Almost every Czech citizen has received a fraudulent SMS or encountered suspicious offers online. Vishing, in the form of calls from fake bank employees or scammers impersonating police officers, has also become commonplace. Despite extensive media coverage of the issue, efforts by many employers to educate their staff, and awareness campaigns by banks, the police and the non-profit sector, fraudsters continue to cost Czech citizens billions of Czech crowns every year. Thanks to the efforts of banks and the Czech Police, substantial amounts of money are successfully saved from being lost, yet overall losses continue to rise (source). Fraudulent advertising on VLOPs plays a significant role in this fraud ecosystem. Through these ads, fraudsters seek to obtain users’ personal data or persuade them to invest substantial sums of money with promises of returns that never materialise.
Since 2025, Online Risk Labs has been continuously monitoring and documenting fraudulent advertising on VLOPs. We focus primarily on financial and investment scams, as well as cases involving the misuse of brands or identities in sponsored content. On Meta’s platforms alone, we have identified more than 2,000 advertisers systematically running fraudulent campaigns since 2025, of which 1,551 were active in 2026.
Between 1 January and 31 August 2026, these advertisers were responsible for a total of 155,000 ads with a cumulative reach of 562 million across the EU and the United Kingdom (we calculate cumulative reach as the sum of the reach of individual campaigns; the number of impressions is comparable or higher). In Czechia alone, this amounted to 46,000 ads with a cumulative reach of 145 million. However, these figures likely represent only the tip of the iceberg.

Fraudulent ad running on Meta’s platforms that links to a fake media website.
Although fraudulent ads are nowadays mostly discussed in connection with Meta’s platforms, we also record problematic advertising on X, TikTok and YouTube, as well as among other sponsored content distributed through Google’s advertising infrastructure. Across all these platforms, we have identified similar types of clickbait ads linking to fake websites (doppelgängers) mimicking reputable media outlets. Our findings to date suggest that we are facing large-scale fraudulent schemes operating across Europe and across multiple platforms rather than isolated campaigns.
The creation and launch of new types of fraudulent campaigns are becoming easier as technology advances. Whether it involves convincing deepfake videos, easier translations into multiple European languages, or the creation of fake websites, the growing availability of increasingly sophisticated AI tools plays a key role.
Fraudsters also exploit gaps in platforms’ control mechanisms and employ various strategies to conceal the actual content of their campaigns. One such strategy is landing page cloaking. On Meta’s platforms, fraudulent actors often run completely non-transparent ads, where the actual content shown to users in their feeds does not match the corresponding ad library record (“chameleon ads”), or hide fraudulent content among multiple “neutral” versions of ad creative. These are far from isolated cases. In 2026, we found that 953 (61%) out of 1,551 active advertisers we identified as systematically running fraudulent advertising campaigns on Meta’s platforms used at least one of these strategies to conceal the actual content of their ads.

Example of a non-transparent (“chameleon”) ad that ran on Meta’s platforms. While users saw a deepfake video in their feeds, the ad record in the Meta Ad Library displayed only an image of a landscape.
The key to addressing the problem often lies with the platforms themselves, particularly in how proactively they approach the detection and subsequent mitigation of risks, including the dissemination of illegal content. Articles 34 and 35 of the Digital Services Act (DSA) require very large online platforms to analyse and assess systemic risks and to take measures to mitigate them. However, there is still considerable room for improvement when it comes to platforms’ proactive approach to combating fraud.
Although, according to our estimates, tens of thousands of fraudulent ads linking to fake websites mimicking reputable media outlets may have run across EU Member States this year, cloaking often makes it difficult to establish that a campaign misuses a media outlet’s identity through a doppelgänger website. On Facebook and Instagram, the problem is further compounded by completely non-transparent “chameleon ads”. In addition, the advertiser and payer listed for an ad often do not correspond to any identifiable natural or legal person.
The fact that we are likely dealing with large-scale fraudulent schemes calls for a more systematic approach by platforms to ad review and moderation. Fraudulent campaigns frequently reuse the same ad creative and repeatedly direct users to the same clusters of domains hosting fake websites. On Meta’s platforms in particular, we regularly encounter dozens of identical fraudulent ads running simultaneously without systematic intervention by the platform.
The seriousness of fraudulent online advertising calls for greater transparency and public scrutiny. The ability of researchers and the public to detect fraud in a timely and systematic manner depends primarily on access to up-to-date advertising data and on the functionality and reliability of ad repositories in accordance with the requirements set out in Article 39 of the DSA.
In the Meta Ad Library, an ad record sometimes appears only after a delay of several hours. In the case of fraudulent campaigns, moreover, the ad library record often does not match the content actually shown to users in their feeds. The Google Ads Transparency Center publishes ad impression data with a 90-day delay, often making it available only after the fraudulent ad itself has already been removed. Targeted and systematic searches for fraudulent advertising are further hampered by the lack of proper full-text search functionality in the ad repository.
Summary of Key Findings:
- From 1 January to 31 August 2026, Online Risk Labs identified approximately 155,000 ads on Meta’s platforms placed by advertisers systematically running fraudulent campaigns. The cumulative reach of these ads (measured as the sum of the reach of individual campaigns) amounted to 562 M across the EU and the United Kingdom. In Czechia alone, we identified 46,000 ads with a cumulative reach of 145 million.
- The problem of fraudulent advertising is not, however, limited to Meta’s platforms. Our evidence points to the likely existence of large-scale fraudulent schemes operating across Europe and across multiple VLOPs. Deepfake videos and clickbait ads that misuse the names and likenesses of well-known public figures and link to fake websites (doppelgängers) mimicking reputable media outlets are used on a massive scale to promote fraudulent investment schemes.
- Fraudulent actors often employ strategies to conceal the actual content of their ads. This primarily involves landing page cloaking. On Meta’s platforms, it is possible to run completely non-transparent ads where the record in the Meta Ad Library does not match the content displayed to users in their feeds (chameleon ads). In other cases, Meta Ad Library records contain the actual fraudulent ads “hidden” among multiple versions of neutral ad creative. 953 (61%) of 1,551 advertisers we identified as systematically running fraudulent campaigns on Meta’s platforms in 2026 used at least one of these forms of concealment.
- Our ability to detect fraudulent ads in a timely and systematic manner and to quantify the scale of the problem depends on the functionality and reliability of ad repositories in accordance with the requirements set out in Article 39 of the DSA. Due to delays in the Meta Ad Library, records of already active ads are sometimes unavailable. The Google Ads Transparency Center publishes ad impression data with a 90-day delay.
Download the full report here:


