Meta Platforms has spent the past year expanding advertiser verification and promoting increasingly aggressive anti-scam enforcement. On Monday, at least 39 advertisements matching a newly identified Indian banking-fraud scheme were still running on Facebook and Instagram after the government warned about the campaign.
The tech giant removed the advertisements shortly after Reuters brought them to the company’s attention while seeking comment, according to the news organization. Meta did not respond to Reuters’ questions about the incident.
The advertisements used sexually explicit material to push Android applications presented as pornography apps. India said ads using names including “Night Play” and “Kyss” sent users to phishing websites, where malicious apps could be downloaded outside official app stores.
One advertisement reviewed by Reuters directed users to download a file called Movexa.apk. India’s advisory said apps involved in the scheme could secretly access information stored on a device, intercept one-time passwords and bank PINs, and initiate transfers from victims’ accounts without their knowledge.
The malware allegations and description of its capabilities come from the Indian government. Reuters separately established that at least 39 advertisements matching the campaign remained active after the advisory and that Meta subsequently removed them.
The advertisements also appear to violate two separate parts of Meta’s own advertising rules: its policies prohibit ingadult nudity and sexual activity in ads, as well as deceptive schemes intended to defraud users.
The discovery comes as Meta publicly promotes a substantial expansion of its anti-fraud systems. In March, the company said it had removed more than 159 million scam advertisements globally during 2025, with 92% removed before users reported them.
In India alone, Meta said it removed more than 12.1 million pieces of advertising content under its fraud, scam, and deceptive-practices policies, with more than 93% removed proactively.
Meta also said it intends for verified advertisers to generate 90% of its advertising revenue by the end of 2026, up from about 70% when the initiative was announced. The company said verification would be concentrated in categories with a higher risk of abuse.
“We aggressively combat scam activity to protect people and businesses,” Meta said in March while announcing new anti-scam tools.
The company has also partnered with India’s Indian Cyber Crime Coordination Centre and the Securities and Exchange Board of India on a public anti-scam campaign.
An investigation published by Reuters in November 2025 found that internal Meta documents had estimated advertisements for scams and banned products could account for roughly 10% of the company’s 2024 revenue, or approximately $16 billion.
Meta spokesman Andy Stone disputed that internal figure at the time, describing it as rough and overly inclusive because it included legitimate advertisements. Meta said the actual amount was lower but did not provide Reuters with a revised figure. The company also said reports of scam ads had fallen substantially as enforcement improved.
India has a growing financial incentive to push the enforcement harder. Cyber-fraud losses in the country approached $2.4 billion in 2025, according to government data cited by Reuters.
The Ministry of Home Affairs said on August 11 that authorities had blocked 3,718 mobile applications, including fraudulent loan apps, through June 30. Its financial cyber-fraud reporting system had helped prevent more than 111.58 billion rupees from being siphoned from victims across more than 3.28 million complaints, according to the ministry.
Monday’s case creates a narrower test for Meta. India had publicly identified the fraud pattern, Reuters could still locate dozens of matching paid advertisements afterward, and those ads disappeared after the news organization contacted the company.
Whether Meta’s systems had independently detected those advertisements before Reuters’ inquiry remains unclear.