Scam ads impersonate businesses and agencies. The FTC asks what platforms should do
The FTC is considering new platform duties for impersonation ads. It is not a final rule, but it matters to consumers, brands and advertisers now.
- AUTHOR
- Karol Rapacz / CEO Breachroad · OSCP · PNPT
- PUBLISHED
- 25 September 2026
- READING TIME
- 10 min read
- TOPIC
- Governance and Compliance
A fake ad in search results or on social media can look like an official message from a bank, public agency, retailer or airline. It leads instead to a scammer’s website, fake support number or form that steals information. The US Federal Trade Commission has opened a public discussion on whether platforms should have additional duties to limit these ads.
The distinction matters: the FTC has not announced a final rule. On 24 September 2026 it issued an Advance Notice of Proposed Rulemaking, an early step in a possible regulatory process. The Commission is gathering information before deciding whether to update its existing Rule on Impersonation of Government and Businesses, propose a separate rule or take other action.
Why the FTC is looking at the advertising system, not only the scammer
A platform is not a simple noticeboard that displays ads in the order received. Optimisation tools help an advertiser select audiences, adapt creative material and increase clicks or conversions. The same capabilities that support a legitimate campaign can extend the reach of a fake bank, retailer or government agency.
The FTC is asking about platforms’ financial incentives, how optimisation tools work, current fraud-prevention controls and whether particular practices may be unfair or deceptive. Potential measures mentioned for discussion include advertiser vetting, ad monitoring, investigation of suspicious campaigns, removal of confirmed impersonation ads and disciplinary action against the advertisers behind them.
That does not mean all of these duties will be adopted. The consultation exists to gather evidence about the scale of the problem, the effectiveness of current safeguards and the potential costs of different responses.
The scale shows this is not a collection of isolated mistakes
According to figures cited by the FTC, consumers made more than one million reports about imposter scams in 2025 and reported nearly $3.5 billion in losses. Almost 30% of consumers who reported losing money to scammers said that the first contact occurred on social media. Reported losses for that group reached $2.1 billion.
These are consumer-reported figures, not a complete audit of the market, and they are not statistics for every country. They do show why the word “sponsored” cannot be treated as automatic confirmation of an advertiser’s identity.
The problem also affects the businesses being impersonated. A victim will often call the genuine brand first, expect reimbursement and describe the event publicly. The organisation bears customer-support, reputation and evidence-gathering costs even though it did not launch the campaign.
What a person can do before clicking or paying
When an ad concerns a bank, government service, technical support, investment or unusually attractive offer, break the path laid out by the advertisement.
- Do not assume that a high position or sponsored label means the company has been verified.
- Open the official app, use a previously saved address or type the known domain yourself. Do not sign in through an ad when money or identity is involved.
- Inspect the complete domain, not only the logo and headline. A scammer can display a genuine brand name while linking to a similar address.
- Do not install remote-access software or disclose an authorisation code to someone you encountered through an ad or fake support line.
- Save the ad, destination URL and account identifier before reporting it. Campaigns can disappear quickly, and evidence helps both the platform and the real company connect related cases.
If money has already been sent, the first step should be an immediate call to the bank through an official channel, not continued conversation with the “agent.”
What a business can do before the law changes
A brand does not need to wait for the result of the US consultation. It should provide an easy-to-find impersonation reporting address and a simple customer guide: which domains and phone numbers are official, what its staff will never request and how a contact can be verified.
The response team should collect evidence in a consistent form: a screenshot of the ad, its destination, the advertising account name, date, country where it appeared and platform case number. A single report may look isolated, while a consistent series can demonstrate a campaign and support escalation.
Monitoring should cover lookalike domains, profiles and ads for the most frequently abused products. Marketing, customer support, legal and security teams need to know who files the report, who contacts victims and who assesses notification duties. They should not promise that every ad will disappear immediately because the company does not control the platform’s system.
An organisation that buys advertising should also protect its own ad account. Strong authentication, limited roles, regular administrator reviews and alerts for new campaigns make it harder to use a legitimate account to distribute a scam.
Why a US consultation has broader significance
The FTC proceeding concerns the United States market and law; it does not create duties in the European Union or other countries. The platforms, advertising systems and brands involved are global, however. The question of whether a service only removes reported abuse or must also prevent its distribution and optimisation will matter to compliance, marketing and security teams elsewhere.
For a business, the practical conclusion does not depend on the eventual wording of a rule. Brand impersonation should be handled as a repeatable incident scenario, with an owner, evidence requirements, response time and prepared customer communication.
Source facts and Breachroad’s conclusions
The FTC confirms the Advance Notice of Proposed Rulemaking, provides the 2025 figures and describes the questions and potential measures under discussion. Comments will be due 60 days after publication in the Federal Register. This is not a final rule or a finding that any particular platform is liable.
The advice for consumers, evidence-collection model, cross-team response and treatment of impersonation as an incident scenario are Breachroad’s conclusions. Related guides explain why a social media ad does not verify a shop and how to spot fake customer support replies on social media. Customer-service and marketing teams can practise safe responses through cybersecurity awareness training.


