"Please don't send that bot anything": A Mixed-methods Study of Personal Impersonation Attacks Targeting Digital Payments on Social Media
Hoang Dai Nguyen (Louisiana State University)
34th USENIX Security Symposium (USENIX Security '25) · Day 2 · Fraud, Malware, Spam
Overview
In an era where digital transactions are increasingly interwoven with social media interactions, a novel and insidious form of social engineering has emerged, termed PROSPER (Payment Re-routing on Social Media via Personal Impersonation). This talk, presented by Hoang Dai Nguyen from Louisiana State University, delves into a comprehensive mixed-methods study that uncovers the mechanics and prevalence of PROSPER attacks. Unlike traditional impersonation scams that target high-profile brands or celebrities, PROSPER attacks specifically target ordinary users by impersonating their friends or acquaintances on social media platforms to reroute digital payments.

Key moments
- 0:00 Introduction to Prosper: Personal Impersonation Attacks on Social Media
- 1:40 Detailed example of a Prosper attack scenario
- 3:30 Methodology for collecting and validating Prosper attacks
- 4:50 Attack speed and deceptive handle creation tactics
- 6:00 Attackers' evasion tactics and PayPal Friends & Family abuse
- 8:00 Recommendations for social media platforms like X
- 8:50 Recommendations for payment platforms to protect users
"Please don't send that bot anything": A Mixed-methods Study of Personal Impersonation Attacks Targeting Digital Payments on Social Media
Speakers: Hoang Dai Nguyen (from Louisiana State University), Sumedha Gana, Madhulika Itha, Fanabel Ngo (all from LSU)
Conference: USENIX Security
YouTube: https://www.youtube.com/watch?v=c0A3nUs9Abc
Overview
In an era where digital transactions are increasingly interwoven with social media interactions, a novel and insidious form of social engineering has emerged, termed PROSPER (Payment Re-routing on Social Media via Personal Impersonation). This talk, presented by Hoang Dai Nguyen from Louisiana State University, delves into a comprehensive mixed-methods study that uncovers the mechanics and prevalence of PROSPER attacks. Unlike traditional impersonation scams that target high-profile brands or celebrities, PROSPER attacks specifically target ordinary users by impersonating their friends or acquaintances on social media platforms to reroute digital payments.
The research highlights a critical vulnerability in the intersection of social media user interfaces and digital payment ecosystems, demonstrating how attackers exploit subtle cues and platform features to defraud victims. The findings reveal the alarming speed and sophistication with which these attacks are executed, often within minutes of a legitimate payment inquiry. This study not only sheds light on a previously under-examined threat landscape but also provides concrete recommendations for social media platforms, payment providers, and users to mitigate the growing risk of personal impersonation in digital payment contexts.
Background
▶ Watch: Introduction to Prosper: Personal Impersonation Attacks on Social Media (0:00)
Social engineering has long been a cornerstone of cyberattacks, with threat actors consistently leveraging human psychology to bypass technical defenses. Historically, impersonation attacks have predominantly focused on mimicking established entities such as popular brands (e.g., Microsoft, Amazon, Netflix) or public figures. The objective of such schemes is typically to gain trust, which is then exploited to steal sensitive credentials, distribute malware, or directly solicit funds through various phishing and scam tactics. These attacks often rely on broad-stroke campaigns, casting a wide net in hopes of ensnaring a percentage of unsuspecting users.
However, the proliferation of digital payment platforms (like PayPal, Venmo, Cash App) and their seamless integration into social media interactions has opened a new vector for targeted exploitation. Users frequently discuss transactions, request payments, or offer services for a fee directly within social media feeds. This environment creates a fertile ground for a more personalized form of impersonation. The problem arises because the trust inherent in personal relationships is implicitly transferred to online interactions, making users less vigilant when they believe they are communicating with a friend. Attackers capitalize on this by inserting themselves into seemingly innocuous conversations about payments, exploiting the trust between individuals rather than the perceived authority of a brand. The casual nature of these online exchanges, combined with the rapid pace of social media, reduces the time users have to scrutinize requests, making them highly susceptible to subtle deceptions.
Key Findings
▶ Watch: Methodology for collecting and validating Prosper attacks (3:30)
The study's mixed-methods approach yielded several critical insights into the nature and efficacy of PROSPER attacks, underscoring their stealth, speed, and reliance on platform vulnerabilities:
- Prevalence and Scale: Through their monitoring system, the researchers identified over 1,000 "trigger tweets" (posts indicating a user was seeking or discussing a digital payment). From these, they confirmed 127 unique accounts that were successfully impersonated in PROSPER attacks, demonstrating a significant and active threat landscape.
- Temporal Urgency: A striking finding was the rapid execution of these attacks. A staggering 80% of PROSPER attacks commenced within just 10 minutes of the original trigger tweet. Some attacks were initiated as quickly as 2-3 minutes, indicating either highly automated attack bots or exceptionally agile human attackers constantly monitoring for payment-related keywords. This rapid response window significantly reduces the victim's time to detect the impersonation.
- Subtle Handle Manipulation: The primary method of impersonation involved creating social media handles that were nearly identical to the legitimate user's. Specifically, 90% of impersonating accounts utilized a handle with only a single different letter, often positioned at the very end of the username. This subtle alteration is designed to be easily overlooked by a quick glance.
- Platform UI Exploitation (X/Twitter): The research identified a critical UI vulnerability on X (formerly Twitter) that exacerbates the effectiveness of handle manipulation. On certain mobile interfaces, X truncates account handles after 30 characters. This means that if the legitimate and impersonating handles differ only by a character beyond the 30th position, the distinction becomes invisible to the victim, rendering the attack even more potent.
- Evasion and Closing Tactics: Attackers do not engage in widespread replies to trigger posts, instead focusing on highly targeted interactions. They employ sophisticated evasion tactics, such as responding even when the legitimate user has already provided payment details, claiming the link is "not working" and providing their own malicious link. They also use emotional appeals, creating a sense of urgency (e.g., "hurry up," "confirm so I can delete evidence") to pressure victims into making hasty decisions and prevent them from verifying the request.
- Abuse of Payment System Features: A significant finding was the exploitation of specific features within digital payment platforms. Attackers frequently instruct victims to use options like PayPal's Friends & Family payment choice. This option, intended for trusted personal transfers, explicitly waives buyer protection, making it impossible for victims to reclaim their funds once sent, effectively turning the transaction into an irreversible gift.
- Detection Evasion Techniques: To further evade potential platform-level detection, attackers were observed deliberately misspelling platform names within their messages, for instance, writing "Pay Pal" instead of "PayPal." This simple yet effective tactic could bypass automated keyword-based filters designed to flag suspicious payment requests.
Technical Deep Dive
▶ Watch: Attack speed and deceptive handle creation tactics (4:50)
The study employed a robust mixed-methods methodology to identify, collect, and analyze PROSPER attacks, combining user surveys with an automated monitoring system and semi-manual validation. This multi-faceted approach allowed the researchers to not only quantify the problem but also to understand the intricate technical and social mechanisms at play.
The research began with a user survey conducted among students at Louisiana State University. The primary goal of this survey was to gather a comprehensive list of common phrases and colloquialisms that individuals use when requesting or discussing digital payments with friends on social media. This step was crucial because a wide variety of informal language ("Do you have PayPal?", "Can you Venmo me?", "What's your Cash App?") could indicate a payment intent. By understanding this natural language, the researchers could formulate effective search queries for their monitoring system, ensuring broad coverage of potential PROSPER attack initiation points.
Based on the survey results, the team developed a sophisticated set of search queries designed to identify "trigger tweets" on X (formerly Twitter). These queries were then integrated into an automated monitoring system. This system continuously scanned the platform for tweets containing the identified payment-related keywords. Upon detecting a trigger tweet, the system was configured to monitor its replies and subsequent interactions. If a reply to a trigger tweet matched certain suspicious patterns—such as a new account interacting or an account with a subtly altered handle—the entire conversation thread would be pulled for further analysis. This automated collection allowed for the capture of attacks in near real-time, which was essential given the rapid execution observed.
Following automated collection, a semi-manual validation process was employed to confirm genuine PROSPER attacks. This human-in-the-loop step was vital to differentiate between legitimate payment discussions and actual impersonation attempts. Validators would scrutinize the accounts involved, comparing handles, profile pictures, and usernames, and analyzing the conversation flow for tell-tale signs of deception, such as the use of evasion tactics or the insistence on specific payment methods. This rigorous validation ensured the accuracy of the dataset used for subsequent analysis.
From a technical attack perspective, the study highlighted several critical enablers:
- Account Handle Fluidity on X: The research found that X (Twitter) stands out among social media platforms for its permissive policy regarding account handle changes. Users can modify their handles as frequently as they desire. This feature, while seemingly innocuous, is a significant enabler for PROSPER attackers. It allows them to quickly create new accounts, adopt an impersonated handle for a brief period to execute a scam, and then change the handle again to avoid detection or repurpose the account for another impersonation. This rapid adaptability makes it exceedingly difficult for platforms to track and ban malicious actors effectively.
- UI Vulnerabilities: The truncation of handles after 30 characters on mobile versions of X is a critical UI flaw. Attackers strategically place the differentiating character beyond this 30-character limit, rendering the impersonation almost invisible to users scrolling through their feed. This exploits a fundamental aspect of human perception, where users often perform quick pattern matching rather than meticulous character-by-character comparison, especially under conditions of urgency or familiarity.
- Payment System Design Flaws: The PayPal Friends & Family option, while designed for convenience in trusted relationships, presents a significant security loophole when exploited by attackers. Technically, this option processes payments as gifts, removing the transactional protections and dispute resolution mechanisms that typically accompany goods and services payments. Attackers explicitly guide victims to use this option, ensuring that once the money is sent, it is virtually irrecoverable, even if the fraud is later detected. This highlights a need for payment platforms to re-evaluate how such features are presented and protected, especially in contexts initiated via social media.
- Social Engineering Tactics: Beyond the technical exploits, the study detailed the refined social engineering tactics. Attackers don't just impersonate; they actively manage the interaction. Their "evasion closing tactics" involve creating a sense of urgency ("hurry up," "confirm quickly") to bypass the victim's critical thinking. They also demonstrate situational awareness, intervening even after a legitimate payment link has been shared, by claiming it's "not working" and redirecting to their own malicious payment method. The deliberate misspelling of platform names (e.g., "Pay Pal") is a simple yet effective technique to bypass basic keyword-based automated detection systems that social media platforms might employ.
Demo / Proof of Concept
▶ Watch: Recommendations for social media platforms like X (8:00)
While the talk did not feature a live, interactive technical demonstration of a PROSPER attack tool, the speaker effectively presented a conceptual demonstration through a clear, step-by-step example scenario. This narrative walkthrough served as a compelling proof of concept, illustrating the practical execution and impact of a PROSPER attack in a real-world context.
The scenario unfolded as follows:
- Initial Interaction (Trigger Post): A legitimate user, "Victim A," posts a tweet offering a service, such as a sketch, for a fee.
- Payment Inquiry: Another legitimate user, "Victim B," replies to Victim A's tweet, expressing interest in the service and asking about payment methods, for example, "Do you have PayPal?" This query constitutes the critical "trigger post" that attackers monitor.
- Attacker Interception and Impersonation: Within minutes of Victim B's inquiry, an attacker swiftly creates an account designed to impersonate Victim A. The attacker's profile picture and username are identical to Victim A's, but their account handle contains a subtle, often single-character difference (e.g.,
@VictimAvs.@VictimAa). - Malicious Reply and Payment Redirection: The impersonating attacker quickly replies to Victim B, posing as Victim A, and provides their own PayPal (or other digital payment) details. Victim B, glancing quickly at the profile picture and username, and missing the subtle handle difference, assumes they are communicating with their friend.
- Payment and Loss: Victim B sends the money to the attacker's account.
- Legitimate User's Discovery and Attacker Evasion: Shortly after, the real Victim A sees Victim B's original inquiry and the attacker's reply. When Victim A tries to warn Victim B, they discover that the attacker has already blocked them. This preemptive blocking prevents Victim A from seeing or replying to the attacker's posts, effectively silencing the legitimate user and preventing them from warning Victim B in time.
This detailed narrative effectively demonstrated the speed, stealth, and social engineering components of a PROSPER attack. It highlighted how easily a user could be deceived by subtle changes, especially when operating under the assumption of trust and the pressure of a rapid online interaction. The blocking mechanism also showcased the attacker's proactive measures to prevent detection and intervention by the legitimate party.
Defensive Implications
▶ Watch: Recommendations for payment platforms to protect users (8:50)
The findings from this study carry significant defensive implications for social media platforms, digital payment providers, and end-users, necessitating a multi-pronged approach to mitigate the risks of PROSPER attacks.
For Social Media Platforms (e.g., X):
- Restrict Account Handle Changes: The current policy allowing frequent handle changes on platforms like X is a major enabler for attackers. Platforms should consider implementing restrictions, such as limiting the frequency of handle changes or requiring a waiting period, especially for newly created accounts or accounts with suspicious activity. This would increase the operational cost for attackers and make it harder to cycle through impersonated identities.
- Integrate Impersonation Monitoring and Detection Systems: Platforms should develop and integrate advanced, real-time monitoring systems similar to the one used in this research. These systems should actively scan for trigger phrases related to digital payments and then analyze subsequent interactions for signs of impersonation, such as newly created accounts, handles with subtle differences, or rapid replies to payment inquiries. Machine learning models trained on the characteristics of PROSPER attacks (e.g., temporal patterns, handle similarity, evasion tactics) could be highly effective.
- Enhance UI for Account Handle Display: The current UI that truncates or de-emphasizes account handles is a critical vulnerability. Social media platforms must prioritize making account handles more prominent, unique, and resistant to visual deception. This could involve:
- Highlighting unique handles: Using distinct fonts, colors, or dedicated display areas that are not truncated.
- Warning for similar handles: Implementing a system that alerts users if they are interacting with an account whose handle is extremely similar to another account they frequently interact with.
- Visual cues for verified accounts: While verification exists, it needs to be more robust and clearly distinguishable, especially for personal accounts.
- Cross-Platform Collaboration: Social media platforms and digital payment providers must establish formal channels for collaboration. This could involve sharing blacklists of known scammer account IDs or payment account details, enabling faster identification and suspension of malicious actors across both ecosystems.
For Digital Payment Platforms (e.g., PayPal):
- Warn for High-Risk Transactions: Payment platforms should implement contextual warnings for transactions deemed high-risk. If a payment is initiated via a link from a social media platform, or if the recipient is new/unverified, or if the transaction uses options like "Friends & Family," a prominent warning should appear, explicitly detailing the risks and lack of buyer protection.
- Educate Users on "Friends & Family" Risks: Platforms need to provide clearer and more frequent educational messages about the implications of using "Friends & Family" or similar options. Users must understand that these options often waive all buyer protections, making them irreversible and unsuitable for transactions with anyone other than genuinely trusted individuals.
- Integrate Social Media Context: Payment platforms could explore integrations that allow them to query social media platforms for context around a transaction request. For example, if a payment link is clicked, the payment platform could check if the source social media account has been flagged for impersonation.
For End-Users:
While platforms bear significant responsibility, user vigilance remains paramount.
- Always double-check handles: Train users to scrutinize the full account handle, not just the profile picture or username.
- Verify out-of-band: If a payment request seems even slightly suspicious, or if it comes from an unexpected context, verify it with the legitimate sender through an alternative, trusted communication channel (e.g., a phone call, a separate direct message).
- Understand payment options: Be aware of the differences between "Friends & Family" and "Goods & Services" payment options and their associated protections. Never use "Friends & Family" for transactions with anyone you don't implicitly trust.
- Report suspicious activity: Report impersonation attempts and suspicious payment requests to both the social media platform and the payment provider immediately.
Implementing these defensive measures requires a concerted effort across the digital ecosystem. Without proactive steps, PROSPER attacks will continue to erode trust and cause financial harm to unsuspecting users.
Key Takeaways
- PROSPER attacks are a growing threat targeting ordinary social media users for digital payment redirection. They exploit personal connections rather than brand authority.
- These attacks are executed with alarming speed, with 80% starting within 10 minutes of a payment-related "trigger post," indicating highly agile or automated adversaries.
- Attackers primarily rely on subtle handle manipulation (90% use a single-character difference), which is exacerbated by social media UI flaws like handle truncation on mobile devices.
- Attackers exploit features of payment platforms, specifically PayPal's "Friends & Family" option, to bypass buyer protection and make stolen funds irrecoverable.
- Social media platforms (like X) need to restrict handle changes and enhance UI to clearly display unique account handles, alongside implementing robust impersonation detection systems.
- Payment platforms must introduce high-risk transaction warnings and educate users on the implications of payment options, while fostering collaboration with social media platforms for shared threat intelligence.
About the Speaker(s)
Hoang Dai Nguyen is a researcher from Louisiana State University (LSU). He presented this paper, which is the result of collaborative work with his colleagues Sumedha Gana, Madhulika Itha, and Fanabel Ngo, all also affiliated with LSU. Their work focuses on understanding and mitigating social engineering attacks, particularly those exploiting human trust and digital platforms for financial gain. This research highlights their expertise in cybersecurity, social media security, and the analysis of online deceptive practices.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Legitimate academic research on a real and underexamined threat — personal impersonation attacks in social media payment flows. The empirical data (1,000+ trigger tweets, 80% attack-within-10-minutes finding, 90% single-character handle delta) grounds it in reality, and the UI truncation vulnerability on X is a genuinely sharp observation. Not a technical research talk in the exploit sense, but a solid threat/behavior study that earns its USENIX slot.
Heather Calloway (CISO) — SOLID
Credible academic research that documents a real, underexamined threat — personal impersonation in payment contexts — with useful empirical grounding. The findings are specific and the mechanisms are clearly described, but the work stops at the platform recommendation layer and never reaches the institutional or organizational accountability questions that would make it matter to security leaders.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)