"Please don't send that bot anything": A Mixed-methods Study of Personal Impersonation Attacks Targeting Digital Payments on Social Media

Hoang Dai Nguyen, Louisiana State Univeristy; Sumit Dhungana, Madhulika Itha, and Phani Vadrevu, Louisiana State University

Personal impersonation attacks on social media are an emerging form of social engineering that exploit trust within interpersonal relationships to redirect digital payments. Unlike brand impersonation, these attacks target everyday users, leveraging real-time public interactions to deceive victims into transferring funds to attacker-controlled accounts. In this paper, we present the first in-depth study of PROSPER (Payment Re-routing on Social media via Personal Impersonation) attacks, focusing on their operational tactics, scale, and impact. Using a mixed-methods approach, we tracked 181 PROSPER attacks over a 3-month period, uncovering 70 distinct digital payment accounts and revealing human-in-the-loop scam operations alongside automated bots, as well as longstanding campaigns involving reused payment accounts.

Our quantitative analysis highlights the scale and persistence of these attacks, while our qualitative analysis provides deeper insights into attacker evasion strategies, victim targeting methods, and how victims are particularly vulnerable to these schemes. Based on these findings, we propose actionable recommendations for social media platforms and payment providers, including UI enhancements, stricter account handle management policies, and the sharing of blacklist information to mitigate these attacks and protect users from financial exploitation.

Category: 
Short Presentation

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {309750,
author = {Hoang Dai Nguyen and Sumit Dhungana and Madhulika Itha and Phani Vadrevu},
title = {"Please don{\textquoteright}t send that bot anything": A Mixed-methods Study of Personal Impersonation Attacks Targeting Digital Payments on Social Media},
booktitle = {34th USENIX Security Symposium (USENIX Security 25)},
year = {2025},
isbn = {978-1-939133-52-6},
address = {Seattle, WA},
pages = {4859--4878},
url = {https://www.usenix.org/conference/usenixsecurity25/presentation/nguyen},
publisher = {USENIX Association},
month = aug
}

Presentation Video