Skip to content
Meta removes fraud app ads in India, after being asked twice

Meta removes fraud app ads in India, after being asked twice

Thenextweb September 1, 2026

Reuters then found at least 39 more of the ads still running and reported on Monday that Meta removed those as well after being asked them.

The apps themselves were capable of accessing information on users’ phones, capturing one-time passwords and banking PINs, and transferring money from accounts without the owner’s knowledge.

Pornography is also an effective lure for this type of malware for reasons that have little to do with the technology itself. Someone who installs an app they would rather keep private may be less likely to report it immediately, particularly if they are embarrassed how they encountered it.

One-time passwords create another vulnerability because they are now part of the security process used by many banking services.

Malware that can read those codes directly from a device can undermine the second factor that is supposed to protect an account if a password has already been compromised.

India has good reason to be concerned the issue. The country recorded close to $2.4 billion in losses from cyber fraud during 2025, while mobile banking has become the main way many people access financial services, particularly among newer account holders.

India is also Meta’s largest market by users, making gaps in its advertising enforcement more significant than they might be elsewhere. Hundreds of millions of accounts are potentially exposed to whatever the platform’s advertising review systems manage to identify and whatever they miss.

The advertising system is what turns this into a platform problem rather than simply a criminal one.

These apps were not being distributed through obscure forums or private networks; they were being through a paid advertising system that Meta operates, moderates, and ultimately makes money from.

Internal projections reported last year also put the issue in financial terms. Meta estimated that scam and banned-goods advertising could account for roughly 10% of its 2024 revenue, or $16 billion .

The regulatory response is now moving in a similar direction across several major markets, although governments are using different tools. India has relied on advisories and direct requests to the company, European authorities are pursuing fines, and US plaintiffs have been taking their claims to court.

European regulators have been raising similar concerns through different mechanisms. Poland has asked the European Commission to fine Meta €250 million over scam advertising, while banks in the UK have said that a large majority of the payment fraud they encounter originates on Meta’s platforms.

Meta has been developing countermeasures at the same time, including new scam-detection systems across WhatsApp, Messenger and .

The same company operates both the advertising auction and the systems intended to detect abusive content within it, which makes repeated failures harder to separate from the incentives built into the platform.

The common issue across these cases is less whether Meta intends to distribute scams and more how reliably it detects them. Nobody is suggesting that Meta wants banking malware in its advertising system.

They were removed after a journalist contacted Meta them, leaving a fairly straightforward question the effectiveness of the platform’s own detection systems: how much harmful advertising is being caught internally, and how much is being discovered by everyone else?

Get the TNW

Get the most important tech news in your inbox each week.

Extracted Entities

Attack Types (1)

Countries (2)

Industries (1)

MITRE ATT&CK (1)

Platforms (2)