Skip to content
UsernameLookup

monitoring / lookalike handles and fake support accounts

Brand impersonation monitoring

Brand impersonation monitoring is a scheduled scan for accounts that pretend to be your company. UsernameLookup generates lookalike handles of every brand term, checks them on 300+ public sites every hour and alerts your team with evidence when a new fake profile appears.

Brand protection team reviewing cases together in a bright office
01 the problem

Fake support accounts show up where your customers ask for help

The most damaging impersonators do not copy your logo on a random site. They register a handle one keystroke away from yours, add "support" or "help" to the end, and reply to customers who tag your real account with a complaint. A customer who is already annoyed gets a friendly direct message, a link to a "refund form" and a request for card details or a login code.

By the time someone forwards a screenshot to your social team, the account has been live for days. Searching each platform by hand does not scale either: a single brand name has dozens of plausible variants, and the account can sit on a network your team does not even watch.

Monitoring turns that into a routine. You add the brand once, we keep checking the variants, and new profiles land on a case board with everything needed to report them.

finding / acmebank risk 85
Handle
@acmebank_support
Variant type
suffix _support
Platform
X
First seen
this scan
HTTP status
200
Page title
Acme Bank Support (@acmebank_support)
new Example finding layout with an evidence snapshot.
02 what we generate

The lookalike patterns we check for every brand

Each brand term expands into a list of variants. The risk score depends on the pattern, because some tricks are almost never innocent and others often belong to fans or unrelated people with a similar name.

Lookalike username patterns checked by brand impersonation monitoring
Pattern Example for acmebank Why it matters
Support suffix acmebank_support, acmebank_help The classic fake customer service account that answers public complaints.
Official prefix official_acmebank, realacmebank Claims authority the real account never needs to claim.
Homoglyph acmeb4nk, acrnebank Swaps letters for lookalikes such as 4 for a or rn for m, hard to spot in a feed.
Separator acme.bank, acme_bank Adds a dot, underscore or hyphen that most readers skip over.
Keyboard typo acmebsnk, acmenank Neighbour key slips that catch people typing fast on a phone.
Giveaway suffix acmebank_giveaway, acmebank_promo Fake contests that collect card details or login codes.

The exact handle of your brand on a platform where you have no account is checked too. That covers squatted names, which are often the first step before an impersonation campaign.

03 workflow

From new account to filed report in four steps

  1. step 1

    Add brands and executives

    Enter brand terms and, on the brand plans, the handles of named executives. Variants are generated automatically and you can remove ones that belong to you.

  2. step 2

    Scans run on schedule

    Every hour on Brand Monitoring, every 15 minutes on Brand Enterprise. Only profiles that are new since the last scan raise an alert.

  3. step 3

    Review on the case board

    Findings move through new, reviewing, reported and closed. Each one keeps the URL, timestamp, HTTP status and page title captured at detection.

  4. step 4

    Report with one link

    A pre-filled link opens the platform's impersonation report form. Attach the evidence, submit, mark the case reported.

04 alerts

Alerts where your team already works

An alert that nobody sees is the same as no alert. Route findings to the place your brand, social or security team watches during the day, and keep the case board as the single record of what was found and what was done about it.

  • Email

    A digest of new findings with the handle, platform, pattern and a link to the case.

  • Slack

    One message per scan with new findings, posted to the channel you choose.

  • Webhook

    JSON payload with every finding, signed with HMAC SHA-256 in the X-UsernameLookup-Signature header, for your ticketing or SIEM.

05 plans and limits

Monitoring capacity on each plan

Brand Monitoring covers 10 brands with hourly scans, 5,000 alerts a month, Slack and webhook alerts, the case board, pre-filled report links and executive impersonation watch for up to 10 named people. Brand Enterprise covers 50 brands every 15 minutes with 25,000 alerts a month, single sign-on and an audit log.

Smaller teams can start with Pro or Investigator, which watch personal usernames rather than brands: 3 handles daily on Pro, 15 handles every 6 hours on Investigator. Every plan is self-serve, billed yearly by default at half the monthly price. Compare everything on the username lookup pricing page.

If your team wants the same data inside its own tools, the username lookup API returns lookups and availability as JSON, and the social media impersonation monitoring for brand teams page walks through a typical weekly routine.

brand monitoring

10 brands, scan every hour

brand enterprise

50 brands, scan every 15 minutes

investigator

15 usernames, scan every 6 h

pro

3 usernames, daily scan

06 boundaries

What monitoring does not do

Monitoring reads public profile pages only. It does not log in to platforms, collect private messages, or try to work out who operates an account. It flags handles that look like yours and shows you the public page, so a person on your team makes the call and files the report.

Anyone can ask us to stop showing results for their own username through the opt-out page, and our acceptable use policy forbids using results to harass or profile private people.

07 faq

Questions about brand impersonation monitoring

What does brand impersonation monitoring actually check?

It takes each brand term you add, generates lookalike handles (typos, homoglyphs, separators, prefixes and suffixes such as _support, _official, _help or _giveaway) and checks the public profile address of every variant on 300+ sites. A new public profile that answers at one of those addresses becomes a finding with a risk score and an evidence snapshot.

How often are brands scanned?

Brand Monitoring scans every brand once an hour and Brand Enterprise every 15 minutes. The Pro and Investigator plans watch personal usernames daily or every 6 hours. Every scan only reports profiles that are new since the last run.

Can you take fake accounts down for us?

We do not file reports on your behalf. Each finding has a pre-filled link to the platform's own impersonation report form plus the evidence you need to attach, so your team submits the report in a minute and moves the case to reported.

Does monitoring look at private accounts or messages?

No. Monitoring only requests public profile addresses, the same pages anyone can open in a browser. It never logs in, never reads private content and never tries to find out who runs an account.

Where do alerts go?

To email, a Slack channel or your own webhook endpoint. Webhook calls are signed with an HMAC SHA-256 signature so your system can verify that the alert came from us.

See which lookalike handles exist today

Start with a lookup of your brand name across 300+ sites, then put the brand under hourly monitoring.