Meta removed dozens of deceptive ads after India raised concerns that fake adult-content apps were being used to steal sensitive data and target bank accounts.

Meta Removes Scam Ads After India Warns About Fake Porn Apps Targeting Bank Accounts

The420 Web Correspondent
6 Min Read

Meta has removed dozens of advertisements from Facebook and Instagram after India raised concerns about a growing cyber fraud campaign that used sexually explicit content to push users towards malicious Android applications.

The advertisements promoted apps with names including Night Play and Kyss. They were presented as entertainment or adult-content applications, but the apps could potentially access sensitive information on a user’s phone and help criminals target banking credentials, OTPs and other financial data.

The development is significant because the advertisements were not being distributed through obscure websites alone. They were appearing on two of the world’s largest social-media platforms, putting the scam directly in front of users through paid advertising.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

How can a fake app turn an advertisement into a banking scam?

An APK is the installation file used by Android devices. Unlike an app downloaded through an official store, an APK obtained from an unknown website or advertisement may come from a source that has not undergone the same level of screening.

The danger increases when the application asks for powerful permissions. These can allow an app to interact with parts of the phone that have nothing to do with its advertised purpose.

In this campaign, the malicious applications could potentially access sensitive device information, intercept OTPs and banking PINs, and assist criminals in carrying out unauthorised transactions. That turns what looks like a simple advertisement into the first step of a financial attack.

India’s cybercrime authorities have been warning about malicious applications for weeks. The Ministry of Home Affairs said in August that I4C had already blocked 3,718 mobile applications, including fraudulent loan apps, by June 30, 2026.

India raised the alarm, but scam ads were still appearing

The latest incident also raises questions about how quickly social-media platforms detect malicious advertising themselves.

According to Reuters, India had already raised concerns about the campaign when the news agency found at least 39 related advertisements still active on Meta’s platforms. Meta subsequently removed those advertisements after Reuters approached the company.

Meta’s advertising systems are designed to identify prohibited and deceptive content before it reaches users. But the episode shows how quickly criminals can adapt their presentation.

Instead of openly advertising a banking scam, the operators allegedly used curiosity and explicit content to get users to install an application. The malicious activity could then take place on the victim’s own device, where the application had access to information and functions granted by the user.

That makes these campaigns particularly difficult for ordinary users to recognise. The advertisement may not contain an obvious request for money, banking details or an OTP.

The bigger problem is India’s growing cyber fraud bill

The campaign comes as India faces a sharp rise in financial cybercrime.

Government data shows that citizens reported ₹22,495 crore in cyber fraud losses during 2025, across more than 24 lakh complaints. The reported amount has risen dramatically from ₹551 crore in 2021.

The Central Government has responded by expanding the role of the Indian Cyber Crime Coordination Centre and its financial-fraud response system. The Citizen Financial Cyber Fraud Reporting and Management System is designed to help banks and police act quickly when victims report stolen money.

By June 30, 2026, the system had helped save more than ₹11,158 crore across more than 32.80 lakh complaints, according to the Ministry of Home Affairs.

But stopping the money after fraud occurs is only one part of the problem. Increasingly, authorities also have to deal with the digital routes through which criminals find victims in the first place.

Meta is not facing this issue in isolation. Regulators and governments in other countries have also increased pressure on major technology companies over fraudulent advertisements. Poland, for example, recently urged the European Commission to impose a €250 million penalty on Meta over allegations that it had failed to adequately address scam advertising. Meta said it was investing in technology and partnerships to tackle increasingly sophisticated scams.

For India, the immediate question is whether removing individual advertisements is enough. Fraudsters can change names, create new pages and modify their advertisements quickly.

The stronger test will be whether platforms can identify the underlying networks behind these campaigns and stop the same operators from repeatedly returning under different identities.

What this means for you: Do not install an Android APK simply because it appears in a Facebook or Instagram advertisement, particularly when the offer promises exclusive videos, cashback, investments, jobs or other unusually attractive content. If you have already installed a suspicious app, remove it, review its permissions and check your bank and UPI accounts for unusual activity.

If money has already been lost, report the fraud immediately through 1930 and the National Cyber Crime Reporting Portal. The faster the transaction is reported, the greater the opportunity for authorities and banks to intervene before the money is moved further.

Stay Connected