ScamWatch puts Meta’s ad business under scrutiny

An analysis of 1.76 million ads found that 16.5% were suspicious and more than 28,000 carried a very high risk rating. Meta disputes the methodology and rejects claims that it profits heavily from fraudulent advertising.

Rafał Brzoska, prezes InPost
Rafał Brzoska, CEO of InPost. For several years, he has been fighting against false advertisements that appear on Meta’s platforms. Photo: press materials
Loading the Elevenlabs Text to Speech AudioNative Player...

Nearly 17% of ads on Meta’s platforms are highly likely to be scams, according to an analysis conducted by the team behind the ScamWatch initiative. Rafał Brzoska, who launched the “150% Stop Scam” campaign, wants the authorities to stop treating fraudulent advertising solely as a matter of content moderation.

The analysis follows the StopScam and ScamWatch initiatives launched in recent months by, among others, InPost founder Rafał Brzoska. The campaign aims to determine the scale of fraud and scams on social media, particularly on platforms owned by Meta.

“Unfortunately, scams are a cancer eating away at our social fabric,” Brzoska said at a conference.

He said the purpose of ScamWatch was to establish the true scale of fraud on Meta’s platforms.

“We are showing the scale of what we ourselves have caught – not merely cases reported by users. (...) But most importantly, having seen the political paralysis across the spectrum, from left to right, we want to help by presenting specific, simple rules that would be very easy to implement and could change the situation,” Brzoska said.

1.76 million ads scrutinized

ScamWatch downloaded 2,045,114 ads into its repository, of which 1,760,358 were analyzed. Of these, 290,829 ads, or 16.5% of the material reviewed, were classified as suspicious. A further 28,215, or 1.6%, were rated as posing a “very high risk.”

The report compares its findings with data from other sources. Its authors cite an analysis by Instrat, according to which Meta generates 37% of its advertising revenue in Poland from fraudulent ads, equivalent to around PLN 760 million. The report also includes data from Bitdefender Labs, which estimates that Poland accounts for around 18-20% of detected cases of fraudulent investment ads on Meta’s platforms.

The “150% Stop Scam” campaign itself collected more than 167,000 signatures and, according to a report by its organizers, generated a combined reach of 63.8 million across published content and media mentions.

In response to the publication of the ScamWatch report, Meta’s press office issued a statement later that evening. It said the report, like Instrat’s report published the previous week, was unreliable.

Brzoska: the problem lies in how the system is designed

Rafał Brzoska accused Meta of breaching obligations under the EU’s Digital Services Act. He pointed in particular to delays in ads appearing in the advertising library, the ability to alter an ad after it has run, and restrictions that make it harder to download data at scale for monitoring and research purposes.

“We have evidence that Meta, in Poland and beyond, is violating the DSA. (...) The fact that we have not implemented the necessary national enforcement rules only limits our room for maneuver as a state and our ability to act effectively and more quickly. But Meta is breaching the DSA in several areas. First, it does not publish scam ads in its advertising library on an ongoing basis and often does so with a 24-hour delay. (...) If someone has not managed to disappear in time, this gives criminals the opportunity to make one more move. They replace an ad for a pornographic app or a deepfake with an ad for jeans or sneakers, so that the evidence of the offense disappears from the library,” Brzoska said.

One of the main mechanisms involves impersonating trusted individuals, companies and institutions. Sebastian Kondracki, the creator of Bielik and author of the report, cited public figures, commercial brands, banks, Lotto and public institutions. Trust in a recognizable brand or face is used to persuade recipients to click, hand over their data or visit a website that leads to a scam.

“This is about exploiting and impersonating someone else’s credibility and trust, and then selling or stealing citizens’ data,” Kondracki said.

Expert's perspective

Instrat has scrutinized Meta and is ready for an independent review

Meta’s response to Instrat’s report should be settled on the basis of data, not statements. We therefore propose that, together with Meta and industry organizations, we appoint an independent external auditor. The auditor should verify both the methodology of our study and the platform’s internal data: the actual scale of advertising revenue, the breakdown of revenue by client, the number of impressions and the effective cost of reaching users with fraudulent ads.

Our report does not claim that around 10% of Meta’s revenue comes from scams. We estimate that fraudulent ads account for around 10–11% of impressions, while at the same time scammers pay several times more to reach users than ordinary advertisers do. This also matters for competition in the advertising market, because in an auction-based system legitimate advertisers have to compete on price with entities engaged in fraudulent activity, which may increase the cost of their campaigns.

If we have made a mistake, an independent audit should demonstrate it. We are ready to submit our findings to such scrutiny and, where justified, revise our conclusions. But we expect the same level of transparency from Meta and for the auditor to be given access to the data needed to establish the true scale of the problem. We stand by the figures presented in the report and are prepared to have them tested against the expertise of specialists in cybersecurity, cybercrime and social-media campaigns.

How scams work on Meta

Sebastian Kondracki described schemes in which only by combining several seemingly unrelated signals – the advertiser’s profile, the payer’s details and the landing page – does the suspicious mechanism become apparent. As an example, he cited a restaurant in New York that advertised a picture of a bird, even though the link in the ad led to an entirely different website.

“There is not even a business rationale for an advertiser somewhere in the world – say, a small café in New York – to advertise a bird and then direct users to a link belonging to a Canadian company,” Kondracki said.

Kondracki also devoted considerable attention to pornographic and sexual content generated by AI. In his view, some ads contain tutorials that direct users to applications for creating sexualized material and deepfakes. He also stressed the risk of children and teenagers being exposed to such content.

“These are ads and tutorials showing, in the most appalling way, how to generate a sexual deepfake. They are available to everyone, including minors,” Kondracki said.

Scams go beyond fake investments

ScamWatch does not focus solely on conventional investment scams. The report identifies 12 categories of abuse, including impersonation of brands, companies, public figures and government institutions; financial and cryptocurrency scams; data theft; false health claims; illegal gambling; pornographic content in advertisements; misuse of children’s images; and the promotion of illegal activities and applications.

Sebastian Kondracki also points to a technical problem in the ad-delivery system. In his view, its biggest weakness is the lack of adequate safeguards at the point when advertisers and ads themselves are admitted to the system. He argues that this is one of the reasons the problem has reached such a large scale.

“The report shows the scale of the problem, and it is enormous. But the most important issue is the lack of any meaningful safeguards in the ad-delivery networks themselves,” said the creator of Bielik.

Expert's perspective

The problem with ads on Meta

The problem of fraudulent advertising on platforms such as Meta needs to be addressed systemically. The services may appear to be free, but in practice users pay with their personal data and attention, while the social costs of this model are also borne by businesses, the justice system and the state. Recommendation systems play a central role because they reward user engagement, increasing the visibility of sensationalist content, clickbait, deepfakes and scams.

More effective removal of illegal content alone will therefore not solve the problem, because algorithms can still promote material that falls just short of the threshold of illegality while remaining socially harmful. The European Union already has tools in place, above all the Digital Services Act and the Digital Markets Act, and they need to be used effectively. The European Commission can bring proceedings against the largest platforms, but efficient national procedures are also necessary. Polish authorities should be able to flag flagrantly illegal content quickly and respond when a platform fails to meet its obligations. Poland currently lacks such an effective mechanism.

Content-blocking mechanisms, subject to judicial oversight, should not be portrayed as a threat to freedom of speech. Their purpose is to protect consumers, personal data and individuals’ likenesses, and to limit the spread of illegal, fraudulent and graphic content. Regulatory pressure is therefore needed in parallel at both the national and EU levels.

KYC not just for banks. Advertisers should be verified too

Rafał Brzoska called for specific legislative action targeting social-media platforms. His first proposal is mandatory verification of advertisers before a campaign can be launched. The entrepreneur pointed to KYC, or “know your customer,” procedures that have long been used in banking and payment services. As he noted, similar requirements also apply in other industries, while InPost itself verifies companies that want to use its services.

According to Brzoska, the problem with digital advertising is that reach can currently be purchased without sufficiently strong links between the advertiser and payer and a specific, verified individual or company.

“Advertisers must be verified by those who display the ads. (...) The rule is very simple. You have to verify your advertiser. That means the advertiser and payer listed in the ad library cannot appear as three ones or four letter Hs. They must be verified before they can pay for the ad,” Brzoska said.

In the report, this proposal amounts to a requirement to establish who is buying the advertisement and who is paying for it and, in the case of higher-risk entities, who their beneficial owner is. If an advertiser cannot be reliably verified, the campaign should not be allowed to launch.

Expert's perspective

Meta needs to be monitored

The fight against scams should not be limited to a single platform or individual categories of fraud. The first problem is access to data. Meta’s Ad Library and its API impose query limits, even though the number of ads targeting Polish users may be far higher. If the scale of the problem is to be assessed reliably, independent researchers and trusted organizations should have broader access to advertising data instead of having to reconstruct the market from limited fragments.

The second issue is the need to extend monitoring beyond Facebook and Instagram. Fraudulent ads also appear in other advertising ecosystems, including Google Ads and programmatic networks operating across websites. Monitoring should therefore cover the largest channels responsible for most ad distribution.

The third element is cooperation. The scale of the problem warrants a broad coalition of civil-society organizations, public institutions and the financial sector. This should cover not only investment scams but also fake casino ads, illegal gambling and attempts to steal data and money through messaging services. In practice, a scam does not end with the advertisement itself: it can move into Messenger or a platform’s business tools, which are not always subject to the same regulatory mechanisms. Monitoring and regulation should therefore cover the entire chain – from ad delivery and the flow of money to direct contact with a potential victim.

Even 150% may not be enough

The second proposal concerns the financial liability of platforms. The initiative’s name comes from its original proposal that an administrative fine should amount to 150% of the revenue generated from running an ad classified as a scam, together with related ads.

At the conference, however, Brzoska significantly toughened that proposal.

“If it turns out they have failed to verify someone, there should be a draconian penalty – either a percentage of revenue or, as we originally proposed, 150% of the amount collected. That principle would create real liability for the platform. It cannot simply mean returning what was collected, because that is no punishment at all. (...) I regret that when we came up with the 150% figure, we did not know the scale of the phenomenon. It should be 300%, 400%, 500%. Ultimately, we leave it to politicians to determine the percentage,” Brzoska said.

The InPost chief also argued that ads unlawfully using his image began to disappear only after he launched the 150% initiative. According to him, their number had not declined earlier, even after court rulings.

“The number of ads featuring me fell only after I launched the 150% initiative. Before the court ruling and after the court ruling, the number of such ads was not only no lower, but was actually increasing,” Brzoska said.

He added that such ads have now virtually disappeared, which, in his view, shows that the platform is capable of removing them effectively.

“All the nonsense they feed us – and you, as journalists – is just that: nonsense,” Brzoska said.

He also issued a direct challenge to Meta.

“If they disagree, I will say it again and encourage them: sue me for saying something that is untrue. Sue me,” Brzoska said.

Fine revenues should go to scam victims

The third element of the package is a compensation fund for scam victims. Part of the proceeds from administrative fines imposed on platforms would be used to support people who have lost money, data or suffered other harm as a result of fraud.

Brzoska also wants some of the money to be allocated to digital education, particularly for people who have the greatest difficulty assessing the authenticity of AI-generated content.

“The fund could easily be financed from the proceeds of these fines. In addition, part of the money could be earmarked by statute for education, especially for people who are digitally excluded, so that they are not left vulnerable simply because their exclusion makes it difficult for them to distinguish what is fake from what has been generated by artificial intelligence,” Rafał Brzoska said at the press conference.

A printed version of the report is to be sent to all members of the Sejm, senators and members of the government.

Rafał Brzoska vs. Meta: from deepfakes to ScamWatch

Rafał Brzoska’s dispute with Meta has been going on for years. Campaigns appeared on Facebook and Instagram using the images of Brzoska and Omenaa Mensah to promote fictitious investments. In one case, fabricated material suggested that the entrepreneur had created an investment platform guaranteeing returns for Poles.

Despite the ads being reported, similar material continued to appear. The case also reached Poland’s Personal Data Protection Office (UODO). The authority issued a statement saying that “following a complaint by Mr Rafał Brzoska, Meta Platforms Ireland Limited must suspend the display, on Facebook and Instagram, of advertisements using Mr. Rafał Brzoska’s real personal data.”

Brzoska and Mensah also pursued the case through civil proceedings. In November 2024, a Warsaw court granted interim relief, banning for one year the publication of specified advertising materials using their images. Meta faced a financial penalty for breaching the injunction. The company appealed the ruling.

On March 27th 2026, the Warsaw Court of Appeal partially upheld the interim relief relating to Omenaa Mensah, while overturning the part concerning Rafał Brzoska, finding that the ban was too broad.

Court: Meta is not merely a passive intermediary

In its reasoning, the court said that when it comes to paid advertising, Meta is not merely a passive provider of infrastructure. It has access to ad content before publication, receives payment for running the ads and provides algorithmic tools that increase their reach and allow them to be targeted at specific groups of users. At the same time, the court stressed that interim relief cannot impose a general obligation on the platform to monitor all future content.

In the summer of 2026, the dispute once again moved beyond the courtroom. Rafał Brzoska warned that fraudulent ads using his image were continuing to appear on Meta’s platforms. In August, he launched the “150%” initiative. Its central proposal is to structure platforms’ financial liability so that the cost of running a fraudulent ad exceeds the revenue generated from it. The proposed 150% penalty, however, remains a policy proposal put forward by the initiative rather than binding law.

ScamWatch tracks fraudulent ads

The next step was the launch of ScamWatch, announced on August 27th. Developed by a team led by Sebastian Kondracki, one of the creators of Bielik, the tool is designed to detect and document suspicious campaigns, link ads to domains and other elements of infrastructure used by scammers, and measure how quickly platforms respond. Users can report suspicious ads through a form, after which cases are analyzed with the involvement of experts from the Rafał Brzoska Foundation. ScamWatch is intended to document specific cases and show how long suspicious ads remain active.

Meta responded to Rafał Brzoska’s actions.

“In recent days, we have seen a campaign that distorts the picture of Meta’s actions and motivations in the fight against scams,” Jakub Turowski, Meta’s Director of Public Policy for Central and Eastern Europe, wrote in a post published on the company’s website.

He stressed that scams harm not only their direct victims but also trust in the broader online advertising market.

“At the same time, they undermine trust in the advertising ecosystem on which our business model depends. Today, we are announcing additional safeguards that we are introducing in Poland, as well as providing an update on the work we have done so far and its results,” Turowski wrote.

The Meta executive also accused the campaign’s organizers of creating a false impression of the company’s financial incentives in dealing with scams.

“It is false and relies on data from unreliable Reuters reports and selectively quoted leaked documents. It misrepresents Meta’s approach to scams and abuse. It focuses on research we conducted to assess the scale of the problem, while ignoring what followed: concrete enforcement action against violations of our policies, product changes and industry partnerships,” Turowski wrote.

Instrat report shows the scale of the problem

In September, Instrat estimated that Meta’s revenue from fraudulent ads in Poland could reach PLN 760 million a year. Meta challenged the study’s methodology and described the report as misleading.

“We estimate that Meta’s revenue from fraudulent advertising may be as high as PLN 2 million a day. That translates into as much as PLN 760 million a year. If we compare that with the revenue reported by Facebook Poland, of around PLN 2 billion annually, scams could account for as much as 37% of revenue,” Dr Jarosław Kopeć, the report’s author, said at the conference.

According to the analysts, 41% of fraudulent ads do not appear in the so-called Ad Library.

“Scammers use technical tricks to avoid losing access to their accounts. They use techniques that allow them to conceal the real, fraudulent content behind what appears to be an ordinary advertisement,” Dr Kopeć added.

As an example, he pointed to an ad using the image of Michał Sołowow. According to the report’s authors, it directs users to a fake Ministry of Finance website and forms part of a financial scam, even though it appears in the Ad Library as an advertisement for a pet-grooming tool.

Meta firmly rejected the estimates.

“This report is a commissioned fiction designed to mislead the public. It was commissioned by a law firm representing a person who has sued us. It is based on flawed assumptions, incorrect definitions and a small sample, producing inflated and absurd figures that misrepresent our extensive efforts to combat scams,” Meta’s press office wrote in response to questions from XYZ.

Key Takeaways

  1. The ScamWatch analysis points to a large volume of potentially harmful advertising across Meta’s ecosystem. Of more than 1.76 million ads analyzed, around 290,800, or 16.5%, were classified as suspicious, while more than 28,000 were rated as very high risk. The report covers not only fraudulent investment schemes but also impersonation of public figures, companies and institutions, data theft, false health claims, illegal gambling, sexual content and AI-generated deepfakes.
  2. Rafał Brzoska and the report’s authors argue that inadequate verification of advertisers before campaigns are launched is one of the sources of the problem. They propose mandatory KYC checks for entities buying ads and greater financial liability for platforms that carry fraudulent content. Brzoska also argues that the originally proposed penalty of 150% of the revenue generated from such ads may be too low. Part of the proceeds from sanctions would go into a fund for victims and finance digital education.
  3. The scale of the problem and Meta’s responsibility remain the subject of a heated dispute. Brzoska accuses the company, among other things, of insufficient oversight of advertising and irregularities involving the Ad Library. Meta says the portrayal of its actions is distorted and that some analyses rely on flawed methodology and inflated estimates. The company strongly disputes, among other findings, Instrat’s estimate that revenue from fraudulent ads in Poland could reach PLN 760 million a year. The dispute has already taken on legal and regulatory dimensions, while the ScamWatch report is set to be sent to members of parliament and the government.

We covered this story because we considered it important and newsworthy. In the interest of full transparency, we note that RiO, a fund owned by Rafał Brzoska, CEO and shareholder of InPost, is an investor in XYZ.