Communication

Cyber Security Authority Warns of Rising Restaurant and Food-Vendor Impersonation Scams

2 min read
Share this article:

The Cyber Security Authority (CSA) has issued a public alert over a surge in restaurant and food-vendor impersonation scams, warning that unsuspecting customers are increasingly being tricked into making fraudulent payments.

According to the Authority, cybercriminals are exploiting platforms such as Google Search and Google Maps by altering or duplicating legitimate business listings. In many cases, they abuse the “suggest an edit” feature, claim unverified profiles, or create duplicate listings with fake phone numbers. Some even purchase sponsored ads to push fraudulent details to the top of search results.

Between January and June this year, the CSA recorded 112 cases of such scams, nearly double the 61 cases reported during the same period last year. Financial losses have also surged, rising from GHS 84,592.00 to GHS 296,083.68. Victims typically contact the fraudsters believing they are legitimate vendors, place food orders, and are then instructed to pay via mobile money or through fraudulent links.

“Once payment is made, communication ceases, and the food is never delivered. In some instances, malicious payment pages harvest personal details such as names, delivery addresses, and mobile money numbers, which are later used to carry out unauthorised transactions,” it added.

The CSA has urged the public to verify vendor contact details through official websites, verified social media pages, or trusted food delivery platforms before placing orders.

Customers are advised to avoid unfamiliar payment links, insist on paying only after delivery, and never share sensitive information such as mobile money PINs, OTPs, or banking credentials. The Authority also recommends that customers monitor their accounts regularly and report suspicious activity immediately to their mobile network operators.

Restaurants and food vendors have been encouraged to claim and verify their Google Business Profiles to prevent impersonation, display official contact numbers prominently, and monitor their listings for unauthorised edits or duplicates.

“Fraudulent listings can be reported to Google through its Business Redressal Complaint Form,” the Authority noted.

The CSA reminded the public that it operates a 24-hour Cybersecurity/Cybercrime Incident Reporting Point of Contact for guidance and assistance. Reports can be made via call or text to 292, WhatsApp on 0501603111, or email at report@csa.gov.gh.

Margaret Adjeley Sowah, ISD