Telling impersonation from partner across a 1,430-agency network
Client: An international leisure and corporate travel group selling through roughly 1,430 accredited agency partners across nine markets in the Gulf, South Asia and East Africa · details anonymised
The Challenge
When your partners legitimately use your brand, impersonation is indistinguishable from business as usual
The group's growth model puts its brand on websites it does not own. Accredited agencies build package pages, run paid search on brand terms and open locally named social accounts — all contractually permitted. An impersonator does exactly the same things. The distinguishing fact, whether a contract exists, lived in the commercial channel-management system, was maintained by a different function, and had never been joined to anything the security team could query. Escalation was therefore driven by whoever complained loudest, usually a customer who had already paid a deposit into an account that was not the group's.
The Solution
Classify by intent, filter what is demonstrably benign, and route the ownership question to the only team that can answer it
ShadowMap does not adjudicate ownership, and the programme was designed around that boundary rather than in spite of it. AI Review removed what could be shown to be unrelated. Findings were then sorted by what the group had to do about them, not by severity score. Where the only open question was whether a partner was authorised, the finding was assigned to a named owner in partner governance with an SLA clock, and the answer — authorised or not — was recorded against the finding. Nothing was auto-dismissed, and nothing was silently escalated on the group's behalf.
The Results
Six thousand signals reduced to sixty-three actions, and an auditable decision on every ownership question
Over twelve months the group worked a queue it could actually staff, closed 88 takedowns inside its annual allowance, and gained a defensible answer to the question its insurer, its board and two of its regulators had all asked in different words: how do you police the use of your brand across your channel? The programme also changed the partner contract, which converted a recurring detection cost into a one-time governance change.
Full Case Study
· 6 min readShadowMap does not decide who your partners are. That is the design decision this programme rests on. Findings are classified by what the site is trying to do, not by how closely its domain resembles yours; anything demonstrably unrelated is filtered; and where the only remaining question is is this agency authorised?, that question is routed to the people who hold the contracts, with a named owner, an SLA and a recorded answer. Over twelve months, 6,270 raw brand signals became 63 findings requiring immediate action and 587 authorisation decisions. None of the 587 was dismissed automatically, and none was escalated to a takedown on the group's behalf without a human confirmation first.
That matters because the alternative is a choice between two bad outcomes. A tool that auto-classifies partner activity as legitimate will quietly drop real impersonations that happen to look well-run. A tool that auto-classifies it as suspicious hands the security team a queue it cannot work, and the queue is abandoned within a quarter. The second half of the problem is less obvious: of the 47 sites the group ultimately confirmed were not authorised, 38 carried the brand name correctly on ordinary, unremarkable domains — partner-owned, agency-owned or free hosting. There was no misspelling to catch. A monitor built on string similarity would have reported none of them.
What the security team could not see
The group's commercial model puts its brand on websites it does not own. Accredited agencies build package pages, bid on brand terms in paid search, and open social accounts named for the group in their local market. All of that is permitted by contract, and much of it is encouraged. An impersonator does the same things, using the same logo and quoting the same real itineraries, and takes a deposit at the end.
The one fact that separates them — whether a contract exists — sat in the commercial channel-management system. It was maintained by a different function, on a different renewal cycle, and had never been joined to anything the security team could query. Below the accredited tier sat an unmeasured population of sub-agents appointed by agencies themselves, which the group could not enumerate at all. In practice, escalation was driven by complaints: a customer would call the contact centre having paid a deposit into an account that was not the group's, typically several weeks after the money had moved.
Why what they already owned did not solve it
The group held a domain-monitoring add-on from its registrar and supplemented it with periodic manual sweeps by the marketing team, with legal issuing cease-and-desist letters on request. Three limits made that arrangement unworkable at channel scale.
The registrar service matched on string similarity, so it saw misspellings and nothing else. A page selling group packages under the correct brand name on a partner's own legitimate domain is not a look-alike of anything. Coverage stopped at domain registrations, leaving social accounts, third-party app stores, marketplace listings and paid-search landing pages unwatched. And the weekly output was a list without state — no owner, no verdict, no record that a candidate had already been checked — so the same registrations returned every week and were re-reviewed by someone who had no memory of the previous answer.
What ShadowMap found
Across twelve months, Brand Protection surfaced 6,270 raw signals spanning domains, hosted pages, social accounts, mobile app listings on third-party stores, marketplace listings and paid-search landers, in the group's operating languages.
AI Review moved 4,118 of those to the Filtered by AI queue: unrelated companies sharing a brand token, news coverage, aggregator mentions and the group's own properties. Nothing was deleted. Filtered findings stay fully visible, and an analyst decision overrides the AI verdict rather than the other way round.
The remaining 2,152 were classified by intent — imitates your booking login to harvest customer credentials; takes deposits to accounts that are not yours; agency or sub-agent, confirm authorisation; references your brand and needs your judgement — and then sorted by what the group had to do about them: 63 act now, 587 confirm authorisation, 1,486 monitoring, 16 informational.
The bucket that does the work
The 587 were assigned to partner governance, not to the SOC, through Action Center with an SLA clock. Twelve months later every one carries a decision, a decision-maker and a date.
Four hundred and two were confirmed authorised and moved to Accepted Risk, tagged with the partner ID. A further 121 were authorised but operating outside the group's brand and payment rules — own payment links, superseded pricing, unapproved logo use — and were referred to the commercial team as a contractual matter rather than a security one, recorded as Action Taken. Forty-seven were confirmed unauthorised. Seventeen remained unresolved after two review cycles and were left in Investigating with an ageing clock, reported as open. The report shows what has not been answered rather than closing it for tidiness.
The volume fell as the register filled. The group exported its accredited-partner list and it was loaded as a tag set; by month four, 61% of confirm-authorisation findings arrived pre-attributed to a known partner. Monthly volume in that bucket dropped from 210 in month one to 63 by month six.
What was validated, and what deliberately was not
CART confirmed that 22 of the credential-harvesting pages were live and accepting input, using marked, non-real test credentials to establish that the form posted to a third-party collector rather than to any group system. It went no further: no attempt was made to reach stored submissions, no payment flow was exercised, and no card data of any kind was used. Every request carried an audit identifier so the group could reconcile the validation activity against its own monitoring.
Partner-owned infrastructure was not tested at all. Those are third-party assets outside the group's authorisation, so they were characterised from public responses only and labelled not tested — confirm with the partner. Separately, 14 look-alike domains from an earlier registrar report were confirmed no longer resolving and demoted to informational, with the reasoning retained: the registrations remain held by the same registrant and can be re-pointed at any time.
Correlation also made the queue smaller. Content fingerprinting matched 96 candidate pages to the group's own white-label booking widget, embedded by accredited agents exactly as intended, and de-escalated them. Within the same reporting window, the Docker Containers and Open Databases surfaces returned zero findings, and the report said so.
What changed
Eighty-eight takedown requests were raised over the year, against an unlimited allowance subject to fair use — 57 from the act-now bucket and 31 from partner sites the group confirmed were unauthorised. Six act-now findings went to payment processors and law enforcement instead. Initiation ran well inside the twelve-hour contractual response window; 71 of the 88 were resolved within seven days, nine took between eight and 30 days, five remain open with registrars in uncooperative jurisdictions and are reported as open, and three were dismissed after the host produced evidence of authorisation that the group then verified and accepted. That last figure is worth stating plainly: ownership is genuinely hard, and the audit trail is what allowed the group to reverse its own decision cleanly.
The durable change was contractual. The partner agreement now requires agencies to declare the domains and social handles they use for group business within 30 days of appointment; 1,180 of 1,430 had done so by year end. Deposit-fraud reports reaching the contact centre fell from 31 in the quarter before the programme to nine in its fourth quarter — the group attributes part of that to takedown speed and does not claim it as the only cause.
For the board, the insurer and two regulators asking how brand use is policed across the channel, the group now has a number, a stated method and a decision record on every one of 587 ownership questions, rather than an assurance.
Related to
More Customer Stories
Other teams, similar problems
Zero exposures in the repositories they controlled — and three live credentials in accounts they did not
Hospitality and LeisureNine brands, eleven countries, one advisory: answering “where do we even run this?” in under an hour
Healthcare — hospitals and diagnosticsExternal Estate Reconciliation for a Multi-Country Hospital Group
Ask what ShadowMap would find on your assets.
A 30-minute live walk-through with a ShadowMap engineer on your own domains. We map you live; you keep the report whether or not you choose to engage.