The phone call began with a Canadian area code and a voice that sounded like a military official. The question was direct: Had a specific investigative journalist been reaching out via WhatsApp to solicit sensitive information?
For Robert Faturechi, a seasoned investigative reporter, the call was a jarring realization. He hadn’t contacted any Canadian officials recently. Instead, he had become the face of a sophisticated social engineering campaign. Someone was using his name, his professional headshot, and his reputation to infiltrate circles of military and defense intelligence.
This case of journalist impersonation scams is not an isolated incident of identity theft, but rather a calculated tactic in a broader landscape of digital espionage. By leveraging the inherent trust placed in the press, lousy actors are bypassing traditional security filters to target high-value individuals—from defense officials in North America to drone developers in Eastern Europe.
As these attacks evolve, they expose a critical vulnerability in the modern media ecosystem: the tension between the need for encrypted, private communication and the necessity of identity verification. When the tools designed to protect journalists from government surveillance are repurposed by impostors to deceive sources, the very foundation of investigative reporting—trust—is placed at risk.
The Anatomy of a Digital Double
The impersonation of Faturechi followed a pattern common in high-level phishing: the creation of a believable persona using publicly available professional data. In the first instance, the impostor used a Miami-based phone number and Faturechi’s official press photo to contact a Canadian military official. The target was specifically chosen for their involvement in international relations, including operations involving Ukraine.
Shortly thereafter, a second attempt targeted a Latvian businessman involved in providing unmanned aerial vehicles (UAVs) to the Ukrainian military. This time, the attacker shifted to Signal, an encrypted messaging app favored by journalists for its security. The “Fake Robert” inquired about the application of drones in conflict zones, attempting to establish a rapport before steering the conversation toward a “secure video chat.”
That invitation was the hook. The instructions provided for the video call were not for a secure meeting, but were instead a phishing attempt designed to trick the businessman into surrendering access to his email account. By refusing the call and insisting on verification, the target avoided a total account compromise.
The Privacy Paradox: Signal and WhatsApp
The use of encrypted platforms like Signal and WhatsApp creates a “privacy paradox.” These apps are essential for protecting sources from state surveillance, but their design—which minimizes the amount of data stored about users—makes it nearly impossible for the platforms to detect and remove impostors.

Signal, for example, stores almost no metadata about who is messaging whom. Even as What we have is a gold standard for privacy, it means that “red flags,” such as the mass distribution of phishing links, are often invisible to the system. Cooper Quintin, a technologist at the Electronic Frontier Foundation, has noted an increase in scams on secure apps as they grow in popularity, noting that attackers view these platforms as high-trust environments where victims are less likely to be suspicious.
WhatsApp has a different approach, monitoring for suspicious behavior such as the creation of multiple accounts from a single location. However, due to the fact that the content of messages is end-to-end encrypted, the company generally cannot take action unless a user manually reports the account. In Faturechi’s case, reporting the account was the only available remedy, yet the ease with which new accounts can be created allows scammers to pivot quickly.
A Global Pattern of State-Sponsored Deception
While some online scams are driven by financial gain—such as “pig butchering” schemes where victims are lured into fake investments—the impersonation of journalists often signals a more sinister objective: intelligence gathering. This is part of a global trend where state-sponsored actors use social engineering to compromise government and media targets.
The risks are not theoretical. In 2016, one of the most consequential phishing attacks in U.S. Political history occurred when John Podesta, chair of Hillary Clinton’s presidential campaign, fell victim to a fake Google security alert. This allowed hackers to access thousands of personal emails, which were subsequently leaked to influence the election and the Democratic Party’s image.
More recently, official warnings have highlighted the sophistication of these campaigns. The FBI has previously issued alerts regarding individuals associated with Russian intelligence who pose as security personnel from encrypted app providers to trick users into handing over account access through the Internet Crime Complaint Center (IC3). Similarly, the German government has warned of state-sponsored actors attempting to commandeer Signal accounts of European officials and reporters.
Other news organizations have faced similar threats. Reuters has reported instances of its reporters in China and Saudi Arabia being impersonated on Instagram, Telegram, and WhatsApp to gather information on activists and political dissidents.
How to Verify a Journalist’s Identity
For individuals contacted by someone claiming to be a member of the press, the best defense is a “trust but verify” approach. Because scammers rely on the urgency and prestige of a news organization, taking a few minutes to conduct independent verification can stop a phishing attack in its tracks.
Most reputable news organizations provide official staff directories. If a reporter reaches out via an unofficial channel (like a random WhatsApp number), a source should follow these steps:
- Check the Official Bio: Visit the news organization’s official website and find the reporter’s bio page.
- Cross-Reference Contact Info: Many investigative reporters list their verified Signal handles or official email addresses directly on their bio pages.
- Verify the Email Domain: Ensure the email ends in the organization’s official domain (e.g., @reuters.com or @nytimes.com) rather than a generic @gmail.com or @outlook.com address.
- Request a Known Channel: Ask the person to send a message from a verified social media account or through the organization’s official contact form.
Key Takeaways for Digital Safety
| Red Flag | Safe Indicator |
|---|---|
| Refusal to do a live phone or video call | Willingness to verify identity via official channels |
| Request to click “secure” links for a meeting | Use of established, verified email domains |
| Contact from a number in an unexpected region | Contact info matches the reporter’s official bio |
| Urgent requests for sensitive data via text | Gradual rapport building with verifiable credentials |
The Long-Term Impact on Investigative Journalism
Beyond the immediate risk of data theft, these scams inflict a deeper wound on the profession of journalism. Investigative reporting depends on the willingness of courageous individuals to share secrets at great personal risk. If potential sources begin to fear that the “reporter” they are talking to is actually a foreign intelligence agent or a cybercriminal, they will stop talking.

Digital security expert Runa Sandvik suggests that journalists who are impersonated must be vocal about the attacks. By publicly flagging the existence of a “fake” version of themselves, reporters can protect their sources and warn the public. Silence only benefits the attacker.
As we navigate an era of deepfakes and AI-generated personas, the ability to prove one’s identity in a digital space will become as vital as the reporting itself. For now, the most effective tool against these scams remains a combination of skepticism and a few clicks of independent research.
The FBI and other international cybersecurity agencies continue to update their advisories on social engineering tactics. Those in sensitive government or defense roles are encouraged to monitor the latest bulletins from the Cybersecurity and Infrastructure Security Agency (CISA) for updated guidance on protecting encrypted communications.
Do you have experience with digital impersonation or tips on how to verify professional identities online? Share your thoughts in the comments below or contact our newsroom.