
Texts and calls
The sponsored ad at the top that is not the real number
Updated 5 October 2026
The assumption is that the top result, the one with the small Sponsored tag, is the company own ad. It usually is, because buying the brand own name is the default move for any marketing department. The expensive part is that the same slot is also the cheapest place to impersonate the brand, which is why so many scam calls start with I searched and called the number on the page. The sponsored line is a paid position. It is not a verification. So treat it as an ad, find the real number on the brand own website, and only then dial.
What the sponsored slot actually is
The slot at the top of a Google results page with the small black Sponsored tag is not an editorial pick. It is a paid placement sold through an auction, and the only thing the auction requires to win is enough money per click. Any advertiser with a working payment method can bid on any keyword phrase, including the brand name of the company you are trying to reach.
That is why the same position that holds a legitimate ad from a bank, an airline or a software vendor can also hold an ad from a scammer that bought the same keyword phrase minutes earlier. The buyer is paying the platform, not the brand. The brand is not consulted, and the brand is not notified. The sponsored tag is the only honest thing on the screen, because it is the only thing that tells you what you are looking at.
Why a fake customer service number sits at the top
The economics favour the scammer. Customer service queries are urgent, emotional and predictable. People lose a card, miss a delivery, lock themselves out of an account, fear a fraud charge, and reach for the phone. They search the brand name plus a phrase like customer service, phone number or support, and dial whatever comes up first. The scammer who bought that exact phrase a few hours earlier gets the call.
The call lands at a small call centre staffed for one task: keep you on the line long enough to extract a one-time passcode, a card number or a remote screen session. Once that data leaves your mouth, the legal category you fall into is the most expensive one, an authorised push payment you made yourself, after forty minutes of expert lying, on a channel you thought was a company you were already a customer of.
The tells that take five seconds
Three tells do almost all the work. First, the sponsored tag. If the listing is at the top of the results and it carries that small label, it is an ad. It is not the verified listing of the company. Second, the URL the ad points to. Hover, do not click. The visible URL often shows the brand name, but the actual link in the status bar at the bottom of the browser is the one that decides where you would land. If it points at a domain that is not the brand own dot, walk away. Third, the phone number itself. If the number you are about to dial only appears inside the ad and nowhere on the brand own website, the ad is the scam, not the service line.
None of those tells require technical skill. They require you to slow down for the five seconds you would otherwise spend on autodial.
The redirect that loads on its own
The ad that pretends to be a help page is the more dangerous variant. The link inside the sponsored slot does not always point at the brand. Sometimes it points at a domain the scammer controls, which then redirects you to the real brand page after harvesting your browser fingerprint, your cookies and the referrer that tells the real site you came in through a paid search ad. The destination you eventually see on screen looks legitimate. The referrer tells the real site that you are a paid lead, which is information the scammer is selling back to itself or to the next layer of the operation.
That is why the only safe move is to type the brand name yourself, go to the brand own domain, and find the phone number on the contact page. The number on the contact page is the one the brand published. The number inside any ad you have not verified is a number somebody paid to put in front of you.
What the attacker does once you call
The script on the other end of the line is the same one the bank text scam uses, just at higher speed. They confirm your name from the dialled number, sometimes from a leaked data broker list. They ask for the last four of your card or the email on the account, the questions any real agent would ask, because they have read the same training material. Then they trigger a one-time passcode to your phone or email and ask you to read it back. The passcode is the door. Reading it to them hands it to them.
From there, the goal is a money movement you authorise. A Zelle or wire transfer for a fake overpayment, refund, fraud alert reversal or settlement. The whole thing takes about twelve minutes if you do not catch it.
How the bands keep getting through
Google publishes enforcement figures that look reassuring until you read what is being measured. The 2024 Google Ads Safety Report, summarised by Bleeping Computer, said Google blocked 5.1 billion ads and suspended 39.2 million advertiser accounts, with more than 700,000 permanent bans for AI driven impersonation scams. The Allure Security analysis of the same period found malvertising volume still rose 10 percent year on year, and forced redirects made up 81 percent of malicious ads in October 2024. The bands keep getting through because the bands are not the people who paid for the ads. They use stolen advertiser accounts that pass the basic legitimacy checks, accounts with a history, accounts that the platform treats as established buyers.
This is why brand bidding does not solve the problem. It just moves the scammer to the next account. The scammer has a portfolio. The brand has a marketing budget. The economics favour the scammer on every axis that matters, which is reach, account rotation speed and the cost of getting banned.
What the brand is actually defending
The defensive work the brand does is mostly invisible to the customer. Trademark programmes at Google and Microsoft let the legal team submit an expedited takedown request when an ad impersonates the brand, but the expedited path is hours, not minutes, and the median phishing campaign takes half its victims in the first hour. Continuous monitoring of paid search results across regions and devices is the part that costs real money, and it is the part most mid sized companies do not do well.
What the customer sees on the brand own site is a contact page that says the official number, a notice that the brand never advertises customer service by search ads, and an email reporting address for misuse. None of that defends the customer who dialled the wrong number in the first five seconds of panic. The brand owns the legal problem. The customer owns the call.
The three things to do before you dial
First, open the brand website yourself by typing the address into the browser. Do not follow the sponsored link. Read the address from a statement, an email you already have, the back of your card, or a paper you already trust. Second, find the phone number on the contact or support page of that website, not on the ad. The number printed on the back of your bank card is the safest one of all, because it is the number the bank told you to call before you ever saw the internet. Third, hang up and redial if the person on the other end asks for a code, a password or a screen share. A real agent has other tools. A scammer only has those tools.
None of that is high tech. It is the price of using the phone for customer service in 2026. The convenience of dialling the top result is the same convenience that decides you do not get the money back.
If you already called the fake number
Call your bank or card issuer from the number on the back of the card and use the words unauthorised transaction if the money has already moved, or attempted account takeover if it has not. Ask for a written Regulation E claim if the transfer was electronic and you did not authorise it. If you pressed confirm on a payment you now regret, say so plainly and ask whether the institution participates in the Zelle impostor reimbursement framework, because the answer varies by bank and is the difference between a denial and a recovery.
Then build the paper trail. Report at reportfraud.ftc.gov and at ic3.gov. None of that is guaranteed to get the money back. The hour of filing buys you a denial that sometimes gets reversed on escalation, and a data point in the counts that eventually move policy.
Where this connects to the bank text and the popup
The fake customer service ad is the same crew as the bank fraud text and the fake virus popup. The script that opens when you call the number is a close cousin of the script that opens when you call the number from the text message, and both end at the same destination: a request for a one-time code that lets the caller log in as you. If you have read our pages on the bank fraud alert text, the device code consent phishing angle, and the virus popup tech support scam, the pattern is the same. Catch them at the door, which means the search bar, which means your own typing, not the sponsored slot the scammer paid for.
Quick answers
- Is the top result always an ad?
- It is only an ad if it carries the Sponsored label. Organic results are ranked by Google and are not paid for, and the order of the two kinds of result is not fixed.
- Can a company block a scammer from buying its name as a keyword?
- Generally no. Google lets any advertiser bid on a trademark in many jurisdictions, including the US and UK, with limited trademark policy exceptions that cover counterfeit goods, not customer service impersonation.
- Why does the brand not just outbid the scammer?
- Scammers rotate accounts within hours and bid at the platform limit, so brand bidding does not remove the threat. It shifts the scammer to the next account in the portfolio and raises the brand own customer acquisition cost.
- If I dial the wrong number and read no code, am I safe?
- Mostly. The phone number itself and any personal details you volunteered on the call are in a scammer database, which is its own downstream risk. Hang up, do not redial, and treat future calls from that number as hostile.
This is general safety information, not legal advice. Scams change. If you need an official desk: FTC ReportFraud or IC3.