Online Seller Impersonation Scams Hit Hardest at a One-Person Shop
A scammer only needs your logo, your product photos, and a real order number pulled from a public review — every one-person shop has already published all three.
A customer who bought a hand-poured candle from your shop eight months ago gets an email. It says her order needs a $4.60 customs adjustment before it can reship. The logo is right. The product photo is one of yours, pulled straight off your own listing page. The sender name is your shop's name, spelled correctly. She pays without a second thought, because nothing about the message looked wrong. It did not come from you — but by every visible signal, it might as well have. This is what an online seller impersonation scam is built to do: borrow a real shop's name, photos, and order details, and turn them against that shop's own customers.
Online seller impersonation scams start with what you already published
A scammer targeting a mall retailer has to build a fake identity from scratch: guess a plausible employee name, fake a support line, hope nobody checks. A scammer targeting a one-person shop just has to copy a public page. Your shop name, your logo, your product photos, your shipping timelines, sometimes even a real order number lifted from a public review or a screenshot a customer posted — a solo seller's storefront hands a scammer everything needed to write a convincing message, because showing all of that publicly is exactly how a small shop earns a sale in the first place.
The FTC's own guidance for small businesses describes this mechanism plainly: criminals set up email addresses that mimic a real, legitimate business, then contact that business's actual customers claiming an account or order problem, aiming to collect a payment or personal information the business never asked for. A one-person shop isn't a special case here. It's close to the ideal target — everything a scammer needs to look authentic is already sitting on a public product page with no one checking who copies it.
The intimacy that sells your shop is the same intimacy a scammer borrows
A big retailer trains customers to expect cold, automated communication — a no-reply address, a case number, a chatbot. Customers are primed to be a little suspicious of all of it. A solo seller succeeds by doing the opposite: a warm shipping note, a personal "thank you so much for supporting a small shop," a direct reply from a real person when something goes wrong. That personal tone is why people buy from you instead of a marketplace giant. It is also exactly the tone a scammer copies, because a message that sounds like a real person reaching out personally is the one customers have been taught, by you, not to be suspicious of.
That is the asymmetry the scam depends on. The fake and the real read the same way, because the real one already involves a personal-sounding message from someone your customer has never met in person.
A warning post fixes yesterday's problem, not next month's
Say the scam gets reported and you post a warning on your shop's Instagram and pin it to your storefront. That helps the customers who saw the post. It does nothing for the shopper who orders next month, sees a similarly convincing message referencing her real order, and has no way to check it against anything other than the message itself. Email authentication tools like DMARC help block some spoofed sender addresses, but they don't reach a scam DM sent through a marketplace's own messaging system or a text — and a customer reading her phone at 9 p.m. isn't checking your domain's authentication records anyway.
The advice usually handed to shoppers — look for spelling errors, hover over the link, call the business directly — assumes the fake is sloppy. A message built from your own real photos and order number usually isn't. And "call the business directly" hits the same wall a lot of solo-seller problems do: when you are the shop, the fake version of you, and the only number to call, there's no second person to reach who isn't also you.
What a customer actually needs is a way to check that isn't the message itself
None of this is solved by writing a better warning or being more careful with your product photos, because the leak isn't carelessness — it's that a small shop's public page is supposed to be public. What closes the actual gap is giving a customer something to check that doesn't depend on trusting the message in front of her: a way to confirm, independently, that a specific order update or account message really was reviewed and sent by the person who runs the shop, without replying to the very message she doubts.
That's the specific, narrow thing a Human ID is for. How it works covers the mechanics — a permanent identity tied to you, and a code attached to a particular message that a customer can look up on her own, on a page you don't control and can't fake your way past after the fact.
It's worth being exact about what that does and doesn't settle. A verification confirms that a message was personally reviewed and authorized by the person shown — not that the order will arrive on time, not that a discount code is real, and not that AI had no role in drafting it. What verification does and does not confirm says so directly, because a shop that overclaims what a green checkmark means is one incident away from losing the thing it was trying to protect.
For a one-person shop, that is a smaller promise than a lot of security advice implies, and a more honest one. It doesn't stop a scammer from copying your product photos tomorrow. It gives the customer holding a suspicious message something to check that isn't just her own judgment about whether the logo looks right — which, for a scam built entirely out of your own real logo, was never going to be enough on its own.
Get your own Human Verified ID
Attach a verified human identity to the messages you personally write and authorize. Free during beta.
Get a free Human ID