Meta removed at least 39 paid Facebook and Instagram ads on August 31, 2026, after Indian authorities warned that fake adult-video apps were being used to steal from bank accounts, and after Reuters asked the company about ads that were still running.
The ads promised explicit videos, then pushed people toward Android files outside Google Play. Install one, grant it broad phone-control permissions, and a scammer could read one-time passwords, capture banking PINs and approve transfers from the victim’s own device, according to India’s cybercrime advisory.
That is not an ad-review near miss. It is a paid distribution channel for banking malware that remained open after a government warning.
India’s Ministry of Home Affairs, through its cybercrime units, warned about malicious Android apps promoted through Facebook and Instagram under names including Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa. Those names appear to be campaign or product labels, not identified companies: public reporting does not name the operators, their ad-buying intermediaries, or how they paid Meta for the ads.
Reuters found the ads after the warning and said Meta removed them only once it flagged them and requested comment. Meta did not answer Reuters’ questions.

The APK route from adult-themed ads to bank theft
The operation relied on a familiar bit of social engineering: offer something embarrassing enough that people may act quickly and hesitate to report trouble later. The paid ad takes a user to a phishing website; the website offers adult content; the “video app” download is malware.
Reuters tested one route and found a site advertising hundreds of sexual videos and continuous content. It prompted the visitor to download Movexa.apk, an Android installation package obtained outside an official app store.
That distinction matters. Android APK files are legitimate software packages, but sideloading means bypassing the app-store review layer and manually authorizing an installation. It is the same basic trap seen in the fake-app crypto theft route: a convincing product label gets the victim to install the attacker’s software, then the attacker gets the permissions that matter.
India’s advisory described what followed. An app given Accessibility permission, a feature intended to let software assist people in using a phone, can read information on the screen, enter or capture OTPs and PINs, confirm transactions, initiate transfers, install additional apps and sometimes route traffic through an attacker-controlled VPN.
In other words, the attacker does not need to crack the bank. They persuade the account holder to install software that can operate the bank app for them.

India recorded nearly $2.4 billion in cyber-fraud losses in 2025. Reuters observed at least 39 ads after the advisory, not a total reach figure or the full number served. But those ads were not obscure links drifting through private chats. They were bought placements in Facebook’s paid-ad infrastructure, delivered through systems designed to find people likely to click.
Meta’s written policies prohibit adult nudity, sexual activity and deceptive practices intended to defraud users. The company nonetheless took down the reported ads after an outside inquiry, not before. The advisory’s date is reported inconsistently: the Hindustan Times put it on August 26, while Reuters described an advisory issued that Monday.
The episode also fits a much larger enforcement problem. In a 2025 investigation, Reuters reviewed internal Meta documents that projected about $16 billion in 2024 revenue from ads for scams and banned goods, roughly 10% of annual revenue. Those were Meta’s internal estimates, not independently audited measures of scam-ad revenue or user exposure.
Independent researchers have seen a related failure in public data. AI Forensics reported in January 2025 that Meta had approved more than 3,000 pornographic ads that generated more than 8 million impressions in the EU over the preceding year. The Indian ads were not merely sexual-policy violations; the adult imagery was the front door to financial theft.
Meta is also under visible cost pressure. Its Family of Apps operating income fell 6% year over year to $23.394 billion in Q2 2026, even as revenue rose 28% to $60.370 billion. Research-and-development spending rose 67% to $21.656 billion, driven in part by data-center, infrastructure, cloud and third-party AI-token costs.
That does not establish why specific scam ads escaped review. It does make the business context hard to ignore: Meta’s ad machine is being asked to fund an expensive buildout while its own internal documents put a very large price tag on the ads it should not have accepted.
For users, the practical rule is brutally simple: do not install an APK pushed by a social ad, especially one that asks for Accessibility permissions. The privacy risks of installing untrusted software are not abstract when that software can see the codes your bank sends you.
Meta eventually removed 39 ads. The unanswered question is how many people saw them before a government warning and a reporter’s email did the moderation job.
Key Takeaways
- Meta removed at least 39 Facebook and Instagram ads linked to fake adult-video apps on August 31, 2026.
- Reuters found the ads still active after India issued its cyber-fraud warning.
- The ads sent users to phishing sites that pushed sideloaded Android APK files, including
Movexa.apk. - India warned that malicious apps with Accessibility permissions can capture banking credentials and approve transactions.
- Meta’s internal documents projected about $16 billion in 2024 revenue from scam and banned-goods advertising.
Further Reading
- Meta removes ads for fraud apps posing as porn after India sounds alarm, Reuters’ report on the active ads, the takedown and its test of the APK download route.
- Night Play, Kyss: MHA warns malicious Android apps, porn being used to steal money, Reporting on India’s warning and the malware’s device-control capabilities.
- Meta is earning a fortune on a deluge of fraudulent ads, documents show, Reuters’ investigation of Meta’s internal scam-ad projections and enforcement records.
- Pay-to-Play: Meta’s Community (double) Standards on Pornographic Ads, AI Forensics’ investigation into Meta-approved pornographic advertising.
- meta-20260630, Meta’s Q2 2026 Form 10-Q.
