A customer sends a screenshot. Your logo is in the ad. Your name is in the headline. The offer is fake, the landing page is worse, and somebody has already asked whether it came from you.
Do not begin with a committee meeting. Start a clock.
On September 24, the Federal Trade Commission opened an inquiry into whether advertising platforms help impersonation scams spread through their optimization tools. The agency reported more than one million imposter-scam complaints and nearly $3.5 billion in reported losses during 2025. Nearly 30 percent of people who reported losing money said the first contact happened on social media.
The FTC is considering future platform obligations. Your customer has a fake checkout page open right now. Here is the first-hour plan.
Preserve first. Report second. Speak only when a warning will help someone avoid harm.
Minutes 0 to 10: preserve the ad before it moves
Scam ads change creative, domains, accounts, and destinations quickly. A cropped screenshot of the logo will not carry the whole case.
- Capture the full ad, including the account name, disclosure label, timestamp, platform, call to action, and any visible ad-library identifier.
- Copy the display URL and the actual landing-page URL. Do not enter credentials, payment information, or personal data.
- Record the device, browser, search query, audience location, and the person who found it.
- Save the customer report and ask what they clicked, entered, downloaded, or paid for.
- If the ad appears on Meta, search the Meta Ad Library by business name, offer language, and advertiser name. Capture related active ads.
Give the evidence folder a plain name: platform-date-advertiser. Put screenshots, URLs, correspondence, and report numbers inside it. One source of truth beats nine frantic email threads.
Minutes 10 to 20: decide what kind of problem you have
Not every confusing ad is impersonation. An old agency account, an unauthorized affiliate, a counterfeit seller, and a criminal checkout require different follow-up.
Answer five questions:
- Does the advertiser claim to be your organization or merely mention it?
- Does the landing page copy your logo, staff, domain style, product photos, or contact information?
- Is it collecting money, passwords, donor information, health details, or customer data?
- Could a former vendor, franchisee, chapter, reseller, employee, or campaign partner have launched it?
- Has anyone lost money, exposed an account, or downloaded a file?
If credentials, payment, malware, or regulated information may be involved, bring in counsel, security, finance, and the relevant insurer. This article is a communications workflow, not legal advice or an incident-response substitute.
Minutes 20 to 35: file reports that can survive a handoff
Use the platform report flow for the ad and the advertiser. When a trademark or copyright complaint fits, route that separately. Save every confirmation screen, case number, and email.
For Google Ads, reference the current misrepresentation policy. It explicitly prohibits advertisers from pretending to be another brand or business or implying an affiliation they do not have. Keep the report factual: who owns the name, what the ad says, where it lands, how the destination copies the business, and what harm has occurred.
Also report the scam at ReportFraud.ftc.gov when it targets U.S. consumers. The platform report seeks removal. The FTC report creates a government record. Do both when the facts support both.
Do not organize a staff pile-on. Twenty duplicate reports from colleagues can create noise without adding evidence. Assign one owner, one backup, and one case log.
Minutes 35 to 45: close the doors the fake ad is borrowing
Customers judge the fake against your real presence. Make the real one easy to recognize.
- Confirm the official website, phone number, email domains, donation pages, payment methods, and social accounts.
- Check whether domain lookalikes, misspellings, or copied landing pages are live.
- Review account administrators, agency access, billing users, and recent password or recovery changes.
- Brief reception, sales, customer service, and gift-processing teams. Give them the fake offer, the official offer, and a short escalation line.
- Tell staff not to argue with the scam account or improvise public replies from personal profiles.
The FTC has warned consumers that social ads are not always thoroughly vetted and that scammers can impersonate real brands. Verification badges and polished creative can help people feel comfortable. They do not replace checking the destination and seller.
Minutes 45 to 60: make the communication decision
A public statement is useful when people could still be harmed. It is unnecessary when nobody saw the ad, the platform removed it, and a post would mainly advertise the scam.
Publish a warning when one or more of these is true:
- customers or donors are actively asking whether the offer is real;
- the fake ad is still running or appears under several accounts;
- money, credentials, or sensitive information may have been collected;
- the scam copies a current campaign closely enough to fool a reasonable person; or
- frontline staff need one official message to share.
Keep the warning short. Name the fake offer. State what your organization will never request. Link to the official page. Tell affected people how to contact their bank, reset credentials, or report the incident. Do not link to the scam or repost its full creative unless counsel and security agree there is a clear reason.
A useful statement sounds like this:
We are aware of a paid ad using our name to promote [fake offer]. It is not ours. Our official offers and payment links appear only at [official domain]. If you entered payment or account information through the ad, contact your financial institution and report the incident at ReportFraud.ftc.gov. Send screenshots to [official contact].
What to track after the first hour
Removal is one milestone. It does not tell you whether the scam reached ten people or ten thousand.
- report and takedown timestamps;
- advertiser names, ad-library IDs, creative variants, and domains;
- customer contacts, confirmed losses, credential exposure, and chargebacks;
- copies of public warnings and internal scripts;
- repeat appearances during the next 30 days; and
- which monitoring, access, domain, and approval gaps need repair.
Then run the drill without an active incident. Search your brand in major ad libraries. Verify who owns platform accounts. Put the evidence checklist, reporting links, counsel contact, insurer contact, and customer-service script in one place. Set a quarterly owner.
The FTC may change platform duties. Your first hour still belongs to you.
The FTC inquiry asks whether platforms should vet advertisers, monitor ads, investigate suspected impersonation, remove confirmed scams, and discipline repeat offenders. Those would be meaningful changes. They are not a reason to wait.
Your response needs an evidence owner, a reporting owner, a customer-protection decision, and a clean official source of truth. Four jobs. One clock.
For the broader decision about whether a brand should comment publicly, use our speak-or-stay-silent brief. If copied reviews or endorsements are part of the scam, the fake-reviews rule breakdown covers the next set of receipts to preserve.
Would your team know what to do in the first hour?
SigServe can build the response brief, reporting workflow, customer language, and practice drill before a fake ad puts the process to a live test.
