The ad looks like it belongs. It has the same rounded corners, the same "Sponsored" tag, the same autoplay video as the shoe ad and the meal-kit ad above it in your feed. A familiar face is talking about an investment platform that turned a small stake into a fortune. Somewhere below it, a blue link promises to show you how. Nothing about the format tips you off, because the format is not the problem. The advertising system underneath it is being used exactly as designed: targeting, retargeting, autoplay video, a landing page tailored to whoever clicked.
It was simply bought by someone selling a lie instead of shoes.
Fraud investigators who track this money describe the same pattern across thousands of complaints: a paid social ad, often featuring a celebrity or news brand the victim already trusts, leading to a slick landing page, a small "test" deposit, and a platform that shows fabricated gains right up until the victim tries to withdraw. The tools that make the ad convincing (audience targeting, lookalike audiences, retargeting, automated ad review) are the same tools that place a shoe ad in front of someone who just searched for sneakers. Understanding how those tools get turned against investors is the fastest way to stop trusting the wrong ad.
This piece walks through how the ad actually reaches you, why platforms approve ads they should catch, why a paid celebrity endorsement is not proof of anything, and what regulators have actually done about it, with named cases, real dollar figures, and the specific steps that separate a real investment opportunity from a funded one.
What the Money Trail Actually Shows
Two federal reporting systems track this, and they measure different things, so their numbers should not be added together. The FBI's Internet Crime Complaint Center (IC3) collects criminal complaints; the Federal Trade Commission's Consumer Sentinel Network collects consumer fraud reports. Both point the same direction.
IC3's 2025 Internet Crime Report recorded $20.877 billion in total reported losses across more than one million complaints, a 26 percent increase over 2024. Investment fraud was the single largest category by dollar loss at $8.6 billion, more than the next several categories combined, including business email compromise (roughly $3.05 billion) and tech-support scams (roughly $2.1 billion). Of that $8.6 billion, $7.2 billion was tied specifically to cryptocurrency investment schemes. IC3 also introduced a new category for 2025: "AI-related" complaints, covering scams that used generative AI in the deception itself, which drew more than 22,000 complaints and $893 million in losses. Adults 60 and older reported $7.7 billion in losses, up 59 percent year over year, with investment fraud alone accounting for $3.52 billion of that.
The FTC's own alert, published April 16, 2026, put 2025 investment-scam losses reported to its Consumer Sentinel Network at $7.9 billion, with a median individual loss over $10,000. The agency's own framing is blunt: "If anyone plays down the risk of an investment or acts like risk disclosures are just a formality you don't need to worry about, keep your money."
A separate FTC Data Spotlight, published April 27, 2026, isolated where these scams begin. Reported losses to scams that started on social media hit $2.1 billion in 2025, eight times the 2020 figure, and investment scams were the single biggest category within that total, at $1.1 billion, more than half of all social-media-originated scam losses. Facebook generated more reported dollar losses than any other single platform, more than text messages and email combined; WhatsApp and Instagram ranked second and third. More than 40 percent of social-media scam victims said the scam began after they ordered something in response to an ad they saw.
How a Scam Ad Gets in Front of You
A paid social ad has to clear an approval process before it runs, and every major platform advertises that it screens for fraud. The reason fraudulent investment ads still circulate at scale is not that this review does not exist. It is that a fraud operation is built specifically to pass it.
Ad Cloaking: One Page for the Reviewer, Another for You
The technique security researchers call "cloaking" is the core workaround. An advertiser submits a landing page that looks entirely legitimate: a generic newsletter signup, an informational article, nothing that trips an automated fraud filter. The platform's review system, whether automated or human, sees that page and approves the ad. Once it is live, the same URL is rigged to detect who is actually clicking, using IP address, device type, browser fingerprint, and referral source as signals. A reviewer's request, a bot crawl, or traffic from the platform's own security team gets the clean page. An ordinary user clicking from their feed gets redirected to the real destination: the fake trading platform, the deepfake video, the crypto "doubling" scheme. According to Varonis, a cybersecurity research firm that has documented commercial cloaking tools sold specifically to help fraud operators evade Google's automated ad screening, this is a mature, purpose-built evasion industry, not an improvised trick. Meta has separately acknowledged the general problem publicly, describing "bad actors" who "disguise the true destination of an ad or post, or the real content of the destination page, in order to bypass our review systems."
The FTC Put Eight Platforms on Notice
Regulators have gone directly at the platforms over this. On March 16, 2023, the Federal Trade Commission voted 4-0 to issue formal orders to eight major platforms (Meta and Instagram, YouTube, TikTok, Twitter/X, Snap, Pinterest, and Twitch), demanding detailed information on how each one screens paid advertising, what automated and human review it uses, and how it handles scam ads once they are reported. The agency's own framing at the time connected the order to a documented jump in reported social-media fraud losses. It is a rare instance of a federal regulator formally investigating the ad-screening machinery itself, rather than only the individual advertisers running fraudulent campaigns through it.
Platform accountability has also been tested outside a regulator's own docket. In April 2026, the nonprofit Consumer Federation of America sued Meta in D.C. Superior Court, a private lawsuit rather than a government enforcement action. According to CBS News' coverage of the complaint, internal Meta documents cited in the filing projected the company would earn roughly 10 percent of its 2024 revenue, close to $16 billion, from ads for scams and banned goods, and estimated that Meta's platforms expose users to about 15 billion "higher risk" scam ads every day.
CFA director Ben Winters said Meta "has consistently chosen to prioritize profit over the safety of their users."
Meta's on-record response pointed to its own enforcement numbers: more than 159 million scam ads removed in the prior year, 92 percent of them before anyone reported them, and 10.9 million accounts taken down for ties to criminal scam centers.
The FTC's own consumer guidance, updated August 10, 2026, states it plainly: "Social media platforms don't always thoroughly vet the ads you see or the advertisers behind them." An ad appearing in your feed, from an account with a blue checkmark or a familiar logo, is not evidence that anyone verified what is behind it.
Borrowed Fame: Deepfake and Paid Celebrity Endorsements
A familiar face lowers a viewer's guard faster than any other single element in a scam ad, and fraud operations have two ways to get one: pay a real celebrity to promote a scheme without disclosing the payment, or fabricate the celebrity's endorsement outright using AI video and audio.
Elon Musk Is the Face Scammers Reach for Most
According to AARP's reporting on the pattern, the FTC logged 247 complaints referencing Elon Musk between February and October in a recent year, tied to reported individual losses as high as $220,000 and $700,000 in specific cases. One named victim, 77-year-old Joseph Ramsubhag of Texas, lost more than $300,000 in retirement savings to a platform called "HXEYY" that used a fabricated Musk endorsement. A related platform, marketed as "Quantum AI," ran deepfake videos claiming Musk had personally invested "$54 billion" in it, alongside a fabricated Jim Carrey "testimonial." These ran as video ads across Instagram, YouTube, TikTok, Facebook, and X, in addition to being pushed through direct messages and spam email.
When the SEC Went After the Celebrities, Not Just the Scheme
Where a real celebrity accepts payment to promote a crypto asset, federal securities law has a specific, enforceable requirement: the celebrity has to disclose that they were paid, and how much. The Securities and Exchange Commission has enforced this directly against the celebrities themselves, not only against the platforms that hired them.
Kim Kardashian was charged in October 2022 for touting the EthereumMax (EMAX) token to her Instagram followers without disclosing a $250,000 payment for a single post; she settled for $1.26 million in disgorgement, interest, and penalties. Former NBA forward Paul Pierce was charged in February 2023 for promoting the same token on Twitter after being paid more than $244,000 in EMAX tokens, and for tweeting a screenshot implying large personal holdings and profits that were not actually his; he settled for $1.409 million. In March 2023, the SEC charged Justin Sun and his Tron and BitTorrent Foundations with securities fraud, wash trading, and orchestrating undisclosed payments to eight celebrities, including Lindsay Lohan, Jake Paul, Soulja Boy, Austin Mahone, Lil Yachty, Ne-Yo, and Akon, to tout TRX and BTT tokens that raised roughly $31 million in unregistered sales; six of the eight celebrities settled for over $400,000 combined. SEC Enforcement Director Gurbir Grewal put the underlying rule in plain terms after the Kardashian settlement: "Investors are entitled to know whether the publicity of a security is unbiased."
Disclosure requirements exist because a paid endorsement and a genuine opinion are not the same evidence. A real celebrity being paid to promote a token they were never told to research is a materially different situation from a total stranger's deepfake video, but neither one tells you the investment itself is sound.
Cloned News Sites and Borrowed Mastheads
The other trust shortcut scam ads exploit is the appearance of independent journalism. A cloned site copies a real outlet's logo, layout, and byline conventions, then publishes a fake "article" (often disguised further as a native ad or "advertorial") reporting that a celebrity endorsed the product in the ad.
The clearest legal precedent for this exact tactic is not, on its own facts, an investment case, and it is worth being precise about that. In a 2017 action, the FTC and a group of internet marketers settled charges over a network of fake news and magazine sites, with domains like goodhousekeepingtoday.com and womenshealthi.com, that mimicked real outlets and carried fabricated celebrity endorsements from Paula Deen, Dr. Oz, Jennifer Aniston, Jason Statham, and Joe Manganiello to sell dietary supplements and skin-care products. The judgment totaled $179 million, suspended to roughly $6.4 million based on the defendants' ability to pay. No comparably specific federal case naming a fake-news-site clone used for an investment or crypto scam turned up in reporting on this topic, but the FTC has already prosecuted this exact production technique, and there is no reason to expect an investment version of it looks any different on screen. A cloned "news" page reporting that a celebrity endorsed a trading platform deserves exactly the skepticism the Tarr case shows it has earned before.
The United Kingdom's Financial Conduct Authority documents a close cousin of this tactic aimed specifically at investors: the "clone firm" scam, where fraudsters build a fake website using the real name, address, and registration number of an actual FCA-authorized investment firm. In the period the FCA studied, Action Fraud recorded more than £78 million stolen this way, at an average loss of £45,242 per victim; the regulator's enforcement director at the time, Mark Steward, noted that fraudsters use "literature and websites that mirror those of legitimate firms," while urging investors to independently verify the firm's registration number rather than trust the number listed on the site itself. That figure is dated and UK-specific, but the underlying mechanic, borrowing a real, checkable identity rather than inventing one, is the same one at work in a cloned news masthead.
When the Funnel Leads to a Real, Named Business
Not every scam ad points to an anonymous offshore platform. Some point to a real, operating US company, run by named people, that the FTC has since sued.
Response Marketing Group operated under several brand names, including Affluence Edu, Cash Flow Edu, and Flip for Life, running infomercials and social media ads for "free" real estate investing events. Those events funneled attendees into $1,000 three-day workshops built on false claims about exclusive funding access and pre-lined-up buyers, which telemarketers then upsold into "Inner Circle" coaching packages costing as much as $30,000. The pitch leaned on two celebrity endorsers: Scott Yancey of A&E's Flipping Vegas and author Dean Graziosi. The FTC and the state of Utah won a combined $16.7 million judgment in May 2023: $15 million against the company and its principals, $1.25 million against Graziosi, and $450,000 against Yancey. Utah's Department of Commerce called it the largest consumer protection settlement in the state's history.
A more recent case follows the same shape with an AI-era pitch. In March 2025, the FTC sued Click Profit, LLC, along with its co-founders and business partners, over an "online business opportunity" recruited through social media and search advertising that promised "guaranteed passive income using cutting-edge AI technology" and exclusive brand partnerships. Ads showed a co-founder displaying cash to imply outsized earnings, backed by exaggerated customer testimonials. Consumers paid more than $45,000 in "management fees" on top of inventory costs; over a fifth of the resulting stores earned nothing at all, Amazon suspended roughly 95 percent of them, and the FTC put total consumer losses at $14 million or more. FTC Bureau of Consumer Protection Director Christopher Mufarridge summarized the deception directly: "Click Profit misled consumers by falsely promising them guaranteed passive income using cutting-edge AI technology and exclusive brand partnerships."
Both cases share a structure with the long-running con known as pig butchering: a credible-looking entry point, a real name attached to add trust, and a paid upsell path that only reveals its true cost after the victim is already invested, financially and emotionally, in believing it works.
Retargeting, Lookalike Audiences, and Why the Second Ad Feels More Convincing
Two ordinary ad-platform tools deserve specific attention because they are what makes a second or third scam ad feel more credible than the first one. Retargeting shows an ad again to someone who already visited a site or clicked a link, on the theory that a warm prospect converts better than a cold one. A "lookalike audience" takes a list of existing customers and asks the platform to find new users who statistically resemble them, based on the same behavioral and demographic signals advertisers use for any legitimate campaign. Neither tool was built for fraud. Both work exactly as well for a fraud operation as they do for a shoe brand, because the platform has no way to tell, from the targeting request alone, which one it is serving.
The FTC's own August 10, 2026 alert makes the connection explicit, warning that scam ads use "personalized targeting based on your browsing history," in the agency's own words for exactly this mechanism. Practically, that means once you have clicked one crypto or trading ad, visited a related site, or even searched for investment terms, the advertising ecosystem treats you as a warmer, more valuable target for the next one, scam or legitimate. That is also why a second look at your own browser tracking cookies and ad-privacy settings is worth doing after you notice a pattern of investment ads showing up unprompted, since it shows you concretely what signal you gave the system, and lets you turn it off.
How to Verify an Investment Ad Before You Trust It
None of the verification steps below require special tools or technical skill. They require treating an ad's appearance as irrelevant to whether the thing behind it is real.
- Search the company name plus "scam," "complaint," or "SEC action" before clicking through, using a second tab rather than the ad's own link.
- Check whether the celebrity or public figure has confirmed the endorsement on their own verified account or official channel: not in a comment reply, not in the ad's video, on their own page.
- Look up any named firm or advisor directly on the regulator's own site, such as the SEC's Investment Adviser Public Disclosure database, FINRA BrokerCheck, or the FCA register, by typing the URL yourself rather than clicking a "verify us here" link inside the ad or landing page.
- Treat "as seen on" news logos with real suspicion and check whether the outlet's own site, searched directly, carries the same story.
- Never trust a document, screenshot, or "proof of funds" that arrived through the same channel as the ad. The same shortcut culture that makes ad platforms easy to abuse has made forged bank statements and payment confirmations trivial to produce and hard to eyeball.
- Assume any guarantee of returns is disqualifying on its own. No legitimate securities offering guarantees a return; regulated investment advertising is required to carry risk disclosures for exactly this reason.
A simple habit catches most of this before it starts: if an investment opportunity arrived to you through an ad rather than through your own search for one, verify it through a source that is not the ad, the landing page it links to, or any phone number or "support chat" it provides.
If You've Already Clicked, Paid, or Shared Information
Acting quickly limits damage even after money has moved. Contact your bank or the platform you paid through immediately and ask specifically about reversing or freezing the transaction; wire transfers and crypto payments are the hardest to recover, but banks can sometimes intercept a pending transfer. Report the scam at ReportFraud.ftc.gov and file a complaint with the FBI's IC3 at ic3.gov. Both feed the data regulators use to build cases like the ones above, and IC3 complaints specifically support law enforcement's asset-recovery efforts. If you shared login credentials, financial account numbers, or your phone carrier PIN with a fake support line, change every reused password and consider whether you are also now exposed to a SIM-swap attempt against your phone number, since that same information is often reused to intercept the one-time codes that protect your other accounts. Expect a follow-up contact from someone offering to "recover" your funds for a fee; that second call is reliably part of the same fraud, not a rescue from it.
It is also worth documenting what you saw: the account name that ran the ad, the platform it appeared on, and the date. Regulators investigating a platform's ad-screening practices, including the FTC's ongoing inquiry into the eight major platforms it put on notice in 2023, rely on exactly this kind of specific complaint record.
The Bottom Line
A fraudulent investment ad is not a crude forgery slipping past an inattentive reviewer. It is a professionally built advertising campaign, using the same targeting, retargeting, and creative tools any legitimate brand uses, deliberately engineered to pass automated review and to look, for the seconds it takes to scroll past, indistinguishable from something real. Elon Musk did not endorse a crypto platform that promises to double your money. Kim Kardashian and Paul Pierce were paid, and disclosed nothing, and the SEC made them pay for it. A "news" site with a familiar logo can be built in an afternoon.
None of that means every social media ad is fraudulent.
It means the ad itself, however polished, is never the evidence. Verify the claim somewhere the advertiser does not control, and treat a guaranteed return as the clearest signal available that the ad is not what it looks like.