A Face for Sale: Who Is Behind the Fake Celebrity Ads, and How Much Meta Makes on Them

A Face for Sale: Who Is Behind the Fake Celebrity Ads, and How Much Meta Makes on Them

2026-08-15

The voice is right. The smile is right. Even the slight forward tilt of the head, familiar from a hundred press conferences, is exactly where it should be. Rafał Brzoska, the billionaire founder of InPost, whose yellow parcel lockers stand on Polish street corners the way mailboxes once did, looks out from the phone screen and explains how an investment platform is quietly changing the lives of ordinary Poles. The trouble is that Brzoska never said any of it. An artificial-intelligence model, trained on his public appearances, said it for him, and the result reached millions of screens the ordinary way: as paid advertising, bought and served on Facebook and Instagram. Lawyers for Brzoska and for his wife, the television host Omenaa Mensah, counted two hundred and sixty-three variants of such material. According to NASK, the state institute that monitors the Polish internet, the likenesses of at least a hundred and twenty-one Polish public figures, from the President and the Prime Minister to journalists, physicians, and priests, were used in similar frauds in 2024 alone; Brzoska later spoke of thousands of people who had lost money to the scheme.

This is not a Polish peculiarity. It is the local branch of a global industry, and its scale is known today from an improbable source: Meta’s own files.

 

Sixteen Billion Dollars and a Pulitzer

Between November, 2025, and January, 2026, Reuters published an investigative series built on a leak of internal Meta documents from 2021 through 2025: financial analyses, safety-team presentations, lawyers’ memos. The series, reported by Jeff Horwitz and Engen Tham, won the agency a 2026 Pulitzer Prize (“inventive and revelatory,” the board called it), and it produced a number that has since appeared in nearly every lawsuit filed against the company. Roughly ten per cent of Meta’s 2024 revenue, close to sixteen billion dollars, allegedly came from ads for scams, illegal gambling, and banned goods. Of that, about seven billion dollars a year was generated by ads the company internally classified as carrying a high risk of fraud, and three and a half billion every six months by ads carrying elevated legal risk, which is to say, ads impersonating celebrities and established brands. In December, 2024, the company’s own analysts estimated that Meta’s platforms were serving fifteen billion ads a day flagged as elevated fraud risk. In an internal presentation from May, 2025, the safety team conceded that the company’s products figured in roughly a third of all successful scams in the United States.

What is most interesting in the documents, though, is not the scale but the mechanics. Meta’s anti-fraud systems required ninety-five-per-cent certainty that an advertiser was a scammer before the account was shut down. Below that threshold, the company applied what it called penalty bids: higher auction rates for suspect advertisers. A suspected fraudster, in other words, could keep advertising, only at a premium, and the premium went to Meta. Small advertisers needed at least eight strikes for promoting financial scams before losing an account; accounts designated High Value racked up more than five hundred violations without suspension. In 2023, users of Facebook and of Instagram were filing roughly a hundred thousand valid fraud reports a week on each platform; ninety-six per cent of the reports were ignored or wrongly dismissed. Presiding over all of it was an internal ceiling known as the revenue guardrail: enforcement was not to cost the company more than 0.15 per cent of revenue, which came to about a hundred and thirty-five million dollars in the first half of 2025. The finishing touch comes from the papers on regulator strategy. In Japan, Meta scrubbed its public Ad Library of material featuring the celebrities most frequently searched by Japanese users, so as to improve the perceived scale of the problem in the eyes of officials. Not the scale. The perceived scale.

A system in which the penalty for suspected fraud is a line of revenue does not have a loophole. It is the loophole.

Fairness requires the other side. A Meta spokesman called the ten-per-cent estimate “rough and overly-inclusive,” noting that it swept in ads that were legal, if suspect. The company says it removed more than a hundred and fifty-nine million scam ads in a year, ninety-two per cent of them before anyone complained, and even Meta’s own Oversight Board concluded, in 2025, that the firm knowingly tolerates a significant volume of fraudulent content rather than risk blocking a handful of genuine celebrity endorsements by mistake. As for the Japanese library, the company’s position is that deleting an ad there deletes it from the platform as well. In February, 2026, Meta itself sued networks of scam advertisers, in Brazil and China among other places. That last fact cuts both ways: a company able to link one fraudster’s scattered accounts, payment cards, and domains when it appears as plaintiff will have a harder time persuading courts that, faced with other people’s claims, it is technologically helpless.

 

The Supply Chain of a Swindle

The question of who is behind all this has no single answer, because the fake celebrity ad is only the first link in a cross-border chain. At the top sit the organizers, who choose markets, finance campaigns, and control the accounts into which victims’ money flows. Below them work affiliates and media buyers, paid per lead or per first deposit. Access to the ad system is supplied by account brokers, who traffic in hijacked or rented business accounts, often ones with a history clean enough to resist bans. Separate contractors produce the deepfakes and the cloned news sites with fabricated interviews, while cloaking technology shows Meta’s moderators a different page than the one victims see. Once a victim leaves a phone number, the call centers take over, among them the scam compounds of Southeast Asia, described by the United Nations Office on Drugs and Crime and by Interpol as organized-crime operations in which some of the “consultants” are themselves victims of human trafficking, forced to work the phones. At the end wait the money mules, the shell companies, and the laundering runs through cryptocurrency exchanges.

The fragmentation is not an accident; it is a design feature. The advertiser claims it merely generated leads, the call center poses as an independent broker, and the company receiving the wire transfers has, on paper, nothing to do with anyone. The common threads emerge only under technical analysis: identical landing-page code across languages, the same analytics identifiers, recurring certificates, VoIP numbers, clusters of crypto addresses. Meta’s place in the chain is the distribution and optimization layer: it sells reach, selects audiences, measures conversion, and collects payment. It does not write the script of the fraud. It supplies the audience.

 

Why Smart People Click

The psychology of these campaigns is better studied than one might expect, and it has nothing to do with gullibility. The first mechanism is authority. From Stanley Milgram’s experiments to Robert Cialdini’s work on influence, the finding has held that people defer to signals of authority regardless of underlying competence, and that symbols work as well as substance. In an ad, a recognizable entrepreneur’s face performs the same function as a uniform: it switches off the question of who you are and leaves only the question of what you want. The second mechanism is processing fluency. A classic 1999 experiment by Rolf Reber and Norbert Schwarz showed that we judge the same sentences to be more truthful when they are simply easier to read, and dozens of later studies confirmed that the brain mistakes ease of processing for truth, and that repetition lends credibility even to obvious falsehoods.

The deepfake combines both mechanisms in the strongest form yet devised. A program of seven studies, with more than twenty-five hundred participants, found that fabricated video and audio shift attitudes as effectively as authentic material, and that neither awareness that deepfakes exist nor confidence in one’s ability to spot them offers protection. A study published this year in Communications Psychology went further: even telling viewers outright that a clip is fake does not eliminate its persuasive force. Add the format itself, since video is processed more shallowly than text and, for that very reason, judged more credible. Add, finally, the halo of the platform: an ad displayed in Facebook’s familiar interface borrows Facebook’s credibility. When the European Commission imposed its first fine under the Digital Services Act, a hundred and twenty million euros against X, it cited precisely this mechanism: a paid verification badge created the appearance of an identity check that had never taken place.

The victim data bear the theory out. The Federal Trade Commission reported in April that nearly thirty per cent of Americans who lost money to fraud last year said it began on social media, more than any other route, with reported losses of 2.1 billion dollars, eight times the 2020 figure; Facebook alone accounted for seven hundred and ninety-four million, more than text and e-mail scams combined. The victim’s profile defies the stereotype, too. Britain’s Financial Conduct Authority describes the typical investment-fraud victim as a man over sixty-five, retired, with capital on hand, while the F.T.C.’s crypto numbers show Americans between twenty and forty-nine losing money at five times the rate of older groups. The deepfake does not hunt the naïve. It hunts the busy, because the heuristics it exploits belong to all of us. We examined this at greater length in our analysis of the psychology of financial fraud.

 

The End of the Passive-Host Fable

The legal half of this story comes down to one question: can a platform that accepts an ad, vets it, targets it, and profits from it answer for it as if it were a passive host of someone else’s content? In recent months, in three different legal systems, courts have begun to say no.

 

Australia: Accessory, Not Host

The Australian Competition and Consumer Commission sued Meta back in March, 2022, in the Federal Court, over so-called celeb-bait crypto ads featuring the entrepreneur Dick Smith, the television host David Koch, and the former New South Wales premier Mike Baird. What is novel is the theory. Alongside misleading conduct, the regulator alleges that Meta was an accessory to its advertisers’ violations, deriving the company’s knowledge from its own paperwork on a persistent problem it had recognized since at least January, 2018. In September, 2025, the court declined, once again, to strike the theory out, and the case has since bogged down in a fight over document discovery. There is still no judgment on the merits; in the meantime, the maximum penalty per contravention has risen to a hundred million Australian dollars.

 

The United States: The Evidence That Vanished

In California, meanwhile, the mining billionaire Andrew (Twiggy) Forrest is pressing a civil suit of his own. As early as June, 2024, the court refused Meta automatic shelter under Section 230 of the Communications Decency Act, the provision that ordinarily immunizes platforms for user content, holding it an open question whether Meta’s targeting and optimization tools had materially co-created the unlawful ads. Then, on August 10, 2026, came a ruling that may shape the whole case. Judge P. Casey Pitts found that Meta had failed to preserve key evidence, including the final versions of the ads actually shown to victims, though it could and should have done so. The company’s explanation, that it needed two years to discover the existence of its own data, the judge called “simply not credible.” If the jury finds the destruction intentional, it may infer that the missing evidence was unfavorable to Meta. It is an evidentiary ruling, not a merits ruling, but it shifts the balance of power, because data about advertisers, targeting, and moderation history often exists only on the platform’s side of the table, and a sanction for losing it strikes at the heart of the defense. Around the Forrest case, public actions are multiplying: a suit by the Consumer Federation of America in Washington, D.C., over the company’s claims about platform safety; a suit by Santa Clara County, the first brought by a local prosecutor; and a letter from Senators Richard Blumenthal and Josh Hawley to the F.T.C. and the S.E.C. that extrapolates, from the internal one-third estimate, more than fifty billion dollars in annual losses to American consumers.

 

Poland: An Active Participant, Not a Billboard

In Poland, the Brzoska and Mensah affair runs on two tracks. The administrative one first. On August 5, 2024, the head of UODO, the national data-protection authority, issued an unprecedented pair of interim orders under the urgency clause of the General Data Protection Regulation, directing Meta to stop displaying, in Poland, ads using the couple’s names and likenesses for three months; in the ads, Mensah appeared by turns beaten, under arrest, or dead. Meta challenged the orders in the administrative courts, then, in March, 2025, withdrew its appeals; the underlying case proceeds before the Irish regulator, Meta’s lead supervisor in Europe. “We accuse Meta of lacking any genuine will to remove such advertisements,” Mirosław Wróblewski, the authority’s president, said toward the end of 2025. An independent review by CERT Polska, the national computer-emergency team, concluded in March, 2025, that the company’s measures were ad hoc, even after it switched on facial-recognition tooling in the European Union to detect exactly this material.

The civil track is the more interesting one doctrinally. In November, 2024, the Warsaw District Court enjoined Meta from displaying or accepting the disputed ads, on pain of a fine for every violation. On March 27, 2026, the Warsaw Court of Appeal heard the company’s challenge and rejected the centerpiece of its defense, the safe harbor of the Digital Services Act. Meta, the court reasoned, decides for itself which ads to publish, verifies them, is paid for them, and steers them algorithmically to chosen audiences, which is the functional opposite of a passive intermediary. Precision requires the full picture: the injunction was upheld as to Mensah but set aside as to Brzoska, as too broadly drawn; his lawyers have promised a narrower motion, and the main action, for an apology and damages, has yet to be decided. For practice, though, what matters is the reasoning. For the first time, a Polish court told a platform that paid, targeted advertising is the platform’s own active business, not someone else’s content.

 

Japan, Brussels, London

Japan shows what the fraud costs a single country. The National Police Agency counted nearly ten thousand social-media investment fraud cases in 2025, with losses of 127.4 billion yen, about eight hundred million dollars, up forty-six per cent in a year; the most borrowed face belongs to Yusaku Maezawa, the founder of the e-commerce giant Zozotown, whose complaint hotline logged more than a hundred and eighty reports in its first ten days. Victims are suing: after a first action by four plaintiffs in Kobe, in 2024, thirty more filed in five district courts, seeking a combined four hundred and thirty-five million yen or so (about three million dollars). And this August, seven Japanese agencies at once, the National Police Agency, the Financial Services Agency, and the Digital Agency among them, jointly demanded that Meta, Google, TikTok, X, and LINEYahoo verify who their advertisers are, with written answers due October 16th, the first joint demand of its kind in the country’s regulatory history.

In the European Union, the ground was prepared earlier: the Commission has had formal proceedings open against Meta under the Digital Services Act since April, 2024, with deceptive advertising among the suspected infringements, and fines under the act reach six per cent of global turnover. In May, BEUC, the Brussels umbrella group, joined by twenty-nine consumer organizations from twenty-seven countries, filed complaints against Meta, Google, and TikTok; in a test that preceded the complaints, the platforms removed twenty-seven per cent of nearly nine hundred reported suspect ads. In Britain, the Financial Conduct Authority counted one thousand and fifty-two unauthorized financial ads on Meta’s platforms in a single week of November, 2025, and two law firms are signing up claimants for a planned group action. Since August 2nd, a second European statute has applied as well: the AI Act’s transparency rules require synthetic media to be labeled as such, on pain of fines of up to fifteen million euros or three per cent of worldwide turnover, and an advertising deepfake is, by definition, unlabeled.

The convergence is striking. The Australian route runs through accessory liability in consumer law, the American one through the limits of Section 230, the Warsaw one through an active role that forfeits the safe harbor. Three legal orders, three different constructions, one conclusion: whoever accepts, vets, targets, optimizes, and profits from an ad shares responsibility for it. A defense of “we remove them as soon as we detect them” sounds thinner and thinner beside an internal ninety-five-per-cent certainty threshold and a spending cap on enforcing one’s own rules.

 

When the Money Is Already Gone

From the victim’s side, cases are usually decided in the first days, and not in a courtroom but on a phone. Before the ad disappears, it must be fixed in place: a screenshot with the address bar and the date visible, a recording of the full redirect path down to the landing page, the domain of the fake news article preserved. Then the phone numbers and profiles of the supposed account manager, recordings or notes of the calls, bank statements, the hashes of crypto transactions, screenshots of the fictitious trading dashboard, and every demand for a “tax,” an “insurance premium,” or a “withdrawal fee.” The lesson of the Forrest case is that data about the advertiser and the targeting often exists only at the platform and has a way of vanishing, which is why, in serious matters, it pays to send Meta a preservation demand at once, specifying the ad, account, and page identifiers. Cross-border recovery, when it comes, depends on the coöperation of banks, exchanges, and prosecutors in several jurisdictions, which is one more reason the file assembled in week one matters.

Under Polish law, several tracks open in parallel: a criminal complaint for fraud under Article 286 of the Penal Code; for the person whose face was taken, a second criminal route under Article 190a § 2, which punishes impersonation by means of another’s likeness with up to eight years and fits the advertising deepfake with a precision its drafters, writing in 2011, could not have foreseen; the civil claims for infringement of personal rights and under the G.D.P.R.; and the notice and complaint machinery of the Digital Services Act. How these bases stack, and in what sequence to fire them, is the subject of our earlier study, Deepfakes and the Law (in Polish). Damages claims against Meta itself remain the hardest, since they require showing the platform’s knowledge, the recurrence of the pattern, and the profit drawn from it, but the past year’s rulings give them, for the first time, something real to stand on. One warning, finally, belongs in every first conversation with a victim: after the first fraud, the “recovery” firms appear, promising to retrieve the money for an up-front fee. They are usually the next link in the same chain.

 

An Arithmetic Waiting to Be Inverted

Return to the numbers, because the whole strategy lives there. Meta put its worldwide exposure to regulatory fines at a billion dollars, at most. Revenue tied to the disputed ads: sixteen billion a year. Hypothetical liability for user losses in Europe, should the law ever require restitution: up to 9.3 billion. As long as the first number is a fraction of the second, no rational corporate ledger recommends changing anything.

The counterfactual, for once, is not hypothetical. In 2023, Taiwan required platforms to verify the identity of anyone advertising financial products; Meta complied under the threat of fines exceeding its profits in that market, and investment scam ads fell by ninety-six per cent. By the company’s own engineering estimate, universal advertiser verification could be switched on worldwide in under six weeks, at a cost of about two billion dollars and as much as 4.8 per cent of revenue. An internal strategy paper filed the prospect under “black swan.”

The point of the parallel proceedings, from Sydney to San Francisco to Warsaw, is to invert that arithmetic: to move the cost of the fraud from the victims to the one party in the chain that knows the advertiser, controls the delivery, and earns on every impression. The law is slow. But it takes only one of these cases to end in a damages award for a new line, cost of losing, to appear in the same spreadsheet that today contains the revenue guardrail.

 

Further reading

The End of the Checkbox

Deepfakes – Your Face Is Not Yours Anymore

How Meta Learned Not to Know: Meta (Facebook) $1.4 Trillion Lawsuit:

Facebook – The Algorithm on Trial

Meta on Trial: How New Mexico’s Child-Safety Case Could Change Social Media Forever

 

Kancelaria Prawna Skarbiec represents victims of investment fraud, including in disputes where the decisive evidence sits with online platforms and payment institutions.

The law and the facts are stated as of August 15, 2026. The figures attributed to Meta come from internal documents described by Reuters and from court filings; Meta disputes their interpretation, and no court has yet entered a final judgment holding the company liable in damages.