Reuters uncovered internal Meta documents revealing that the company projected $16 billion in 2024 revenue from advertisements linked to scams and banned goods, accounting for approximately 10% of its total revenue. Meta's safety staff estimated that its platforms were involved in a third of all successful scams in the United States, though some of this involvement may be due to the use of WhatsApp for communication rather than direct ad placement. The documents also showed that Meta only bans advertisers if automated systems are 95% certain of fraud; otherwise, the company imposes higher ad rates as a penalty, potentially incentivizing the acceptance of high-risk ads.
Meta's management reportedly weighed the financial benefits of scam ads against potential regulatory costs, with $3.5 billion in revenue every six months coming from ads deemed to have "higher legal risk," such as those impersonating brands or celebrities. The company was willing to forgo only a small fraction of its revenue—about $135 million—to clamp down on suspicious advertisers, suggesting a calculated approach to balancing profit and compliance risk. These revelations have raised significant concerns about Meta's role in facilitating online scams and its internal decision-making regarding fraudulent advertising.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
A large data leak involving Chinese security firm KnownSec was reported in the same news roundup. The summaries did not provide further technical detail, but identified it as a notable disclosure.
Reuters published an investigation revealing Meta's internal projections and policies around scam and banned-goods advertising revenue. The reporting brought public attention to the scale of fraud-related advertising on Meta's platforms and the company's internal enforcement thresholds.
A Russian initial access broker tied to the Yanluowang ransomware group pleaded guilty to hacking U.S. companies. The plea marked a concrete legal action against a facilitator in the ransomware ecosystem.
Authorities took down a large credit card fraud operation, according to the reporting summaries. The action was presented as a significant law enforcement disruption of financially motivated cybercrime.
Reporting cited ransomware attacks affecting Jaguar Land Rover in the UK and Asahi in Japan as examples of the continuing economic damage caused by ransomware. The references framed these incidents as part of a broader trend rather than newly disclosed breaches.
The United Kingdom suspended some intelligence sharing with the United States over concerns tied to suspected drug-trafficking vessel operations and related legal issues. The move was reported as a significant policy response in the intelligence relationship.
The Russian military-linked group Sandworm carried out wiper attacks against organizations in Ukraine's grain sector. The campaign was described as an effort to damage a strategically important part of Ukraine's economy.
State-backed hackers also breached F5 and stole sensitive files including source code, with Lawfare's summary attributing the activity to the Chinese group Salt Typhoon. As with the SonicWall incident, the attackers reportedly showed restraint by not turning the access into mass exploitation.
Reporting said state-backed hackers compromised SonicWall's MySonicWall cloud backup service and stole sensitive configuration data. The intrusion was notable because the attackers did not escalate to broad mass exploitation.
Reuters reported that Meta generally banned advertisers only when automated systems were at least 95% certain they were fraudulent; otherwise, the company often imposed higher ad rates as a penalty. The policy was described in internal documents cited in reporting published in November 2025.
Internal Meta documents reviewed by Reuters showed the company projected about $16 billion in 2024 revenue from advertisements tied to scams and banned goods, roughly 10% of total revenue. The documents also indicated Meta platforms were linked to about one-third of successful scams in the United States.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
lawfaremedia.org
Open sourcegovinfosecurity.com
Open sourcenews.risky.biz
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.