{"id":407939,"date":"2026-09-01T13:12:02","date_gmt":"2026-09-01T13:12:02","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=407939"},"modified":"2026-09-02T04:09:12","modified_gmt":"2026-09-02T04:09:12","slug":"cloaked-facebook-dating-ads-innocent-business","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/cloaked-facebook-dating-ads-innocent-business\/","title":{"rendered":"Cloaked Facebook Dating Ads Frame an Innocent Business"},"content":{"rendered":"<p>The Facebook ad promises an online dating service. The final WhatsApp chat looks reassuring because the number belongs to a real, searchable local business.<\/p><div id=\"mwtad689115207\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>There is one problem: that business never created the ad, offers nothing related to dating, and has no idea why strangers keep arriving in its inbox.<\/p>\n<figure><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Realistic reconstruction of a cloaked dating ad redirecting users to an unrelated local business messaging number\" title=\"\" class=\"lazyload\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/cloaked-ads-opening.webp\"><\/figure>\n<div id=\"mwtad3046299866\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>Targets and reviewers see different pages<\/h3>\n<p>The case examined here involved dating ads running under unrelated Facebook Page names. Clicking the promotion sent selected users through a tracking route with a hashed path.<\/p><div id=\"mwtad2236081426\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The domain&#8217;s homepage looked harmless. The suspicious material appeared only through the exact route used by the ad and under the right visitor conditions.<\/p>\n<p>That difference is the important clue. Cloaking is designed to show risky content to the intended audience while presenting something cleaner to reviewers, bots, or other visitors.<\/p>\n<h3>The funnel borrows a genuine WhatsApp number<\/h3>\n<p>The final page displayed the public WhatsApp number of an unrelated Singapore business. Users messaged that account expecting a dating service.<\/p><div id=\"mwtad1056855413\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Nothing in the documented case showed that the WhatsApp account had been hacked. The number remained under the business&#8217;s control and was already visible on its website and Google Business Profile.<\/p>\n<p>Copying a public number is enough. The operator gains a real, old, searchable contact without needing technical access to the account itself.<\/p>\n<h3>The innocent business becomes the complaint desk<\/h3>\n<p>People arriving from the ad see a legitimate business profile and assume it belongs to the advertiser. The company receives confused, angry, or explicit messages about a service it never offered.<\/p><div id=\"mwtad3691222482\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Meanwhile, the Page, creative, redirect, and landing route can be replaced. The real number stays online, absorbs reports, and draws attention away from the party running the campaign.<\/p>\n<p>Warning signs include:<\/p>\n<ul>\n<li>Dating ads running under unrelated Page identities.<\/li>\n<li>A harmless domain homepage but a suspicious hashed path.<\/li>\n<li>Different content shown to reviewers and targeted users.<\/li>\n<li>A final WhatsApp account in an unrelated industry.<\/li>\n<li>No evidence that the visible business approved the promotion.<\/li>\n<li>Users arriving with expectations the business cannot explain.<\/li>\n<li>Disposable Pages and routes surrounding a permanent public number.<\/li>\n<li>A mismatch between the ad, landing page, and final provider.<\/li>\n<\/ul>\n<figure><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Realistic reconstruction of an ad reviewer seeing a clean page while a targeted phone sees a dating funnel leading to a redacted business chat number\" title=\"\" class=\"lazyload\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/09\/cloaked-ads-reconstruction.webp\"><\/figure>\n<div id=\"mwtad270382146\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Cloaked Facebook Dating Ads Scam Works<\/h2>\n<h3>Step 1: Disposable Pages carry the ads<\/h3>\n<div id=\"mwtad856832844\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The campaign uses generic or unrelated Facebook Page identities. A Page may contain copied posts or enough ordinary activity to look established during a quick check.<\/p>\n<p>When one Page is disabled, another can replace it. The underlying creative and redirect system may continue with only small changes.<\/p>\n<h3>Step 2: Targeting narrows who can see the real promotion<\/h3>\n<p>Delivery can be limited by country, age, language, device, interests, schedule, or other audience signals. Someone outside that group may never reproduce the experience.<\/p>\n<div id=\"mwtad2188863471\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>Selective exposure reduces casual discovery and makes reports look inconsistent. The business owner, platform reviewer, and victim may each see a different page.<\/p>\n<h3>Step 3: A clean homepage hides the risky route<\/h3>\n<p>The root domain can display an ordinary template, blank page, or harmless business content. A scanner that checks only the homepage finds little.<\/p>\n<p>The ad opens a unique path. That route can inspect referral information, cookies, location, browser, and device before deciding what content to return.<\/p>\n<h3>Step 4: Suspected reviewers are diverted<\/h3>\n<div id=\"mwtad334695349\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>A crawler or reviewer receives the clean version. A target arriving from the ad receives a dating pitch, form, redirect, or chat button.<\/p>\n<p>The operator can rotate the risky destination without changing the visible ad link, keeping the funnel useful after one page is reported.<\/p>\n<h3>Step 5: A real business number adds borrowed trust<\/h3>\n<p>The landing page inserts a publicly listed WhatsApp number from an unrelated company. A business profile with a name, address, and history looks safer than a fresh anonymous account.<\/p>\n<p>The number may be copied from a website, directory, or Google listing. Its owner does not need to know the dating funnel exists.<\/p>\n<h3>Step 6: Users contact the wrong party<\/h3>\n<p>People ask the business about dating membership, profiles, charges, or someone pictured in the ad. Some may send personal details before noticing the mismatch.<\/p>\n<p>The innocent company cannot provide support or refunds. Staff must manage privacy, harassment, reports, and reputational damage created by someone else&#8217;s campaign.<\/p>\n<h3>Step 7: The campaign rotates, but the damage remains<\/h3>\n<p>The Page, ad, hash, and destination can vanish after complaints. Cached links and copied creatives may continue sending traffic to the public number.<\/p>\n<p>Because users report the visible WhatsApp account, the actual advertiser and cloaking infrastructure can receive less scrutiny.<\/p>\n<div id=\"mwtad1041743479\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What Cloaking Looks Like in Practice<\/h2>\n<p>Not every redirect is malicious. Advertising and analytics systems commonly use redirects for measurement, localization, attribution, and testing.<\/p>\n<p>Hashed paths are also normal in many web applications. The concern appears when the exact ad path serves content unrelated to the homepage and changes based on who is looking.<\/p>\n<p>Useful evidence includes the full ad URL, Page ID, creative ID, timestamp, country, device, redirect chain, screenshots, and final chat link.<\/p>\n<p>A screenshot of the root domain is not enough. Investigators need the precise path and the conditions under which the advertisement was delivered.<\/p>\n<p>Do not repeatedly test the funnel on a business computer containing valuable sessions. A redirect can collect identifiers, deliver files, or lead to credential theft.<\/p>\n<p>For an ordinary user, the practical test is simple. If the final contact belongs to a company that denies the promotion, stop. Do not assume the visible account controls the ad.<\/p>\n<div id=\"mwtad3071428950\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Innocent Business Can Respond<\/h2>\n<p>Collect several complete examples before they disappear. Ask affected users for the original ad screenshot, Page name, complete link, date, time, country, and what they saw before WhatsApp opened.<\/p>\n<p>Search Meta&#8217;s <a href=\"https:\/\/business.facebook.com\/ads\/library\/?active_status=all&amp;ad_type=all&amp;country=ALL&amp;media_type=all\" target=\"_blank\" rel=\"noopener\">Ad Library<\/a> for the advertiser and related creatives. Record the library IDs and Page transparency information.<\/p>\n<p>Report the specific ad, Page, redirect, and false association. Explaining that a public number was copied is more accurate than claiming the WhatsApp account was taken over without evidence.<\/p>\n<p>Publish a brief warning on the verified business website and profile. State clearly that the company does not offer the advertised dating service.<\/p>\n<p>Use an automatic WhatsApp reply that warns visitors not to send personal data and asks them to report the ad. Do not request intimate screenshots.<\/p>\n<p>Report the exact redirect path to the registrar, host, content-delivery provider, and security vendors. A domain-only report may miss the cloaked route.<\/p>\n<p>Monitor search results regularly for the company number alongside dating terms. That can reveal other active Pages, advertisements, and domains copying the same contact.<\/p>\n<p>Do not abandon a long-held number immediately unless the abuse becomes unmanageable. The operator may simply scrape the replacement once it becomes public.<\/p>\n<div id=\"mwtad3188111494\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How Users Should Check the Final Contact<\/h2>\n<p>Read the WhatsApp business profile carefully. If the industry, location, company name, and website do not match the ad, do not continue.<\/p>\n<p>Open the company&#8217;s website independently and look for a warning. Do not use another link supplied by the dating page.<\/p>\n<p>Send no photographs, identification, payment details, login codes, or intimate material while trying to understand the mismatch.<\/p>\n<p>Save and report the ad before closing it. The advertiser Page and library record may be easier to identify than the temporary landing page later.<\/p>\n<p>Leaving Facebook for WhatsApp is not automatically fraudulent. The unexplained change in business identity is the stronger warning.<\/p>\n<p>If another number contacts you after the innocent business denies involvement, treat that new account as part of the unverified funnel, not as customer support.<\/p>\n<div id=\"mwtad3053062443\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Risks Continue After the Misrouted Chat<\/h2>\n<p>The dating page may collect age, location, phone number, email, photos, preferences, or card details before WhatsApp opens.<\/p>\n<p>A membership or verification step can start recurring billing. The charge may use a descriptor unrelated to the service shown in the ad.<\/p>\n<p>The real business number may be only a credibility checkpoint. A second account can later continue the scam and request payment or personal material.<\/p>\n<p>Links sent during the conversation can lead to fake login pages, malware, adult-subscription traps, cryptocurrency requests, or fabricated identity checks.<\/p>\n<p>Anyone who shares intimate images can face sextortion from another account. The framed business may never see or control that exchange.<\/p>\n<p>The business faces staff time, harassment, bad reviews, and the risk that its legitimate WhatsApp channel is reported or restricted.<\/p>\n<p>Employees may be tempted to click the ad repeatedly to understand it. That exposes business devices and logged-in accounts to the same untrusted redirects affecting customers.<\/p>\n<p>Separate the advertiser from the copied contact when filing complaints. False reports against the innocent number add another layer of harm.<\/p>\n<p>The lack of an immediate payment request does not make the funnel harmless. Audience validation, contact collection, and identifying people willing to continue may be valuable first-stage goals.<\/p>\n<div id=\"mwtad734553577\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Preserve Evidence Without Spreading the Harm<\/h2>\n<p>Capture the ad before opening it. Save the Page name, transparency details, creative, caption, call-to-action, visible destination, date, and time.<\/p>\n<p>A screen recording can show the redirect from Facebook to the intermediate path and final form or chat. Do not enter real data to reveal more pages.<\/p>\n<p>Take separate captures of the clean homepage and targeted destination. The contrast explains why the platform and victim may report conflicting results.<\/p>\n<p>Record the copied business number privately, but redact it from public posts. Repeating the number beside dating terms can worsen search results and harassment.<\/p>\n<p>Preserve any reply from the legitimate company confirming that it did not authorize the campaign. That helps platforms distinguish impersonation from a customer dispute.<\/p>\n<p>Recheck only when necessary. Cloaking rules can change by device, account, location, time, and referral data, so the original path may stop reproducing.<\/p>\n<p>Send each provider the evidence relevant to what it controls. Meta can review the ad, while the host and registrar can investigate the redirect infrastructure.<\/p>\n<h2>Company, Address, and Fulfillment Checks<\/h2>\n<h3>The advertiser Pages were unrelated<\/h3>\n<p>The documented dating ads appeared under Page names unrelated to the legitimate business. No verified commercial relationship was shown.<\/p>\n<p>Record the Page ID and transparency details rather than relying on the visible name.<\/p>\n<h3>The clean homepage did not explain the ad path<\/h3>\n<p>The root domain did not establish what selected users received through the hashed route.<\/p>\n<p>Verification must follow the exact ad URL and redirects, not just the homepage.<\/p>\n<h3>The real business address did not validate the ad<\/h3>\n<p>A public phone number, website, and Google Business Profile can all be copied. The business&#8217;s existence makes the contact credible but does not validate the dating offer.<\/p>\n<p>No evidence showed that the company purchased or approved the promotion.<\/p>\n<h3>No dating service was fulfilled by the business<\/h3>\n<p>The company received confused inquiries but did not provide the service users expected.<\/p>\n<p>Do not pay, subscribe, or share data when the final provider denies any connection to the ad.<\/p>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Close the funnel.<\/strong> Stop following redirects and do not move to another number or app.<\/li>\n<li><strong>Save the ad evidence.<\/strong> Capture the Page, library entry, full URL, hashed path, time, and final contact.<\/li>\n<li><strong>Verify the visible business.<\/strong> Use its independently found website before blaming or reporting the WhatsApp account.<\/li>\n<li><strong>Report the specific ad.<\/strong> Include the cloaked destination and false association in the Meta report.<\/li>\n<li><strong>Report the actual scam account.<\/strong> Use WhatsApp&#8217;s tools for any number that sent deceptive messages.<\/li>\n<li><strong>Cancel subscriptions.<\/strong> Contact the card issuer about recurring charges and replace the card if necessary.<\/li>\n<li><strong>Change exposed passwords.<\/strong> Use unique credentials and revoke sessions after entering a login.<\/li>\n<li><strong>Run a full Malwarebytes scan.<\/strong> Do this if the site downloaded a file, extension, or application.<\/li>\n<li><strong>Use AdGuard after cleanup.<\/strong> It can reduce malicious ads and redirects but cannot undo submitted data.<\/li>\n<li><strong>Document sensitive exposure.<\/strong> Note which photos, IDs, cards, or account details were provided.<\/li>\n<li><strong>Report financial loss.<\/strong> Contact the payment provider first, then the FTC or relevant local authority.<\/li>\n<li><strong>Ignore recovery accounts.<\/strong> An upfront-fee tracing offer may come from another scammer.<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Was the real business WhatsApp account hacked?<\/h3>\n<p>The evidence did not show that. The public number appears to have been copied into an external funnel.<\/p>\n<h3>What is ad cloaking?<\/h3>\n<p>It is the deliberate delivery of different content to intended targets and reviewers in order to hide the real destination.<\/p>\n<h3>Are all tracking redirects suspicious?<\/h3>\n<p>No. Legitimate ads use tracking. Concern rises when the path hides content that the homepage and reviewers do not see.<\/p>\n<h3>Why use an innocent business number?<\/h3>\n<p>A real searchable account supplies credibility and absorbs complaints while the advertiser rotates disposable Pages and domains.<\/p>\n<h3>Should the business remove its public number?<\/h3>\n<p>Not automatically. Preserve evidence, warn customers, report the campaign, and assess the harm before abandoning a legitimate channel.<\/p>\n<h3>Can the business make Meta remove the ads?<\/h3>\n<p>It can report the ads and false association with evidence, but removal timing is not guaranteed. Document every Page and route.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The clever part of this campaign is not taking over a WhatsApp account. It is borrowing a real business&#8217;s public number and using cloaking to hide how visitors reached it.<\/p>\n<p>When the final contact does not match the ad, stop. Preserve the full route, report the advertiser and redirects, and avoid punishing the innocent business used as camouflage.<\/p>\n<div id=\"mwtad3320797411\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The Facebook ad promises an online dating service. The final WhatsApp chat looks reassuring because the number belongs to a real, searchable local business. There is one problem: that business never created the ad, offers &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Cloaked Facebook Dating Ads Frame an Innocent Business\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/cloaked-facebook-dating-ads-innocent-business\/#more-407939\" aria-label=\"Read more about Cloaked Facebook Dating Ads Frame an Innocent Business\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":408313,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-407939","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/407939","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=407939"}],"version-history":[{"count":0,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/407939\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/408313"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=407939"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=407939"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=407939"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}