Meta scam ads: Breaking down Meta’s malvertising machine
That too-good-to-be-true deal in your Facebook feed might be one of millions of scam ads on Meta — and Meta’s own internal documents suggest the company has been profiting from the problem. Here’s what threat researchers at Norton found when they measured the scale of the problem, how these ads reach victims, and how to stay safer against scams on Meta.
Malicious ads on Meta platforms (which include Facebook, WhatsApp, and Instagram, among others) aren’t a fringe problem. In November 2025, Reuters reported on a cache of internal Meta documents projecting that about 10% of the company’s 2024 revenue (roughly $16 billion) would come from ads for scams and banned goods. A May 2025 Meta safety presentation, cited in the same reporting, estimated the company’s platforms were involved in about a third of all successful scams in the U.S.
Our Threat Researchers set out to measure the scale of the Meta scam ad problem independently, publishing their findings in two articles: The Scam Ad Machine and The Scam Ad Machine Part II. Studying ads on Meta’s platforms across the EU and UK using Gen’s cyberthreat detection tools, they found that nearly one in three ads (30.99%) pointed to a scam, phishing, or malware link. That data is from Europe, not the U.S., but the pattern is still telling.
Meta’s scam ad problem
Scams don’t always look like obvious scams. Many take the form of malvertising (malicious or fraudulent advertising) on normally trusted platforms. These are ads built to deliver scams, phishing attacks, or malware instead of a real product. They blend into your feed like any other promotion.
To measure how common Meta malvertising has become, our Threat Researchers at Norton ran a large-scale study using Meta’s Ad Transparency API, the public tool that shows which ads are running on Meta’s platforms. Over 23 days, the team analyzed 14.57 million ads across the EU and UK — accounting for about 10.76 billion impressions (the number of times ads were shown to users). Of those, 4.51 million were tied to scams: nearly one in three ads (30.99%) led to a scam, phishing, or malware link, adding up to more than 304 million scam-ad impressions.
One note on the scope of research: that measurement covers the EU and UK, where ad-transparency rules make this kind of analysis possible. Meta doesn’t disclose the same data for U.S. ads — but the U.S. numbers tell their own story.
In the U.S., the Federal Trade Commission (FTC) reports that people lost more than $12.5 billion to fraud in 2024. And social media is now the costliest way scammers reach people: according to another FTC study on social media scams, nearly 30% of those who reported losing money to a scam in 2025 said it started on social media, with about $2.1 billion lost. If you’re wondering where that risk concentrates, we’ve also ranked the riskiest social media platforms for cyberthreats.
How Meta scam ads work
Scammers don’t rely on just one trick. However, our researchers did find a repeatable set of techniques, like URL masking, typosquatting, and hidden impersonation. Similarly to VibeScams (AI-built fake websites), scam ads are designed to be churned out at scale. Here’s how these ads are often built:
- Multi-facet ads: A single ad bundles several images and links, most pointing to real marketplaces like Amazon, eBay, or Etsy. But one link in the mix leads to the scam — for example, a fake storefront — so the ad reads as an ordinary shop advertisement.
- URL masking: The ad displays a trusted brand’s web address, but clicking sends you to a different site the scammer controls.
- Typosquatting and deceptive subdomains: Scammers register fraudulent look-alike domains (with a small misspelling or extra word) and dress them up with prefixes like “go.” or “shop.” to look official. Sometimes the ad’s preview image doesn’t match the page it actually opens to.
- Unicode text obfuscation: By swapping in look-alike characters or hidden spacing, scammers write ad text that reads normally to you but scrambles the keyword filters meant to catch it.
- Hidden impersonation: The same character trick as typosquatting or unicode text obfuscation disguises a celebrity’s name or a fake “Dr.” credential — enough to borrow their authority while slipping past automated name detection.
Why Meta scam ads are effective
These techniques work because they fit right into a normal browsing experience. A scam ad borrows the trust signals you rely on — a familiar brand name, clean design, a professional-looking storefront — so nothing feels off at a glance. On a phone, scrolling quickly, few people stop to inspect where a link actually leads before tapping — especially if they trust the platform where it appears.
The trap can also tighten the more you struggle against it. Reuters, citing Meta’s internal documents, found that the ad system tends to serve more scam ads to people who have already clicked one, because it feeds you more of whatever you engage with.
And these ads are built to outlast enforcement. Our Threat Researchers describe a “Hydra” pattern: remove one ad, and near-identical versions reappear through fresh disposable accounts faster than takedowns can keep up. If you’re not familiar with Greek mythology, the Hydra was a monster that would regrow several new heads whenever one was cut off.
What is Meta doing to address its scam ad problem?
Meta says it’s fighting fake ads, and points to the scale of its efforts. The company reported removing more than 159 million scam ads in 2025, 92% of them before anyone reported them. But our research points to a structural limit: taking down individual ads doesn’t dismantle the operation behind them, so near-identical versions keep reappearing. Meta also disputes how much money is involved, calling the internal estimate Reuters reported — that scams accounted for about 10% of its 2024 revenue — “rough and overly-inclusive.”
Meta scam prevention
Alongside takedowns, Meta has rolled out tools meant to warn you before you engage with a likely scam. These include device-linking alerts on WhatsApp, suspicious friend-request warnings on Facebook, and AI-powered scam detection in Messenger chats. It’s also leaning on advertiser verification: Meta says it wants verified advertisers to account for 90% of its ad revenue by the end of 2026, up from 70%, concentrating on the highest-risk categories.
Meta fraud ads lawsuits
What has been measured and documented is now being argued in court. In May 2026, Santa Clara County sued Meta in California Superior Court, the first scam-ad case brought by a local prosecutor in the US.
The county’s argument echoes the research: it alleges Meta doesn’t just fail to stop scam ads, but knowingly profits from them, even charging suspected scammers more to keep their ads running. The county is seeking penalties and business reforms. Meta disputes the claims, says it will fight them, and argues the case leans on Reuters reporting that distorts its motives.
Santa Clara isn’t alone. The Consumer Federation of America has sued Meta in Washington, DC, claiming it misled the public about its anti-scam efforts, and the US Virgin Islands attorney general has a similar suit underway. For now it’s all unproven in court, but the scrutiny over Meta’s handling of fraudulent advertising has moved beyond the headlines.
How to stay safer from scams on social media
The good news: a few habits go a long way to protect yourself against scam ads and other social media threats.
- Go to the source, not the ad: If an ad catches your eye, open a new tab and type in the brand’s official website instead of tapping through. You’re more likely to land on the real site, not wherever the ad points.
- Be skeptical of urgency and bargains: Countdown timers, “today only” pressure, and prices that seem too good to be true are classic bait. Slow down before you act.
- Check where a link actually leads: The web address shown in an ad isn’t always where the click takes you. On mobile especially, press and hold a link to preview the real destination before you tap.
- Never enter login, payment, or personal details in an ad: Sign in and pay only on sites you’ve reached directly, never through an ad’s landing page.
- Vet the advertiser: Tap the page name behind the ad. A brand-new page, few followers, or a mismatched history is a red flag, much like spotting a sketchy seller on Facebook Marketplace.
- If you already clicked: Change the password on any account you logged into and turn on multi-factor authentication, contact your bank if you shared card details, scan your device, and watch for follow-up scams, including unexpected messages on apps like WhatsApp.
- Add a layer of protection: Norton 360 Deluxe includes AI-powered protection against scams, fake websites, and malware. It can flag fake stores and phishing sites as you browse, check suspicious texts, and help you ascertain whether a fishy message is really a scam.
FAQs
Where do Meta scams come from?
Meta scams often come from organized operations rather than lone scammers. In their study, our Threat Researchers repeatedly traced clusters of scam campaigns to payment and infrastructure linked to China and Hong Kong, run through short-lived pages set up mainly to push ads, indicating that a polished, local-looking ad — like many social media scams — can still trace back to an industrial operation.
Who’s behind Meta scam ads?
A small number of advertisers seem to cause most of the harm. Our Threat Researchers found that the top 10 scam advertisers accounted for about 56% of all the scam ads they identified: roughly 2.5 million ads from just a handful of operators. These tend to be organized, persistent groups running high volumes of disposable ads through throwaway accounts, not one-off bad actors.
How do you report scam ads?
You can report a scam ad in a few steps. On Facebook or Instagram, tap the ••• menu on the ad, choose Report ad, and pick the option for a scam or misleading ad; other platforms like YouTube have similar ad-reporting options. To help authorities track fraud, also report it to the FTC and, if you lost money, to the FBI’s Internet Crime Complaint Center.
Editors’ note: Our articles offer educational information and are written to raise awareness about important topics in Cyber Safety. Norton products and services may not protect against every type of threat, fraud, or crime we write about. For more details about how we research, write, and review our articles, see our Editorial Policy.
Want more?
Follow us for all the latest news, tips, and updates.