A Google Business Profile can display the correct phone number and still send a customer toward a scammer. A newly documented Google Maps abuse pattern does not depend on winning an edit to the official contact field at all. Instead, contributors upload misleading images that visually contain a different phone number, betting that users will trust what looks like branded business artwork and dial the number shown inside the photo.
Search Engine Roundtable reported the case on September 10 after local-search practitioners surfaced an example involving a roofing company. According to the account, a Maps contributor uploaded an AI-generated image carrying the client’s business name alongside a phone number that did not belong to the company. The image then appeared prominently on the profile, reportedly looking close enough to a cover or primary image that a customer could reasonably mistake it for information supplied by the business itself.
The incident illustrates a subtle local-search security problem. The attacker does not necessarily need control of the Business Profile, access to the owner’s Google account or approval for a phone-number edit. User-contributed media becomes the delivery mechanism. If the image looks legitimate and its embedded number is more visually persuasive than the profile’s official contact information, the attacker can attempt to divert calls while the structured business data remains untouched.
The scam exploits the difference between profile data and what users actually see
Google Maps combines information from business owners, Google’s own systems and public contributors. Photos are therefore not automatically first-party assets just because they appear on a company’s listing. In the reported case, the contributor was said to have more than 150 photo contributions across unrelated U.S. businesses, with the same incorrect phone number appearing in images for other companies. Search Engine Roundtable characterized the pattern as systematic spam affecting dozens, potentially hundreds, of profiles.
That scale should be treated as a reported observation rather than a Google-confirmed campaign count. The source is a community incident documented through local-search professionals, not a published Google investigation with verified victim totals or loss figures. What the evidence does show is a repeatable mechanism: generate convincing business-themed artwork, insert a controlled phone number, upload it as contributor media and rely on Maps’ presentation to give the image credibility.
Importantly, this does not mean Google’s native Call button has been hijacked. If the official Business Profile phone number remains correct, that structured action can still point to the legitimate business. The risk arises when a user sees the fraudulent number inside a prominent image and manually calls it, believing the artwork is authoritative. That distinction is why ordinary audits that only verify the phone field can miss the attack completely.
AI image generation makes impersonation cheaper, not fundamentally new
Phone-number substitution and local listing fraud predate generative AI. What image generation changes is the cost of producing plausible-looking creative at scale. An attacker no longer needs design skill or access to authentic brand assets to create a polished image that resembles a promotional card, service advertisement or business announcement. A company name, generic industry imagery and a large call-to-action number can be assembled quickly and repeated across many listings.
The technique is particularly effective because users are accustomed to seeing text inside business photos: menus, storefront signs, service vans, flyers, price boards and promotional graphics all contain contact information in legitimate contexts. A fraudulent image can therefore blend into a media gallery without needing to imitate the Google interface itself. The attack is social engineering layered onto user-generated content rather than a conventional takeover of the listing database.
Google’s Maps user-generated content policies prohibit impersonation and misrepresentation, including content that distorts facts to scam users or tricks them through phishing and baiting. The reported images would appear to raise obvious policy concerns if their purpose is to impersonate businesses and redirect callers. The challenge described by the affected party was not the absence of a relevant rule, but getting the offending media removed quickly enough.
Reporting exists, but the reported case shows why businesses need their own monitoring loop
The business representative said the image had been reported and Google support contacted, but the response received at that stage was generic and did not resolve the specific problem. Uploading more legitimate photos, a logo and a cover image reportedly failed to push the fraudulent image out of its prominent placement. Search Engine Roundtable therefore presented the incident as an example of spam remaining visible despite attempts to flag it, rather than evidence that Google never removes this type of content.
Google provides official instructions for reporting inappropriate photos and videos: users can open the media on the business page, choose the reporting option and submit the issue for review. Google also says its Maps moderation combines machine-learning systems with trained human reviewers to identify policy-violating contributions. Those systems provide a formal remediation path, but a business facing an active call-diversion attempt has a reason to monitor independently rather than assume automated moderation will identify every malicious upload immediately.
A practical audit should therefore include the photo gallery as well as the structured profile fields. Multi-location brands in particular can periodically inspect the images customers see most prominently, look for unexpected phone numbers, URLs, QR codes or calls to action, and review suspicious contributor histories when the same creative pattern appears across locations. Screenshots, media URLs, contributor details and timestamps should be preserved before reporting so the business has a record if escalation becomes necessary.
Local SEO now has a fraud-monitoring dimension
This case expands the definition of Business Profile hygiene. Local teams traditionally monitor hours, categories, addresses, phone numbers, reviews and suggested edits because inaccuracies in those fields can cost visits and calls. User-contributed imagery deserves similar attention when Google can display it prominently enough to influence customer behavior. A correct database record is not sufficient if a misleading visual element competes with it on the same surface.
Businesses can also reduce ambiguity outside Maps. The official phone number should be easy to verify on the company website, location pages and other trusted first-party channels, while frontline staff should know to record reports from customers who encountered an unfamiliar number on Google. A sudden pattern of callers mentioning a different contact number can be an early signal that the problem is visual rather than a conventional profile edit.
The broader issue is not that AI-generated images have discovered a magical way to rewrite Google Maps. It is that generative tools make convincing user-generated impersonation inexpensive, while local search interfaces mix first-party and community media in a space users often treat as authoritative. That creates an attack surface between technically correct business data and human perception.
For local marketers, the lesson is straightforward: verify what customers see, not only what the Business Profile dashboard says. A scammer may never touch the official phone number and still attempt to capture the call. In this emerging abuse pattern, the malicious edit is not in the field—it is in the picture.