Last updated:

How financial institutions monitor impersonation and scam accounts: early warning on fake investment funneling and coordinated posting

A financial institution's name, logo, senior executives and products can all be misused on social media: fake official pages, fake celebrity investment endorsements, fake customer service, or account clusters posting heavily about individual stocks. Once people are drawn into private messages or closed groups, the conversation that follows is beyond the reach of public content monitoring. This article covers four types of anomalous accounts, how to organize search terms, what to do after finding them, and the current text of relevant regulations.

Infographic for Impersonation & Scam Account Monitoring for Banks, illustrating key concepts from Use Cases

Quick answer: how financial institutions monitor impersonation and scam accounts

Monitoring impersonation and scam accounts at a financial institution means continuously watching public social media content for accounts that use the name of the institution, its executives or its products, and for account clusters posting heavily about individual stocks or financial products. This covers scenarios such as impersonating official identities, fake celebrity investment endorsements, fake customer service and coordinated posting; suspicious leads are passed to staff for verification, and records are preserved while the entry points are still public. Monitoring does not determine who is behind an account or whether anything illegal occurred; where criminal conduct is suspected, the competent authorities investigate in accordance with the law, and guilt is decided by the courts.

Who it is for

  • Brand, PR and digital channel teams at banks, securities firms, investment trust and advisory firms, insurers and electronic payment providers
  • Units responsible for fraud-prevention awareness, customer protection and complaint handling
  • Compliance, risk management and information security teams that need visibility into external risk signals

Common difficulties in monitoring and verification

  • If impersonating content only comes to light through customer inquiries, it may already have been visible for some time
  • After an account changes its name or profile picture, you need to re-check whether it is related to earlier leads
  • Reporting to platforms or cooperating with investigations requires reviewable records such as URLs, screenshots and timestamps

Four types of anomalous accounts financial institutions face on social media

The four types below are grouped by account behavior. A single scam may use several of them at once, for example drawing attention with an impersonating ad and then having a fake customer service account take over in the comments.

1. Impersonating the institution or its senior executives

These accounts mimic the institution's official page or an executive's personal account, with a name that differs by a single character or adds something like "Service Center", and a profile picture using the institution's logo or the executive's photo. They may repost official announcements to build credibility, then slip in promotions, giveaways or investment invitations, asking people to send a private message or join an external group. The risk is not only that individuals get scammed; it can also erode customers' trust in official channels.

2. Fake celebrity investment endorsements

Scammers may also borrow the names and likenesses of financial personalities, entrepreneurs or an institution's senior executives, using ads or posts to promote investment courses, hot-stock groups or high-return schemes. The fake content may also use synthetically generated images or voices. Article 339-4 of Taiwan's Criminal Code lists committing fraud using false images, voices or electromagnetic records of another person produced by computer synthesis or other technological means as one of the circumstances of aggravated fraud. As long as the scam misuses the names of an institution's staff or products, victims may end up contacting the institution's customer service.

3. Fake customer service

Fake customer service accounts show up in the comments on official posts or under discussions where people complain about service. They claim to be customer service and ask people to message them privately, then request account numbers, passwords or verification codes, or steer people into downloading unknown apps. What they exploit is people's genuine need for service.

4. Coordinated posting about individual stocks or financial products

The fourth type is not impersonation. Instead, a group of accounts posts similar bullish or bearish content about a particular stock, fund or other financial product within a short period to manufacture buzz. The goal may be to move the price, or to drive traffic to investment scam groups. Because it blends in with genuine market discussion, a misjudgment could lead to unfair accusations against ordinary investors, so concentrated posting alone is not grounds for concluding there is manipulation. For how to analyze these situations, see How to spot fake accounts: four layers of signals and common false positives, and for a definition of coordinated behavior, see What is coordinated inauthentic behavior.

Type Where it appears Observable signs Impact on the institution
Impersonating the institution or its senior executives Fake pages, personal accounts, paid ads Name and profile picture mimic the official account; asks people to message privately or join external groups Customers get scammed; may undermine the credibility of official channels
Fake celebrity investment endorsements Ads, short videos, posts Uses a celebrity's name or likeness, promises returns, and directs people to groups or external websites May increase verification requests to customer service; the institution's staff or product names get dragged in
Fake customer service Comments on official posts, complaint threads Claims to be customer service, asks for login credentials or verification codes, steers people into downloading apps Risk of account takeover
Coordinated posting Stock discussion boards, social media groups, comment sections Multiple accounts post similar claims about the same product Product reputation suffers; may be used to drive traffic

Why early detection matters: once traffic moves to private messages and closed groups, it is out of monitoring range

If impersonating content uses posts, ads or comments as an entry point to lead people into private messages, closed groups or external websites, the non-public conversation that follows falls outside the scope of public content monitoring. What monitoring can observe is the window during which the entry point is still on a public platform.

Once content is removed, an account is suspended or an ad stops running, the original page may be hard to retrieve. If the institution only finds out after customers call, the entry point may already be gone, making it hard even to confirm which account to report.

The point of early detection is that the URL, name, content and time can be recorded while the entry point is still public. These records are the foundation for reporting, issuing clarifications and cooperating with investigations.

How to organize search terms: four common keyword categories

Whether you search manually or use a monitoring tool, terms that are too narrow easily miss impersonation variants, while terms that are too broad pull in a lot of irrelevant discussion. The four categories of terms below can serve as a starting point, to be adjusted based on the search results.

  1. Institution names : official name, short name, English name, former names, and impersonation variants such as homophones, look-alike characters, added symbols and Simplified Chinese characters.
  2. Product and service names : flagship products, digital account and app names, and recent promotions, since scammers may ride the buzz of real campaigns to impersonate them.
  3. Names of senior executives and spokespeople : chairman, CEO, executives who speak publicly and advertising spokespeople. Pay particular attention to the scope of personal data handling for this group.
  4. Known scam scripts : claims such as guaranteed profits, insider tips, joining a group to get stock picks, customer service handling things by private message, or account irregularities requiring verification. Scam scripts change over time, so update them regularly with reference to the 165 Anti-Fraud Hotline website and the awareness materials published by the competent authorities.

Search results still require manual confirmation of the source and authorization relationship. Compiling a list of official and authorized accounts in advance reduces the chance of mistaking a branch page or an authorized staff member's account for an impersonation. We recommend reviewing the term list regularly and updating it whenever scam scripts or impersonation tactics change.

InfoMiner's capabilities and limitations

InfoMiner uses web crawlers to collect content published publicly on social media platforms, and can cover PTT, Dcard, Facebook, YouTube, Threads, TikTok/Douyin, LINE OpenChat, X and Instagram; actual sources and update frequency depend on the plan and platform access conditions, and gaps may occur when platforms change or restrict access. On that basis, the system provides real-time intelligence assessment and produces leads on suspicious accounts and account clusters for staff to verify; specific requirements can be assessed separately for customization.

The system looks for behavioral signals. It does not determine who is behind an account or whether anything illegal occurred, and it does not map identities across platforms. Whether an account is an impersonation must be verified by people; where criminal conduct is suspected, the competent authorities investigate in accordance with the law, and guilt is decided by the courts. If an institution needs to process its internal verification records and knowledge with AI on its internal network, it can evaluate on-premise deployment of RAGi; the actual configuration depends on the deployment plan.

For a full description of anomalous account detection and the industries it serves, see Social media anomalous account detection solution; for other applications in financial services, see Industry Solutions.

What to do once you find one: preserve, report, assign internal roles, clarify publicly

The order in which you act affects what you can do later. We recommend the four steps below, with the responsible unit for each step agreed in advance.

Step 1: preserve records

Preserve first, then report, because once an account is taken down the original page may be hard to retrieve. Save the account URL and display name, page screenshots, post and ad content, posting times, any messaging app accounts or URLs mentioned in comments, and the capture date and who captured it. Screenshots should show the URL and time.

Step 2: report to platforms and regulators

Reports can be filed through each platform's current reporting mechanisms. Taking the Facebook Help Center as an example, anyone can report a profile or Page impersonating someone else, whether or not they have an account. Reports can be filed by authorized staff of the institution, and if the channel provides fields for additional information, the preserved records can be submitted there. Ads and accounts involved in fraud can also be reported through the 165 Anti-Fraud Hotline website, or by calling the 165 hotline.

Step 3: assign internal roles

Impersonation incidents touch PR, customer service, compliance and information security. Agree in advance who confirms whether an account is official, who files reports, how customer service answers inquiries and when legal is brought in to assess. If the impersonating content asks for login credentials or verification codes, the information security and account risk control teams should be informed at the same time.

Step 4: clarify publicly

Once impersonation accounts spread, announce on the official website and official social media accounts which channels are genuine, remind the public not to give out passwords in direct messages from unknown sources, and explain how to verify. The announcement must reflect the institution's actual service policies. It does not need to reproduce the scam content, which would only spread it further, and it should not speculate about who the scammers are. Customer service messaging should match the announcement.

Capability limits and false positives

Monitoring only sees public content; direct messages, closed groups and group chats are out of scope. The scope and accessibility of public data also differ by platform, which limits how complete the leads can be. Once an account is deleted or renamed, its original page and post history may be hard to retrieve, so previously preserved records become the main basis.

False positives also need to be built into the process in advance. Branch Pages, authorized sales staff accounts and partner finance creators may all have names similar to the official account. If accounts are discussing the same stock at the same time because of an earnings release or major news, simultaneous posting alone cannot establish coordination. Leads should first be checked against the list of official accounts and authorized parties and then verified by people; system output should not be used directly to publicly label an account as a scam.

Regulatory notes: what current law says

Below are excerpts of selected current provisions relevant to scam accounts on social media. This is not a complete list of obligations, and the Laws & Regulations Database of the Republic of China (Taiwan) is the authoritative source. For how they apply to a specific case, consult your legal team or a lawyer; this article does not constitute legal advice.

  • Fraud Crime Hazard Prevention Act (promulgated July 31, 2024; partially amended January 21, 2026): Article 27 provides that the Act applies to online advertising platform operators that provide online advertising services in Taiwan and reach a certain scale. Article 30 requires that ads published on platforms must not contain fraud-related content, and that platforms verify the identities of those commissioning and funding the ads. Article 32 provides that when an online advertising platform operator within the scope of Article 27 learns that an ad is a fraudulent ad or clearly involves fraud, it must remove the ad or take other necessary measures, either on its own initiative or within the deadline set in a notice from judicial police authorities, the competent authority for digital economy industries or the relevant competent authorities, and must provide information such as the ad commissioner's details to judicial police authorities. An operator that violates Article 32, Paragraph 1 is jointly and severally liable, together with the ad commissioner and funder, to anyone harmed by relying on the ad. Article 33 provides that when an online advertising platform operator is notified by the relevant competent authority or judicial police authorities that content is suspected of involving fraud, it must first restrict access to or viewing of the content, or remove it.
  • Article 8 of the same Act : financial institutions must exercise the due care of a good administrator over deposit accounts, electronic payment accounts and credit cards, and must enhance customer identity verification for anomalous accounts suspected of involvement in fraud. This article governs financial accounts, not social media accounts.
  • Article 339-4 of the Criminal Code of the Republic of China : committing fraud by disseminating to the public through the internet or other means of mass communication, or by using computer synthesis or other technical means to create false images, audio or electromagnetic records of another person, both constitute aggravated fraud.
  • Articles 19 and 20 of the Personal Data Protection Act : monitoring involves handling posters' personal data. Non-government agencies collecting or processing personal data must have a specific purpose and meet one of the conditions listed in Article 19; use should in principle stay within what is necessary for the specific purpose of collection, and use beyond that purpose must meet one of the conditions listed in Article 20. Being publicly visible does not mean data can be collected or used freely, and the special categories of personal data listed in Article 6 are subject to separate rules. Consult your legal team or a lawyer on specific questions of legality.

Article 3 of the Act assigns the financial regulator responsibility for anti-fraud financial management measures, and operational requirements for each sector follow the financial regulator's latest announcements. The relevant provisions can be looked up in the Laws & Regulations Database of the Republic of China (Taiwan).

Further Reading

FAQ

No. The system continuously collects public social media content and assesses suspicious accounts and account clusters in real time; what it produces are suspicious leads for staff to verify. Whether an account is an impersonation must be confirmed by staff checking it against the list of official accounts. Where criminal activity is suspected, the competent authorities investigate in accordance with the law, and guilt is decided by the courts.
No. Public content monitoring does not cover private messages or closed groups. What can be observed are the entry points on public platforms, such as impersonating pages, ads, comments and posts. That is why the URL, content and time need to be recorded while the entry point is still public, as the basis for reports and for cooperating with investigations.
Preserve the record first, then report it. Save the account URL, display name, screenshots that show the URL and time, the post content and the capture date, because once the account is taken down the original page may be hard to retrieve. Then report it in your official capacity through the platform's current reporting mechanism. Fraud-related ads and accounts can also be reported through the 165 Anti-Fraud Hotline website.
Monitoring involves personal data and must comply with the Personal Data Protection Act (PDPA). Being publicly visible does not mean data can be freely collected or used: the applicable legal basis has to be confirmed according to the data type, source and purpose, and use should in principle stay within what is necessary for the specific purpose of collection. The system does not perform cross-platform identity matching. For specific legal questions, consult your legal team or counsel.

Product information and inquiries

To learn about InfoMiner's capabilities, scope of application and limitations, get in touch with us.

Contact Us