Skip to content

Demo site. Fictional data; nothing is sent to anyone. Open the guided demo

Privacy for executives and public-facing staff

Short answer

Senior and public-facing staff are easy to research and worth impersonating. Criminals pose as them by email, text and AI-generated voice to redirect payments or gain access. Reducing what is public about a person helps, and so does asking data brokers to delete their records. The main defence against impersonation fraud is a verification procedure that does not rely on recognising a voice or an email address.

Published
Last reviewed

General information, not legal advice. This page has not yet been reviewed by a lawyer; check the linked primary sources before relying on it.

Key takeaways

  • The FBI counted about $55.5 billion in exposed losses from business email compromise between October 2013 and December 2023.
  • In May 2025 the FBI warned of texts and AI-generated voice messages impersonating senior US officials.
  • The FTC's Impersonation Rule prohibits falsely posing as a business or one of its officers.
  • Confirm payment and account changes through a second channel.
  • UltoPulto for Teams is planned, not built.

What is the problem?

An executive's name, role, voice and photo can all be public. That is enough to pose as them. The same goes for public-facing staff who are not executives, such as spokespeople, recruiters and branch managers.

The FBI describes business email compromise as a scam that targets businesses and individuals who make legitimate transfers of funds. It recorded 305,033 incidents and about $55.5 billion in exposed losses worldwide between October 2013 and December 2023. In November 2024 FinCEN said it had seen an increase in suspicious activity reports from financial institutions describing suspected use of deepfake media.

How does it happen?

  1. Research. Roles, voices and images are gathered from public material. The FBI advises limiting online content of your image or voice where possible.
  2. Contact. A message arrives by email, text or voice. The FBI's May 2025 notice describes texts and AI-generated voice messages that claim to come from a senior official and then move the target to another platform or a malicious link.
  3. Request. The target is asked to change account details, move money or share credentials.

Separately, data brokers hold and sell personal information about individuals, executives included.

What laws may apply?

  • FTC Impersonation Rule. In effect since April 2024. It prohibits falsely posing as a business or an officer of one, or as a government entity, in or affecting commerce. The FTC says violators may have to pay refunds and civil penalties of up to $53,088 per violation.
  • California. The CCPA lets residents ask businesses to delete personal information collected from them, and to authorize another person to submit the request. DROP, the state's free platform, sends a deletion request to registered data brokers, which must check it at least every 45 days.

These are the individual's rights and may depend on where that person lives. A request made for someone else needs their authorization. Other fraud laws may also apply to impersonation.

What you can do yourself

These steps are free and do not need UltoPulto.

  1. Set a rule that any change to account or payment details is confirmed through a second channel, such as a call to a number already on file.
  2. Agree a verification phrase for sensitive requests by phone. The FBI suggests this for families.
  3. Turn on multi-factor authentication on every account that allows it.
  4. Do not send login credentials or personal information by email.
  5. If money has been sent, contact your financial institution immediately to request a recall, then file a complaint at ic3.gov.
  6. Have each person search their own name and opt out of people-search sites. California residents can use DROP for free.
  7. Where the role allows, limit public recordings and keep personal social accounts private.

What UltoPulto can do

  • Run an Exposure Scan for an individual, with results hidden until that person confirms a code sent to their email.Built
  • Send removal and suppression requests to people-search sites and data brokers under the law that applies where the person lives.Built
  • Send formal takedown notices to platforms for impersonation and deepfakes that you report.Built
  • Re-scan on a schedule, open cases for anything new, and keep an evidence trail on every case.Built
  • Real delivery of requests: a request is sent only once our team has verified the recipient's privacy contact. Until then it stays a draft.In rollout
  • UltoPulto for Teams: employee and executive protection with strict privacy boundaries between employee and employer.Planned
  • Impersonation and deepfake monitoring, and voice-clone monitoring.Planned

What UltoPulto cannot do

  • We are not a fraud control. We cannot verify a caller, block a payment or detect a cloned voice on a call.
  • We cannot act for an employee on an employer's instruction alone. Each person signs their own authorization and can revoke it.
  • We cannot remove company filings, press coverage or other legitimately public business information.
  • We cannot remove anyone from an AI model that has already been trained.

Sources

  1. 1Business Email Compromise: The $55 Billion ScamFBI Internet Crime Complaint CenterGovernmentOpened 2026-10-04
  2. 2Senior US Officials Impersonated in Malicious Messaging CampaignFBI Internet Crime Complaint CenterGovernmentOpened 2026-10-04
  3. 3Criminals Use Generative Artificial Intelligence to Facilitate Financial FraudFBI Internet Crime Complaint CenterGovernmentOpened 2026-10-04
  4. 4FinCEN Issues Alert on Fraud Schemes Involving Deepfake Media Targeting Financial InstitutionsFinancial Crimes Enforcement Network, US TreasuryGovernmentOpened 2026-10-04
  5. 5FTC Highlights Actions to Protect Consumers from Impersonation ScamsFederal Trade CommissionGovernmentOpened 2026-10-04
  6. 6California Consumer Privacy Act (CCPA)California Department of Justice, Office of the Attorney GeneralGovernmentOpened 2026-10-04
  7. 7Delete Request and Opt-out Platform (DROP)California Privacy Protection AgencyGovernmentOpened 2026-10-04

Questions

Is removing an executive's personal data enough to stop impersonation fraud?

No. It reduces what is easy to find. The FBI's advice on business email compromise centres on verifying requests through secondary channels or two-factor authentication.

What is business email compromise?

The FBI defines it as a scam that targets businesses and individuals who perform legitimate transfer-of-funds requests. It is often carried out by compromising a legitimate account through social engineering or computer intrusion.

Is impersonating a company executive illegal in the US?

It may be. The FTC's Impersonation Rule prohibits falsely posing as a business or an officer of a business in or affecting commerce. Other laws may also apply.

Can a company buy UltoPulto for its staff?

Not yet. UltoPulto for Teams is planned and not built.