Meta Missed Hundreds of CSAM 'Nudify' Ads

Wired Security · Medium sophistication
Last updated September 8, 2026

Researchers found hundreds of paid ads running across Meta platforms that promoted “nudification”/face‑swap apps and included abusive sexual content involving minors, including some using real children’s photos pulled from the web. The ads used manipulative marketing text (for example, claiming there are “no restriction” on what can be done with a child’s image) and drove clicks to app-store downloads. The report highlights how deceptive ad copy and seemingly innocent images can be used to funnel users to harmful tools.

Key findings

  • Researchers reported “more than 250 additional ads containing CSAM” running since the start of August, despite prior removals.
  • Ads followed a repeatable lure pattern: an “innocuous picture” plus text implying unlimited manipulation, then a click-through to download AI face-swap/video apps from official app stores.
  • Some abusive ads used images of identifiable real children sourced from the web (including public influencer photos and stock-photo sites), not only AI-generated images.
  • The ads ran across multiple Meta surfaces (Facebook, Instagram, Messenger, Threads, and Meta’s ad network) and were shown to tens of thousands of accounts across several countries.

Who’s being targeted

  • Commonly targeted roles: All employees, Marketing, Communications, IT (endpoint/app control), Trust & Safety / Content Moderation, HR (employee safety reporting channels).
  • Affected industries: Social media platforms, Online advertising, Consumer internet / app marketplaces.
  • Attack channels: website.
  • Impersonated: An AI face-swapping / video app advertiser.

Awareness takeaways

  • Treat “curiosity hook” ads as risky, don’t click or install apps promoted via sensational teaser text.
  • Assume official-looking platforms and app stores can still be used as distribution channels for harmful or policy-violating content; use allowlists and approved-software processes at work.
  • If you see abusive or clearly policy-violating ads, report them quickly through both the platform’s tools and internal escalation channels; delays can increase harm.

Red flags to watch for

  • Manipulative/sexualized teaser language designed to drive curiosity clicks
  • Claims implying there are “no restriction” on using someone’s image
  • Ad redirects to download an app based on shock/curiosity rather than a legitimate business need
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re scrolling Instagram and see a normal photo of a teen with the text: “not just a photo… there are no restriction.” Researchers found hundreds of these paid Meta ads. They use innocent pictures of preteen or teenage girls, then push you to download AI face-swap or video apps from Apple or Google’s app stores. Here’s the twist: some of these ads used real kids’ photos pulled from the web and bragged, “This is the AI that men actually use.” If an ad’s only hook is shock or sexualized curiosity, that’s your red flag. At work, if you see a “not just a photo” style ad pushing an AI app, don’t click it, screenshot it and report it through the platform and our internal security channel.

Similar attacks

Fake SSO + MFA Push Used in Real Breaches

Fake SSO + MFA Push Used in Real Breaches

This weekly roundup includes two real social-engineering-driven incidents. Attackers used social engineering to access Apollo Global Management’s cloud platforms and steal sensitive personal data, and separately attempted a ShinyHunters phishing attack against ReliaQuest using a fake SSO login page…

August 28, 2026
Scareware Google Ads Keep Running After Reports

Scareware Google Ads Keep Running After Reports

University researchers found large numbers of deceptive “software” ads (including scareware) running through Google’s ad system, generating over 100 million impressions in Europe. They reported some ads via Google’s “Report this ad” flow, but several ads were acknowledged as policy violations and…

September 2, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026
One-Click Google SSO Takeover via Device-Code Bug

One-Click Google SSO Takeover via Device-Code Bug

A researcher found two bugs in Google’s “device code” sign-in flow that could let an attacker get a valid Google sign-in token for a victim by getting them to open a single crafted link. In the most dangerous version, the victim sees no consent screen and no extra 2FA prompt, yet the attacker can…

July 17, 2026