Poland's €250M Meta scam-ad complaint: 87% not removed
Poland asked the EU to fine Meta €250M after CERT Polska reported 122 scam ads and 106 stayed up. What brand impersonation means for small businesses.
A national cybersecurity team reported 122 fraudulent Facebook ads to Meta. Meta declined to remove 106 of them. That is an 87% rejection rate against reports filed by a government CERT — and it is now the basis of a formal request that the European Commission fine Meta €250 million. If a state agency's takedown requests get ignored at that rate, you should assume yours will too.
What actually happened
On August 27, Poland's digital affairs minister Krzysztof Gawkowski sent a letter to European Commissioner Henna Virkkunen asking the Commission to fine Meta €250 million (about 1.1 billion zloty) over its handling of fraudulent advertising, Reuters reported.
The evidence is a test run by CERT Polska, the national incident response team. Of 122 adverts it flagged as fraudulent, Meta refused removal in 106 cases, removed 10, and gave no response in the remaining six (details via Notes From Poland). Gawkowski argues the pattern may breach the EU's Digital Services Act.
Meta says it does not seek to profit from fraudulent advertising, and points to removing roughly 380,000 pieces of content and 137,000 ads violating its fraud policies in Poland alone between July 2025 and June 2026 — most, it says, before any user reported them.
Both things can be true. Volume removal at scale, and a very low hit rate on the specific, human-reported cases. The campaign behind the complaint started with InPost founder Rafał Brzoska, whose face was being used in scam ads alongside other prominent Poles.
Why brand impersonation in ads matters for your business
You are not Meta's enforcement priority. Neither is CERT Polska, apparently.
Impersonation ads are cheap, targeted, and profitable, and the well-known-local-business is a better mark than the multinational — your customers recognize your name and have no way to check whether the ad is yours. When the fake runs, the chargebacks, the angry calls, and the reputational damage land on you. The takedown, on this evidence, may not.
What actually works:
Monitor the ad libraries yourself, on a schedule. Meta's Ad Library is public and searchable by advertiser name and keyword. Searching your own brand, your founder's name, and your top product terms weekly is a fifteen-minute job. It is also the only way you find out before a customer does.
Give customers a way to verify. One canonical page on your own domain listing your real ad accounts, real phone number, and real checkout domain. When someone calls asking about a promotion you never ran, you send that link. This is why owning your domain and your customer list beats renting reach.
Report through the DSA channel, and keep the receipts. EU users have a statutory illegal-content reporting path and the platform owes a response. Log every submission and every outcome. Poland's complaint exists because someone kept a spreadsheet — 122 in, 10 down.
Assume the ad channel is adversarial infrastructure. If your entire acquisition funnel starts on a platform that will not police your brand, that is concentration risk. Email, SMS, and direct traffic are the parts a scammer cannot buy their way into.
We build the owned layer — the site, the list, the checkout, the verification page — because the rented layer answers to someone else's enforcement queue.
Key takeaways
- Poland asked the European Commission on August 27 to fine Meta €250 million over fraudulent advertising
- CERT Polska reported 122 scam ads: Meta refused removal in 106 cases, removed 10, and did not respond to six
- Meta says it removed ~380,000 content items and 137,000 ads for fraud in Poland between July 2025 and June 2026
- Bulk enforcement and poor per-report response can coexist — do not rely on takedown as your brand protection
- Search Meta's public Ad Library weekly for your brand, founder name, and product terms
- Publish a verification page on your own domain and log every DSA report you file
How much of your revenue starts on someone else's platform? We build the owned layer — storefront, customer list, checkout, and a verification page customers can trust — so a scam ad costs you a support ticket instead of a quarter. See what we build, or talk to us about your channel risk.
Sources: Reuters, Notes From Poland.
- #scam-ads
- #meta
- #brand-protection
- #digital-services-act
- #smb
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Shopify Storefront MCP cart tools end Aug 31: move to UCP
Shopify stops maintaining Storefront MCP get_cart and update_cart on August 31, 2026. The UCP Cart MCP replacement is not a drop-in — PUT semantics changed.
Read itOwner raises $240M to be every local business's CTO
Owner hit a $2.3B valuation selling local businesses one vendor for site, ordering, POS, CRM, and AI phone. Convenient — and total lock-in. Read the exit clause.
Read it