What changed, in one number

Building a convincing clone of a business website used to take an attacker roughly sixteen hours of work. With generative tooling it now takes about five minutes. Everything else about brand impersonation in 2026 follows from that single cost collapse.

When an attack takes two days of effort, attackers select targets worth two days. When it takes five minutes, they stop selecting and start scaling. That is why brand impersonation stopped being a large-enterprise problem and became an ambient one.

The scale, honestly stated

Security researchers identified over 30,000 impersonation domains targeting major global brands in 2024, and quarterly phishing volumes have stayed at historic highs since, exceeding a million attacks in a single quarter. More than half of all browser-based phishing attempts now involve brand impersonation of some kind.

The AI contribution is measurable rather than theoretical. Microsoft's 2025 Digital Defense Report found AI-generated phishing achieving a 54% click rate against 12% for human-written attempts — a four-and-a-half-fold improvement in the thing that actually determines whether an attack works.

One caveat on reading these figures. The headline reports concentrate on the most impersonated brands — Check Point's Q2 2026 analysis put Microsoft at 23% of all brand phishing attempts — because that is what is easy to count. Impersonation of a mid-sized regional business does not appear in any quarterly index. It is undercounted, not uncommon, and its victims are your customers rather than a security vendor's telemetry.

Why smaller brands are attractive targets

Three reasons, none of them flattering.

Nobody is watching. Large brands run monitoring and have takedown relationships with registrars. A twenty-person company usually finds out when a customer forwards a suspicious email, which is typically days late.

Trust is higher and verification is lower. Customers of a small brand often deal with the same two people, and a message that fits that pattern gets less scrutiny than a generic notice from a bank.

The assets are all public. Your logo, photography, typography, tone of voice, team names, and full site copy are published deliberately. A cloning tool needs no privileged access to anything it uses against you.

The variants worth recognising

Impersonation is not only a fake website. The recurring forms are a spoofed domain hosting a copy of your site, a fake social profile using your brand assets, an executive lookalike account contacting your staff or customers, a rogue mobile app, and increasingly a fake customer support presence that intercepts people searching for your help channels.

Homograph attacks deserve specific mention because they defeat careful readers. These substitute Unicode characters that render almost identically to Latin ones, producing a domain that is visually indistinguishable in most fonts while being an entirely different string. Researchers documented a real surge in these in January 2026. Advice to "check the URL carefully" does not defend against them, which is why the technical controls below matter more than customer vigilance.

What to set up before anything happens

All of this is cheap, and all of it is dramatically less useful once an attack is live.

Defensive domain registrations. Register the obvious variants of your primary domain — common misspellings, the hyphenated form, and the main alternative extensions in the markets you sell to. This is a small annual cost that removes the easiest options from an attacker's list. It cannot cover every permutation and is not meant to; it raises the effort floor.

Email authentication, properly configured. SPF, DKIM, and DMARC with an enforcing policy rather than the monitor-only setting most domains are left on. This is the single highest-value control on the list, because it stops mail sent from your actual domain being delivered, and a large share of impersonation attempts rely on exactly that. Many businesses have these records present but set to take no action, which provides reporting and no protection.

Monitoring. Certificate transparency logs and new-domain registration feeds will surface lookalikes within hours. Commercial brand protection platforms package this; for a small business, monitoring certificate transparency for your brand string covers a useful share of cases at no cost.

A prepared takedown pack. Trademark registration numbers, proof of first use, the registrar and host abuse contacts, and a template complaint — assembled in advance and stored somewhere you can reach in a hurry. Preparing this during an incident is what turns a two-day takedown into a two-week one. If your trademark position is unsettled, our guide to checking trademark and domain availability covers the groundwork.

The first twenty-four hours

Order matters here, and the instinct to fix it immediately causes the most common mistake.

Preserve evidence first. Full-page screenshots showing the URL, the WHOIS record, hosting details, and any emails driving traffic to the fake. Registrars reject vague complaints, and the fake will disappear the moment the attacker senses attention. Evidence gathered afterwards does not exist.

Report in parallel, not in sequence. The domain registrar, the hosting provider, and the browser safe-browsing programmes all at once. Safe-browsing listings often produce a visible warning to customers faster than the takedown itself completes, which is the part that limits actual harm.

Tell your customers on channels you own. A short, factual notice on your site and your email list. Describe the real domain and the real contact routes rather than reproducing the fake one. Say what you will never ask for. Customers forgive being targeted; they are less forgiving about learning of it from someone else a week later.

Then check what leaked. If credentials were harvested, the incident is no longer only a brand problem, and any obligations you have under privacy law start running from that point.

The design side nobody mentions

There is a brand-side lever that most security coverage misses. Clones are convincing in proportion to how generic the original is. A site built on a widely used template with stock photography and unremarkable typography is trivially reproducible, because the attacker is not really copying you — they are assembling the same commodity parts.

Distinctive, proprietary work is genuinely harder to fake well. Custom typography, original photography of real people and real premises, motion and interaction that took effort to build, and a consistent voice all raise the cost of a convincing copy and lower the quality of the ones that get made. This is not a security control and should not be sold as one, but it is a real second-order benefit of design investment, and it compounds with the recognition benefits covered in keeping a brand consistent across every surface.

The corollary is worth stating plainly: the cheaper and more generic your digital presence, the cheaper and more convincing its counterfeit.

What this reasonably costs

Defensive domains run to a modest annual figure for a handful of variants. Email authentication is configuration time, not licence cost, and is often a half-day job for someone who has done it before. Free certificate transparency monitoring covers the common cases; commercial brand protection is a recurring subscription that makes sense once you have enough customers that a day of confusion is expensive.

Set against that, the cost of an incident is a takedown process, an unplanned customer communication, and a variable amount of damage to the thing you have spent years building. The asymmetry is stark enough that the preparation is worth doing even at a low estimated probability. Send us your domain and we will tell you which of these you already have and which are missing.