Why Facebook’s war on ad blockers could help scammers
Reports that uBlock Origin is stepping back from the never-ending effort to filter Facebook ads are a reminder that ad blocking is no longer only an argument about inconvenience, publishers, and lost advertising revenue.
It is also an issue of security.
For years, ad blockers have occupied an uncomfortable place in the web economy. Publishers and platforms rely on advertising to fund their services, while users install blockers to escape intrusive banners, autoplay videos, tracking scripts, and feeds that increasingly feel designed around monetization rather than the people using them.
That debate is usually framed as a contest between a platform’s right to make money and a user’s desire for a cleaner browsing experience. But it leaves out an important detail: Ads are not always merely ads.
Malwarebytes General Manager Mark Beare stated:
“While it’s easy to look at ad blockers solely as a way of hurting monetization for these businesses, the other thing that ad blockers are doing is blocking malicious and scam ads.”
Sometimes ads are scams. At other times, they lead to malicious sites. And often, they impersonate trusted brands, promise fictional government payments, promote fake investment opportunities, or send victims into private messaging channels where the fraud continues.
In those cases, an ad blocker is not simply removing something annoying. It’s removing a route into a scam.
The advantage lies with the platforms
The reported decision by uBlock Origin’s team to stop continually chasing changes to Facebook ads highlights a structural advantage held by large platforms.
An ad blocker generally works by identifying requests, scripts, page elements, and patterns associated with advertising or tracking. A platform that controls the entire delivery stack can alter those patterns: It can change element names, move content into new components, serve ads through first-party infrastructure, or make sponsored content look more like ordinary posts.
This creates a familiar cat and mouse game. Filter-list maintainers identify a new method, the platform changes its implementation, users receive an update, and then the cycle starts all over. Again and again.
It’s the difference in resources that matters. A major platform can deploy changes on an enormous scale and has dedicated teams working on its products, advertising systems, and infrastructure. Open-source filter maintainers and independent blocking tools do not have the same staffing, telemetry, or ability to anticipate upcoming changes in how ads are delivered or how the platform will modify its systems.
That does not mean platforms should be expected to design their products around every third-party extension. Nor does it mean every attempt to detect or resist blocking is malicious. Advertising funds a great deal of the online content and services people use every day.
Not every blocked ad is harmless
A platform’s ability to make ads harder to distinguish from ordinary content should come with a corresponding responsibility: Make sure the ads being delivered deserve the trust implied by that integration.
Internal Meta documents reviewed by Reuters showed that the company projected about 10% of its 2024 revenue, or $16 billion, would come from ads for scams and banned goods. Meta said the estimate was “rough and overly-inclusive,” and that the true figure was lower.
That is a clear mismatch with Meta’s advertising rules, which explicitly prohibit deceptive and misleading ads, including schemes intended to scam people. Meta said its ad-review system examines ads before they go live and can re-review them later, but Meta also acknowledges that an ad may begin delivering before it has been reviewed against every policy.
That time gap is important. Scam campaigns are built to exploit speed and scale. Fraudsters can test new creatives, swap landing pages, impersonate a brand or public figure, and adapt when enforcement catches up. Meta disputed Reuters’ characterization of its anti-fraud efforts.
This is not an argument that every ad on Facebook, Instagram, or another large platform is dangerous. Most are not. The problem is that users cannot reliably tell, at a glance, which ad is a legitimate offer and which one is an attempt to steal money, credentials, or personal data.
Better moderation of ads is better for everyone
Rather than treating every blocker as a threat to revenue, a more productive response to ad blocking is to make the advertising experience safer, less invasive, and more accountable.
That starts with focusing less on defeating filters and more on preventing harmful ads from being approved or reaching users in the first place.
Some practical priorities include:
- Verify advertisers more consistently, especially in high-risk categories such as financial services, cryptocurrency, health products, job offers, and government-benefit claims.
- Review not only the visible creative, but also the destination page, redirects, tracking behavior, and later changes to the advertiser’s site.
- Detect and act on coordinated impersonation campaigns quickly, rather than treating each fraudulent ad account as an isolated incident.
- Make it easy for users to report ads and give them useful feedback when action has been taken.
- Tackle ads before they can direct people into private messages, where scammers can continue the conversation outside public scrutiny.
- Treat repeat offenders, cloned campaigns, and accounts linked to known fraud infrastructure as a network problem, which is much more effective than moderating them one ad at a time.
- Give users meaningful controls over ad personalization, tracking, and the volume of ads they see.
Meta has policies against scams in place, continues to remove ads that violate those policies, and has announced additional anti-scam measures. Those are necessary steps. The question is whether they are sufficient for an environment where criminals are motivated, well-funded, and able to adapt rapidly.
No ad-review system will catch everything. Criminals will continue to use deception, compromised advertising accounts, and fast-changing infrastructure to get around automated checks.
That is why layered protection matters here as well.
Users should be able to choose tools that reduce tracking, block intrusive advertising, and stop access to known malicious sites. They should also be able to use browser protections, security software, and healthy skepticism when an ad promises easy money, a surprise refund, a miracle product, or a deal that seems too good to be true.
If ad blockers and the platforms that rely on advertising can find ways to work together, allowing security tools to intercept the malicious content their moderation systems miss, we can make the internet safer for everyone.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →