NegativeSEO.ICU logo — negative SEO reference and recoveryNegativeSEO.ICUNegative SEO reference & recovery
Abstract hexagonal tile illustration representing Google Business Profile Hijacking
Content & Platform AttackYour Google Business Profile

Google Business Profile Hijacking

Documented threat Observed in the wild, works against ordinary sites today.

Since April 2026 Google emails verified owners about suggested edits before they go live, which moves nearly all of the remaining risk onto profiles nobody has claimed.

Five different attacks that feel like one

A Google Business Profile is the record Google holds for a physical or service-area business — its name, address, phone number, website, primary and secondary categories, hours and photographs. It is the thing that renders as a listing in the local pack, as a pin card on Google Maps, and as the knowledge panel beside a search for the business name. Owners call all of it "my Google listing", and when it goes wrong they call all of it hijacking.

Five mechanically different things sit under that word, and they have five different fixes:

  1. Malicious suggested edits. Google Maps invites any signed-in user to correct a place's facts — its help page says plainly, "If you're familiar with a place, you can provide feedback." The attack is to change a field. Changing the phone number or the website diverts leads directly. Changing the primary category — the label that tells Google what kind of business this is, and one of the strongest relevance inputs in the local pack — is the most damaging to ranking. Changing the address can move the pin out of the area you actually serve and, if it looks fraudulent, can trigger a suspension.
  2. Fraudulent ownership requests. A stranger formally asks Google for management access to your verified profile. See the next section, because the window is shorter than almost everyone says.
  3. Account compromise. The Google account managing the profile is phished or credential-stuffed. This is not an SEO attack at all. It is an account-security incident — an unauthorized party holding valid credentials to a system — and it is the variant most likely to end with the attacker removing you as a manager of your own listing.
  4. Weaponized reporting. Rather than editing anything, the attacker repeatedly reports the listing for policy violations until Google suspends it. Nothing on the listing changes; the listing disappears. This is the variant most often mistaken for an algorithm update.
  5. Edit and extort. Documented by Joy Hawkins of Sterling Sky: bad actors spam suggested edits to damage a profile, then telephone the owner posing as "Google Support" and offer to fix it. The sabotage is the lead generation for a fraud, which means the perpetrator is often not a competitor at all.

The asymmetry that made this attractive for years is worth naming: the edit was anonymous, it was free, the owner was never asked, and often the owner was not even told. One of those four facts changed in April 2026.

April 2026 moved almost all of the risk onto unclaimed profiles

This is the change that should reframe the whole subject, and most published advice has not caught up with it.

In its April 2026 post on protecting businesses on Maps, Google states that verified business owners now receive proactive email alerts about suggested edits before those edits go live, alongside models that block unhelpful edits faster, rolled out globally on Android, iOS and desktop. A silent edit that landed and sat for weeks was the core of this attack. Pre-publication notice to the verified owner substantially defuses it.

Two qualifications, both important. First, it only helps an owner who reads the email — the control is now email-dependent, and a profile verified to a departed marketing manager's address or a defunct agency account has no control at all. Second, the mechanics are documented only in a blog post: Google has published no help-center counterpart, no statement of which edit types trigger an alert, no notice period, and no statement about unclaimed profiles, which almost certainly get nothing. Treat the details as undocumented and the direction as real.

The practical consequence is a different page than the one I would have written two years ago. The defensive question is no longer "how do I fight suggested edits". It is "is this profile claimed, is it verified, and does a human read the email on the account today". An unclaimed profile is this attack's natural habitat: nobody is notified, nobody appeals, nobody notices, and none of the owner-side controls exist. Claiming it is the single highest-value defensive act available to a local business, and it costs nothing but an afternoon.

The ownership-request window is 3 days, not 7

A specific correction, because the wrong number is everywhere and it is the difference between keeping a listing and losing it.

When a stranger requests ownership of a verified profile, Google notifies the current owner by email. Google's own page on requesting ownership of a Business Profile states that the owner has 3 days to respond, and that a requester who gets no response "may have the option to claim the profile" through verification.

Three days and an email address are the entire defense. Older Google documentation, and a large number of secondary sources that have never been revised, say seven days. That appears to be a genuine change rather than an error, but the seven-day figure is so widespread that an owner planning around it can be two days late by the time they act. Assume three.

The failure mode this produces is mundane and completely avoidable: an owner on vacation, an owner who lost access to the mailbox on the account, an owner who filed the notification as phishing. Some ownership-request emails are phishing, and the real ones look similar — so verify by logging into the profile directly rather than by clicking anything in the message. But do not ignore it. The clock runs either way, and nothing has to be hacked for a stranger to end up holding your listing.

The evidence: Google's own numbers, and Google's own lawsuits

Google publishes annual counts of profile-abuse enforcement, and the trend line is the most useful evidence available that the edit surface is under continuous pressure. In 2018 it reported removing more than 3 million fake business profiles and disabling more than 150,000 user accounts. For 2024 it reported 12 million fake profiles removed or blocked, 70 million policy-violating edits blocked or removed, and 900,000 accounts restricted. For 2025: over 13 million fake profiles, 79 million inaccurate or unverified edits blocked, and more than 782,000 accounts restricted.

Seventy to seventy-nine million blocked edits a year is the number that matters here. Google's phrasing deliberately covers both malicious and merely wrong edits, and the figures are unaudited with no published false-positive rate — but whatever the split, the edit channel is under industrial-scale attack and Google says so itself.

The independent evidence is older and still descriptive of the shape of the problem. Pinning Down Abuse on Google Maps, a peer-reviewed paper presented at the World Wide Web conference in 2017, analyzed over 100,000 suspended listings and found that attackers systematically circumvented postcard verification to create or hijack listings, and that abuse concentrated in categories where a customer needs someone physically present and needs them urgently — unaccredited locksmiths above all, plus restaurants and hotels. That profile has not changed in the years since.

The strongest evidence that the attack pays, though, is that Google has gone to federal court over it more than once. In Google LLC v. Ethan QiQi Hu, filed in the Northern District of California in June 2023 against Hu and associated entities, Google alleged roughly 350 fraudulent Business Profiles and more than 14,000 fake reviews, with the defendants then attempting to sell information about the consumers lured through the false listings. In March 2025 Google filed again, this time over more than 10,000 illegitimate listings concentrated in the same duress verticals the 2017 researchers identified — locksmiths and towing — using call interception and bait-and-switch pricing. Platforms do not litigate about theoretical problems. They also do not litigate on behalf of any individual victim, and no business should plan around being rescued by one of these cases.

Who is still exposed

Specific conditions, not general fear:

  • Unclaimed and unverified profiles. This is the overwhelming majority of the remaining risk, and the whole of the recommended fix.
  • Profiles verified to an unmonitored address — a departed employee, a former agency, a personal mailbox nobody opens. Both the 2026 edit alerts and the 3-day ownership window are email-dependent, which makes the mailbox the load-bearing control and almost nobody has checked it.
  • Multi-location brands where no one person owns the monitoring, and franchisee listings have drifted out of the corporate account.
  • Duress verticals — locksmiths, towing, emergency plumbing, garage doors, addiction treatment, bail bonds — where a single intercepted call is worth enough to fund organized abuse.
  • Weaponized reporting, which the 2026 edit alerting does not address at all. Suspensions remain opaque and slow, and a suspended owner is told neither who reported them nor why.

Note what is not on that list: a claimed, verified profile on an address a human reads, with someone checking the fields monthly. For that business the exposure is materially lower than it was even a year ago, and anyone selling monitoring as though nothing changed in April 2026 is selling last year's threat model.

How you find out — the fields to check and the metrics that move first

The signal usually arrives in your numbers before it arrives in your eyes.

  • Calls collapse while views hold steady. In Business Profile performance data this is the signature of a swapped phone number, and it is visible days before anyone notices the listing text. A collapse in website clicks with views intact is the signature of a swapped URL.
  • Field-level diffing. The method that works is boring: write down your canonical values — exact business name, address with suite formatting, primary category, every secondary category, phone, website, hours, service area — and compare against the live profile on a schedule. Check category and phone first, because they do the most damage and are the least likely to be noticed.
  • Pending edits and "Updates from Google" shown in the profile interface. Approve or reject them; do not let them lapse.
  • A logged-out check. Your owner view is not what a customer sees. Look at the profile in a private browser window, on a phone, the way a stranger would.
  • Your manager list. Accounts you do not recognize are where the evidence lives in an account-compromise case.
  • Referral and call-tracking records, which give you the exact date and often the exact hour traffic stopped. The date is the evidence.

What it is mistaken for. A legitimate automatic update, because Google merges data from the web and from third parties and an innocent automatic change looks identical to a malicious one at first glance. A category change an agency made years ago that nobody remembers authorizing. A duplicate listing outranking the real one. A proximity change after a pin adjustment. A local algorithm update. And, very often, a suspension the owner never noticed — which produces total disappearance rather than a corrupted field, and has an entirely different remedy.

Undoing it: secure the access before you fix the data

  1. Screenshot before you correct anything. Once you fix the field, the evidence of what it was changed to is gone, and with it your ability to demonstrate a pattern to Google or to a court later.
  2. Claim and verify the profile if it is not already. Everything below assumes verified ownership. An unverified profile has essentially no remedies, and verification is the remedy.
  3. Secure the account first. If a manager you do not recognize still has access, your corrections will simply be changed back. Change the password, turn on two-factor authentication, review connected apps, remove unknown users and managers, and confirm the primary owner is you. If the account itself was compromised, start with Google's account recovery, not with the listing.
  4. Correct the fields directly in the profile. Owner edits generally outrank public suggested edits. Record what each value was, what it became, and when.
  5. Reject pending suggested edits rather than letting them expire.
  6. Repeat the correction if it reverts. One reversion is normal. A pattern of reversions within hours is an ongoing attack, and the response changes from data hygiene to escalation.
  7. Escalate through the Business Redressal Complaint Form for misleading or fraudulent information about a business name, phone number or URL. Google is candid on the form itself that it cannot guarantee any action will be taken. Submit evidence rather than indignation: dated screenshots, the correct values, and documents proving them.
  8. Use Business Profile support for a suspension, which is a different queue entirely. Reinstatement turns on proving the business is real and eligible at the stated address — a lease, a utility bill, business registration, signage photographs.

What does not help: deleting and recreating the listing, which costs you the review corpus and the profile age and often produces a duplicate Google then suspends; creating a second listing as a workaround; mass-emailing support; filing a Search Console reconsideration request, which addresses website manual actions and has no connection to Business Profiles; disavow files; and paying anybody who telephones claiming to be Google Support. Google does not cold-call to sell listing repairs, and that call is the second half of the edit-and-extort scheme.

Recourse, and where it runs out

The platform routes are the Business Redressal Complaint Form for factual fraud on a name, address, phone or URL; the ownership-request flow, which is both the attack surface and the way back; and Business Profile support for suspensions. None of them gives you a case number, a dialogue or a deadline. Realistic outcome: clear-cut factual fraud gets corrected, ambiguous cases do not, and no published data exists on suspension appeal rates or reinstatement timelines — so ignore anyone quoting one.

On the legal side, one distinction decides most of these cases. Submitting a false suggested edit through a public form is almost certainly not unauthorized access under the Computer Fraud and Abuse Act, 18 U.S.C. 1030, because the form is open to everyone by design; since Van Buren v. United States (2021) the Supreme Court has read the statute's "exceeds authorized access" language narrowly. Compromising the owner's Google account almost certainly is. The CFAA is a poor fit for edit abuse and a good fit for account takeover, and I found no reported decision applying it to Maps edits at all.

The theory closest to the actual injury is the Lanham Act, 15 U.S.C. 1125(a) — false designation of origin — where an attacker redirects your customers by putting their own phone number on your listing. State-law tortious interference fits where the perpetrator is identifiable. Where they are not, the published route is a suit against a Doe defendant plus a third-party subpoena to Google for the identity behind the edits and reports. One practitioner account, from 39 Celsius in September 2019, describes an eight-year-old profile that suffered repeated false spam reports and unauthorized edits, a suspension of over 30 days, and roughly an 84 percent loss of impressions and clicks; Google initially reported no recent edits, then produced identifying information once directed to the original profile record rather than the suspended one, and the listing and its rankings were restored. That is a single firm's narrative of its own matter, with no case name or docket — cite it as such. It remains the clearest published example of what finally ends a determined campaign, and serving the subpoena is sometimes itself the remedy, because the attack simply stops.

One last observation worth recording. There is no encyclopedia article on Business Profile hijacking, and none on listing abuse generally. This is a documented, litigated, industrial-scale category of fraud with no reference coverage at all, which is part of why owners meeting it for the first time find so little that is not written by somebody selling a monitoring subscription.

Frequently asked questions

Someone changed my Google listing's phone number. How do I get it back?

Screenshot the wrong value first, then correct the field yourself in the Business Profile — owner edits generally override public suggested edits, and this usually takes minutes. Then check the manager list for accounts you do not recognize, because if the change came from inside the account it will simply revert. If it reverts more than once, escalate through the Business Redressal Complaint Form with dated screenshots and documentation of the correct number.

How long do I have to respond to an ownership request?

Three days. Google's current documentation says the existing owner is notified by email and has 3 days to respond, after which the requester may be able to claim the profile through verification. A great many sources still say seven days, which is the older figure and is now wrong. Verify the request by logging into the profile directly rather than clicking links in the email — but do not dismiss it as phishing, because the clock runs regardless.

Does Google warn me before someone's suggested edit goes live?

If the profile is verified and you read the email on the account, yes — Google said in April 2026 that verified owners now get proactive email alerts about suggested edits before they publish. If the profile is unclaimed, no. That single difference is where nearly all of the remaining risk in this attack now sits, which is why claiming and verifying the listing matters more than any monitoring product.

My listing vanished from Maps entirely. Was it hijacked?

That is more likely a suspension than a hijack. Hijacking corrupts fields and leaves the listing visible; a suspension removes it. Weaponized reporting — repeated false policy complaints until Google acts — produces exactly this, and the 2026 edit alerts do nothing about it. Work the reinstatement route through Business Profile support with documentary proof the business is real and operating at the stated address, and do not create a second listing while you wait.

Can I find out who made the edit?

Not through any self-service route. The only published path is filing suit against an unidentified defendant and subpoenaing Google for the attribution data, which is slow and expensive. One practitioner account reports that Google did produce identifying information once it was directed at the correct profile record. Before going there, confirm you are dealing with a person rather than an automatic update from Google's own data merging, which looks identical from the outside.

Someone called offering to fix my listing for a fee. Is that legitimate?

No. Google does not telephone businesses to sell listing repairs. Joy Hawkins of Sterling Sky documented the pattern where the same actors damage a profile with suggested edits and then call the owner pretending to be Google Support with an offer to fix it — the sabotage is the sales lead. Hang up, fix the fields yourself from the owner dashboard, and treat the call as evidence rather than as help.

Top