Meta has removed a number of fraudulent advertisements from Facebook and Instagram after Indian authorities flagged a growing scam pattern in which users were allegedly lured with explicit-content previews and encouraged to download malicious Android applications.
The government raised concerns that some of these apps were designed to steal sensitive information, including login credentials, one-time passwords (OTPs) and bank PINs, potentially allowing fraudsters to access victims’ financial accounts.
According to government data cited by Reuters, cyber fraud in India resulted in losses of around $2.4 billion in 2025, highlighting the growing financial threat posed by online scams as digital payments continue to expand across the country.
Indian authorities said advertisements appearing on both Facebook and Instagram were operating under names including ‘Kyss’ and ‘Night Play’. Clicking on some of the ads reportedly redirected users to phishing websites or prompted them to download applications from outside official app stores.
The government has specifically warned about a rise in financial fraud involving malicious Android applications disguised as pornography or adult-content apps.
Reuters identified one advertisement promoting a video application that promised access to adult content and directed users to download an Android package named “Movexa.apk” instead of obtaining the application through an official app store.
Security risks can increase significantly when users install APK files from unknown sources, as such applications may request access to sensitive device permissions.
Apps Can Steal OTPs And Banking Details
According to the government advisory, malicious applications of this nature can potentially gain access to private information stored on a device and intercept sensitive financial data.
The suspected capabilities include:
- Stealing personal and login credentials
- Capturing one-time passwords
- Accessing banking information and PINs
- Monitoring sensitive information stored on smartphones
- Initiating unauthorised financial transactions
The scam relies heavily on curiosity and urgency. Attractive thumbnails and promises of exclusive content are used to persuade users to click quickly, while the malicious application provides the fraudsters with an opportunity to access information on the device.
Dozens Of Scam Websites Reportedly Remained Active
Despite the government’s advisory, Reuters found that around 39 websites linked to the scam pattern were still active. Some reportedly continued to use sexually explicit thumbnails to attract visitors and generate clicks.
Meta subsequently removed the advertisements after Reuters brought the specific ads to the company’s attention.
Meta’s advertising policies prohibit adult nudity and sexual activity in advertisements and also prohibit deceptive practices designed to mislead users or defraud them.
India Steps Up Pressure On Tech Platforms
The latest action comes amid increasing scrutiny of technology platforms over their role in the spread of financial scams.
The Indian government had recently raised another concern involving Google’s Firebase platform, directing action against hundreds of accounts allegedly being used by fraudsters to impersonate banks.
The developments underline a broader challenge for social media and technology companies: scammers are increasingly using legitimate digital platforms to reach potential victims before shifting them to phishing pages or malicious applications.
An internal Meta projection cited in reports has estimated that scams and advertising involving banned goods could account for a significant share of the company’s revenue, underscoring the scale of the problem facing online platforms.
How Users Can Stay Safe
Cybersecurity experts and government advisories repeatedly recommend avoiding APK files or applications offered through unknown websites, particularly when the download is triggered by an advertisement promising sensational or exclusive content.
Users should download apps only from trusted official app stores, avoid granting unnecessary permissions and never share OTPs, banking PINs or passwords with anyone.
A tempting advertisement may take only seconds to click, but a malicious application installed on a smartphone can potentially expose far more valuable information.
