures sent in their name, and synthetic media — deepfake video and cloned voice — published where it can be seen.
Where a confirmed case goes
The platform channel, plus a briefing note written for the named individual.

This is monitoring of an executive digital identity. It is not physical protection, and nothing here should be read as a close-protection or personal-security service.

Marks and imagery

What is matched
Image similarity against your logos and wordmarks, so a visually identical page is caught even when the domain string, the handle and the body copy are all innocent.
Where a confirmed case goes
The host or platform, on a trademark basis.

The cheapest convincing impersonation to build is a pixel-perfect copy published under a name with nothing to do with you — which anything matching on strings alone misses by construction. In the partner network above, 38 of the 47 sites eventually confirmed unauthorised carried the brand name correctly, on ordinary domains. There was no misspelling to catch on any of them.

Customer-facing leaks

What is matched
Branded material naming your customers where it should not be: dump posts, paste sites, and offers using your name as the hook.
Where a confirmed case goes
Host abuse process; the underlying exposure routes to Data Exposure Monitoring.

The overlap is deliberate. One post can be both a brand problem and a data problem, and it is worked once rather than twice in two products.

Executive monitoring

The voice on the call is the newest counterfeit

Executive impersonation used to mean a spoofed profile and a badly written email. It now includes a short video and a passable voice. One incident, read three ways.

Worked example

A payment approval requested by your CFO

What the recipient sees
A message from an account carrying the right photograph, the right title and a plausible set of shared connections, followed by a thirty-second voice note that sounds like the person it claims to be. Nothing about it resembles the examples in the awareness training.
What is actually detectable from outside
The account, mostly: how recently it was created, the gap between claimed tenure and profile history, imagery matched against the executive photographs registered with us, and reuse of the same media across other accounts. Where the video or audio is published somewhere we can reach it, it is examined for the artefacts that generation tends to leave behind.
What we will and will not claim
We will tell you an account is impersonating a named executive, and hand you the media, the account history and where it is being distributed. We will not certify a clip as synthetic on our word alone — generated-media detection is an arms race, and a vendor who tells you it is settled is selling you something. Where the read is inconclusive, it says inconclusive.

How a case is built

From what you actually look like, to what comes down

Each step depends on the one before it. Skip the first and the rest degrades into keyword alerting with your brand name in it.

Sourcing

Where the partner-network figure comes from, and what it is not

The number this page opens on belongs to one customer network, and by now you have been quoted several of these by several vendors. Here is what was counted, who counted it, and what it does not entitle us to say.

The partner-network reconciliation — derivation and exclusions As of August 2026
  • The 1,430 is the size of one group’s accredited-partner register, exported by the group and loaded into their tenant as a tag set. It is their number, not a discovery of ours. What we contributed was matching it against what was actually being published in their name.
  • Every candidate was tested against that register before it reached anyone, so a match arrived either attributed to a named partner or carrying the question of whose it was — never as an undifferentiated impersonation alert.
  • The volume of ownership questions fell as the register filled. Once a partner had been confirmed once, recurring candidates arrived pre-attributed instead of being re-investigated from scratch each cycle.
  • Where the register was incomplete — the sub-agents appointed by agencies themselves, which no head office could enumerate — the finding said so and waited, rather than being resolved either way to keep the queue tidy.

Deliberately excluded

  • Not a benchmark. One network’s shape decides its numbers: how many markets it sells in, how much of the brand it delegates, and whether anyone has ever written the partner list down. Quoting these figures at a different organisation would be inventing a metric with extra steps.
  • No removal time and no success rate. Removal depends on the platform, the evidence it demands and its own queue, and a duration we do not control is not one we will publish as though we did. Response and removal commitments are contractual and belong in your agreement, where they can be read in full.
  • No customer name. A brand-protection record names the impersonated brand by definition, so the engagement is described by its shape — a distribution network with an accredited tier and an unmeasured population of sub-agents beneath it — and never by its logo.

Where this gets sharper

Brand Protection works from one correlated exposure model

Questions buyers actually ask

Before you evaluate this

We already watch look-alike domain registrations. What does this add?

Domain Monitoring covers the registration layer, and it should — that is where permutations and homoglyphs are caught early. This page covers the surfaces with no registration record at all: platform profiles, store listings, executive identity and the marks themselves. The practical difference is image similarity. A convincing impersonation does not need a suspicious domain string; it needs your logo, and it can sit under a name that shares nothing with yours. String matching cannot see that one, and it is the cheapest kind to build.

What do you need from us before this is useful?

Three things, and one of them is the part most vendors skip. Your marks and logo files, so image similarity has something authoritative to compare against. Your named executives and the photographs they actually use, so an executive lure is separable from a stale profile. And your list of authorised partners, resellers, franchisees and regional entities — because the difference between an impersonator and a distributor is contractual, and no external signal reveals it. Where that list is incomplete, matches land in the pending state with the evidence attached instead of being asserted either way.

Our brand is impersonated constantly. Does this just produce another queue to ignore?

That is the correct worry, and it is why disposition sits at the centre of this page rather than detection volume. A confirmed case arrives with the evidence pack already assembled, so what is left for your team is an authorisation, not an investigation. Known partners are suppressed and stay suppressed. Out-of-scope matches are closed with the reason recorded, so the closure is auditable instead of invisible. What reaches a human is the ambiguous set and the confirmed set, and both route into Slack, Jira, ServiceNow or your SIEM with the evidence attached rather than arriving as a weekly PDF.

See who is using your name, and which of them you authorised

One brand, one apex domain, a written snapshot of the impersonations visible from outside. No call required.