Meta removes fraud app ads in India, after being asked twice


The Meta Platforms logo displayed on a mobile device screen with a person standing in the background

Meta Platforms technology company displayed on a mobile device.

Image Credits Credit: gguy via Shutterstock

Meta removed dozens of advertisements for apps that presented themselves as pornography but actually functioned as banking malware, after the Indian government issued an advisory.

Reuters then found at least 39 more of the ads still running and reported on Monday that Meta removed those as well after being asked about them.

The sequence is what makes the story notable. A government warning led to some of the advertisements being removed, while a reporter’s email prompted Meta to take down the rest.

Advertising makes this different from ordinary malware distribution. An app listed in a store still has to be discovered and installed by a user, whereas a paid advertisement is actively delivered to people selected by an advertising system because they are considered likely to engage with it.

The apps themselves were capable of accessing information on users’ phones, capturing one-time passwords and banking PINs, and transferring money from accounts without the owner’s knowledge.

Pornography is also an effective lure for this type of malware for reasons that have little to do with the technology itself. Someone who installs an app they would rather keep private may be less likely to report it immediately, particularly if they are embarrassed about how they encountered it.

One-time passwords create another vulnerability because they are now part of the security process used by many banking services.

Malware that can read those codes directly from a device can undermine the second factor that is supposed to protect an account if a password has already been compromised.

Meta did not respond to Reuters’ questions. The company removed the flagged advertisements without commenting on the findings, following a pattern that has become familiar in cases involving problematic advertising on its platforms.

India has good reason to be concerned about the issue. The country recorded close to $2.4 billion in losses from cyber fraud during 2025, while mobile banking has become the main way many people access financial services, particularly among newer account holders.

India is also Meta’s largest market by users, making gaps in its advertising enforcement more significant than they might be elsewhere. Hundreds of millions of accounts are potentially exposed to whatever the platform’s advertising review systems manage to identify and whatever they miss.

The advertising system is what turns this into a platform problem rather than simply a criminal one.

These apps were not being distributed through obscure forums or private networks; they were being promoted through a paid advertising system that Meta operates, moderates, and ultimately makes money from.

Internal projections reported last year also put the issue in financial terms. Meta estimated that scam and banned-goods advertising could account for roughly 10% of its 2024 revenue, or about $16 billion.

That figure changes the context around every subsequent enforcement announcement. Removing an advertisement after someone flags it is part of the cost of operating the platform, while the advertisement itself generated revenue for the same company responsible for deciding whether it should be there.

The regulatory response is now moving in a similar direction across several major markets, although governments are using different tools. India has relied on advisories and direct requests to the company, European authorities are pursuing fines, and US plaintiffs have been taking their claims to court.

India has been escalating its scrutiny for months. It has summoned Meta over Instagram advertising promoting child sexual abuse material and separately ordered the company to remove those advertisements.

European regulators have been raising similar concerns through different mechanisms. Poland has asked the European Commission to fine Meta €250 million over scam advertising, while banks in the UK have said that a large majority of the payment fraud they encounter originates on Meta’s platforms.

Meta has been developing countermeasures at the same time, including new scam-detection systems across WhatsApp, Messenger and Facebook.

The same company operates both the advertising auction and the systems intended to detect abusive content within it, which makes repeated failures harder to separate from the incentives built into the platform.

The common issue across these cases is less about whether Meta intends to distribute scams and more about how reliably it detects them. Nobody is suggesting that Meta wants banking malware in its advertising system.

The criticism is that the system continues to accept those advertisements, while government agencies, banks, and journalists sometimes identify them before Meta does.

Scale is a legitimate part of the explanation. Millions of advertisements enter Meta’s systems every day, and no moderation process can be expected to identify every fraudulent campaign immediately.

That does not, however, explain why the additional 39 advertisements remained active after the company had already received a government warning about the same type of threat.

The 39 advertisements Reuters found were still running after the government advisory had been issued.

They were removed after a journalist contacted Meta about them, leaving a fairly straightforward question about the effectiveness of the platform’s own detection systems: how much harmful advertising is being caught internally, and how much is being discovered by everyone else?

Get the TNW newsletter

Get the most important tech news in your inbox each week.

Published
Back to top