I spend a lot of time trying to get impersonation accounts taken down. At some point, I started wondering how much effort it actually takes to put one up in the first place.
So I picked the CEO of a company and created an X account impersonating that person. I used a Yahoo email address and my phone. From start to finish, it took less than five minutes.
At no point did I have to prove I was the CEO. I wasn’t asked for an ID or any other meaningful verification that I was the person whose name and identity I was using.
I stopped there. I didn’t contact anyone or use the account for anything. The goal was simply to see how much friction existed between deciding to impersonate someone and having the account live.
There wasn’t much.What became more interesting was the contrast. Creating the account was simple. Trying to report an impersonation account was a very different experience.
Creating the account was the easy part
When I went through the process of reporting an impersonation account on X, it was a very different experience. Depending on the circumstances, a reporter may be asked to verify their identity, provide a government-issued ID, complete biometric verification, or show that they’re authorized to act on behalf of the person or company being impersonated. In my testing, I also encountered a limit on how many impersonation reports could be submitted in a day.
Some amount of friction here makes sense. Platforms can’t remove an account every time someone submits a complaint, and the reporting process itself needs to be protected from abuse. But after going through both sides myself, the imbalance was hard to ignore.
I was able to create a fake identity in a few minutes with very little scrutiny. On the other side, much of the burden falls on the person or company being impersonated to prove that the account shouldn’t exist. For a single account, maybe that’s manageable. At the volume we’re seeing today, it becomes a very different problem.
The volume has changed
After I ran the test, I asked our team to pull our X impersonation data. Since October 2021, Bolster AI has identified 17,526 impersonation findings on X. The longer-term trend was already moving upward, but the recent activity stood out.
Our trailing 12-month baseline before June 2026 was about 259 findings per month. In June, we saw 1,300. July came in at 841, followed by another 1,236 in August.
| Period | Findings |
| Previous 12-Month Average | 259 |
| June 2026 | 1,300 |
| July 2026 | 841 |
| August 2026 | 1,236 |
That’s three straight months at more than three times the previous 12-month baseline, with June and August both near five times the baseline. September’s data is incomplete, so the drop at the end of the chart shouldn’t be read as a decline.
I don’t think the important takeaway is simply that “impersonation is increasing.” What’s more interesting is what this kind of volume does to the defender’s side of the equation.
If creating an account takes a few minutes but resolving one requires investigation, evidence, and a platform-specific reporting process, the economics work in the attacker’s favor.
They can afford to lose accounts.
An impersonation account doesn’t need to live very long
We tend to think about takedown as the finish line: find the malicious account, report it, and get it removed.
The attacker doesn’t necessarily care about keeping that account alive for long. If it stays up long enough to contact potential victims, direct someone to another site, or establish enough credibility to move the interaction somewhere else, it may have already done its job.
Removing it afterward is still important, but the attacker can create the next account at very little cost.
That’s why I think time-to-takedown only tells part of the story. The real question is whether defenders can disrupt impersonation at roughly the same speed that attackers can create and replace the accounts they’re using. Right now, those two sides operate under very different constraints.
This is a scale problem, not just a detection problem
Finding impersonation accounts is important, and detection has gotten much better, but finding something doesn’t automatically stop it. Once a fake account is identified, someone still has to review it, determine whether it violates policy, get the right evidence in front of the platform, and follow the case through resolution.
When you’re dealing with one account, that’s a workflow. When you’re dealing with hundreds or thousands, it’s an operational problem.
My experiment took less than five minutes. That’s obviously not the same thing as running a real impersonation campaign, but that’s also why I found it useful. There was nothing particularly sophisticated about what I did.
And that barrier is only getting lower. With AI, threat actors can generate profile images, bios, posts, messages, and other supporting content with less time and effort, making it easier to create convincing accounts and repeat the process at scale.
The attacker doesn’t have to make defending impossible. They just have to make creating the next account cheaper and faster than dealing with the last one.
Attackers can afford to lose accounts. Defenders can’t afford to get behind.