Journalist Impersonation: The New Threat to Investigative Reporting

by ethan.brook News Editor

A phone call from an unfamiliar Canadian area code served as the first warning for Robert Faturechi, an investigative reporter at ProPublica. The caller, identifying himself as a Canadian military official, had a specific question: Had Faturechi been reaching out via WhatsApp to solicit information?

The encounter was the beginning of a troubling pattern of impersonating this ProPublica reporter, a tactic where scammers leverage the perceived trust and authority of investigative journalists to deceive high-value targets. In this instance, the impostor wasn’t seeking money through traditional means, but appeared to be targeting individuals with sensitive knowledge of foreign militaries and defense technology.

The deception involved the leverage of Faturechi’s official ProPublica headshot and name to create a veneer of legitimacy. The targets included a Canadian defense official and a Latvian businessman involved in providing equipment and drone development for the Ukrainian military. In both cases, the impostor attempted to move the conversation toward secure messaging apps to avoid detection and eventually attempted to compromise the targets’ digital security.

This evolution in online deception highlights a growing risk for both journalists and their sources. By spoofing the identities of reporters, bad actors can bypass the natural defenses of government officials and industry experts who might otherwise be wary of unsolicited contact but are willing to speak with a recognized member of the press.

The Anatomy of the Impersonation

The tactics used by the impostor shifted across different platforms, moving from WhatsApp to Signal and LinkedIn. In the first instance, the scammer used a Miami-based phone number to contact the Canadian official, claiming, “This is Robert Faturechi from ProPublica. I really need to get in touch with you.”

The Anatomy of the Impersonation
A screenshot of the conversation between a Canadian official and Fake Robert. Obtained and redacted by ProPublica

Two weeks later, a different approach was used with a Latvian businessman. The impostor contacted the target on Signal, asking about expertise in unmanned aerial vehicles (UAVs) and expressing interest in their application in Ukraine. When the target requested a phone call, the impostor refused, stating they were not “comfortable” speaking on the phone and insisted on written communication or voice messages.

The scam culminated in a phishing attempt. When the Latvian businessman insisted on a video call, the impostor provided “step-by-step instructions” for a secure chat. These instructions were actually designed to trick the user into surrendering access to their email account. The target eventually blocked the account, averting the breach.

A Pattern of Global Journalist Spoofing

Faturechi’s experience is not an isolated incident. News organizations globally have reported similar campaigns where reporters are used as “bait” to gather intelligence or compromise accounts. Recent examples include:

  • The New York Times: Recently flagged an account on X (formerly Twitter) falsely claiming to be an intern for the organization.
  • Reuters: In 2023, the agency reported that two of its reporters in China were impersonated via Instagram and Telegram to target activists protesting COVID-19 policies. More recently, a Reuters correspondent in Saudi Arabia warned followers of a WhatsApp impersonator.
  • Bellingcat: The investigative group has also received reports of email scams impersonating its staff.

While some of these are little-scale deceptions, others are linked to state-sponsored activity. The German government issued a warning this year regarding likely state-sponsored actors attempting to commandeer Signal accounts of European officials and reporters. Similarly, the FBI announced that individuals associated with Russian intelligence posed as Signal’s security department to trick American government officials and journalists into providing account-takeover information.

The Privacy Paradox of Secure Messaging

The use of Signal and WhatsApp in these scams highlights a fundamental tension between user privacy and platform security. Signal is designed to store as little information as possible. it knows the phone number used to create the account and the date of creation, but it does not store who a user is messaging.

The Privacy Paradox of Secure Messaging

Cooper Quintin, a technologist at the Electronic Frontier Foundation, noted an upswing in scams on the app as its popularity grows. While Signal has implemented features to slow down spammers and make links from unknown senders unclickable, the platform’s commitment to privacy makes it difficult to detect impersonators without compromising the particularly encryption that makes the app safe for journalists.

Digital security expert Runa Sandvik, who consults for ProPublica, noted that while platforms like Instagram or Facebook use verification badges to confirm identities, such a system is not feasible for Signal. Implementing verification would require the nonprofit to collect more user data and employ a staffing level it does not currently possess, thereby eroding the privacy protections users rely on.

WhatsApp, conversely, monitors for suspicious behavior—such as launching many accounts from a single location—to root out scammers. A spokesperson for WhatsApp stated the company has a “strong track record of banning those trying to scam others” and took “appropriate action” against the account spoofing Faturechi, though they declined to specify the exact nature of that action.

How to Verify a Journalist’s Identity

Because secure apps cannot easily verify identities, the burden of verification falls on the recipient. For those contacted by someone claiming to be a reporter, the most effective defense is independent verification through the news organization’s official channels.

Most reputable investigative outlets provide a public directory of their staff. At ProPublica, every journalist has a bio page that lists their official email address (ending in @propublica.org) and their verified Signal handle or phone number. By comparing the contact information of the person reaching out with the information listed on the official bio page, a source can quickly determine if they are speaking with the real reporter or an impostor.

This process of “doing your own reporting” is the most reliable way to scuttle a scam. If a reporter refuses to use a verified organizational email or insists on using a platform that contradicts their official bio, it is a significant red flag.

The impact of these scams extends beyond the individual. For investigative journalists, the primary currency is trust. When sources—often courageous individuals taking personal risks—begin to doubt the identity of the reporters they are contacting, the flow of critical information to the public may be stifled.

As these phishing and impersonation tactics evolve, security experts suggest that journalists should be public about these incidents. By alerting the public to specific impersonation attempts, reporters can protect their sources and warn others of the current tactics being used by bad actors.

The next critical step in addressing these threats involves ongoing updates from the FBI and European security agencies regarding state-sponsored phishing campaigns. Users are encouraged to monitor official government security advisories and the IC3 portal for new patterns of digital deception.

Do you have experience with digital impersonation or a tip about secure messaging scams? Share your thoughts in the comments or contact our newsroom.

You may also like

Leave a Comment