Product1 distinct publisher3 min readPublished
The apps posed as pornography and harvested one-time passwords. Both rounds of takedowns followed an outside prompt rather than Meta's own ad review, and that is why the paid channel is the story.
The Product Desk · Product desk

build
Meta's Hatch asks for account connectors in the first of three onboarding steps1 distinct publisher
product
Meta's $18bn settlement is a product spec, and $5.3bn of it is aimed at TikTok and YouTube1 distinct publisher
invest
The remedy New Mexico won at trial is the one Meta's $18 billion settlement does not contain1 distinct publisher
invest
Meta's Hatch agent tops out at $199.99 a month, with DoorDash and Etsy behind the meter2 distinct publishers
Compiled by The Product DeskSomething wrong?How this is made
An app sitting in a store has to be discovered and installed by someone who went looking. An ad arrives because a targeting system picked the recipient as likely to engage with it [8]. The people who received these ads were the ones Meta's system read as receptive to a pornography ad, and that is also the audience with a reason to keep the install quiet, which pushes back the complaint that would have flagged it [7].
On the handset, the app could pull one-time passwords and banking PINs and move money out of an account without the owner knowing [3]. In OTP flows, the code in the message is treated as proof that the person is holding the device. In practice, the device already approved a permission list during install, and after that approval the code and the device sit on the same side of the fence [19]. Mobile banking is the main route to financial services for many newer account holders in India, so that fence is the account [12].
Meta's own numbers give the scale of the incentive. An internal projection reported last year estimated scam and banned-goods advertising at roughly 10 percent of 2024 revenue, about $16 billion [9]. Set the enforcement against that. India's recorded cyber fraud losses for all of 2025, close to $2.4 billion [5], come to about 15 percent of that one-year advertising figure [13]. Poland's request that the European Commission fine Meta 250 million euros over scam advertising [11] is roughly 1.6 percent of it, before anyone converts currency [14]. India has separately summoned Meta over Instagram ads promoting child sexual abuse material and ordered their removal [17], and banks in the UK say a large majority of the payment fraud they encounter starts on Meta's platforms [15]. The company running the auction is also the company running the review that decides what the auction may carry [18].
Meta is building scam detection into WhatsApp, Messenger and Facebook [16]. Hold that apart from what happened to these particular ads: one batch came down after a government advisory, the remainder after a reporter asked [1][2], and the questions were answered with removals rather than comment [4].
The version of this you can apply on Monday to any channel you depend on, or that your customers can be reached through, comes down to two things: whether the channel pushes to an audience it selects or waits to be found, and whether the party paid for delivery also judges what is admissible. Where both answers are the unhappy one, the detection lag is the interval until someone outside the company writes in. In this case that interval was long enough to cover a government advisory and 39 ads still running afterwards [2].
Ranked by verification strength, evidence, and original report placement.
Meta removed dozens of advertisements for apps that presented themselves as pornography but actually functioned as banking malware, after the Indian government issued an advisory.
Reuters then found at least 39 more of the ads still running and reported on Monday that Meta removed those as well after being asked about them.
The apps were capable of accessing information on users' phones, capturing one-time passwords and banking PINs, and transferring money from accounts without the owner's knowledge.
Meta did not respond to Reuters' questions and removed the flagged advertisements without commenting on the findings.
Pornography is an effective lure for this malware because someone who installs an app they would rather keep private may be less likely to report it immediately, particularly if embarrassed about how they encountered it.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One retelling of someone else's fieldwork
The falsifiable core — an advisory, dozens of ads gone, 39 more still live, removed after an email — is specific enough to be checked, but nothing in our coverage lets you check it. Reuters did the finding; The Next Web summarises it without quoting or linking the original, the advisory is never described, and Meta said nothing. The surrounding figures are weaker still: the $16 billion internal estimate is credited only to unnamed reporting 'last year', and the UK bank claim names no bank.
Two takedown rounds, no reach numbers
What is concretely observable amounts to enforcement events: one batch pulled after India's advisory, at least 39 more pulled after Reuters asked, and Poland's fine request as the regulatory echo. What would actually size the harm is absent — impressions, spend, install counts, how long the 39 ran, how many accounts were drained. In a market The Next Web calls Meta's largest by users, 'hundreds of millions potentially exposed' is a denominator, not a measurement.
Careful argument, borrowed arithmetic
The framing is unusually restrained for this beat: The Next Web concedes that scale explains some misses and states plainly that nobody thinks Meta wants malware in its auction. The overreach happens in the numbers, where a country-wide fraud loss total gets divided by one company's internal revenue estimate from a different year, and a euro fine is expressed as a percentage of a dollar figure without conversion. Those comparisons look like measurement and are closer to rhetoric; strip them and the underlying story — outsiders found it twice, the platform didn't — needs no inflation.
The house takes a cut of what it polices
This story's conflict is not hidden, it is structural and stated: the same company runs the auction, runs the abuse detection inside it, and banks the spend either way. Removing an ad after someone flags it costs a little; the ad had already been paid for. The reported internal estimate that scam and banned-goods advertising might be a tenth of 2024 revenue is what gives that asymmetry a number, even unverified. Worth noting the reporting incentive too: this is an aggregation of another outlet's scoop, which rewards the sharpest available framing.
Solid on the sequence, soft on the scale
We can stand behind the shape of what happened — two rounds of removals, both triggered from outside Meta — because it is reported specifically and Meta did not dispute it. Confidence drops sharply on everything used to size the problem: the fraud-loss total, the revenue estimate, the fine request, the bank claims, all single-sourced through one aggregating publisher with no primary documents and no company response.