Meta has dismantled dozens of fraudulent advertisements appearing on Facebook and Instagram following an alert from India's government about a coordinated campaign deploying sexually explicit content to trick users into downloading malicious software targeting bank accounts and financial credentials. The social media giant acted after authorities in New Delhi flagged a troubling pattern in which scammers were weaponising adult material as bait to distribute what appeared to be pornography applications, which functioned instead as sophisticated banking trojans capable of harvesting sensitive financial information.

India has become increasingly vulnerable to digital fraud schemes as its population embraces mobile payments and online banking at accelerating pace. Government statistics reveal that cyber fraud losses totalled nearly $2.4 billion across 2025, a sobering figure that underscores how criminals are capitalising on the country's rapid digitalisation. The sheer scale of financial damage demonstrates that fraudulent activity has evolved from isolated incidents into an industrial-scale enterprise, with organised groups systematically targeting India's growing digital economy.

The Indian government's advisory detailed how malicious advertisements operating under labels including "Night Play" and "Kyss" were directing unsuspecting users toward fraudulent websites designed to look legitimate. These deceptive landing pages employed psychological manipulation by prominently featuring adult video thumbnails and suggestive imagery to overcome user scepticism and drive installation rates. The scheme exploited a fundamental vulnerability in human behaviour: the combination of social shame and curiosity that discourages victims from reporting compromised accounts or seeking help from authorities.

Journalists investigating the scope of this fraud discovered at least 39 such advertisements remained active even after the government's Monday advisory had been publicly disseminated. The persistence of these listings suggested either insufficient moderation resources at Meta or inadequate detection systems capable of identifying such schemes in real time. Following direct communication with the technology company about these remaining advertisements, Meta subsequently removed all identified listings, though the company declined to comment on either the removal process or the underlying government concerns.

Meta's own stated advertising policies explicitly prohibit content featuring adult nudity and sexual activity, and similarly ban promotions for products, services, or schemes utilising deceptive practices intended to financially exploit consumers. These policy frameworks ostensibly should have prevented such advertisements from appearing on the platform in the first place, raising questions about enforcement effectiveness and whether detection algorithms adequately monitor for sophisticated fraud patterns that combine multiple policy violations simultaneously.

One particularly illustrative example involved an advertisement linking to a website promoting what appeared to be a video streaming application offering extensive pornographic libraries with continuous content availability. Installation required users to manually download and execute a file named "Movexa.apk" from outside the regulated Google Play Store ecosystem, a significant red flag that should have triggered heightened scrutiny. This offline installation requirement deliberately circumvented app store security reviews designed to identify malicious code, essentially forcing users to disable their devices' standard protective mechanisms.

The malicious applications identified in this scheme possessed dangerous capabilities extending far beyond typical banking trojans. According to India's government analysis, these programs could silently access confidential information stored on infected devices, intercept one-time passwords sent via SMS for authentication purposes, capture personal identification numbers associated with bank accounts, and most alarmingly, autonomously initiate unauthorised fund transfers without the account holder's knowledge or consent. The sophistication of these capabilities suggests either professional criminal development or assistance from individuals with legitimate software engineering expertise.

This latest security incident represents the second major fraud-related crisis India has directed at major technology platforms within recent weeks, indicating a broader pattern rather than isolated incidents. Authorities previously compelled Google to deactivate hundreds of accounts operating on its Firebase platform after discovering that criminals were exploiting the infrastructure service to impersonate legitimate banking institutions. The recurring nature of these incidents across different technology companies suggests that fraudsters are systematically probing various platforms for vulnerabilities that can be weaponised at scale.

Remarkably, Meta's own internal projections disclosed by journalists indicate that the company anticipated fraudulent advertising and prohibited goods listings would constitute approximately ten percent of its total 2024 revenue—an estimated $16 billion annually. This figure reveals that despite public commitments to eliminating scam advertising, Meta's business model apparently tolerated or accommodated substantial volumes of fraudulent content, arguably because the platforms generating such listings remained profitable even after accounting for associated costs, reputational damage, and regulatory pressure.

For Malaysian and Southeast Asian readers, this incident carries significant implications beyond India's borders. The advertising and malware distribution techniques employed in this scheme are readily transferable across international boundaries and could easily be adapted for deployment targeting Malaysian and other regional consumers. The methods utilised—combining psychological manipulation, social embarrassment, and financial incentives—represent universal vulnerabilities rather than India-specific phenomena. Southeast Asian nations with rapidly growing digital payment adoption face comparable vulnerability profiles, suggesting that similar campaigns may already be operating regionally or could emerge as fraudsters refine and redeploy successful strategies.

The incident also highlights the enduring tension between technology platforms' profit incentives and their stated commitment to user safety. While Meta removed the advertisements following external pressure, the delay between government advisory and actual removal, combined with the company's apparent internal acceptance of substantial fraud-generated revenue, raises fundamental questions about whether market-based approaches to content moderation adequately prioritise consumer protection. Regulatory bodies across Southeast Asia may find this case instructive when evaluating whether additional legislative frameworks become necessary to compel more proactive fraud prevention measures from technology companies operating regionally.