Fake Ads Put Meta’s Role in Paid Advertising Under Growing Legal Scrutiny in Poland

25 August 2026

The continuing appearance of fraudulent advertisements featuring InPost founder and CEO Rafał Brzoska is intensifying a wider debate in Poland over the responsibility of technology platforms for paid content distributed through their advertising systems. The dispute returned to public attention in August after another sponsored Facebook advertisement misused Brzoska’s identity, presenting fabricated material suggesting that he had been detained by police. The incident came roughly two years after Brzoska first began challenging Meta over fraudulent advertisements appearing on Facebook and Instagram.

The latest case is not isolated. Polish fact-checkers have identified further fraudulent campaigns involving Brzoska during 2026, including manipulated material directing users towards bogus investment services. Examination of Meta’s advertising library has also indicated that some accounts associated with such campaigns have been responsible for numerous advertisements, demonstrating how scammers can repeatedly alter and redistribute fraudulent content.

Brzoska responded to the latest advertisements by publicly criticising Meta and identifying individuals responsible for parts of its Polish operations. His Instagram account was subsequently temporarily restricted, adding another dimension to an already contentious relationship. Meta has rejected suggestions that users are penalised simply for criticising the company and has argued that directing public criticism towards individual employees can create security concerns. The two issues are nevertheless separate: the disagreement over Brzoska’s comments does not resolve the question of why fraudulent paid advertising using his identity continues to return.

The conflict dates back to 2024, when manipulated advertisements began using the identities of Brzoska and his wife, Omenaa Mensah, to promote investment scams and other fabricated stories. Some campaigns incorporated deepfake techniques to make the endorsements appear authentic.

Brzoska notified Meta of the problem in July 2024 before turning to Poland’s Personal Data Protection Office, UODO. On 5 August 2024, the regulator ordered Meta Platforms Ireland to stop displaying fraudulent advertisements in Poland that used Brzoska’s personal information. The restriction was imposed for three months, the maximum duration available under the emergency GDPR procedure used by the authority.

UODO considered the problem to extend beyond potential damage to Brzoska’s reputation. The regulator also identified a risk to Facebook and Instagram users who might believe the fraudulent investment promotions and consequently suffer financial losses.

Meta challenged UODO’s measures and sought to have their enforcement suspended. The Warsaw Voivodeship Administrative Court declined to do so in December 2024. The administrative dispute subsequently ended without a final judgment on Meta’s challenge after the company withdrew its complaints in March 2025 and the proceedings were discontinued. The withdrawal therefore cannot be treated as a judicial finding that Meta was ultimately liable, although UODO’s emergency intervention remained unoverturned.

A separate civil case has potentially greater significance because it examines Meta’s involvement in the advertising process itself. One of the central legal questions is whether the company should principally be regarded as providing infrastructure through which third parties publish material, or whether its participation in paid advertising is sufficiently active to create greater responsibility for what is distributed.

Proceedings before the Warsaw Court of Appeal have challenged the assumption that paid advertisements should necessarily be treated in the same way as material uploaded independently by ordinary platform users. The court’s preliminary reasoning examined the functions performed by Meta’s advertising operation, including accepting advertisements through its commercial system, reviewing them before publication, receiving payment and using targeting and optimisation technology to determine how they are distributed.

The legal significance needs to be treated cautiously. The proceedings concern interim protection and do not represent a final judgment establishing that Meta is responsible for every fraudulent advertisement appearing on Facebook or Instagram. They do, however, indicate that the protections available to online intermediaries may not automatically settle the issue when disputed material is paid advertising distributed through a system in which the platform plays a more extensive commercial and technical role.

That distinction could have consequences beyond the Brzoska case. There is a fundamental difference between providing space where somebody publishes a social-media post and operating a paid advertising marketplace. In the latter case, the platform establishes advertising rules, receives payment, provides targeting tools and operates the technology determining which audiences see the material. The legal question is whether those additional functions also create additional responsibilities when criminals exploit the system.

Meta maintains that fraudulent advertising damages users, legitimate advertisers and its own business and says it continues to invest heavily in detection technology and other safeguards. The company has also pointed to the rapidly changing techniques used by criminals attempting to circumvent its controls. Fraudsters can change accounts, websites, payment arrangements and advertising material quickly, while increasingly accessible artificial intelligence tools make convincing impersonation considerably easier to produce.

That provides important context for assessing Meta’s position. The continued appearance of fraudulent advertisements does not by itself establish that the company has failed to meet its legal obligations. Perfect prevention across an advertising operation of Meta’s scale would be extremely difficult.

The recurrence of scams involving the same prominent individual after complaints, regulatory intervention, litigation and extensive publicity nevertheless raises a different question: whether removing individual advertisements after they have been detected is sufficient when variations of the same fraud repeatedly return.

The Brzoska case is particularly revealing because of the resources available to the person targeted. As a prominent businessman, he can obtain specialist legal representation, approach regulators and attract national media attention. Most people whose identities are misused in fraudulent advertising would have considerably fewer resources available to pursue either the platform or the advertisers responsible.

This imbalance is one reason the dispute has developed into something broader than a confrontation between one entrepreneur and one technology company. The outcome could help establish how much protection individuals can expect when their identities are repeatedly exploited through commercial advertising systems.

The issue also extends beyond protection of the person being impersonated. Fake celebrity endorsements are generally intended to exploit the credibility of recognisable individuals to persuade users to provide personal information, transfer money or invest through fraudulent services. UODO specifically identified this wider consumer risk when it intervened in 2024.

The regulatory environment surrounding large platforms has also changed since the dispute began. The EU’s Digital Services Act places additional obligations on very large online platforms concerning systemic risks, advertising transparency and procedures for addressing illegal content. The legislation does not make platforms automatically responsible for every unlawful advertisement, but it increases scrutiny of how the largest digital businesses identify and mitigate risks created by their services.

The Brzoska litigation consequently sits at the intersection of personal-data protection, personality rights, consumer fraud, intermediary liability and the commercial operation of digital advertising platforms.

There are legitimate arguments on both sides. Meta operates advertising infrastructure on an enormous scale and faces criminals who continually modify their methods to evade detection. Expecting every fraudulent advertisement to be identified before publication may not be technically realistic. At the same time, paid advertising differs from entirely independent user activity because the platform receives revenue from advertisements and provides the technology through which advertisers select and reach audiences.

The Polish proceedings have not yet produced a definitive answer. What has changed is the assumption that describing a technology company as an intermediary necessarily ends the discussion. The courts’ examination of Meta’s role in reviewing, targeting and distributing paid advertising indicates that the way the advertising business actually operates can matter when responsibility is assessed.

Meanwhile, the practical problem remains. Approximately two years after Polish regulators first intervened, fraudulent material involving Brzoska continues to appear.

The eventual importance of the dispute may therefore extend considerably beyond the individual advertisements. As online advertising becomes increasingly automated and artificial intelligence makes impersonation easier and cheaper, European courts and regulators will increasingly have to determine where the responsibility of the criminal advertiser ends and that of the platform operating and monetising the distribution system begins.

The Brzoska case has not settled that boundary, but it is becoming an important test of where that boundary should be drawn.

Source: WEI

front page info
LATEST NEWS