A familiar face, a seemingly exclusive investment tip—and just a few clicks later, the money ends up in the hands of scammers. What has long been treated as one of the unavoidable risks of social media could increasingly become a problem for platform operators themselves.

In a dispute between the financial platform Finanzfluss and Meta, the parent company of Facebook, the Frankfurt Regional Court ruled that Meta must make a monetary payment and prevent the further dissemination of the disputed illegal content on its platforms. If the company fails to comply with the court’s orders, it could face fines of up to 250,000 euros. The lawsuit was triggered by fake accounts and deepfakes that used the name “Finanzfluss” or the face of founder Thomas Kehl to provide purported investment tips.

The relatively small monetary payment is not the key issue here. What is far more important is the question of what responsibility large platforms bear for illegal content disseminated through their systems. For Facebook, Instagram, and other large platforms, this very issue could take on even greater significance in the future.

Attracting Customers with Someone Else's Face

Since 2024, accounts have reportedly been popping up repeatedly on Facebook and Instagram that used the name of the well-known financial platform Finanzfluss or the face of its founder, Thomas Kehl.

The principle is as simple as it is dangerous: People see a familiar face and trust that person. They’re told there are special investment tips or exclusive opportunities to invest money. Those who are interested are then lured into private chat groups, for example. But waiting there aren’t Thomas Kehl or Finanzfluss—instead, there are suspected scammers with dubious offers.

This harm affects two parties at once. Consumers can lose money. At the same time, the reputation of the individuals and companies whose names, images, or artificially generated videos are used for the scam suffers.

Finanzfluss founder Thomas Kehl is equally clear in his assessment of the regional court’s decision: “It is an important step toward protecting people from widespread financial fraud, which is affecting more and more people. I hope we have set the ball rolling to steer case law in the right direction.”

 Meta makes money from advertising—and that's exactly what makes this such a hot-button issue

At the heart of this dispute lies a fundamental question: How much responsibility does a company bear when its platform not only hosts third-party content but also uses technical systems to sort, distribute, and, in some cases, display it as paid advertising?

This is particularly relevant for Meta because advertising accounts for by far the largest share of its business. Finanzfluss had accused the company of not doing enough to combat fraudulent profiles and ads.

For those affected, this raises a simple question: Can a platform claim that it is merely providing the technical platform when its own systems determine which ads users see?

Deleting alone may no longer be enough in the future

The Frankfurt case is not an isolated incident. Other affected parties have already taken legal action against Meta over falsified or misused content.

The case of Eckart von Hirschhausen, a doctor and TV host, is particularly well-known. His name and likeness were used in advertisements for questionable diet products. In 2025, the Frankfurt Higher Regional Court ruled that Meta cannot simply delete the reported ad after being notified of such content. The company must also search for additional posts that disseminate the same or very similar illegal content and remove those as well.

This is particularly relevant in light of modern AI. Today, images, voices, and videos can be quickly altered and reposted. If a platform were to simply remove only the exact post that was reported, scammers could resume their activities shortly thereafter with a slightly altered version.

Between Fraud Prevention and Excessive Oversight

This, however, is precisely where the difficult part of the debate begins. The more platforms are required to actively search for similar illegal content on their own, the more important the question becomes of how reliably they can distinguish between illegal and legal posts.

Automated systems are not error-free. If the guidelines for removal are defined too broadly, there is therefore a risk that legitimate posts will also be flagged. Platforms might also be tempted, when in doubt, to remove too much rather than too little in order to avoid potential consequences. This brings the discussion to the question of how users’ freedom of expression can be protected.

The solution, therefore, cannot be to require Facebook and Instagram to proactively review every single post. At the same time, it seems unconvincing to remove known scam patterns only when affected users report them again.

Striking a balance between effective protection against fraud and preserving legitimate content is therefore likely to become one of the most challenging issues in dealing with large online platforms.

The Digital Services Act is changing the rules of the game

An important foundation for this is the European Digital Services Act, or DSA for short. The rules have been fully in effect since 2024 and are intended, among other things, to ensure that large online platforms cannot simply ignore systemic risks.

This also includes the dissemination of illegal content. At the same time, this does not mean that platforms are required to monitor all of their users' posts across the board.

Oliver Marsh of Algorithmwatch describes the challenge this poses as follows: “The DSA leaves a lot of room for interpretation. Platforms are not required to monitor all content, but they must assess systematic risks and take action against them, provided they have the appropriate systems in place.”

This does not mean there is a blanket obligation to monitor all content as a precautionary measure. Rather, courts must determine on a case-by-case basis what measures can be required of platforms when certain risks or specific illegal content are already known.

For Meta, it's about more than just a cash payment

The monetary penalty that Meta must pay as a result of the Frankfurt ruling is unlikely to have any significant financial impact on a corporation of this size. More crucial is the obligation to take action against the further dissemination of the illegal content in question. Violations of the court’s requirements could result in fines of up to 250,000 euros.

Meta rejects the decision and is considering further steps. The company points out that it has already taken significant measures to combat fraud and is continuing to expand its AI-based safeguards.

It therefore remains to be seen whether and in what form the court's decision will stand.

legaldata: Responsibility, yes—but not at any cost

The real significance of this case lies not in a single fraudulent Facebook ad. Rather, it raises the question of what responsibility a company bears when it earns billions from advertising and uses its algorithms to determine which ads millions of people see.

Platforms can automatically review ads, identify target audiences, and deliver content to a very large number of people in a very short amount of time. This inevitably raises the question of why these same technical capabilities cannot be utilized even more consistently when a specific fraud pattern is already known.

No one can expect Meta to anticipate every attempt at fraud. But when the same faces, names, and promises are used time and again in fraudulent ads, the long-term solution cannot consist solely of “report and delete.”

However, we must not lose sight of the other side of the issue. A platform that, out of fear of consequences, proactively removes anything that even appears suspicious would not be a convincing solution either. Protection against fraud must not result in legitimate content being unnecessarily removed.

That is precisely where the real challenge lies: platforms must effectively combat known patterns of fraud without resorting to the precautionary removal of legal content. The Frankfurt ruling is therefore, above all, one thing: yet another signal that large platforms cannot simply shirk their responsibility for what is disseminated through their systems.

Subscribe to the newsletter

and always up to date on data protection.