Meta removed dozens of malicious advertisements disguised as pornography apps that were stealing banking credentials and financial data from users following intervention by the Indian government and journalists.
Key Points
- Meta removed fraudulent advertisements that functioned as banking malware capable of stealing one-time passwords and PINs.
- The Indian government issued an initial advisory, leading to the removal of some ads, while Reuters identified 39 additional active ads.
- These malicious apps exploited the privacy concerns of users to avoid reporting and bypassed security measures like two-factor authentication.
- India recorded approximately $2.4 billion in cyber fraud losses in 2025, highlighting the risks to its massive user base.
- Meta’s internal projections suggest scam and banned-goods advertising could account for roughly $16 billion of its 2024 revenue.