The Cyber Security Authority (CSA) has raised the alarm over a sharp increase in restaurant and food-vendor impersonation scams, with financial losses to customers and businesses climbing to GH¢296,083.68 in the first six months of 2026, emphasizing the growing cyber risks for Ghana’s digital commerce ecosystem.
According to the Authority, it recorded 112 reported cases between January and June this year, compared with 61 cases during the same period in 2025. The corresponding financial losses rose significantly from GH¢84,592.00 to GH¢296,083.68, reflecting the increasing sophistication of fraud targeting online food orders.
In a public alert, the CSA said cybercriminals are exploiting online business listings by impersonating legitimate restaurants and food vendors on platforms such as Google Search and Google Maps, deceiving customers into sending payments for orders that are never fulfilled.
The Authority explained that fraudsters manipulate business listings by abusing features such as “suggest an edit,” claiming “unclaimed business profiles,” or creating duplicate listings that replace genuine contact numbers with fraudulent ones. In some instances, the scammers also purchase sponsored advertisements so the fake contact details appear prominently in online search results.
Unsuspecting customers then contact the fraudulent numbers, believing they are dealing with the legitimate business. After placing orders, victims are instructed to transfer payment to mobile money accounts controlled by the criminals, after which communication is cut off, and no food is delivered.
The CSA further warned that some victims are directed to fraudulent payment links presented as order confirmation or payment processing portals. These fake websites collect personal information, including names, delivery addresses and mobile money numbers, enabling fraudsters to carry out unauthorised financial transactions.
The Authority advised consumers to verify restaurant contact details through official websites, verified social media pages or trusted food delivery platforms before placing orders. It also urged the public to avoid unfamiliar payment links, insist on payment after delivery where possible, and never disclose mobile money PINs, one-time passwords or banking credentials.
Customers were additionally encouraged to independently confirm payment instructions with businesses using verified contact details, avoid approving unsolicited payment prompts, and regularly monitor their mobile money accounts for suspicious transactions.
For restaurants, food vendors and other online businesses, the CSA recommended claiming and verifying their Google Business Profiles to secure control over their listings and reduce the risk of unauthorised alterations.
Businesses were also encouraged to prominently display official contact numbers and approved payment channels on their verified websites and social media platforms, while making it clear to customers that they would never request PINs or one-time passwords.
The Authority further urged businesses to routinely monitor their online listings for duplicate profiles or unauthorised edits and to report fraudulent listings or manipulated business information through Google’s Business Redressal Complaint process.
The alert highlights the growing importance of protecting digital business identities as online commerce expands, with fraudulent manipulation of business listings emerging as a growing threat to consumer confidence and the digital economy.
