For businesses building their brands online, having a website and social media page may no longer be enough.
The Cyber Security Authority (CSA) is urging Ghanaian businesses, particularly online retailers and small enterprises, to actively monitor their digital identities, secure their payment channels, and verify the people delivering their products as fraudsters increasingly impersonate legitimate brands.
Mr. Stephen Cudjoe-Seshie, Deputy Director-General in charge of Technical Operations at Ghana’s Cyber Security Authority, told The High Street Journal that businesses should consider their digital reputation as part of their core operations rather than something to address only after customers have been defrauded.
The warning comes as online commerce and digital customer engagement expand in Ghana, creating new opportunities for businesses but also more channels through which criminals can mimic legitimate companies.
The CSA reported in April that it had received 54 cases of fraudulent online business impersonation between January 1 and April 26, resulting in financial losses of GH¢266,195.
Mr. Cudjoe-Seshie said one of the first protections for an online business should be ensuring that its payment identity is clearly connected to the registered company.
“If you have a registered business, you should be able to use that registration to register a mobile money number,” he said.
He warned businesses against directing customers to make payments into personal accounts when the transaction is being conducted on behalf of a company.
The logic, he explained, is not simply about making a business appear more professional. A corporate identity gives customers and authorities something traceable when a transaction goes wrong.
“If you use a company’s name, for example, then if something goes wrong, we can trace that institution,” he said.
The same principle applies to businesses’ logistics arrangements.
Mr. Cudjoe-Seshie said online businesses should be careful about the riders and courier operators they use because the delivery process can also become a source of fraud or reputational damage.
A customer who orders a product from an apparently legitimate online business may encounter a fraudulent or unreliable delivery operator and subsequently associate the experience with the original brand.
“That impacts your brand,” he said.
Businesses, therefore, need to know who is handling their deliveries and whether those operators are properly registered.
But one of the biggest risks may occur before a customer even contacts the business.
The CSA has previously warned that criminals can create fake business profiles on Google Maps and manipulate search engine results so that fraudulent phone numbers appear prominently when customers search for legitimate companies.
Mr. Cudjoe-Seshie said businesses should therefore periodically search for themselves online and use digital reputation-management tools to detect fake accounts, websites, or profiles using their names and logos.
“Periodically, you should run a search for your business,” he said. “If somebody has also created a company with the same name on Instagram, for instance, then you know someone is impersonating you.”
The advantage, he said, is that the company can report the impersonation before customers begin losing money.
He said businesses have to take greater responsibility for protecting their own digital presence.
That includes the security of the systems behind the online storefront.
A phishing email that compromises an employee’s credentials can give criminals access to corporate accounts, potentially allowing them to take control of websites, social media accounts, or email communications.
Business email compromise also presents a risk to companies engaged in larger transactions, as criminals can monitor communications and intervene when they identify an opportunity to redirect a payment.
Mr.Cudjoe-Seshie said businesses should use strong passwords and multi-factor authentication and independently confirm any changes to payments associated with third-party relationships.
“If you are doing a transaction, it always pays to call in to the other side to confirm that you are still on the same page,” he said.
The guidance carries added weight for SMEs, where limited cybersecurity capacity can make it harder to identify and respond to digital threats.
Digital security is becoming part of how customers judge the credibility of an online business. A fraudulent listing, compromised email account, or altered payment channel can expose customers to losses while leaving the legitimate business to deal with the reputational damage.
The CSA is therefore urging businesses to take a more proactive approach to protecting their digital identity, rather than waiting for impersonation or fraud to occur before responding.
