The Facebook ad promises an online dating service. The final WhatsApp chat looks reassuring because the number belongs to a real, searchable local business.
There is one problem: that business never created the ad, offers nothing related to dating, and has no idea why strangers keep arriving in its inbox.

Overview
Targets and reviewers see different pages
The case examined here involved dating ads running under unrelated Facebook Page names. Clicking the promotion sent selected users through a tracking route with a hashed path.
The domain’s homepage looked harmless. The suspicious material appeared only through the exact route used by the ad and under the right visitor conditions.
That difference is the important clue. Cloaking is designed to show risky content to the intended audience while presenting something cleaner to reviewers, bots, or other visitors.
The funnel borrows a genuine WhatsApp number
The final page displayed the public WhatsApp number of an unrelated Singapore business. Users messaged that account expecting a dating service.
Nothing in the documented case showed that the WhatsApp account had been hacked. The number remained under the business’s control and was already visible on its website and Google Business Profile.
Copying a public number is enough. The operator gains a real, old, searchable contact without needing technical access to the account itself.
The innocent business becomes the complaint desk
People arriving from the ad see a legitimate business profile and assume it belongs to the advertiser. The company receives confused, angry, or explicit messages about a service it never offered.
Meanwhile, the Page, creative, redirect, and landing route can be replaced. The real number stays online, absorbs reports, and draws attention away from the party running the campaign.
Warning signs include:
- Dating ads running under unrelated Page identities.
- A harmless domain homepage but a suspicious hashed path.
- Different content shown to reviewers and targeted users.
- A final WhatsApp account in an unrelated industry.
- No evidence that the visible business approved the promotion.
- Users arriving with expectations the business cannot explain.
- Disposable Pages and routes surrounding a permanent public number.
- A mismatch between the ad, landing page, and final provider.

How the Cloaked Facebook Dating Ads Scam Works
Step 1: Disposable Pages carry the ads
The campaign uses generic or unrelated Facebook Page identities. A Page may contain copied posts or enough ordinary activity to look established during a quick check.
When one Page is disabled, another can replace it. The underlying creative and redirect system may continue with only small changes.
Step 2: Targeting narrows who can see the real promotion
Delivery can be limited by country, age, language, device, interests, schedule, or other audience signals. Someone outside that group may never reproduce the experience.
Selective exposure reduces casual discovery and makes reports look inconsistent. The business owner, platform reviewer, and victim may each see a different page.
Step 3: A clean homepage hides the risky route
The root domain can display an ordinary template, blank page, or harmless business content. A scanner that checks only the homepage finds little.
The ad opens a unique path. That route can inspect referral information, cookies, location, browser, and device before deciding what content to return.
Step 4: Suspected reviewers are diverted
A crawler or reviewer receives the clean version. A target arriving from the ad receives a dating pitch, form, redirect, or chat button.
The operator can rotate the risky destination without changing the visible ad link, keeping the funnel useful after one page is reported.
Step 5: A real business number adds borrowed trust
The landing page inserts a publicly listed WhatsApp number from an unrelated company. A business profile with a name, address, and history looks safer than a fresh anonymous account.
The number may be copied from a website, directory, or Google listing. Its owner does not need to know the dating funnel exists.
Step 6: Users contact the wrong party
People ask the business about dating membership, profiles, charges, or someone pictured in the ad. Some may send personal details before noticing the mismatch.
The innocent company cannot provide support or refunds. Staff must manage privacy, harassment, reports, and reputational damage created by someone else’s campaign.
Step 7: The campaign rotates, but the damage remains
The Page, ad, hash, and destination can vanish after complaints. Cached links and copied creatives may continue sending traffic to the public number.
Because users report the visible WhatsApp account, the actual advertiser and cloaking infrastructure can receive less scrutiny.
What Cloaking Looks Like in Practice
Not every redirect is malicious. Advertising and analytics systems commonly use redirects for measurement, localization, attribution, and testing.
Hashed paths are also normal in many web applications. The concern appears when the exact ad path serves content unrelated to the homepage and changes based on who is looking.
Useful evidence includes the full ad URL, Page ID, creative ID, timestamp, country, device, redirect chain, screenshots, and final chat link.
A screenshot of the root domain is not enough. Investigators need the precise path and the conditions under which the advertisement was delivered.
Do not repeatedly test the funnel on a business computer containing valuable sessions. A redirect can collect identifiers, deliver files, or lead to credential theft.
For an ordinary user, the practical test is simple. If the final contact belongs to a company that denies the promotion, stop. Do not assume the visible account controls the ad.
How the Innocent Business Can Respond
Collect several complete examples before they disappear. Ask affected users for the original ad screenshot, Page name, complete link, date, time, country, and what they saw before WhatsApp opened.
Search Meta’s Ad Library for the advertiser and related creatives. Record the library IDs and Page transparency information.
Report the specific ad, Page, redirect, and false association. Explaining that a public number was copied is more accurate than claiming the WhatsApp account was taken over without evidence.
Publish a brief warning on the verified business website and profile. State clearly that the company does not offer the advertised dating service.
Use an automatic WhatsApp reply that warns visitors not to send personal data and asks them to report the ad. Do not request intimate screenshots.
Report the exact redirect path to the registrar, host, content-delivery provider, and security vendors. A domain-only report may miss the cloaked route.
Monitor search results regularly for the company number alongside dating terms. That can reveal other active Pages, advertisements, and domains copying the same contact.
Do not abandon a long-held number immediately unless the abuse becomes unmanageable. The operator may simply scrape the replacement once it becomes public.
How Users Should Check the Final Contact
Read the WhatsApp business profile carefully. If the industry, location, company name, and website do not match the ad, do not continue.
Open the company’s website independently and look for a warning. Do not use another link supplied by the dating page.
Send no photographs, identification, payment details, login codes, or intimate material while trying to understand the mismatch.
Save and report the ad before closing it. The advertiser Page and library record may be easier to identify than the temporary landing page later.
Leaving Facebook for WhatsApp is not automatically fraudulent. The unexplained change in business identity is the stronger warning.
If another number contacts you after the innocent business denies involvement, treat that new account as part of the unverified funnel, not as customer support.
The Risks Continue After the Misrouted Chat
The dating page may collect age, location, phone number, email, photos, preferences, or card details before WhatsApp opens.
A membership or verification step can start recurring billing. The charge may use a descriptor unrelated to the service shown in the ad.
The real business number may be only a credibility checkpoint. A second account can later continue the scam and request payment or personal material.
Links sent during the conversation can lead to fake login pages, malware, adult-subscription traps, cryptocurrency requests, or fabricated identity checks.
Anyone who shares intimate images can face sextortion from another account. The framed business may never see or control that exchange.
The business faces staff time, harassment, bad reviews, and the risk that its legitimate WhatsApp channel is reported or restricted.
Employees may be tempted to click the ad repeatedly to understand it. That exposes business devices and logged-in accounts to the same untrusted redirects affecting customers.
Separate the advertiser from the copied contact when filing complaints. False reports against the innocent number add another layer of harm.
The lack of an immediate payment request does not make the funnel harmless. Audience validation, contact collection, and identifying people willing to continue may be valuable first-stage goals.
How to Preserve Evidence Without Spreading the Harm
Capture the ad before opening it. Save the Page name, transparency details, creative, caption, call-to-action, visible destination, date, and time.
A screen recording can show the redirect from Facebook to the intermediate path and final form or chat. Do not enter real data to reveal more pages.
Take separate captures of the clean homepage and targeted destination. The contrast explains why the platform and victim may report conflicting results.
Record the copied business number privately, but redact it from public posts. Repeating the number beside dating terms can worsen search results and harassment.
Preserve any reply from the legitimate company confirming that it did not authorize the campaign. That helps platforms distinguish impersonation from a customer dispute.
Recheck only when necessary. Cloaking rules can change by device, account, location, time, and referral data, so the original path may stop reproducing.
Send each provider the evidence relevant to what it controls. Meta can review the ad, while the host and registrar can investigate the redirect infrastructure.
Company, Address, and Fulfillment Checks
The advertiser Pages were unrelated
The documented dating ads appeared under Page names unrelated to the legitimate business. No verified commercial relationship was shown.
Record the Page ID and transparency details rather than relying on the visible name.
The clean homepage did not explain the ad path
The root domain did not establish what selected users received through the hashed route.
Verification must follow the exact ad URL and redirects, not just the homepage.
The real business address did not validate the ad
A public phone number, website, and Google Business Profile can all be copied. The business’s existence makes the contact credible but does not validate the dating offer.
No evidence showed that the company purchased or approved the promotion.
No dating service was fulfilled by the business
The company received confused inquiries but did not provide the service users expected.
Do not pay, subscribe, or share data when the final provider denies any connection to the ad.
What to Do if You Have Fallen Victim to This Scam
- Close the funnel. Stop following redirects and do not move to another number or app.
- Save the ad evidence. Capture the Page, library entry, full URL, hashed path, time, and final contact.
- Verify the visible business. Use its independently found website before blaming or reporting the WhatsApp account.
- Report the specific ad. Include the cloaked destination and false association in the Meta report.
- Report the actual scam account. Use WhatsApp’s tools for any number that sent deceptive messages.
- Cancel subscriptions. Contact the card issuer about recurring charges and replace the card if necessary.
- Change exposed passwords. Use unique credentials and revoke sessions after entering a login.
- Run a full Malwarebytes scan. Do this if the site downloaded a file, extension, or application.
- Use AdGuard after cleanup. It can reduce malicious ads and redirects but cannot undo submitted data.
- Document sensitive exposure. Note which photos, IDs, cards, or account details were provided.
- Report financial loss. Contact the payment provider first, then the FTC or relevant local authority.
- Ignore recovery accounts. An upfront-fee tracing offer may come from another scammer.
Frequently Asked Questions
Was the real business WhatsApp account hacked?
The evidence did not show that. The public number appears to have been copied into an external funnel.
What is ad cloaking?
It is the deliberate delivery of different content to intended targets and reviewers in order to hide the real destination.
Are all tracking redirects suspicious?
No. Legitimate ads use tracking. Concern rises when the path hides content that the homepage and reviewers do not see.
Why use an innocent business number?
A real searchable account supplies credibility and absorbs complaints while the advertiser rotates disposable Pages and domains.
Should the business remove its public number?
Not automatically. Preserve evidence, warn customers, report the campaign, and assess the harm before abandoning a legitimate channel.
Can the business make Meta remove the ads?
It can report the ads and false association with evidence, but removal timing is not guaranteed. Document every Page and route.
The Bottom Line
The clever part of this campaign is not taking over a WhatsApp account. It is borrowing a real business’s public number and using cloaking to hide how visitors reached it.
When the final contact does not match the ad, stop. Preserve the full route, report the advertiser and redirects, and avoid punishing the innocent business used as camouflage.