Privacy & Social · September 25, 2026
What to Do When Scammers Use Your Business Name in a Fake Giveaway
A practical response plan for documenting a fake prize promotion, warning customers, reporting impersonation, securing accounts, and reducing repeat harm.

Confirm that the giveaway is not authorized by your company or a partner. Preserve the fake account, post, advertisement, messages, links, and payment instructions without clicking or replying. Secure your real accounts, report the exact impersonation through official channels, and publish one clear customer warning on pages you control. Direct affected people promptly to their financial provider and appropriate government resources.
A fake giveaway can copy a company logo, employee name, product photo, social profile, or promotion page. The scammer may claim that a customer won a prize and then ask for a fee, gift card, cryptocurrency payment, password, verification code, or personal information. The FTC says a request to pay or provide financial information to claim a prize is a scam warning sign.
Impersonation and account compromise are different problems. A lookalike profile may have no access to the real account, while a compromised account can publish from an authentic profile. Check both possibilities before announcing what happened. An inaccurate warning can confuse customers and amplify the fake promotion.
In the United States, the FTC's Impersonation Rule prohibits material false claims that someone is a business or is affiliated with, endorsed by, or sponsored by a business. Platform rules and other laws may also apply, but the facts and location matter. This guide is general education, not legal advice. Serious financial harm, threats, identity theft, or repeated brand abuse may require qualified legal, security, or law-enforcement help.
A practical step-by-step approach
01Verify that the promotion is not authorized
Ask marketing, social media, customer service, franchise, and outside-agency contacts whether the giveaway is real. Compare the handle, profile URL, website domain, official rules, contact method, and dates with approved campaigns. Do not call something fake until the company has checked its own records and partners. Record who confirmed the result and when.
02Preserve evidence without engaging
Capture the full profile and post, exact URL, username, date, advertisement identifier when visible, direct messages, phone numbers, email addresses, lookalike domains, QR codes, and payment instructions. Save original files and a short timeline. Do not reply from a personal account, scan a suspicious code, download an attachment, or send a small payment to test the claim.
03Check and secure your real accounts
Review recent sign-ins, active sessions, administrators, recovery details, connected applications, scheduled posts, advertising accounts, and changes to contact information. Remove access that is no longer needed, reset affected credentials, and enable strong multifactor authentication. CISA recommends MFA for business accounts and advises using phishing-resistant methods where available.
04Map every place the scam appears
A campaign may use a social profile, paid ad, copycat website, email, messaging app, and payment destination. Build one private list with each exact location and its owner. Keep original evidence separate from public screenshots, and redact customer, financial, and security details before sharing.
05Report through the official channel
Use the platform's current impersonation, scam, trademark, or fraudulent-ad process that best matches the facts. For a lookalike domain, identify the registrar, host, or payment provider and submit a focused abuse report. Include proof that you represent the real business, the exact fake location, and the harm. Standards differ, so removal and timing cannot be guaranteed.
06Publish one clear customer warning
Place a short notice on the company website and verified social accounts. State that the named promotion is not authorized, identify the fake handle or domain in plain text, tell people not to pay, click, or share information, and provide the company's verified contact page. Do not make the warning link to the scam, repeat unsupported accusations, or repost harmful personal information. Update the notice if the facts change.
07Help affected people take the next safe step
Someone who paid should contact the bank, card issuer, payment app, gift-card company, or cryptocurrency service immediately and ask what protective steps are available. U.S. consumers can report fraud at ReportFraud.ftc.gov, report cyber-enabled crime to IC3, and use IdentityTheft.gov when personal information was misused. Recovery is never certain, so avoid promising that money or accounts will be restored.
08Reduce the chance of a repeat incident
Create one official promotions page that customers can use to verify active campaigns. Publish consistent rules, dates, eligible locations, and contact details for legitimate giveaways. Keep a current account-access list, protect email and social administrators with MFA, monitor brand-name variations, and give customer-service staff an approved response. Review the incident after it closes and assign an owner for continued checks.
Information to gather
A clear record makes it easier to choose the right channel, communicate accurately, and avoid unnecessary repetition. Start with:
- Confirmation from marketing, partners, franchisees, and agencies that the giveaway is unauthorized
- Fake profile, post, ad, message, domain, phone, email, and payment destination evidence
- Real-account login, administrator, recovery, connected-app, and advertising review
- Official platform, registrar, host, payment-provider, FTC, or IC3 report confirmations
- Approved customer warning with a verified company contact and no live scam link
- Victim guidance for payment providers, fraud reporting, and identity-theft recovery
- Official promotions page, access owner, monitoring schedule, and after-action review
What not to do
Pressure can lead to decisions that create a second reputation problem. Avoid:
- Contacting the scammer from a personal account or trying to trick the person into revealing an identity
- Clicking links, scanning codes, downloading files, sharing a verification code, or making a test payment
- Posting customer details, financial records, security data, or an active malicious link in the warning
- Organizing mass reports, submitting false legal claims, or threatening an unverified person publicly
- Assuming every similar promotion is fake before checking authorized partners and campaigns
- Promising removal, arrest, account recovery, repayment, search changes, or a deadline
Frequently asked questions
Should our business contact the fake giveaway account?
Usually no. Direct contact can expose an employee account, confirm that the scam is receiving attention, or create more opportunities for manipulation. Preserve the evidence and use official platform, provider, payment, and law-enforcement reporting channels. If contact is necessary for a legal or security investigation, let the authorized professional manage it.
What should a public warning about a fake giveaway say?
Identify the unauthorized promotion and exact fake handle or domain in plain text, say that the business will not ask winners to pay or share passwords or codes, and direct customers to one verified company contact. Keep the warning factual, brief, and easy to update. Do not include a clickable scam link or private victim information.
Where should a fake giveaway be reported?
Report the exact account, post, and advertisement through the platform's official scam or impersonation process. Report a lookalike domain, payment destination, or message through the responsible provider when appropriate. In the United States, fraud can be reported to the FTC and cyber-enabled crime to IC3. Use official websites reached independently, not links sent by the scammer.
What should a customer do after paying a fake giveaway fee?
The customer should stop contact, preserve receipts and messages, and contact the bank, card issuer, payment app, gift-card company, or cryptocurrency service immediately. They can also report the incident at ReportFraud.ftc.gov and IC3.gov, and use IdentityTheft.gov if personal information was misused. Those steps may help, but they do not guarantee recovery.
Can a reputation company guarantee that a fake giveaway will be removed?
No. A responsible provider can document the campaign, secure company-controlled accounts, prepare accurate reports, publish a customer warning, coordinate legitimate escalation, and monitor for copies. Outcomes depend on the evidence, account status, platform rules, providers, applicable law, search engines, and other third parties. No provider can guarantee removal or timing.
Primary resources
Policies and features can change. Review the current source before submitting a request:
- FTC: fake prize, sweepstakes, and lottery scams
- FTC: Impersonation of Government and Businesses Rule
- FTC: business guidance on the Impersonator Rule
- FBI IC3: report cyber-enabled crime
- CISA: require multifactor authentication
- FTC: IdentityTheft.gov recovery help