A single Google Maps contributor account has uploaded AI-generated photos to well over a hundred Google Business Profile listings, each image carrying the same phone number that does not belong to the business it appears on. Search Engine Roundtable reported the scheme this week, citing a LinkedIn thread where marketer Naomi Stevens documented the issue on a client’s roofing company profile. The stakes are straightforward: a searcher who calls the number printed on the photo reaches the scammer instead of the business.

The mechanism is what makes this durable. Google Business Profile validates the phone number field itself, checking format and, for verified listings, tying it to ownership confirmation. A phone number typed or drawn into an uploaded photo is just pixels. It passes through the same review pipeline as any other contributor photo, with no requirement that the digits in the image match, or even relate to, the structured data on the listing.

Stevens described the fake image as prominent enough to function as a cover photo. “I checked the contributor and they have 150+ photo contributions to unrelated businesses across the US, with the same incorrect phone number appearing on images for other businesses too,” she wrote, calling it systematic spam aimed at redirecting calls. According to the report, the contributor has been operating under the name Jack Edward and has targeted a broad spread of business categories and locations.

Reporting the photo did not resolve it. Stevens said she flagged the image and contacted Google support, and received a generic reply listing unrelated troubleshooting steps. Adding a logo, a new cover image, and additional photos did not push the fraudulent image out of its prominent placement either. That gap, a scam pattern that is trivially detectable by matching the repeated phone number across contributions, yet unresolved after direct reporting, is the part of this story worth sitting with. Google has the contributor’s upload history and the shared digit string in hand; nothing in the reporting indicates that pattern is being matched automatically.

For anyone managing a Business Profile, the checklist is narrow but concrete. Open the listing’s photo tab and look specifically at contributor-submitted images, not just the ones the business itself uploaded, since Google can surface a contributor photo as the default cover image. Zoom into any photo that looks like a business card, storefront sign, or flyer and read the phone number printed on it against the number in the listing’s official fields. If a mismatch turns up, report the photo through Google’s standard photo-flagging flow, then separately file a report through the Business Profile support channel referencing the contributor’s profile URL, not just the image, since the account is the unit worth escalating.

Monitoring should not be a one-time check. Because the exploit works by targeting the visual layer rather than the data layer, it will not show up in structured-data audits, Search Console, or standard listing-verification tools built to catch inconsistencies in name, address, and phone fields. Local SEO teams managing multiple locations should add a recurring manual scan of listing photos to their review cadence, treating the photo carousel as an unmoderated surface until Google demonstrates otherwise.

Search Engine Roundtable’s Barry Schwartz noted that Google could plausibly match the recurring phone number across contributions with existing tooling, since the number is identical on every fraudulent upload. Until that kind of automated matching is confirmed, businesses that depend on inbound calls from their Maps listing should treat the photo tab as an active attack surface, not passive content, and audit it on the same schedule as their listing’s core NAP data.

Search Engine Roundtable, in a report by Barry Schwartz published September 10, 2026, first documented the scam.