How scams target you online—and how to fight back

The prophet Jeremiah once asked,

Wherefore doth the way of the wicked prosper? wherefore are all they happy that deal very treacherously?

Every generation of people perceives a collapse in ethical behavior, and if the trust level of human civilization had really been sliding that badly for so long—the book of Jeremiah was written 2600 years ago—nothing would be left for us by now.

That perception of decline is not surprising, considering that most people respect norms of honesty and reciprocity, but the transgressors tend to attract more attention. Often, people who comment on moral collapse are older adults comparing their experiences with their own peer group to the crimes of the younger, higher-profile 30 under 30 crowd.

So we can’t just go by vibes, by our feelings of how much of a rip-off everything is now. We have to take a step back and look at the stats. And this time, possibly because of how network effects amplify the impact of a few big companies, it’s a real problem.

According to the FTC, people in the USA lost $2.1B to social media scams in 2025. Internal documents from Meta, which owns Facebook, Instagram, and WhatsApp, estimated that the company is involved in about 1/3 of successful scams here.

And Meta isn’t the only company that designs an Internet platform to work better for scammers. Google tweaks their systems and policies to benefit scams, too. The FBI warns,

Cyber criminals use advertisements that imitate legitimate companies to misdirect targets conducting an internet search for a specific website.

Google Search is a major scam risk because of some choices in software design and ad policies that make their platform work better for scammers and worse for those trying to catch them. As Prof. Tressie McMillan Cottom wrote, we are now living in a scam culture.

Scams weaken our trust in social institutions, but their going mainstream—divorced from empathy for the victims or stigma for the perpetrators—means that we have accepted scams as institutions themselves.

Google and Meta are large enough, and have enough impact on how people and companies find each other, that their internal collapse in business ethics has an oversized impact on the whole economy.

The ways that big companies profit from online fraud is pretty complicated, but I think I can explain it if we work backwards. And the better we understand how scam culture has been coded into everyday business practices, the better we will be able to roll it back.

The auction

Most online advertising, legit or criminal, is placed using some kind of auction. Probably the best known is the system behind Google’s search ads, which Edelman et al. explained in Internet Advertising and the Generalized Second-Price Auction: Selling Billions of Dollars Worth of Keywords.

Every time there is some opportunity to show an ad to you—whether it’s because you did a web search, scrolled a social media feed, or visited a web site with ads—some computer program in a data center somewhere acts like a very fast auctioneer, selling off the ad space to the highest bidder.

The bidders in the auction are AI, using three different kinds of information to “decide” how much to bid.

  • Context: where the ad will appear
  • Intent: what you’re doing (if a bidder infers that you’re shopping, the ads reaching you go way up in value)
  • Personal information: some other qualities about you that a bidder has collected or inferred.

If you notice that you get different ads on search engines or social media from other people, you have probably been classified differently from them, so different bidders are bidding high enough to win the auctions.

Why Facebook and Google tolerate scams

The auction mechanism explains why Meta and Google seem so incompetent at filtering out the scam ads. An auction generally gets higher prices when there are more bidders. And the ad auction is no exception. (How is it that social sites make it so easy to tag people who appear in photos, but they somehow can’t spot a bank logo in an ad and alert the real bank?)

Meta estimated that they get 10% of their revenue from illegal and policy-violating ads—but that doesn’t mean that scammers are responsible for 10% of their revenue. All of the legit advertisers are paying more, too, because every time “their” AI bidder participates in an ad auction, it has to go up against not just legit competitors, but scammers too.

No wonder that, as Bob Sullivan explains, Facebook’s algorithm pushes people into the arms of criminals. Meta and Google refuse to take some basic steps to make it easier for law enforcement and consumer organizations to spot scam advertisers, or for their real advertisers to spot their fake competitors.

Know the scam, avoid the ad?

I’m fortunate enough to avoid some kinds of online scam ads. For example, I rarely see those urgent Microsoft warnings, you know, the ones that will put you on the phone with a “tech support” person to talk you through installing a computer virus.

I don’t get those tech support ads because AI bidders can infer that I keep up with computer stuff. But I’m sure that there are plenty of scams I would be more likely to fall for. I’m probably about as gullible as average if a scammer could figure me out—maybe a realistic urgent alert related to an upcoming trip?

In general, the less accurately I can be targeted, the better. I probably won’t get any fewer scams by being misclassified, but I’d rather get scam ads that I’ll laugh at than scam ads I’ll click on.

In order for the scam problem to flourish, though, the scams must be getting matched up to the people likely to fall for them.

Normal companies passing targeting data

The Big Tech companies collect some data about what you watch and do on their sites and apps. But a lot of targeting data comes from a place you wouldn’t expect. It’s actually provided to the Big Tech platforms by normal small businesses.

Why?

Companies that advertise with Google and/or Meta are encouraged to share their customer information.

For example, they can report when somebody bought something, or send a customer list to the Big Tech company to train the AI to find people similar to their customers to show ads to. They can even report on who’s reading what pages of their web site.

And because of the built-in auction mechanisms on the platform, every advertiser ends up sharing information with every other advertiser. Every customer list that you appear on helps to train the AI to target you for ads you’re likely to respond to—including the scam ones.

Legal options

Do you have a right to stop companies from passing info about you?

It’s complicated, but in California you have a better chance than in most other places. California has a bunch of privacy laws.

That’s good news. Even better news is that a bill that would have rolled back some of our most important privacy protections has been amended, and right now it looks like we will keep our right to sue over the worst violations. More on that at: Facts and Fiction on the California Invasion of Privacy Act and the problematic SB 690 from Oakland Privacy.

A lawyer can work backward from a scam ad you received, to the AI that targeted you for the scam, to the sources of information that trained the AI. Justice is within reach.

Doing legit businesses a favor

People who do online marketing are family members and citizens, too. They don’t want to support Big Tech’s noisy, resource-sucking data centers, social media mental health harm, or other corporate crimes, any more than the rest of us do.

But sometimes Big Tech companies make it hard to justify not spending money with them. And it’s hard to speak out in the marketing meeting and say, “our company should do the right thing.”

But over time, privacy cases can help change that.

When a marketing person has trouble justifying moving the budget away from Big Tech and into legit marketing projects, the benefit of avoiding legal issues can shift the balance. It’s sort of like the…

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论