7 min read

Social Media Platforms and Fraud: Why the EU Is Rethinking Liability

Social Media Platforms and Fraud: Why the EU Is Rethinking Liability
Social Media Fraud: Why the EU Is Making Platforms Liable
7:20

Social media is now one of the biggest starting points for financial scams, from fake investment ads to impersonation and money mule recruitment. Until recently, the cost of that fraud landed almost entirely on banks. That is changing. Under the EU's PSD3 and PSR reforms, online platforms can be held liable to reimburse banks when they are told about fraudulent content and fail to remove it. For fraud teams, the shift formalises a principle they already work by: fraud responsibility does not begin at the point of payment.

Key takeaways

  • Social media is the leading origin point for reported scams. In the US, the FTC found one in four people who lost money to fraud since 2021 said it started on social media; in the UK, the PSR linked Meta's platforms to 54% of reported scam cases in 2023.
  • The EU's PSD3 and PSR reforms add conditional liability for online platforms: if a platform is told about fraudulent content and fails to remove it, it can be liable to reimburse the bank that refunded the victim.
  • Negotiators reached a provisional agreement in November 2025; the Council published final compromise texts in April 2026, with formal adoption and a staged implementation period to follow.
  • The wider signal for fraud teams: regulators expect risk to be recognised earlier and across organisational boundaries, not explained after the money has moved.
  • Banks that classify account risk and act before payment are better placed on both counts -regulatory exposure and actual loss prevention.

Social media has woven itself so tightly into everyday life that it’s easy to forget how much power it now holds. It’s where people maintain relationships, discover opportunities, seek advice, and increasingly, make decisions that carry real financial consequences. Unsurprisingly, this means social media is also a major starting point for online scams.

For fraud teams, this creates a familiar tension. Many scams originate on social platforms, but the financial loss often crystallises when a payment is executed through a bank or PSP. Until now, responsibility has largely fallen on financial institutions.

This is why the EU’s recent provisional agreement on PSD3 and PSR introduces conditional liability for online platforms in specific fraud scenarios, particularly where reported scam content is not acted upon. Read on to unpack what the legislative changes involve, and what they could mean in practice for fraud managers overseeing APP risk, mule activity, and regulatory exposure.

 

 

What PSD3 and PSR Reforms Could Change for Online Platforms

 

At a high level, the proposed EU rules introduce something genuinely new into the fraud equation: conditional liability for social media platforms. Where platforms fail to act on scam content that has been reported and allowed to persist, they may be liable to compensate financial institutions for resulting losses. The change comes as part of a payment services deal to bring into force the Third Payment Services Directive (PSD3) and the Payment Services Regulation (PSR).

The agreement was reached on 27 November 2025. The Council published the final compromise texts in April 2026, with publication in the EU's Official Journal and formal adoption following. Most analysis expects the rules to apply within roughly two to three years of adoption, so for now this is a window to prepare rather than a live obligation. 

Dimension Under PSD2 (current) Under PSD3 / PSR (agreed)
Authorised (APP) / impersonation scams No EU-wide reimbursement duty PSPs must reimburse victims of PSP-impersonation ("spoofing") scams, where the customer reports it to police and notifies the bank
Online platform responsibility None specific to payment fraud Platforms liable to reimburse the bank when notified of fraudulent content they then fail to remove
Advertising financial services No EU-wide authorisation requirement Major platforms and search engines may only advertise financial services from authorised firms
Where responsibility sits At the point of payment Extended upstream, across the fraud journey

 

These broader changes in EU payment regulation emphasize greater consumer protection, transparency, and reimbursement obligations. Banks are expected to intervene earlier, absorb more liability, and prevent harm rather than simply resolve disputes after the fact. 

The interesting news here is that platforms like TikTok, Instagram, Facebook, LinkedIn, and X are now being pulled into that same accountability loop. For fraud managers, the significance is how regulators are formalising the idea that fraud responsibility doesn’t begin at the point of payment.

This has practical implications. Disputes may no longer focus solely on whether a transaction was authorised, but on whether reported scam activity was allowed to persist on social media and whether reasonable steps were taken across the ecosystem to disrupt it.

Industry representatives argue that the law sets a “dangerous precedent” by shifting responsibility away from those best positioned to prevent fraud. Platforms owned by Meta, X, etc, that host vast volumes of user-generated content feel that banks should be taking responsibility for fraud. 

But these platforms are not neutral or powerless bystanders. They design recommendation systems, monetise reach, and control takedown processes. Accountability is expanding and questioning whether the wider fraud journey showed signals that should have triggered earlier action.

 

How the EU Is Expanding Fraud Responsibility Beyond Banks

It would be short-sighted to view this legislation as a niche intervention aimed solely at the social media platforms owned by Big Tech. What it really reflects is a broader shift in how early companies are expected to act when combating fraud.

Regulators are no longer satisfied with post-event explanations about where fraud technically occurred. The question increasingly being asked is whether warning signs existed earlier, and whether those signals were ignored, fragmented, or simply invisible across organisational boundaries.

In practice, this shift reflects a growing expectation that organisations can demonstrate:

  • Earlier awareness of risk, not just post-transaction detection

  • Clear reasoning for intervention, rather than opaque automated decisions

  • Proportionate responses, avoiding unnecessary friction for legitimate users

  • Cross-channel visibility, where fraud signals rarely stay confined to one system

Social platforms are being pulled into scope precisely because they sit upstream in many fraud journeys. For banks and payment service providers, this should feel familiar. Similar logic already underpins APP reimbursement rules and emerging payment regulation: if an institution could reasonably have detected risk before funds moved, liability follows.

What we’re seeing here is that fraud prevention is a shared, cross-ecosystem responsibility. This is where the conversation shifts to pre-fraud signal intelligence. Whether it’s a social media company receiving a report about a marketplace scam, or a bank monitoring accounts to predict future fraud, the common requirement is the ability to recognise risk before harm occurs.

 

Social Media as a Source of Online Scams

The move to impose liability on social media platforms didn’t come out of nowhere. It reflects a simple reality that scams are no longer confined to a peripheral misuse of social platforms… they’re everywhere. Data from the FTC in the USA found that one in four people who reported losing money to fraud said that the scam started on social media. 

Channel Share of reported scam cases (UK, 2023) Share of scam losses
Meta platforms (Facebook, Instagram, WhatsApp) 54% (119,338 cases) 18% (£62.7m)
Telecoms (calls and texts) 12% (26,975 cases) 31.5% (£107.2m)
Email 2% 10% (£35m)



For fraudsters, social media offers a uniquely efficient environment. It combines reach, targeting, and trust in a way no other channel can. Messages arrive in familiar interfaces, from accounts that appear genuine and contextual. Also, ads appear that seem algorithmically relevant. The result is a steady stream of fraud that feels personal rather than criminal.

 Common types of social media fraud 

In practice, the most visible scams on social platforms tend to come in a handful of different forms.

  • Impersonation: Fake profiles/pages posing as banks, customer support, employers, or trusted public figures.

  • Investment and crypto scams: Sponsored posts, direct messages, or group invitations promising insider access or time-limited opportunities.

  • Mule recruitment: “Side-hustle” or payment-task offers that persuade users to move funds on someone else’s behalf.

  • Marketplace and online-shopping scams: ads for goods that never arrive, often impersonating real retailers. These are the single largest category of social-media fraud reports.
  • Romance scams: long-grooming approaches that begin with a friend request or DM and end in a transfer, frequently starting on Meta platforms.

It is the scams like these that have been previously reported yet allowed to persist on social media platforms that the EU’s new regulatory changes aim to address. 

 

Detecting Fraud Before the Payment Happens

Those who act pre-emptively by identifying patterns, correlating signals, and classifying risk early are better positioned to intervene proportionately and defensibly. Those who wait for confirmation, completion, or loss will increasingly find themselves on the wrong side of both regulators and business outcomes.

As fraud responsibility spreads across platforms and providers, opaque, last-minute decision-making becomes harder to defend. Visibility, context, and clear classification are becoming just as important as stopping the fraud itself.

Online payment scams develop across interactions, accounts, and behaviours, often long before a payment is initiated. Rather than focusing solely on transaction-level alerts, institutions need account-level intelligence. Acoru’s account monitoring solution helps your business ingest relevant fraud data, unify signals across disparate channels, and take action before money moves and someone gets scammed. 

Where this leaves banks and fraud teams

Platform liability does not take pressure off banks; it adds a second party to the same problem. The institutions in the best position under the new regime are the ones that can see risk building before a payment is authorised, show why they acted, and keep friction off legitimate customers. That is an account-level intelligence problem more than a transaction-level one, and it is where fraud prevention is heading regardless of how the liability debate settles.

Get your Acoru demo here.

 

Frequently asked questions (FAQs)

 

Are social media platforms liable for scams that start on their sites?

Increasingly, yes, in specific circumstances. Under the EU's agreed PSD3 and PSR reforms, an online platform can be liable to reimburse a bank that refunded a scam victim if the platform was told about the fraudulent content and failed to remove it. It is conditional liability tied to notice and inaction, not blanket responsibility for everything posted.

What do the PSD3 and PSR reforms change for online platforms?

They pull platforms into the payment-fraud accountability chain for the first time. Alongside the reimbursement liability above, major platforms and search engines will only be allowed to advertise financial services from firms that are authorised in the relevant member state, which targets the fake-investment ads that drive a large share of losses.

When will the new rules take effect?

A provisional agreement was reached in November 2025 and the Council published final compromise texts in April 2026. After formal adoption and publication, a staged implementation period applies, so most analysis points to the rules taking effect within roughly two to three years rather than immediately.

Which scams most often start on social media?

Marketplace and online-shopping scams generate the most reports, while investment and crypto scams and romance scams tend to cause the largest losses. Impersonation and money mule recruitment are also common, which is why platform-origin fraud matters to both fraud and AML teams.

How can banks detect social-media-originated fraud before the money moves?

The scam usually plays out on the platform long before a payment is authorised, so transaction-level alerts fire too late. Account-level intelligence - scoring and classifying accounts on their behaviour and counterparty patterns - gives banks the chance to spot and act on risk before the transfer, which is also what the new rules expect them to be able to show.

3 Best Practices for Detecting APP Fraud in Banking

1 min read

3 Best Practices for Detecting APP Fraud in Banking

Authorized push payment (APP) fraud is a type of scam in which criminals manipulate victims over days or even weeks before convincing them to...

Read More
Fraud Detection in Banking: Everything You Need to Know

1 min read

Fraud Detection in Banking: Everything You Need to Know

Banks analyze payments in real time, apply rules to identify suspicious activity, and intervene when a transaction appears fraudulent. But what if ...

Read More
APP fraud reimbursement: why scam refunds don't stop the fraud

1 min read

APP fraud reimbursement: why scam refunds don't stop the fraud

The UK's authorised push payment (APP) reimbursement requirement took effect on October 7th, 2024, and there is now enough data to move past the...

Read More