- Recognize why platform ad targeting makes impersonation scams more effective.
- Understand what the FTC is asking platforms to do, and what’s unchanged.
- Decide what verification signals to publish so customers can spot fakes.
A homeowner searches for a local plumber online. A paid ad appears near the top of the results. It shows a familiar company name, the right logo, and a price quote that looks reasonable. She clicks through, fills out a form, and pays a $200 deposit on a checkout page that matches the company’s branding.
Two days later, nobody shows up. She calls the real plumbing company. The owner has no record of the job, no deposit, and no idea the ad exists.
He pulls up the search results on his own phone. There it is: his company name, his logo, his service area. The ad links to a site he has never seen. Someone bought that ad, built that page, and collected that money. He is now fielding an angry call from a customer he never had, about a transaction he never made.
(This is a hypothetical composite, but it reflects a pattern the FTC has flagged in its guidance on business impersonation scams.)
This article is for founders and small business owners who want to understand the new FTC inquiry into platform-driven impersonation, learn where the real risks are, and build a simple verification policy that protects their business starting today.
A fake flyer tricks a few people. A fake ad finds the right ones.
Think about a fake flyer stapled to a telephone pole. It might fool a few people who happen to walk by. Most won’t notice it. The reach is limited by foot traffic and geography.
A fake ad inside a platform’s targeting engine is different. The platform studies user behavior, figures out which people are most likely to click and pay, and then serves the ad directly to those people. That is what ad optimization does: it finds the ideal customer and puts the message in front of them. The same system that makes your real ads effective can make a fraudulent ad devastatingly effective too.
The distinction matters. A platform is not just a bulletin board where someone pins a flyer. It is an active delivery system. When a fraudulent ad enters that system, the platform’s own tools can push it toward the people most likely to fall for it. If you run Facebook or Google ads yourself, the same targeting tools that find your customers can find them for an impersonator. That’s worth understanding if you rely on platform advertising to grow your business.
The FTC is asking a question it has never asked before
On September 24, 2026, the Federal Trade Commission published what is called an Advance Notice of Proposed Rulemaking, as shown in the timeline below. That is the earliest possible stage of federal rulemaking. It means the FTC is asking the public a question, not writing a rule. No new obligations exist yet for platforms or businesses.
The question: should online platforms be required to do something about ads that impersonate real businesses and government agencies? The FTC is looking at five specific measures that platforms might be required to take:
- Verify the identity of advertisers before their ads go live
- Screen or monitor ads for signs of impersonation
- Investigate ads that are flagged as suspected scams
- Remove confirmed impersonation ads
- Discipline advertisers who run impersonation ads
The comment window stays open for 60 days after the notice appears in the Federal Register. Anyone can submit feedback, including small business owners. You can read the full FTC announcement here.
“Today’s advance notice of proposed rulemaking asks whether the Commission should require platforms to take concrete steps to prevent impersonation ads from ever reaching consumers.”
To be clear: this is not a law. It is not a final rule. It is not even a proposed rule. It is the FTC raising its hand and asking whether platforms should share responsibility for catching fake business ads before customers see them. The agency has been moving in this direction for a while. In February 2024, it proposed separate protections against AI-generated impersonation of individuals, which shows a broader pattern. The FTC has also fined ad firms for selling deceptive AI tools to small businesses.
The legal floor already exists. An impersonation rule took effect on April 1, 2024. It bans falsely posing as a business or government entity. It also bans false claims of affiliation, endorsement, or sponsorship. The FTC can now take impersonators to federal court and try to recover the money they collected.
But the current rule targets only the person doing the impersonating. It says nothing about the platform that delivered the ad. The con artist is already breaking the law. The platform that amplified the con is not. That is the gap the FTC’s new inquiry is trying to measure.
Fake ads are just the start
Paid ads on search engines and social media are the most visible form of impersonation. The opening scenario covered that. But a paid ad is only one of at least five doors someone can walk through using your business name.
Cloned social media profiles are common and surprisingly easy to build. Someone creates a Facebook page or Instagram account using your company name, copies your profile photo, and starts responding to customer questions or running promotions. A fake Google Business listing can do the same thing, showing a fraudulent phone number when someone searches for your company.
Spoofed invoices are another path. Your customers receive an email that looks like it came from your company, with your logo and formatting, asking them to pay an outstanding balance. The bank details on the invoice belong to someone else. The customer pays, assumes everything is fine, and only discovers the problem weeks later when the real invoice arrives.
Then there is the version that targets your own team. Someone sends an email that appears to come from your CEO or a trusted vendor. The message asks your bookkeeper to wire funds to a new account, or to update payment details for a recurring bill. This is sometimes called CEO fraud or business email compromise. The request feels routine, the email looks right, and the money moves before anyone asks a second question. Fake invoices targeting small businesses are more common than most owners realize, as one restaurant owner learned when a fraudulent invoice nearly cost the business thousands.
Fraudulent refund and credential requests round out the list. Someone contacts your support team pretending to be a customer and asks for a refund to a different card or account. Or they pose as a partner and request login credentials for a shared tool. These attacks come into the business disguised as normal operations.
Impersonation also happens over the phone and through text messages. It is not limited to digital ads.
A 30-minute policy that outlasts any rule change
You do not need to wait for the FTC to act. The single most useful thing you can do is make your real business easier to identify than a fake one. A simple verification policy does that. You can build one in about 30 minutes, with no budget and no outside help.
One of the strongest moves is publishing what your business will never ask for. When customers know that you will never request gift cards or wire transfers, they can spot a fake request immediately. Scammers who impersonate businesses often send official-looking letters and invoices that rely on the customer not knowing what the real company would actually do.
- Publish your official domain, phone number, email address, and support channels on your website and on every receipt or invoice you send
- State clearly what your business will never ask for, such as gift cards, wire transfers, passwords, or Social Security numbers
- Create a short “How to verify it’s really us” page on your website that customers can check when they receive an unexpected message
- Require two people to approve any change to payment instructions from a vendor or client before money moves
- Name one person on your team as the escalation contact when anyone suspects impersonation
- Set up a free Google Alert for your business name so you find out quickly when someone else uses it
None of this requires a security consultant or a special budget. It is a policy you write, publish, and share with your team in a single sitting.
Screenshot first. Report second. Warn customers third.
If you discover that someone is using your business name right now, follow that sequence. Evidence disappears fast. Fake ads get paused. Fake profiles get deleted. Screenshots are the first thing you need.
Capture the full URL, the timestamp, any ad identifiers or post IDs, and the content of the page or message. If there is a checkout page, screenshot that too. Save everything to a folder with the date.
Next, file a report through the platform’s fraud or impersonation reporting tool. Every major platform has one. Note the ticket number or confirmation you receive.
If money was diverted, call your payment processor or bank immediately. Time matters. The sooner you flag the transaction, the better your chance of stopping or reversing it.
Finally, file a report at ReportFraud.ftc.gov. A platform report does not guarantee the fake ad or account will be removed, and it does not guarantee you will recover any funds. The FTC report creates a record that helps regulators track patterns.
If platforms start checking IDs, your next ad campaign might wait
There is a real tension in what the FTC is exploring. If platforms must verify every advertiser’s identity before an ad goes live, that process takes time. A small business launching a seasonal promotion or a time-sensitive campaign could face delays that a larger company can absorb more easily.
“Scammers pretend to be someone you know or trust and try to scare or rush you into paying or giving them information.” The FTC’s own guidance describes the problem. The question is whether the fix creates new friction for the businesses it is meant to protect.
Advertising costs could also rise. More verification means more overhead for platforms, and platforms tend to pass costs along. And there is the false-positive problem. Content-moderation sweeps have already caught legitimate sellers by mistake, suspending accounts or pulling ads that broke no rules. If you have ever had a Facebook ad flagged or a Google Merchant account suspended for no clear reason, you already know what over-broad enforcement feels like. A founder could end up fighting two battles at once: one against the impersonator and one against the platform’s verification system.
Nothing to comply with yet, but the direction is clear
You do not need to file a comment unless you want to. There is nothing to comply with right now.
But the FTC’s direction is visible. Between the 2024 impersonation rule, the 2024 proposal on AI-generated fakes, and now this inquiry into platform responsibility, the agency is steadily expanding its focus from the people committing fraud to the systems that deliver it.
Whatever comes out of this process, the verification policy you build today still works. Publishing your official channels, telling customers what you will never ask for, and requiring two-person approval on payment changes protects your business whether or not a new rule ever takes effect.
