Meta eliminates fraudulent app advertisements in India following two requests.
Meta has eliminated numerous advertisements for apps that claimed to be pornography but were, in fact, banking malware, following an advisory from the Indian government. Subsequently, Reuters uncovered at least 39 additional ads that were still active and reported on Monday that Meta removed them as well after being questioned about them.
The timeline is what makes this incident significant. A government alert led to the removal of some ads, while an inquiry from a reporter resulted in the elimination of the rest. The advertising aspect distinguishes this scenario from typical malware distribution; an app in a store must be found and installed by a user, unlike a paid ad that is actively presented to users deemed likely to engage with it.
The apps could access users' phone information, capture one-time passwords and banking PINs, and transfer funds from accounts without the owner's consent. Pornography serves as a compelling bait for this malware, as individuals who download such an app may hesitate to report it due to potential embarrassment over how they found it.
One-time passwords introduce another vulnerability, as they are now part of the security protocols for various banking services. Malware that can directly read these codes from a device can jeopardize the two-factor authentication that is meant to safeguard an account if the password has been compromised.
Meta did not respond to Reuters' inquiries and removed the flagged ads without commenting on the findings, maintaining a pattern seen in past cases involving problematic advertising on its platforms. India is understandably concerned about this issue, having reported nearly $2.4 billion in losses due to cyber fraud in 2025. Mobile banking has become the primary means for many to access financial services, particularly among new account users.
Furthermore, India is Meta's largest market in terms of users, amplifying the impact of lapses in its advertising enforcement. Hundreds of millions of accounts could be vulnerable to whatever the platform's advertising review mechanisms identify and whatever they fail to detect.
This advertising system transforms the problem into one pertaining to the platform rather than just criminal activity. These apps were not distributed through obscure sites or private networks; they were promoted via a paid advertising system managed and profited from by Meta.
Internal estimates from last year suggested that fraudulent and prohibited advertising could represent about 10% of Meta's revenue for 2024, amounting to approximately $16 billion. This statistic alters the context of any subsequent enforcement announcements, as removing an ad after being flagged is simply a cost of running the platform, while the ad itself generated income for the company responsible for its presence.
Regulatory actions are now increasing across several major markets, though governments are employing various methods. India has utilized advisories and direct requests to Meta, while European authorities are issuing fines, and U.S. plaintiffs are taking their grievances to court.
India has stepped up its scrutiny over the past months, summoning Meta regarding Instagram ads promoting child sexual abuse material and ordering the removal of such ads. European regulators have also expressed similar concerns through different channels; Poland has urged the European Commission to impose a €250 million fine on Meta over scam advertising, while UK banks have reported that a significant majority of payment fraud arises from Meta's platforms.
Meanwhile, Meta has been working on countermeasures, including new fraud-detection systems for WhatsApp, Messenger, and Facebook. The same company manages both the advertising auction and the abusive content detection systems, complicating the issue of repeated failures linked to the platform's incentives.
The core problem in these cases is less about whether Meta intends to distribute scams and more about the effectiveness of its detection capabilities. No one is alleging that Meta supports banking malware in its advertising system; the criticism lies in the fact that these ads continue to be accepted while government agencies, banks, and journalists occasionally identify them before Meta does.
Scale plays a role in this explanation, as millions of ads filter through Meta's systems daily, making it unrealistic for any moderation process to catch every fraudulent campaign immediately. However, this does not clarify why the 39 additional ads remained active even after the company had received a government warning about similar threats.
The 39 ads that Reuters discovered were still operational after the government advisory was issued were ultimately removed following a journalist's inquiry to Meta. This situation poses a simple yet important question regarding the effectiveness of the platform's own detection systems: how much harmful advertising is detected internally, and how much is identified by external sources?
Other articles
Meta eliminates fraudulent app advertisements in India following two requests.
Applications masquerading as pornography have the potential to intercept one-time passwords and banking PINs. Meta has taken down the ads that Reuters identified but did not respond to their inquiries.
