
Meta
is liable for
fake profiles.
Meta
is liable for
fake profiles.
of
Is a platform liable for fake profiles that unknown individuals use to promote fraudulent investment schemes under someone else’s identity and trademark? And is it enough to simply delete reported content at some point?
Reports of fraud using someone else’s photo
A company operates a well-known website featuring comparison tools and guides for financial products. Its founder and CEO is the public face of the site, appearing in videos and a podcast. Unknown individuals posted profiles, posts, and advertisements on Instagram and Facebook using the company’s commercial designation as well as the founder’s name and photos. Among these was an AI-generated deepfake video purporting to offer investment tips. Anyone who followed the links ended up in private Messenger groups where allegedly fraudulent investments were promoted.
The company submitted reference images via Meta’s reporting tool and reported approximately 256 violations between July 29, 2024, and August 28, 2024, alone. A formal cease and desist letter from a lawyer followed on October 1, 2024. Meta deleted the content, though in some cases only after several weeks, while new counterfeits continued to appear. In court, Meta defended itself by arguing that it was merely a neutral hosting service for third-party content. The company therefore took legal action against Meta.
Frankfurt Regional Court Rules Against Meta
In its judgment of September 16, 2026—Case No. 2-06 O 234/25— the Frankfurt am Main Regional Court largely granted the plaintiffs’ claim. Meta must refrain from disseminating the disputed fake content and variants that are substantially identical to it. Meta must provide the plaintiffs with information regarding the reach and revenue generated. In addition, Meta is liable for damages in principle and owes the founder monetary compensation.
Why doesn’t the liability exemption apply?
This question touches on a core issue of IT law. Under the EU’s Digital Services Act (DSA), hosting services are generally liable for third-party content only after they become aware of it. If they act promptly at that point, they remain free from liability. This privilege requires that they play a neutral, purely technical role. The ECJ has interpreted the predecessor provision in the E-Commerce Directive (Webgroup and Coyote ECJ judgment of June 16, 2026—Case Nos. C-188/24 and C-190/24). According to this interpretation, an operator exercises control if its algorithm determines, in its own interest, under what conditions and in what order content is disseminated.
The Frankfurt Regional Court applies this case law to the DSA. Meta determines, through an automated auction, which ads appear to which users and in what order. Meta also uses algorithms to direct regular posts into other users’ feeds. Both practices serve its own economic interests, namely advertising revenue and increased engagement. Knowledge of the specific content is therefore no longer relevant. The situation is likely different for purely chronological feeds, such as those used by Mastodon or Bluesky.
Ultimately, it is therefore up to the service provider to decide, in its own interest, whether to use algorithms to determine the conditions under which content is displayed, thereby assuming control over the content and, consequently, responsibility for the content it displays.
Meta is therefore not merely liable as a so-called “interferer”—that is, as an indirect participant obligated only to cease and desist. Meta is liable as a principal and is therefore also liable for damages.
What happens if the defense does apply?
Even with the privilege, Meta is liable because the platform did not act promptly. Reference images, documented reports, and a cease and desist letter described the infringements in such detail that Meta could have detected them automatically. A removal period of 14 or 20 days is no longer considered prompt in the case of such clear violations. Furthermore, the platform must explain when it became aware of the infringement and what actions it took in response.
Based on the Munich Higher Regional Court’s ruling of January 20, 2026—Case No. 18 U 2360/25— the court extends this obligation to future fake profiles that are essentially identical. Accordingly, the ban covers, for example, profile names to which numbers or special characters have been added. It is not necessary to report each individual profile again.
What does this mean for platforms?
Until now, the focus has been on liability upon becoming aware of an issue, as we reported, for example, regarding Google’s liability as a “disturber” under the DSA. The Frankfurt ruling takes a earlier approach, focusing on the business model. We have already described a similar approach in connection with the elimination of YouTube’s liability privilege.
Here’s how to deal with fake profiles
- Document violations thoroughly. Save screenshots that include the date, profile name, and links. Make a note of when the post was reported and deleted.
- Use the platform’s reporting channels. Upload reference images and report each case using the designated tools. The acknowledgments will later serve as proof that the platform was aware of the issue.
- Describe patterns of infringement precisely. Identify your own accounts and clarify whether you place ads yourself. Describe which combination of names, images, and commercial designations indicates a fake account.
- Secure rights to visual material. Agree in writing with employees and photographers on exclusive rights of use. In the Frankfurt case, the copyright claims failed precisely because of this.
- Consider taking legal action in a timely manner. If the platform is slow to respond, a cease and desist letter, a preliminary injunction, or a lawsuit may be necessary.
Conclusion
For companies and public figures whose faces or trademarks are misused in scam ads, the ruling opens up new possibilities. It shifts the responsibility—rightly so—to those who control the ad placements and profit from them.
It remains to be seen whether this line of reasoning will hold. The ECJ had to rule on French regulations concerning, among other things, a navigation service—not a social network. If taken to its logical conclusion, nearly every major platform with an algorithmic feed would lose its liability exemption. This conflicts with the principle that platforms are not generally obligated to monitor content. Ultimately, however, this would be welcome, as otherwise those affected would continue to fight a losing battle.
We’d be happy to
advise you on
IT law!







