← Back to news
The Register - Security26 Sept 2026 · 2 min read

Impersonation Ad Poses as Google Security Team While Displaying Voice Phishing Script

A fraudulent advertisement impersonating Google’s security team has drawn attention for an apparent contradiction: it claims that representatives do not read from scripts during voice-phishing calls,...

A fraudulent advertisement impersonating Google’s security team has drawn attention for an apparent contradiction: it claims that representatives do not read from scripts during voice-phishing calls, while also presenting language that can be used as a call script.

The ad appears designed to lend credibility to phone-based social engineering, commonly known as vishing. Such scams typically rely on a caller claiming to represent a trusted company, financial institution, government agency, or technology provider. The caller may then attempt to persuade a target to disclose passwords, verification codes, payment information, or to install remote-access software.

How voice phishing uses trusted brands

Brand impersonation is a common tactic because familiar names can reduce skepticism. Attackers may use paid advertisements, spoofed phone numbers, cloned websites, and urgent warnings about account activity to make their messages appear legitimate.

The wording in the ad illustrates another risk: scam materials can be distributed openly while being framed as security guidance or customer-support information. Claims that a legitimate company uses a particular calling approach should not be treated as proof that an unexpected call is genuine.

Steps to reduce exposure

  • Do not provide passwords, multi-factor authentication codes, or recovery codes to an unsolicited caller.
  • End unexpected support or security calls and contact the organization through a phone number or website you locate independently.
  • Be cautious of requests to install remote-management tools, download files, or move funds to a so-called safe account.
  • Verify account alerts by signing in directly through an official app or bookmarked site, rather than following links or instructions from a caller.
  • Report suspected impersonation ads and calls to the platform hosting the ad and to relevant consumer-protection or anti-fraud authorities.

Organizations can help limit these campaigns by monitoring for brand abuse, educating customers about support procedures, and making legitimate contact channels easy to find. Users should assume that unexpected calls involving account security require independent verification, regardless of the name displayed on the screen or cited by the caller.

Share this article:TwitterLinkedIn