The Cyber Security Authority (CSA) has issued a public alert over a sharp rise in restaurant and food-vendor impersonation scams, warning that cybercriminals are manipulating online business listings to defraud unsuspecting customers.
According to the Authority, 112 cases involving vendors and customers were recorded between January and June 2026, up from 61 cases during the same period last year. Financial losses linked to the scam also surged from GH¢84,592.00 in the first half of 2025 to GH¢296,083.68 this year.
In the alert, the CSA said it was “tracking a growing scam in which cybercriminals create and, in some cases, alter the contact details of legitimate restaurants and food vendors on Google Search, Google Maps, and other online platforms to trick unsuspecting customers.”
The Authority explained that fraudsters manipulate online business listings by exploiting Google’s “suggest an edit” feature, claiming “unclaimed business profiles,” or creating duplicate listings that replace genuine contact numbers with fraudulent ones. In some instances, the criminals also purchase sponsored search advertisements to push the fake listings to the top of search results.
As a result, customers unknowingly contact the fraudsters, believing they are dealing with legitimate restaurants or food vendors.
The CSA said that after taking customers’ orders, “the fraudsters instruct them to make payment to a specified mobile money number. Once payment is made, the fraudsters discontinue communication, and the food is never delivered.”
The Authority further warned that some victims are directed to fraudulent payment pages disguised as order confirmation or payment processing portals.
According to the advisory, “the malicious payment page requests information such as the customer’s name, delivery address, and mobile money number.” It added that “once the victim submits the requested information, the fraudsters use the credentials to perform unauthorised transactions, resulting in financial losses.”
To reduce the risk of falling victim to the scam, the CSA urged the public to verify restaurant and food vendor contact details through official websites, verified social media pages or trusted food delivery platforms before placing orders.
It also advised customers to “be cautious of payment requests through unfamiliar links,” “insist on payment after delivery and inspection,” and “never share your mobile money PIN, OTP, banking credentials or other personal information on any website or with any individual.”
The Authority further cautioned the public to “not approve payment prompts you did not initiate” and to regularly monitor their mobile money accounts for unauthorised transactions, reporting any suspicious activity immediately to their mobile network operator.
For restaurants, food vendors and other online businesses, the CSA urged operators to “claim and verify your Google Business Profile” to maintain control of their listings, prominently display official contact numbers and approved payment channels, and regularly check for unauthorised edits or duplicate business profiles.
The Authority also encouraged businesses to report fraudulent listings and unauthorised changes to Google through its Business Redressal Complaint Form.
The CSA reminded the public that its 24-hour Cybersecurity/Cybercrime Incident Reporting Point of Contact remains available for reporting cybercrime incidents and obtaining assistance through Call or Text: 292, WhatsApp: 0501603111, or Email: report@csa.gov.gh. The advisory was issued under reference CSA/CERT/MPA/2026-07/02.






