From Two Facebook Ads to 852: CERT Polska Maps a New Fraud Infrastructure on Meta

Cert Pol

From Two Facebook Ads to 852: CERT Polska Maps a Toll-Fraud Network on Meta

On 23 September 2026, CERT Polska, Poland’s national Computer Security Incident Response Team operated by the research institute NASK, published the results of a technical investigation into a toll-fraud campaign targeting Polish Android users which, although initially triggered by only two deceptive Facebook advertisements, ultimately led investigators to identify 1,235 Meta advertisements displayed under 74 different profile names. Of those advertisements, 852, displayed under 60 profile names, could be technically linked to 17 Google Play applications through common code, shared infrastructure or other technical indicators. 

The significance of these findings extends beyond the individual malware campaign. CERT Polska had already warned Meta in 2024 about recurring weaknesses in its advertising systems and had proposed concrete measures intended to reduce fraudulent advertising. In March 2025, it concluded that several of those recommendations had not been adequately implemented. At the same time, the European Commission has been formally investigating Meta’s policies and practices concerning deceptive advertising under the Digital Services Act since April 2024. 

The September 2026 investigation therefore raises a question that goes beyond the removal of individual advertisements after they have been reported: whether Meta’s advertising system is capable of recognising and disrupting recurring malicious advertising infrastructure once the relevant systemic risk has already been identified and communicated.

From two advertisements to a coordinated distribution infrastructure

CERT Polska’s investigation began on 14 September 2026, when researchers identified two Facebook advertisements directed at Polish users which falsely claimed that the user’s PDF application had expired and warned that stored files would soon become inaccessible unless the application was updated.

The advertisements did not lead to a PDF utility. Instead, users were directed to a Google Play listing for an unrelated application called Messenger Pro. Once installed, the application executed a multi-stage chain ultimately capable of delivering toll-fraud functionality. CERT Polska subsequently observed active command-and-control infrastructure issuing tasks involving premium SMS messages and recurring carrier-billing payments. 

What initially appeared to be two advertisements promoting one suspicious application proved to be part of a substantially larger operation. Through repeated searches and technical analysis, CERT Polska expanded its dataset to 1,235 unique Meta advertisements displayed under 74 identified profile names. The advertisements promoted 29 identifiable Google Play packages, while in another 90 cases the advertisement had already been removed and its original destination could no longer be reconstructed.

Technical analysis ultimately connected 17 applications to the same operation. Six of those applications exposed recovered toll-fraud components or direct links to fraud payloads, while eleven additional applications contained malicious loaders connected to the same infrastructure, even though investigators were unable to recover their final fraud modules. Taken together, those 17 applications accounted for 852 Meta advertisements displayed under 60 different profile names. 

CERT Polska was careful not to infer common control merely from similar names, advertising themes or visual presentation. Connections were established through evidence such as identical advertising files, exact advertising destinations, shared loader code and specific DNS, TLS and hosting relationships. That methodological caution matters because the report does not simply aggregate suspicious-looking advertisements; it reconstructs a technically connected distribution infrastructure.

CERT Polska also expressly makes no attribution concerning the operator’s identity, nationality or location.

The operation was not necessarily confined to Poland. The loader’s country gate permitted execution on devices with SIM cards from 15 countries, including Austria, Germany, Switzerland, France, Greece and Romania. CERT Polska’s observations concern Polish users, and the report does not establish whether advertisements were placed in the other countries. The technical design, however, was clearly prepared for a wider European market.

Meta as the acquisition layer, Google Play as the installation layer

The investigation also illustrates why contemporary online fraud cannot be adequately analysed by examining each intermediary in isolation.

According to CERT Polska’s reconstruction, Meta provided the paid acquisition channel through which advertisements were displayed to users within Facebook and directed them towards the malicious applications, while Google Play provided the installation channel through which those applications were distributed. Users therefore moved from a paid advertisement presented within one trusted platform environment to an application distributed through another service that many consumers reasonably associate with some degree of technical review and security screening. 

That expectation deserves attention in its own right. Google Play is itself designated as a very large online platform under the Digital Services Act and is subject to the same systemic-risk obligations as Facebook. In this case, 17 applications presenting themselves as messengers and utility tools, requesting SMS permissions and containing malicious loaders, passed Google’s review and were distributed through the store until CERT Polska identified them.

Neither function, taken on its own, establishes that the respective platform operated or knowingly participated in the underlying fraud. Nevertheless, large-scale online fraud rarely depends on one actor controlling every stage of the process. Advertising platforms provide access to potential victims, app stores or hosting providers facilitate the distribution of software, domains and cloud infrastructure maintain the technical operation (in this case, domains registered through Amazon Registrar and payloads hosted on Alibaba Cloud Object Storage Service), and telecommunications or payment systems ultimately enable monetisation.

The relevant harm therefore frequently emerges from the interaction of several infrastructure providers, each of which may be several steps removed from the final financial loss. An analysis limited to the last transaction risks overlooking the earlier infrastructure that made the fraudulent operation scalable in the first place.

CERT Polska had already identified weaknesses in Meta's advertising controls

For Meta, the September 2026 findings do not arise in an informational vacuum.

Between January and November 2024, CERT Polska tested Meta’s ordinary reporting process by reporting 122 advertisements that it had classified as fraudulent through a standard Facebook user account. Only ten advertisements were removed. In 106 cases, representing 86.8% of the reported advertisements, Meta closed the report with the message that the advertisement had not been removed, while six reports received no response. 

Following that exercise, CERT Polska presented Meta with a series of specific recommendations, including more effective detection of harmful Polish-language content, increased Polish-speaking moderation capacity, measures against accounts repeatedly associated with fraudulent advertising, integration of trusted local threat intelligence and improvements to the transparency and timeliness of Meta’s Ad Library. 

According to CERT Polska, those recommendations were communicated directly to Meta representatives. On 31 March 2025, the organisation published an assessment of Meta’s subsequent response and concluded that the company was not adequately meeting several of the demands. Fraudulent content continued to appear on Meta’s services, ordinary user reports remained ineffective in a significant number of cases, and not all of the measures proposed to improve the safety of Polish users had been implemented. CERT Polska’s own wording was more direct: “Meta refused to directly implement the Warning List”; Meta “did not declare any changes” to the Ad Library mechanism; no response was received on the expansion of Polish-speaking moderation; and “systemic solutions are still lacking.”

 Precision is required here. Not every 2024 recommendation would have stopped this campaign. The advertisements led to Google Play listings, not to suspicious domains, so automatic blocking of domains on the CERT Polska Warning List would not have intercepted them. The recommendation that does bear directly on the September findings concerns measures against advertisers repeatedly associated with fraudulent advertising. The operation’s use of 74 profile names, 60 of them linked to the confirmed applications, is exactly the pattern that defeats enforcement at the level of individual accounts and advertisements.

Removal of individual advertisements did not terminate the operation

The new CERT Polska report also contains an important limitation that should be acknowledged.

Both Meta and Google acted on the specific material that CERT reported. Google removed Messenger Pro from its store on 15 September 2026, and the other identified applications were subsequently reported and removed as well. CERT also reported the relevant advertisements to Meta, which removed the advertisements identified by the researchers.

The underlying operation, however, did not disappear with those removals. CERT Polska observed that new application packages continued to appear, that the command-and-control infrastructure remained operational and that applications already installed on users’ devices could continue communicating with that infrastructure. The organisation also expressly noted that Meta’s removals concerned the advertisements identified by CERT, while other advertisements connected to the operation may have remained active without CERT’s knowledge or expired independently. 

This distinction is central to the regulatory question. Notice-and-removal procedures may interrupt individual distribution paths once somebody has identified them, but they do not necessarily disrupt the infrastructure through which new advertisements, profiles, applications and technical endpoints can be generated and substituted.

The unresolved DSA question

The European Commission opened formal proceedings against Facebook and Instagram on 30 April 2024. Those proceedings expressly cover Meta’s policies and practices relating to deceptive advertising. 

Since then, the Commission has issued preliminary findings against Meta in other strands of its Digital Services Act investigations. In October 2025, it preliminarily identified deficiencies concerning researcher access and Meta’s mechanisms for notifying illegal content and challenging moderation decisions. In April 2026, it issued preliminary findings concerning the protection of children under 13, and in July 2026 it preliminarily concluded that the addictive design of Facebook and Instagram breached DSA obligations. 

The October 2025 findings on notice mechanisms are directly relevant here. CERT Polska’s 2024 test, in which 86.8% of reports submitted through a standard user account were closed without removal, is empirical evidence of the kind of deficiency the Commission has already preliminarily identified under Article 16 DSA.

As of 25 September 2026, however, the Commission’s publicly available enforcement information still contains no preliminary findings concerning the deceptive-advertising strand of the proceedings opened more than two years earlier. 

In the context of fraudulent advertising, this shifts the regulatory inquiry away from the narrow question of whether Meta removed one particular advertisement after receiving notice and towards broader questions concerning campaign detection, advertiser controls, repeated account behaviour, destination analysis, shared infrastructure and the use of available threat intelligence.

The relevance of the DSA’s systemic-risk regime lies precisely in the fact that the obligations imposed on very large online platforms are not confined to knowledge and removal of individual items of illegal content. The largest platforms must assess systemic risks arising from the design and functioning of their services and adopt reasonable, proportionate and effective measures to mitigate those risks. The relevant framework therefore requires an assessment not only of individual content decisions but also of the systems through which risks repeatedly emerge.

Several provisions are directly engaged. Articles 34 and 35 require very large online platforms to assess and mitigate systemic risks, and Article 35(1)(e) expressly names the adaptation of advertising systems as a mitigation measure. Article 23 requires online platforms to suspend, after prior warning, recipients who frequently provide manifestly illegal content, which is the legal counterpart of CERT Polska’s recommendation on repeat advertisers. Article 39 requires a reliable and searchable advertising repository, the provision to which CERT Polska’s criticism of the Ad Library’s timeliness relates.

Meta may respond that its own Ad Library made CERT Polska’s reconstruction possible in the first place. That point cuts both ways. If an external team can link hundreds of advertisements from publicly available data, a platform with access to internal signals (payment instruments, device and account relationships, creative hashes and destination data) should be able to recognise the same relationships earlier and without external prompting. That is the standard against which mitigation under Article 35 has to be measured.

The campaign was not investment fraud

The September operation is also relevant because its structure differs from the fake-investment campaigns EFRI has repeatedly examined.

The advertisements did not promise extraordinary financial returns, impersonate well-known investors or direct users towards fraudulent trading platforms. Instead, they used false software warnings and apparently ordinary applications, while the monetisation mechanism involved premium SMS and carrier billing rather than transfers to an investment fraud scheme.

That difference does not make the case less relevant. On the contrary, it illustrates why effective controls against fraudulent advertising cannot be limited to a narrow category such as financial advertising.

The story used by the fraudster can change. The structural risk remains the same where paid advertising infrastructure can repeatedly be used to place deceptive content before users and move them into an external fraud chain.

Where the money went, and what victims can recover

CERT Polska’s report documents the monetisation layer in unusual detail. The operation used premium-rate short codes (92505, 92512 and 92513) listed in the premium-rate register of Poland’s telecommunications regulator UKE, charged at 30.75 PLN per message and operated through international aggregators. In parallel, it enrolled users in carrier-billing subscriptions; in one captured case, the offer stated a charge of 17 PLN every seven days.

This is the typical profile of mass small-value harm: individual losses are small, often unnoticed on a phone bill and rarely worth pursuing alone, while the aggregate across many devices may be substantial. It is also the point in the chain where identifiable, regulated and solvent parties sit: the registered short codes, the aggregators and the mobile network operators that collect the charges.

For victims, the legal position is weak. Payments made through a telecommunications operator for digital content, within the thresholds of Article 3(l) of the Second Payment Services Directive (EUR 50 per transaction and EUR 300 per month), fall outside the scope of that Directive. The refund rights for unauthorised payments that apply to card and bank transfers therefore do not apply. Whether and how charges can be recovered depends on national telecommunications rules and operator practice.

From individual advertisements to recurring fraud infrastructure

EFRI has previously examined Meta’s scam-advertising problem, Poland’s request for a EUR 250 million DSA fine, the absence of an effective victim-redress mechanism and the emerging European case law concerning Meta’s own role in the algorithmic distribution of paid advertisements.

The latest CERT Polska findings add a different element to that analysis. They demonstrate why the relevant unit of enforcement cannot remain the individual advertisement when the underlying conduct is organised through campaigns, recurring profiles, substitute applications and reusable infrastructure.

Our Assessment

CERT Polska’s September investigation does not establish Meta’s legal liability for the toll-fraud operation or an infringement of the DSA, nor does it prove that Meta had prior knowledge of each of the 852 advertisements before they were displayed.

It does establish that a national CSIRT, beginning with only two Facebook advertisements, was able to reconstruct a technically connected operation encompassing 852 Meta advertisements linked to 17 applications through shared code or infrastructure.

This occurred after CERT Polska had already documented serious weaknesses in Meta’s handling of fraudulent advertising, communicated concrete recommendations to the company and subsequently concluded that several of those measures had not been implemented adequately. 

Meta removed the advertisements reported by CERT, just as Google removed the applications brought to its attention. Those actions are necessary and should be acknowledged.

The regulatory issue, however, begins where individual removal ends.

If recurring malicious advertising infrastructure can only be identified after external investigators reconstruct hundreds of related advertisements, advertiser profiles, applications and technical endpoints, the relevant question under a systemic-risk regime is whether the platform’s own controls are capable of recognising the same relationships early enough to prevent repeated distribution at scale.

Fraud operators do not work advertisement by advertisement; they operate campaigns and infrastructures**, routinely replacing one domain, account, application or technical endpoint with another**. Meta does not operate an isolated notice board; it operates an advertising system capable of analysing and distributing paid content across a global user base**, at a scale that neither individual victims nor external investigators can replicate**.

The Digital Services Act was intended to address systemic risks of precisely this kind. More than two years after the Commission opened its investigation into Meta’s deceptive-advertising practices, CERT Polska’s latest findings make the effectiveness of that enforcement increasingly difficult to assess from the outside.

EFRI therefore calls for three steps:

1. The Commission should issue preliminary findings in the deceptive-advertising strand of the Meta proceedings and extend its scrutiny to Google Play’s app-review controls.

2. Very large platforms should be required to act at the level of campaigns and infrastructure rather than individual advertisements, and to report publicly on such campaign-level disruptions.

3. Victims of carrier-billing fraud need an effective right to a refund against the operators and aggregators that collect the charges, whether through closing the gap in payment-services law or through binding telecommunications rules.

More about this topic.