Meta publicly dismantles the Instrat scam-ad report — and the fight reveals how little anyone can verify
On 18 September Meta published a point-by-point public rebuttal of a report by the Polish think tank Instrat, which had estimated that fraudulent advertising generates around PLN 760 million a year for the company in Poland — roughly 37% of Facebook Poland’s reported revenue, and 10.85% of total advertising reach across its platforms there. The company called the report “fiction that misleads the public”, prepared by a law firm representing someone suing Meta.
The dispute is worth reading closely, because both sides are making arguments that matter to any brand whose identity is used in advertising fraud.
What Meta disputes
The rebuttal is unusually granular. Meta’s core objections:
- Every removed ad is counted as a scam. Instrat used removal as the proxy for fraud, but Meta’s systems remove ads for restricted goods, third-party intellectual property, quality and format violations too — so the revenue base is wrong from the start.
- The reach figure is EU-wide. Numbers covering 27 member states were treated as Polish users.
- Frequency is an assumption. Three impressions per person, taken from a US vendor’s estimate based on 2,800 of its own clients — neither Polish nor scam-specific.
- Price is abstract. The authors concede they could not estimate CPM empirically.
- The qualitative sample is 108 ads observed on a single iOS profile the researchers had deliberately primed by viewing and clicking particular ad types.
- Three days extrapolated to a year, with the days differing from one another by up to 80%.
Meta then lists its own record: 137,000 fraudulent ads removed in Poland between July 2025 and June 2026, more than 88% before any user report; an 83% drop in the scam-ad report rate per impression since July 2024; a new anti-impersonation AI system that has caught 50% more ads impersonating public figures than its predecessor; and mandatory verification for 100% of financial services advertisers targeting Poland.
What the rebuttal does not answer
The methodological criticisms are serious — but they are criticisms of an estimate that exists only because the underlying data is not available. Instrat’s own finding is that up to 41% of scam ads may not be properly visible in the Ad Library, alongside download limits, technical errors and registration delays. That is the part Meta’s rebuttal does not address: if outside researchers had reliable access, they would not need primed iOS profiles and three-day samples.
Nor does it engage with CERT Polska’s test, cited by Poland’s digital affairs ministry in its August request that the European Commission fine Meta €250 million: of 122 ads reported as fraudulent, 106 were left up, 10 removed, and six drew no response at all. That is a measurement of the reporting channel itself — the one every brand owner is told to use.
The context behind both: Poland’s case sits on top of an April 2026 Warsaw Court of Appeal ruling in Rafał Brzoska’s suit, which held that Meta can be liable for advertisements on its platforms rather than sheltering behind passive-host status, and the European Commission’s ongoing DSA proceedings over illegal content and deceptive AI-generated material.
What this means for you
If your executives’ faces, your logo or your brand name appear in fake investment ads — the pattern that made Brzoska’s case, and one we see constantly in iGaming, fintech and crypto — the Polish fight tells you three practical things.
First, platform transparency tools are not a reliable detection layer. When a well-resourced think tank has to prime a phone and sample three days to guess at scale, your brand-protection team cannot expect the Ad Library to surface everything targeting your name.
Second, reporting is necessary but demonstrably insufficient on its own: a national CERT reporting 122 fraudulent ads and getting 10 removals is the clearest available benchmark of what the consumer-grade channel achieves. Escalation paths — rights-holder channels, trademark complaints, regulator engagement, and where warranted litigation — exist precisely because the front door underperforms.
Third, the legal ground is shifting in brand owners’ favour. A European appellate court has already said the passive-host defence does not automatically cover advertising, the DSA proceedings are live, and platforms are responding with verification regimes — Meta’s 100% verification requirement for financial advertisers in Poland is exactly the kind of structural fix that pressure produces.
Counsel’s note. Most brands respond to impersonation ads by filing reports and waiting, then conclude the platform “does nothing”. The more useful move is to build your own evidence record while you file: capture the ad, the advertiser page, the landing domain and the payment destination, log every report and its outcome with timestamps, and track the removal rate. That record is what converts a support ticket into a legal demand, a regulator complaint or a court filing — it is precisely the kind of data that moved Polish regulators. We broke down the deepfake-investor pattern in our guide to investor impersonation scams.