Customer Support Impersonation Scams Scale Faster Than Your E-Commerce Team Does
When one founder answered every message personally, customers knew whose voice they were reading. At twenty employees and five channels, they usually can't tell anymore — and neither can the scammers copying your tone.
Customer support impersonation scams aren't new. Fake "your package is on hold" texts and fake "verify your order" emails have circulated for years, built to mimic ordinary retail outreach because ordinary retail outreach is what people expect to see in their inbox. What's changed for a growing e-commerce brand isn't the scam. It's how much company the scam now keeps, as the brand's own legitimate messages start arriving from more senders, on more channels, than any one customer can track.
When one founder ran the store, every text, email, and DM came from a single person with a single voice and a single number. A returning customer could usually tell that voice from an impostor's. Once the brand has a support team fielding tickets, a marketing team sending SMS drops, a returns desk processing refunds, and maybe a contracted live-chat vendor covering nights and weekends, that one voice becomes a dozen — each with its own number, its own inbox, its own script. The scam templates and the legitimate messages start arriving in the same format, from numbers the customer has never seen before, phrased almost identically.
Customer support impersonation scams are built to copy what you already send
The messages that succeed as scams are the ones that read like your real messages, because that's what makes them convincing. "Your order has shipped — track it here." "There's an issue with your payment method." "Your refund is ready to claim." "Reply STOP to unsubscribe." A brand doing SMS marketing, transactional order updates, and support outreach at real volume is, by necessity, sending a steady stream of short, urgent-sounding messages from short codes and local-looking numbers. That's precisely the shape scammers reproduce. It isn't limited to SMS and email, either — a growing brand's affiliate program, giveaway promotions, and social media team all generate the same kind of direct, first-name outreach on Instagram and TikTok that impersonators copy just as easily. The larger and more automated a brand's outreach gets, the harder it is for a customer to separate a real automated message from a fake one, because both are designed to look routine.
Growth adds senders faster than it adds ways to tell them apart
A single founder's outreach doesn't scale into an organization's outreach just by getting bigger — it splinters. Support tickets get answered by different agents on different shifts. Marketing sends come from a separate platform with its own number pool. Returns and chargebacks get handled by a specialist who emails from an address the customer has never received mail from before. Seasonal hiring during peak volume adds temporary agents and outsourced contractors who are gone again a few weeks later, right as message volume — and impersonation attempts — peak alongside them. None of this is a problem when it happens inside the company. It becomes a trust problem the moment a customer receives a message from one of these senders and has no way to independently confirm that a real person on the brand's team is actually behind it.
What it costs when customers stop trusting the channel
The cost shows up in ordinary places. Legitimate shipping and refund texts get reported as spam by customers who've been burned before, which can affect deliverability for the whole list. Support replies go unanswered because the customer assumes it's a phishing attempt. Chargebacks get filed against legitimate charges because the customer can't recall authorizing anything from an unfamiliar sender, and the resulting disputes land on the support and finance team to untangle one by one. None of this requires a successful scam to hurt the business — the mere resemblance between a real message and a fake one is enough to make customers hesitate on both, and hesitation on a time-sensitive order or payment message is exactly what a brand can least afford.
Giving every message a name customers can check
The fix isn't asking customers to become better at spotting fraud. It's giving every person who messages a customer on the brand's behalf a way to be checked independently, the same way a solo founder's name and number used to work as a built-in check. A support agent, a marketing sender, or a returns specialist can attach a Human ID to the messages they personally send, and for a specific batch or a specific reply, generate a verification code tied to that exact communication. A customer who's unsure can look the ID or the code up directly, on a page the brand doesn't control, and see who's actually standing behind the message — without the brand having to convince anyone to trust it first. It doesn't claim the message content is accurate, or that no software helped draft it. It answers a narrower, more useful question: is a real, identified person on this team willing to put their name on this specific text?
Before you add the next channel
Every new support platform, SMS vendor, or seasonal hire is one more sender a customer has to learn to trust from scratch. Before adding another one, it's worth asking who on the team is currently unverifiable to the people they're messaging, and whether the brand has any way to prove authorization beyond "we sent it, trust us." Organizations that issue verified IDs to their whole customer-facing team give customers that independent check up front, before the next scam wave makes them suspicious of the real thing too.
Verify your team's communications
Give every person on your team a verifiable identity your clients can check in seconds. Free during beta.
Request organization access