

Meta scam ads after Frankfurt: the hosting shield cracks
On 16 September 2026 a Frankfurt court set a fine of up to EUR 250,000 for each future breach of its order that Meta stop distributing impersonation adverts aimed at one German finance brand. For anyone advertising regulated products on Facebook or Instagram, that number is a signal about where the approval queue is heading.
By Katie Delaney / 2026-09-20 / 16 min read

What the Frankfurt court held about meta scam ads and the hosting shield#
per breach: the ceiling on fines if Meta breaks the injunction the Frankfurt Regional Court issued on 16 September 2026
A fox reads the hedgerow before it commits to the hunt, and on 16 September 2026 the hedgerow rearranged itself. The Frankfurt Regional Court ruled in case 2-06 O 234/25 against Meta Platforms Ireland and in favour of Finflow GmbH, the company behind the financial education brand Finanzfluss, and its founder Thomas Kehl, according to the anonymised judgment that the plaintiffs' lawyers at Spirit Legal published.
Fraudsters had borrowed Kehl's face and the brand's name on Facebook and Instagram to steer people towards investment chat groups. The court ordered Meta to stop distributing that content, to disclose its reach and revenue, and to compensate the plaintiffs for the damage. For meta scam ads, the sting sits in the enforcement clause: up to EUR 250,000 for each future breach.
The legal hinge is Article 6 of the Digital Services Act. The EUR-Lex text of the regulation frames it as a shield for a provider that merely stores information, on condition that the provider has no actual knowledge of illegal content, or acts expeditiously to remove it once it does.
Meta's defence was the classic one: we host, we do not choose. The court did not accept it. Meta itself told the judges that it decides the ranking and timing of adverts in an automated auction, with a quality score as a third component, and the court held that merely running an auction to criteria Meta sets gives Meta a control and decision-making function over the adverts that is superior to the individual advertiser's. That is our translation of the passage Spirit Legal quotes from page 31 of the judgment.
Choosing an audience does not change the picture, the court added, because Meta still decides which concrete users see the advert.
The reasoning behind the meta scam ads ruling leans on the Court of Justice of the European Union. In joined cases C-188/24 and C-190/24, decided on 16 June 2026, the Court said, in its own press summary, that a provider which determines by algorithm the conditions, manner and priority order in which information is rebroadcast exercises control over that information and is not exempted from liability. Frankfurt carried that logic across to ad auctions. In the alternative, it held that even if Article 6 applied, Meta had not removed the content expeditiously, pointing to removal times of 20, 14 and 62 days for three items in the case.
Read the edges of the meta scam ads ruling too#
The judgment is first instance and not final. Spirit Legal says an appeal to the Higher Regional Court in Frankfurt is possible, and the law journal MIR called an appeal not unlikely. The court also drew a line: services that leave the choice of content to users, such as purely chronological feeds on Mastodon or Bluesky, probably exercise no such control. Meta's reply, reported by The Next Web, was that it respectfully disagrees and is considering next steps. Everything below on meta scam ads therefore rests on attribution: the court held, the plaintiffs' counsel said, Meta replied.
The meta scam ads lawsuit in numbers: 256 reports and up to 62 days#
The numbers in the meta scam ads lawsuit are the part that plays best in a boardroom, because they are counts rather than adjectives. The plaintiffs used Meta's own Brand Rights Protection Tool, which the judgment describes as letting rights holders register marks, search by keyword, phrase or URL, and upload up to 200 reference images. Between 29 July and 28 August 2024 they reported about 256 violations through it, according to the judgment. The law journal MIR, drawing on the court's press release, says almost 260 for August 2024 alone; the two figures describe the same trail.
Then comes the slow part. The judgment recites removal times item by item. A fake Kehl profile reported on 30 May 2025 stayed up for 20 days. A second fake Kehl profile and a fake Finanz Fluss profile each took 14 days. One Instagram imitation took four days, another came down the same day, and a deepfake video advert, which Meta's own information showed running from 3 to 15 June 2025 and reaching more than 5,000 users, was recorded at 62 days from the claimants' reported notification.
That last count rests on the claimants' account of when they reported it; the judgment treats the report as their claim. Taken together, the claimants put removal times between zero and 62 days.

Meta's counter-arguments, as the judgment records them, were the ones every platform reaches for. A name alone is a weak signal among billions of accounts. Article 8 of the Digital Services Act imposes no general duty to monitor. Spotting equivalent variants at scale is not technically possible. In this meta scam ads case the court granted the plaintiffs' claims anyway and let the injunction reach altered and equivalent spellings of the brand and the founder's name, per the Spirit Legal press release. For a platform built on volume, equivalence is where the order bites.
In the meta scam ads record, persistence is the detail a fox notices. After the claimants sued, the judgment records, Kehl consented on 24 September 2025 to enrolment in Meta's facial recognition programme, which Meta had offered during earlier settlement talks, and fresh infringing content still appeared almost daily, for example in November 2025. The claimants also kept one employee on full-time watch and had hired a specialist takedown firm. Being impersonated was already a staffed cost line before any court got involved.

Meta scam ads face a regulatory pile-on, not one German case#
| Item | Value |
|---|---|
| 86.8% of 122 flagged scam adverts stayed | 86.8% of 122 flagged scam adverts stayed |
| live, Poland's minister said | live, Poland's minister said |
Frankfurt is one thicket in a wider wood of meta scam ads scrutiny. On 26 August 2026 Poland's digital minister asked the European Commission to fine Meta EUR 250 million over scam adverts, citing tests by the national cybersecurity team CERT Polska, according to Reuters as carried by Business Standard. He said Meta left 106 of the 122 flagged adverts in place, removed ten and did not respond on six.
Meta told Reuters it was making every effort to stop fraud. Digital Watch Observatory reported on 28 August that the Commission had yet to open an inquiry aimed specifically at financial scam adverts, and that Warsaw's referral alleges breaches of six Digital Services Act articles.
In Britain the pressure arrives from two directions. The Financial Conduct Authority said on 24 April 2026 that, within accounts it asked platforms to take down, it found 1,267 illegal financial adverts that reached at least 2,338,372 UK accounts, and that 66% came from firms or individuals already on its Warning List. The data was specific to Meta platforms, and the regulator said platforms were not doing enough to uphold their own policies, per the FCA press release.
Ofcom then published draft fraudulent advertising codes on 10 July, which Lewis Silkin summarises as nearly 40 measures, among them robust checks when advertisers open accounts, checks that anyone advertising financial services products is legally permitted to, and bans for advertisers who post fraudulent adverts. The consultation closes on 2 October 2026, with final decisions expected next year.
Set that beside the money. Reuters reported last year that internal documents suggested about 10% of Meta's 2024 revenue, roughly $16 billion, would come from ads for scams and banned goods, as The Next Web recalled. Meta says it removed 134 million scam adverts in 2025, according to PPC Land, which attributes the figure to a VAB analysis. Both sets of numbers can hold at once, and the disclosure order in Frankfurt is built to find out which one describes the Finanzfluss case.
| Rule or policy | What it asks for | Where it stands on 20 September 2026 |
|---|---|---|
| DSA Article 6 | A shield only without actual knowledge, or with prompt removal | In force; Frankfurt held Meta's control defeats it (first instance) |
| DSA Articles 34 and 35 | Very large platforms assess systemic risks and mitigate them, including by adapting advertising systems | In force for very large platforms |
| Meta finance ad policy | Advertisers may need to verify identity and show regulatory authorisation | Live on the Transparency Centre |
| Ofcom draft fraud code | Advertiser checks, permission checks for financial products, bans for repeat offenders | Draft; consultation closes 2 October 2026 |
| FCA position | Platforms to stop illegal financial promotions at source | Stated on 24 April 2026 |
- DSA Article 6A shield only without actual knowledge, or with prompt removalIn force; Frankfurt held Meta's control defeats it (first instance)
- DSA Articles 34 and 35Very large platforms assess systemic risks and mitigate them, including by adapting advertising systemsIn force for very large platforms
- Meta finance ad policyAdvertisers may need to verify identity and show regulatory authorisationLive on the Transparency Centre
- Ofcom draft fraud codeAdvertiser checks, permission checks for financial products, bans for repeat offendersDraft; consultation closes 2 October 2026
- FCA positionPlatforms to stop illegal financial promotions at sourceStated on 24 April 2026
The scent runs the same way in every row of the meta scam ads debate. Whether the pressure comes from a court, a regulator or Meta's own rulebook, the verification duty is moving upstream, towards the moment an advertiser opens an account or submits a finance advert. Article 35 of the Digital Services Act even lists adapting advertising systems among the mitigation measures very large platforms may take.
What meta advertiser verification asks of finance advertisers today#
Start with what Meta already says. As of 20 September 2026, the Meta Transparency Centre policy on financial and insurance products says advertisers promoting financial products and services may be required to verify their business and/or individual identity and to demonstrate that they are authorised by the relevant regulators where that is a requirement, and that any such authorisation may be subject to review by Meta.
It adds that targeting some countries needs a licence, and it lists insurance, mortgages, loans, investment products and credit card applications among the products that may need one. That is meta advertiser verification in Meta's own words, and the phrase to notice is may be required: the trigger is discretionary.
The same page bars adverts that promote binary options, contract for difference trading and initial coin offerings. For adverts targeting the United States, it bars investment offers that suggest interaction with the advertiser through direct messaging, on or off the platform. That last rule is the WhatsApp-group pattern the Frankfurt fraudsters used, and it shows the policy already knows where the scent leads.
Here is where folkfox sticks its neck out, and it is a forecast, not a report. Before the meta scam ads ruling, the cost of approving a bad finance advert fell mostly on the victim. After it, on the court's first-instance reasoning, some of that cost can land on the platform, with a fine ceiling of EUR 250,000 a breach in these plaintiffs' injunction.
A platform facing that arithmetic tightens the door: more identity checks, more licence evidence, more manual review in finance, crypto, health and gambling categories, and, we expect, slower approvals and more false positives for honest advertisers. Meta has announced no such change; its statement, per The Next Web, says only that it disagrees and is weighing next steps. The moves are cheap to make early and costly to make in the middle of a rejected launch.
Curious if this actually changes anything for verification on our end or if it just ends up being a Meta problem that never touches advertiser accounts.
The r/PPC poster asks the right question about meta scam ads. Our reading is that the ruling reaches advertisers in two ways, in this order: first as friction, from stricter gates on finance categories, then as protection, from a platform with a sharper reason to act when your brand is impersonated. Fintech and web3 teams already know the first half. The MiCA licence piece shows how licence evidence decides who gets adverts in Europe, and the Revolut social engineering case shows how quickly a verification step becomes an attack surface.

How facebook scam ads turn into a paid social budget line#
Begin with the budget argument, which is folkfox opinion rather than finding. The plaintiffs staffed the problem: one full-time employee and, earlier, a specialist removal agency, according to the judgment. Few brands have a Finanzfluss-sized audience, about 1.5 million YouTube subscribers and more than 600,000 Instagram followers in the court's recital, but every brand that advertises financial products on Facebook or Instagram sits in the same undergrowth.
Facebook scam ads that wear your logo cost you three ways. Customer losses and complaints land on your desk. Your own ad account is judged beside lookalikes that share your name. And someone has to find, document and report each fake, on the clock.
Read the chart of removal times the way a fox reads a trail: not the average, the outlier. The court did not decide the case on the typical delay. It decided it on control, and the delays supplied the evidence that a shield built for passive storage had stopped fitting an auction house. What the chart does show is how long a fake can trade on your name while you wait, and that is a cost, whatever the appeal brings.
Treat meta scam ads exposure as a line in the paid social plan, next to creative and media, with a named owner and a monthly number. Our paid social services work for regulated advertisers starts from exactly that split: media spend, verification evidence, and impersonation monitoring, each with its own budget and its own report.
The same logic reaches beyond fintech. iGaming, web3 and health advertisers share the traits that make platforms nervous: regulated claims, licence dependence, and lookalike scams that borrow trusted names. If your category already needs a licence check, and our pages on fintech marketing, web3 marketing and healthcare marketing each describe where that bites, assume the check will get stricter, not looser. Retargeting budgets already leak to fake traffic, as we covered in bot traffic and retargeting CPMs; fake adverts wearing your name are a second leak in the same pipe. Platform-side friction also has form: see how Meta child-safety settlement ads met a TikTok policy wall.
A five-step order of work before the approval queue lengthens#
Build, launch, then chase the paperwork
Creative goes live in the queue, a rejection arrives, and licence evidence is assembled under deadline while the media plan stalls.
Evidence, monitoring, then spend
Identity and licence evidence sit ready, impersonation monitoring runs before launch, and the first advert meets a queue that already knows who you are.
The order matters more than the effort. Paperwork first, monitoring second, spend third. Most teams do it the other way round: they build the campaign, hit a rejection, and only then go hunting for the licence evidence that would have cleared it. A fox plans the escape route before entering the henhouse.
Watch four things about meta scam ads over the coming months, because each could change the arithmetic: whether Meta appeals and what the Higher Regional Court says; how the European Commission answers Poland's referral; Ofcom's final decisions on fraudulent advertising, which its consultation says will arrive next year; and the change log on Meta's own financial services policy page, which is where a quiet tightening would show first.
None of this needs a courtroom. It needs an owner, a checklist and a monthly review. If you would rather hand the checklist to a team that runs it daily, that is what our fintech marketing and paid social practice does, and you can start the conversation whenever the queue starts to slow.
Frequently asked questions#
Why are there so many scam ads on Facebook?
Several forces overlap. Adverts are cheap to make, and Ofcom's draft code, as summarised by Lewis Silkin, notes that generative AI has cut the cost further. An auction sells reach to whoever bids. Regulators and courts now say enforcement lags: the FCA found 1,267 illegal financial adverts on Meta platforms in one April 2026 action. Meta says it removes scam adverts at scale and keeps investing.
What did the Frankfurt court rule about meta scam ads?
On 16 September 2026 the Frankfurt Regional Court, in case 2-06 O 234/25, held that Meta cannot rely on the Digital Services Act Article 6 hosting exemption for these impersonation adverts, because running an ad auction is control. It ordered Meta to stop distributing the content, disclose reach and revenue, and compensate the plaintiffs, with fines up to EUR 250,000 per breach.
Is the meta scam ads lawsuit final?
No. The judgment is first instance. The plaintiffs' counsel and the MIR law journal both say an appeal to the Higher Regional Court in Frankfurt is possible, and Meta told the press it respectfully disagrees and is considering next steps. The injunction binds Meta only in respect of the two plaintiffs and their marks.
Does Meta advertiser verification apply to fintech advertisers?
It can. Meta's financial and insurance products policy, as of 20 September 2026, says advertisers promoting financial products may be required to verify their business or individual identity and show regulatory authorisation where required, and that Meta may review it. Targeting some countries needs a licence. Check the policy page for your product and market.
Will Meta ad approvals slow for finance brands after the meta scam ads ruling?
Nobody outside Meta can say yet, and Meta has announced no change. It is folkfox's forecast, not a finding, that platforms facing fines and regulators will add checks in finance, crypto, health and gambling categories, so slower approvals are plausible. Getting verification and licence evidence ready first is the low-cost hedge.
How do I report a fake advert that impersonates my brand on Meta?
The plaintiffs in the Frankfurt case used Meta's Brand Rights Protection Tool, which per the judgment lets rights holders register marks, search by keyword, phrase or URL and upload up to 200 reference images. Log the URL, a screenshot, and the time of each report and each removal, because delays were the evidence in court.
Read more on this topic#
TikTok advertising: 5 practical policy lessons
When a platform policy wall meets a settlement advert, five lessons for policy, creative and media teams.
Read the pieceFintechSocial engineering fraud: 5 sharp lessons from Revolut
How a fake government request reached a fintech, and what the first 72 hours and verification should look like.
Read the pieceWeb3MiCA licence: 5 proven moves for crypto growth teams
A licence now decides who gets ads and passporting in Europe; how to market while an application is pending.
Read the pieceFintechFintech digital marketing agency: 5 sharp Nubank lessons
A claims risk map for a rate-first US launch.
Read the pieceVerified first, then visible
At folkfox, paid social for regulated advertisers treats verification evidence, impersonation monitoring and media planning as three budgets, not one.
Want folkfox in your Google results and AI answers? Set folkfox as a preferred source.