Brand impersonation is hard to stop: AI makes attacks regenerate like Hydra
a16z Newsletter · rss · 2026-08-26
Brand impersonation is notoriously hard to detect and dismantle because information isn't "lost" and attacks occur off the brand's own platforms. A report by Doppel reveals the scale and challenges of this threat:
Status & Data
- Low Discovery: Brands typically spot less than 10% of impersonations, with 94% catching fewer than half of their impersonators.
- Multi-platform Coordination: Over 80% of brand impersonations occur on at least two channels simultaneously (social media, lookalike domains, mobile apps, ads, etc.). Multi-surface campaigns have grown roughly sevenfold in two years.
Takedown Difficulty
- Rapid Domain Regeneration: About 60% of taken-down malicious domains are pointed at a new scam within 24 hours, and 90% within 90 days.
- Sleeper Domains: Over one-fifth of malicious domains are "aged" domains that sat dormant for years before activation.
- Removal Latency: While 97% of requests eventually succeed, platform response times vary, leading to a long tail of persistent threats.
Conclusion
Traditional one-off takedowns fail to solve the problem. Attackers use AI to rebuild attack vectors cheaply and at scale. Defenders need continuous, cross-surface automated monitoring.
More from Safety
- AVE Project: Creating a Shared Vocabulary for AI Agent Vulnerabilities — SelectionBitter6821 · 2026-08-26
- Recovering encrypted LLM reasoning traces leaks sensitive data — dl_weekly · 2026-08-26
- AI Finds a Way: 26 Stories of AI Outsmarting Humans and Unleashing Creativity — jeffclune · 2026-08-26
- Data Centers and the Open Access Order: Impersonal Regulation vs. Collective Decision — AndyMasley · 2026-08-26
- Employee used personal ChatGPT with client data: Is this common? — Business_Roof786 · 2026-08-26
- Using Codex/Claude risks giving your business ideas to OpenAI/Anthropic — dbasch · 2026-08-26