Notes · August 29, 2026
How a scam ad gets past Meta's review
30 min read
This page explains how Meta's ad review works: what it looks at before an ad goes live, what escapes it, and why the same system that rejects a florist's caption lets through an ad pointing at a site built to steal card details. It's written from the side of someone who buys space on that platform every day, with the primary source next to every number. If you're short on time, the two sections that matter are the one on the 95% threshold and the one on why a surcharge weighs far more heavily on a business that actually sells something.
How a scam ad gets past Meta's review
Meta's review judges the ad and its landing page as they appear at the moment it looks at them. The system compares creative, text and destination against the rules, and decides. Anyone who wants to get through doesn't attack that comparison: they show the system something different from what the person clicking after approval will see.
The distinction between the ad and its destination is the whole game. An ad isn't a fixed object: it's an ad plus an address, and that address leads to a site that belongs to somebody else and can change at any moment. Meta includes the destination among the things it reviews — the ad destination, meaning where an ad directs people, for example a Facebook Page or a website — but it looks at that destination when its system visits it.
Meta writes one sentence, on its own page about ad review, that almost nobody quotes and that's already half the answer to the question in the title. The Help Centre page about ads in review says: "An ad may not be reviewed against all policies before delivering impressions, although all ads are subject to re-review at any time". Meta's Italian localisation of that same sentence says something rather different, and I come back to it further down.
Approval on Meta is a snapshot, not a certificate: it covers what the system saw at the moment it looked.
A system that admits an ad may go live without having been checked against every policy is describing a trade-off, not confessing a scandal. The part that matters comes next, and it's what happens between approval and removal: who decides, with how much certainty, and who pays the bill when the decision is wrong.
What Meta actually reviews before an ad goes live
The Help Centre lists six categories of element Meta may look at before an ad goes live, and states that the list isn't closed. They are "images, video, or text"; targeting information; ad destination; special ad categories; advertiser permissions; "other critical components and information". The wording that introduces them says review may include specific components of an ad, and gives the six as examples — so it's an open list, not a guaranteed perimeter.
Meta's review starts automatically before publication and closes within twenty-four hours for most ads. The hedging matters more than the figure: Meta writes "most" in the Help Centre and "typically" in the Advertising Standards. Twenty-four hours isn't a commitment, it's the statistic of a process. Anyone who has launched a campaign on a Friday evening already found that out on their own.
Automation does nearly all the work in ad review, and Meta's English wording is precise about it: the system "relies primarily on automated technology". Meta's Italian localisation of the same page drops the adverb and says the system is based on automated technology, full stop. Another Help Centre page in Italian, the one about ads rejected after approval, keeps it. One sentence, two different translations.
Human reviewers enter ad review with two functions Meta declares, and the second one is the exception. Meta says it uses human reviewers to train and improve the automated systems, and in some cases to review ads manually. Meta doesn't explain what makes an ad land in front of a person, and it presents manual review as the exception: the wording is "in some cases".
Meta's Italian localisation translates review as "controllo", which is why the Italian pages are hard to find with the obvious search terms. The page is titled "Informazioni sulle inserzioni in fase di controllo", the button says "Richiedi un controllo", the standards section is "Applicazione delle nostre normative". Anyone searching for "revisione delle inserzioni" is using a calque from English rather than the wording in the interface, which is why those pages don't come up.
Why an approved ad can be rejected later
Meta's approval isn't final, and Meta says so. Ads remain subject to review and re-review, and can be rejected at any time. The Help Centre gives the matter a page of its own.
The Help Centre page on ads approved and then rejected gives three example triggers, and declares the list open: Meta writes that approved ads can be selected for another review for various reasons, and introduces the three with "for example". The first example is user signals: somebody hides, blocks, reports or gives negative feedback on an ad. The second is a sudden spike in engagement, especially alongside reports. The third is chance, because review may be carried out at random to ensure accuracy.
An ad nobody reports is still exposed to re-review, but it loses user signals, the most direct of the three triggers Meta lists. That's a direct consequence of those triggers, and it works against you exactly where it should work hardest: people who fall for a scam often don't report it, out of embarrassment or because they haven't understood what happened to them. The signal that sets off a re-review comes through more loudly from an annoying ad than from a harmful one.
A second review track exists, and it covers the domain rather than the ad. On the restricted domains page Meta says it "continuously" reviews domains, using signals of its own: user feedback, and domains associated with ad accounts disabled for violations or for payment risk. When a domain is identified as suspicious or in violation, every ad that directs people to that domain is rejected, and the block lasts sixty days, renewable if the linked accounts produce further suspicious activity.
The ad track and the domain track have different triggers and different clocks, and keeping them apart is what makes the picture coherent instead of contradictory. An ad gets looked at again for reasons Meta describes as examples, among them audience reaction and a random draw; a domain is watched continuously and penalised in sixty-day blocks. Honest advertisers meet the second track as a rejection message: "Ads must not promote restricted domains. Please use a non-restricted domain to continue advertising." if you want to keep advertising.
Re-review of a live ad is silent until it ends badly. Meta states that if your ad undergoes additional review you won't be notified unless it violates the Advertising Standards. There's also an operational detail familiar to anyone working to a deadline: editing targeting, creative, optimisation or billing event restarts review from scratch, while changing the ad set's bid, budget or schedule doesn't.
What cloaking is and why automated review doesn't catch it
Cloaking is showing the review system a different page from the one a real person will see, and review misses it because it's looking at the wrong page in perfect good faith. Meta defines it as "any attempt to circumvent our content policies by intentionally presenting different off-platform content, such as URLs or applications, to our integrity systems versus what is shown to users".
The official definition of cloaking doesn't sit in the Advertising Standards. It sits in the Community Standard on spam, inside the block on deceptive URLs, and it reaches the Advertising Standards by reference: ads must comply with the Community Standard on spam. The anti-fraud rule that matters most to people buying ads isn't in the advertising rulebook but in the general anti-spam rules, which explains why so much writing on the subject never cites it: looking where it seems logical to look, you don't find it.
Cloaking doesn't break through a surveillance system, it hands that system a false input. The difference matters because it changes the remedy: a flaw gets a patch, a false input needs repeated checks, unannounced and carried out with the appearance of an ordinary user, which cost far more than a scan. Meta calls it "a malicious technique that impairs ad review systems", and the verb is calibrated: it doesn't say the system is blind, it says somebody is degrading its sight.
The Community Standard on spam lists three simpler variants of cloaking alongside it, and those are the ones you run into more often. Deceptive links are content that promises one thing and delivers something materially different. Deceptive redirection covers sites that ask for an action — a captcha, watching an ad, a click — and change domain once you've done it. Landing page impersonation is a site posing as a known brand using typos and lookalike domains.
Meta took cloaking to court on 26 February 2026. In a post published that day the company announced four lawsuits against four advertisers; one of them, against Lý Văn Lâm of Vietnam, is expressly about the use of cloaking to get around the ad review process.
Why the same system rejects a legitimate caption
Reviewing an ad's text and reviewing its landing page look at objects of a different nature, and only the first is an easy problem. Text is compared against written prohibitions: the Advertising Standards ban precise categories of claim, from earnings promises to references to personal attributes to health claims. That's a closed problem, one a machine solves quickly and with a margin of over-reach. A landing page belongs to a third party, changes whenever it likes and can behave differently depending on who visits it: an open problem.
People who build scams write to the letter of the rule, and Meta's internal documents put a number on that in one specific case. Singapore's police handed Meta a list of 146 scams aimed at users in that country. Company staff found only 23% of them actually in violation of the policies. The remaining 77%, an internal presentation notes, "violate the spirit of the policy, but not the letter". Meta contests the overall reading of those documents through spokesman Andy Stone, who called them "a selective view that distorts Meta's approach to fraud and scams".
The 77% of scams that violate the spirit but not the letter measures the problem from one side only, and it's worth saying so rather than glossing over it. It shows that a great many scams sit formally inside the rules; it doesn't show that honest businesses are rejected too often. On the second side there's no public figure: how many legitimate ads are rejected in error, and how many of those are later reinstated, Meta doesn't publish and nobody has measured from outside. What I can say, as a professional observation and not as a measurement, is that in day-to-day work the rejection of a compliant ad is an ordinary event and the re-review that overturns it is routine.
People who build scams write to the letter of the rule. An honest business writes what it thinks, and every so often walks straight into it.
What the documents seen by Reuters say about the 95% threshold
Internal Meta documents seen by Reuters indicate that the company bans an advertiser only when its automated systems predict that advertiser is "at least 95% certain to be committing fraud"; below that threshold, if it still considers them a likely scammer, it charges higher ad rates instead of removing them. Meta contests the reading of those documents: Stone told Reuters they present "a selective view that distorts Meta's approach to fraud and scams". The source is the investigation published on 6 November 2025, by Jeff Horwitz, part of the series for which Horwitz and Engen Tham won the 2026 Pulitzer Prize for Beat Reporting.
Meta's objection covers the whole body of documents seen by Reuters, not only individual figures. Stone rejected Reuters' reading wholesale and answered on the merits on several points, among them the 10.1% estimate, the 0.15% cap and the purpose of penalty bids. On other figures I report below, Reuters carries no specific reply, and I flag that where it happens.
The 95% threshold concerns banning the advertiser, not removing the individual ad, and that distinction has to hold. Reuters writes that Meta "only bans advertisers" once 95% is reached: below that level the company doesn't close the account, while its ads stay subject to ordinary review like anyone else's. It isn't a free pass for the ads, it's a tolerance threshold for the people buying them.
The 95% in Meta's documents is a model's estimate, not an established certainty, and the difference is everything. Reuters' text says "its automated systems predict": a model assigning a probability, not an inquiry establishing a fact. Between "we are 95% certain" and "the model estimates 95%" lies the same distance that separates a conviction from a suspicion.
The 95% threshold is the single most important fact in this whole story, and it usually travels without the source it came from. It's worth setting next to the other threshold, the one anyone who has ever had an ad rejected knows. To shut down an advertiser its own model considers probably fraudulent, Meta set near-certainty internally. For the rejection of a single ad, in the public pages cited in this article, no comparable threshold is stated.
Meta set the certainty needed to ban a suspect advertiser at 95%, internally. For the rejection of a single ad, no number appears in its public pages.
That banning an advertiser and rejecting an ad carry different thresholds is reasonable; what can't be done from outside is compare the two standards of proof. Banning an advertiser ends a commercial relationship and, if the decision is wrong, produces real damage and a dispute; rejecting an ad is reversible, and Meta itself expects the advertiser to fix it and ask for a new review. What isn't declared to the people buying is how much proof is needed on the other side. On banning an advertiser an internal number exists and we now know it; on rejecting a single ad nothing comparable is published, and without that number the asymmetry can be observed but not measured.
What penalty bids are
Below the ban threshold Meta doesn't take the suspect advertiser off the market: it makes them pay more to stay on it. Reuters calls this mechanism penalty bids and reports that documents from the previous summer described it as one of the central elements of the company's plan against scams. Stone confirmed both its existence and its purpose, saying the aim was to reduce scam advertising by making suspect advertisers less competitive in auctions.
Penalty bids act before the auction and show up as a higher price to win it. Reuters describes it like this: to advertise on Meta's platforms a business has to compete in an online auction, and before the bids are placed the automated systems calculate the probability that the advertiser is involved in fraud; likely scammers who stay below the removal threshold have to pay more to win that auction.
The effect on Meta's own accounts is stated in the Reuters investigation, and it's the line almost every pickup leaves out. Reuters writes: "For Meta, the financial impact was mixed: While the company would sell fewer scam ads, it would make more money from those that it did, offsetting some of the lost revenue". Fewer scam ads sold, more revenue from each one that's sold. Stone, on the same point, said that in the months after the rollout tests showed both a fall in reports and a slight dip in overall ad revenue.
Why a surcharge weighs more on a business that actually sells something
A surcharge hits cost, and cost is the line on which a business selling a product and an operation that takes money without delivering are most different. What follows is my own reasoning about auction economics, not a data point: no public source measures the margins of a fraudulent operation, and anyone quoting one is making it up. What can be done is to compare cost structures.
A business selling a real product pays for the product, logistics, returns, support and warehousing. What's left is the share of the price it can spend to acquire a customer, and that's a fraction, not the whole price. A fraudulent operation of the kind Reuters describes — the sort that takes the money and doesn't deliver — has costs of its own: accounts to source, infrastructure, people, and the far from trivial problem of collecting the money and laundering it. What it doesn't have is cost of goods, returns, support or refunds. The reasoning that follows applies to that form of fraud, not to every advertiser Meta's systems judge suspect. Revenue per victim therefore stays much closer to profit per victim than it ever does for someone actually selling something. And when the scheme is after card details rather than the advertised price, the take isn't even the figure written in the ad.
A rise in cost per impression turns into a proportional rise in cost per acquisition only if click rate and conversion rate stay the same. It's the step that holds the whole argument up, and it has to be stated with its condition because without it the statement is false. If the price of a thousand impressions doubles and the share of people who click and then buy stays the same, every customer acquired costs twice as much. The ceiling beyond which that cost becomes unsustainable, though, isn't the same for everyone, because it depends on how much is left to the seller after paying for everything else.
The same surcharge runs into two very different spending ceilings. A seller keeping a small share of the price reaches its ceiling after a modest rise in cost per acquisition and stops buying space; an operation that takes money without delivering has a much higher ceiling and needs a much larger rise to reach it. Careful not to pull the conclusion further than the premise: that ceiling is higher, it isn't infinite. A large enough surcharge stops someone with no cost of goods too, and the point isn't that the toll doesn't work, it's that at equal toll it hits first whoever has least to hide.
Whether a surcharge applied to a suspect advertiser also raises the auction price for everyone else is a question I can't answer. In an auction the price needed to win depends partly on what others are bidding for the same audience, and a suspect advertiser who is charged more rather than removed is still inside that auction. Whether this raises the price for everyone else depends on how much weight that competitor carries with that audience, and neither Reuters nor Meta has quantified it. The question ought to be put to Meta, because Meta is the only one who knows the answer.
A toll set the same for everyone pushes out first whoever has the thinnest margin. That isn't necessarily the scammer.
What the advertising the system doesn't block is worth
Internal documents seen by Reuters show that Meta had projected, towards the end of 2024, taking around 10% of its annual revenue, $16 billion, from advertising for scams and prohibited goods; the precise figure in the documents is 10.1% of 2024 revenue. Meta rejects it: Stone called it "rough and overly-inclusive", said the real number was lower because the estimate also took in plenty of legitimate ads, and refused to give the updated figure.
The perimeter of the 10.1% figure is wider than scams, and that detail changes what the number means. In the documents the line covers "scams, illegal gambling and prohibited goods". Anyone quoting it as scams alone inflates it without noticing.
The verb in the Reuters original is projected, and a case is won or lost on that word. Meta had estimated it would take that amount, not that it had taken it: an internal projection about 2024, not a set of accounts. Secondhand pickups saying "Meta earns 16 billion from scams" are turning a contested forecast into an established take.
The documents seen by Reuters estimate 15 billion "higher risk" scam ads a day shown by the company's platforms, defined as those carrying clear signs of being fraudulent. A twin number, in the same investigation, is often confused with this one: the 22 billion organic scam attempts a day, which aren't advertising and which Reuters keeps explicitly separate. On neither estimate does Reuters carry a reply from Meta.
The Reuters investigation shows that Meta had quantified the problem with accounting precision. In the first half of 2025 the team charged with vetting suspect advertisers couldn't take actions costing more than 0.15% of total revenue. On $90 billion that's about $135 million. Stone replied that the 0.15% came from a revenue projection document and wasn't a hard limit. Four fraudulent campaigns removed over the course of 2025 were worth $67 million a month in ad revenue on their own, a figure on which Reuters carries no reply. An internal review in April 2025, into the online communities where scammers trade methods, concluded, word for word, that "It is easier to advertise scams on Meta platforms than Google", without the document explaining why.
What the difference is between a rejected ad and a blocked account
Meta documents two levels of consequence, not three. The first covers the single ad, which is rejected and which as a rule can be corrected and republished: the official wording is that advertisers "will typically be provided an opportunity to edit their ads", so it's the practice, not a guarantee. The second covers assets — business portfolio, ad account, Page, user account — and is called an advertising restriction.
The category "account limitation" doesn't exist in Meta's documentation, however often it turns up in explainers. The verb "limit" appears in the official text as a description of what the company may do, not as the label of a state of its own. The documented names are two: rejected ad, and advertising restriction on assets, with the ad account liable to be disabled.
Advertising restrictions differ by cause, and it's worth knowing the difference before you need it. There are restrictions for policy violations and restrictions for "unusual activity", and Meta declares the second kind temporary: it may temporarily limit some features while it investigates the problem. What a restriction contains ranges from a daily spending cap to the complete loss of the ability to advertise.
An ad account disabled for policy violations can lose unused prepaid services. If an ad account is disabled for policy violations and stays ineligible for reinstatement for six months, unused prepaid services can be cancelled and after that period the account is no longer recoverable; Meta also reserves the right to disable it permanently before the six months are up.
Tolerance before a ban isn't the same for everyone, according to the documents seen by Reuters. A small advertiser, one 2024 document says, had to be flagged at least eight times for promoting financial fraud before Meta banned them; some large spenders, described internally as "High Value Accounts", could pile up more than 500 strikes without being shut down. The investigation gives no formal definition of that category and no spending threshold, so anyone explaining exactly what a High Value Account means is adding something the source doesn't contain. On these two thresholds Reuters carries no reply from Meta.
Why a market for rented ad accounts exists
An account's history feeds into how its ads are judged, and Meta says so. In the Help Centre it writes that it may take an advertiser's historical compliance with the Advertising Standards into account when assessing its ads before impression data is available. It's a stated possibility, not a quantified rule: Meta doesn't say how much weight it carries, nor that an older account gets approved faster. What can be said is that past compliance is a factor, and a factor like that can be bought along with the account.
A market for renting trusted ad accounts really does exist, and it's Meta itself that says so. On 26 February 2026 the company announced it had sent cease and desist letters to eight former Meta Business Partners offering abusive services. Among them, fake account-unblocking services and "renting access to trusted accounts that helped clients evade our enforcement systems": rented access to trusted accounts, with the declared purpose of evading the enforcement systems. In the same text Meta announces it's reviewing the admission criteria for its partner programme.
The lawsuits and the cease and desist letters Meta announced on 26 February 2026 are two different things and get confused regularly. There are four lawsuits, covering advertisers in Brazil, China and Vietnam; there are eight cease and desist letters, covering former partners. Meta writes that it will consider legal action against the eight only if they don't comply.
I write as a Meta Business Partner, and renting out trusted accounts touches the badge I carry. A partner programme is a list of people the platform has given a trust signal to; when that signal becomes a rentable asset, the programme stops certifying competence and starts certifying access. The remedy doesn't run through stricter review of ads, it runs through making an account's reputation non-transferable.
An ad account's reputation is an asset that can be rented. In February 2026 Meta sent cease and desist letters to eight of its former partners who were doing exactly that.
What the numbers Meta publishes say, and what they don't
Meta publishes substantial figures on its own fight against scams, and they're self-reported, without external audit and without a denominator. On 11 March 2026 it announced that it had removed over 159 million scam ads in 2025, 92% of them "before anyone reported them", and had shut down 10.9 million accounts linked to criminal scam centres.
The 159 million removals don't say how many scam ads were published, because Meta doesn't publish the denominator. Knowing that 159 million ads were removed tells you nothing about how many got through, in the same way that the number of tickets a city issues tells you nothing about how many violations took place. The internal estimate of 15 billion high-risk ads a day that appears in the documents seen by Reuters sits on a different order of magnitude, and the two numbers aren't directly comparable precisely because one counts removals and the other estimates exposure.
The fall in reports that Meta often cites measures something different from what it appears to measure. In the post of 3 December 2025, titled "Scams Are Bad for Business: Our Ongoing Efforts to Fight Fraud", the company writes that over the previous fifteen months user reports about scam ads fell by more than 50%. Those are reports received, not scams published: a fall can mean fewer scams, or more fatigue, or that the people who fall for them don't report.
Meta stated the fall in scam ad reports twice in twenty-seven days, and the two figures don't match. On 6 November 2025 Stone told Reuters of a 58% reduction over eighteen months; on 3 December 2025 the company newsroom spoke of more than 50% over fifteen months. Different time windows give different results and there isn't necessarily a contradiction, but they're two distinct figures and shouldn't be used as if they were the same one.
The stated target on advertiser verification concerns a share of revenue, not a share of advertisers. On 11 March 2026 Meta wrote that it aims to have verified advertisers generate 90% of ad revenue by the end of 2026, against 70% at that date. The remaining 10%, it adds, will come from low-risk activity such as the local ice cream shop. That leaves a great many small advertisers outside the verification perimeter.
What someone with a rejected ad sees
The route for contesting a rejection exists and is documented in two places that don't match each other. The Advertising Standards say that if you believe an ad, an ad account, a user account, a Page or a business account has been rejected or restricted by mistake you can request a review of the decision in Account Quality, and point you to facebook.com/accountquality. The Help Centre, on the same action, tells you to request a new review in Meta Business Support Home and points you to facebook.com/business-support-home. Two different names and two different addresses, in the same company's documentation, for the same request.
Meta admits in writing that its own system gets things wrong, and it's the most useful sentence an advertiser can know because it licenses you to insist. Meta writes: "Our enforcement isn't perfect, and both machines and people make mistakes".
Nobody publishes how long Meta actually takes to answer a review request, and I can't say either. The article stops here on purpose: I could measure the times on my own requests, which are my sample and not the market's, and anyone writing an average without declaring the sample is inventing it. I write this because it's exactly the kind of number that circulates online with no source.
Meta's Italian pages say things its English pages don't, and two cases are worth flagging to anyone who cites the localised documentation. On ad review, the English reads "An ad may not be reviewed against all policies before delivering impressions", while the Italian says "un'inserzione non può essere controllata rispetto a tutte le normative prima di avere dati sulle impression" — an ad cannot be reviewed against all policies: the localisation turns a possibility into a structural impossibility. The second case is more serious. The English Advertising Standards say Meta may restrict ad accounts "that don't follow our Advertising Standards"; the Italian version reads "potrebbe limitare gli account pubblicitari che rispettano gli Standard pubblicitari", ad accounts that do follow the Advertising Standards. The negation is missing in the Italian, and the sentence states the opposite of the original. Anyone quoting that version in full hands a weapon to the first reader who opens the English.
What should change
Two changes would matter more than "more review": making an account's reputation non-transferable, and narrowing the gap between the proof required to ban a scammer and the proof required to reject a clean company's ad. What follows is a position of mine, not a reconstruction from documents.
As long as an account's historical compliance stays a rentable asset, anyone wanting to get around stricter review of ads can buy access to an account that already has that history. Meta acknowledged the problem when it sent cease and desist letters to eight former partners and when it announced it was reviewing the programme's criteria, but a cease and desist hits the seller, not the fact that there's something to sell.
Closing the gap between the two thresholds doesn't necessarily mean lowering the 95%, which for an irreversible action like shutting down an advertiser remains a defensible caution. The work can be done from the other side: raise the proof required to reject the ad of somebody with a clean history, and publish response times on review requests. Today the cost of the error falls on one side only, and the side paying it has no way even to measure it.
For anyone looking at a suspicious sponsored post right now, meanwhile, the first tool is public and needs no account. The Ad Library tells you who declared they paid for that ad, how long it has been running and on which platforms. It doesn't tell you whether the ad is a scam: it tells you where to start looking.
Frequently asked questions
How does a scam ad get past Meta's review? Review judges the ad and its landing page as they appear at the moment it looks at them. Anyone who wants to get through shows the review system a different page from the one the person clicking after approval will see. Meta itself writes that an ad may not be reviewed against all policies before delivering impressions.
What is ad cloaking? Cloaking is the attempt to circumvent the policies by intentionally presenting different content to the platform's integrity systems from what is shown to users. The official definition sits in Meta's Community Standard on spam, not in the Advertising Standards, and it reaches the Advertising Standards by reference.
What does Meta review before approving an ad? The Help Centre lists six categories: images, video or text; targeting information; ad destination; special ad categories; advertiser permissions; critical components and additional information. The list is declared open, not exhaustive, and review starts automatically before publication.
How long does ad review take on Facebook? Review closes within twenty-four hours for most ads, but Meta uses "most" and "typically": it isn't a guaranteed commitment. Ads can also be re-reviewed at any time, including after publication.
What is Meta's 95% threshold? Internal documents seen by Reuters, published in the investigation of 6 November 2025, indicate that Meta bans an advertiser only when its automated systems estimate that advertiser at least 95% certain to be committing fraud. Below that threshold it doesn't close the account but applies higher ad rates. Meta contests the reading of those documents.
What are penalty bids? Penalty bids are the ad cost mark-up which, according to the documents seen by Reuters, applies to advertisers the automated systems consider likely scammers but who stay below the ban threshold. They have to pay more to win the auction.
Why doesn't a surcharge stop scam ads? A surcharge hits cost, and an operation that takes money without delivering has no cost of goods, no returns and no support: it can therefore carry a much higher cost per acquisition before leaving the market. A business on a thin margin reaches its ceiling far sooner. At equal amount, the toll hits first whoever has least to hide. This is reasoning about auction economics, not a measured figure.
How much does Meta make from scam ads? Internal documents seen by Reuters show the company had projected taking around 10% of 2024 revenue, $16 billion, from scams, illegal gambling and prohibited goods. It's an internal projection, not an established take, and Meta calls it "rough and overly-inclusive", arguing the real number was lower without providing it.
Why was my ad approved and then rejected? Approval isn't final. Meta lists three example triggers, noting that the reasons can be others: users hiding, blocking or reporting the ad, a sudden spike in engagement, and random review. A re-review generates no notification unless it ends in a rejection.
How do you request a review of a rejected ad? The request goes through two routes that Meta's documentation doesn't reconcile: the Advertising Standards point to Account Quality at facebook.com/accountquality, the Help Centre to Meta Business Support Home at facebook.com/business-support-home.
Why are Facebook ad accounts rented out? An account's historical compliance is a factor Meta says it may consider when assessing its ads, and a factor like that can be bought along with the account. In February 2026 Meta sent cease and desist letters to eight former Meta Business Partners offering rented access to trusted accounts to help clients evade its enforcement systems.
Does editing an ad restart the review? It depends on what you edit. Targeting, creative, optimisation and billing event restart review. Bid, budget and ad set schedule don't.
Changelog
29 August 2026: first published. All Reuters and Meta figures were verified against the primary source on 28 August 2026.
Read also
Another note on how the rules change inside Meta:
Davide Cosmai
Meta Ads Expert & Growth Strategist · Meta Business Partner. 15+ years running Meta campaigns. €52M+ in revenue generated for clients.