Internal Authority Impersonation
Attackers impersonate executives, IT, or HR personnel to manipulate employees into divulging credentials, transferring funds, or executing unauthorized actions under a false sense of urgency.
Mapped to
MITRE ATT&CK®
Sub-themes
TH0011.1
CXO Impersonation
Attackers pose as high-ranking executives (CEO, CFO, COO) to pressure employees into urgent actions, such as transferring funds or sharing confidential documents.
TH0011.2
IT Impersonation
Adversaries deceive employees into divulging credentials by impersonating IT staff and claiming that urgent security updates require the victim’s password or trick users into entering credentials on fake IT portals. These tactics exploit employees' trust in IT departments and their role in managing access control.
TH0011.3
HR Impersonation
Phishing emails disguised as HR communications trick employees into revealing sensitive personal details, such as Social Security numbers, tax information, or payroll credentials. These attacks may involve performance reviews or urgent requests related to employment benefits.
TH0011.4
Accounting & Finance Impersonation
Attackers pose as finance staff to request invoice payments, payroll changes, or banking updates, exploiting trust in internal financial roles.
TH0011.5
Coworker Impersonation
Attackers pose as peers to request files, credentials or approvals, leveraging users' trust at their coworkers.
TH0011.6
Manager Impersonation
Attackers impersonate supervisors to demand urgent tasks or document access, exploiting both authority, and urgency.