The Cyber Security Authority (CSA) has issued a public alert over a growing wave of online scams in which fraudsters impersonate legitimate restaurants and food vendors to defraud unsuspecting customers.
According to the Authority, cybercriminals are creating or altering the contact details of genuine restaurants on Google Search, Google Maps and other online platforms, causing customers to unknowingly place orders with scammers instead of the actual businesses.
The CSA said it recorded 112 reported cases involving vendors and customers between January and June 2026, a sharp increase from the 61 cases reported during the same period in 2025. Financial losses also rose significantly from GH¢84,592 to GH¢296,083.68.
In a public alert issued on July 16, the Authority explained that fraudsters exploit Google’s “suggest an edit” feature, claim unverified business profiles or create duplicate fraudulent listings by replacing legitimate contact numbers with fake ones.
The scammers also purchase sponsored search advertisements in some instances to ensure the fake contact details appear at the top of search results.
Unsuspecting customers who call the listed numbers are instructed to place food orders and make advance payments through mobile money. Once payment is made, communication ceases and the ordered food is never delivered.
In other cases, victims are directed to fraudulent payment links under the guise of confirming orders or processing payments. These fake websites request personal information, including names, delivery addresses and mobile money numbers.
The CSA warned that once victims submit the requested information, the fraudsters use the credentials to carry out unauthorised transactions, resulting in financial losses.
To protect the public, the Authority advised customers to verify restaurant and food vendor contact details through official websites, verified social media accounts or trusted food delivery platforms before placing orders.
It also urged the public to avoid making payments through unfamiliar links, insist on paying after delivery and inspection where possible, and never disclose mobile money PINs, one-time passwords (OTPs), banking credentials or other sensitive personal information.
The Authority further advised customers to reject payment prompts they did not initiate, confirm payment instructions directly with vendors using independently verified contact details, and regularly monitor their mobile money accounts for suspicious transactions.
For restaurants, food vendors and other online businesses, the CSA recommended claiming and verifying their Google Business Profiles, displaying official contact numbers and approved payment channels on verified platforms, and regularly monitoring their online listings for unauthorised edits or duplicate profiles.
Businesses were also encouraged to report fraudulent listings or unauthorised changes to Google through its Business Redressal Complaint Form.
The CSA reminded the public that its 24-hour Cybersecurity and Cybercrime Incident Reporting Point of Contact is available for reporting cybercrime incidents and seeking guidance. Victims can call or text 292, send a WhatsApp message to 0501603111, or email report@csa.gov.gh.


READ ALSO:
Bawumia calls for discontinuation of prosecutions undertaken in his name







