Platforms

Meta's anti-scam campaign reached 303 million people. The numbers show why education alone won't stop the $114bn problem.

Written by Lucy Hall and reviewed, fact-checked and signed off by a SocialDay editor before publication. Read our editorial standards and corrections policy. Spotted something wrong? Tell the newsroom.

The scale problem

Since May 2026, Meta's One Step Ahead campaign has reached more than 303 million people across 18 countries, delivering over 1.3 billion impressions and more than 1.2 million link clicks, making it one of the platform's largest safety education efforts in Asia-Pacific. The campaign was designed alongside more than 25 local safety organizations, law enforcement and government agencies, including Australia's Scamwatch, Singapore's Anti-Deception Coordination Centre, and India's National Cyber Crime Reporting Portal.

The numbers look strong. But against the backdrop of scam losses of up to $114.1 billion across East Asia, Southeast Asia, Australia and New Zealand in 2025, at least tripling from 2023, raw reach is not enough. The question for social media marketers is whether a campaign this large can actually drive the behaviour change needed to disrupt industrialised fraud networks.

303M people reached by Meta's One Step Ahead campaign Meta newsroom, September 2026

The partnership model behind the campaign

What makes One Step Ahead different from typical platform safety announcements is the co-design structure. Meta built the campaign around three principles: safety advice should be practical, easy to act on, and come from a source people trust. That last principle explains the heavy reliance on government and law enforcement partners. When a scam prevention message carries the branding of a national police force or consumer protection agency, it borrows trust the platform can't manufacture alone.

In Singapore, the campaign reached 1.6 million people, with Meta working alongside the Singapore Police Force and the National Crime Prevention Council. The campaign encourages users to activate security features, including two-factor authentication and passkeys on Facebook and Instagram, and promotes the ScamShield website as a centralised resource for scam types and protection.

The model is being replicated. Clara Koh, director of public policy for Southeast Asia, said scammers are now operating at an industrial scale and using artificial intelligence to mass-produce fake profiles. That industrial threat requires an industrial response, which is why Meta's treating this as infrastructure rather than a one-off awareness push. The campaign will continue throughout 2026, with new tools and locally tailored resources rolling out across the region.

Scammers count on the fact that no single organization sees the full picture. What we have built with the Singapore Police Force changes that.

Daryl Poon, Meta's director of law enforcement outreach for Asia-Pacific

The enforcement layer education sits on top of

Education campaigns don't exist in a vacuum. Meta removed or restricted 3.64 million shell pages linked to potential scam infrastructure in 2026, acting in July before they could be used. Shell pages are empty, harmless-looking Pages with no ads and no violating content, but which scammers had built as ready-made infrastructure to activate for a campaign at a moment's notice, sometimes with a history so a scam campaign does not have to wait for new accounts to age.

That enforcement is the reason the education messaging can credibly ask users to take protective steps. If the platform is pulling down millions of scam-ready assets before they go live, the ask to turn on two-factor authentication looks less like offloading responsibility and more like a coordinated defence.

Meta has removed 65 million scam ads from Facebook and Instagram so far in 2026, with 94% of those ads removed before anyone reported them. The 94% figure matters. It shows detection at scale, which changes the economics for scammers. If most infrastructure is being removed pre-activation, the cost per successful scam rises.

In June, Meta and the Singapore Police Force ran a targeted operation ahead of school holidays, focusing on misleading prices, fake promotions for well-known brands, exaggerated product claims and tactics designed to create urgency or scarcity, resulting in action against more than 33,600 entities. Timed enforcement ahead of seasonal fraud spikes shows the partnership is operational, not symbolic.

What actually changes behaviour

The One Step Ahead campaign pushes specific, actionable security steps, primarily two-factor authentication and passkeys. Bayesian time series analysis revealed that mandatory 2FA significantly reduced the number of compromised bank accounts, whereas optional 2FA did not, according to a 2026 study on Canadian banks. That gap between mandatory and optional adoption is the difference between a campaign that informs and one that protects.

MFA is highly effective, blocking 99.9% of modern automated cyberattacks and preventing 96% of bulk phishing attempts. But effectiveness only matters if adoption happens. Most users only adopt 2FA because they are forced to do so (37-44% depending on the 2FA solution), while 35-53% use it voluntarily. That leaves education campaigns fighting friction and apathy at the same time.

The Sauce previously covered how Meta's Muse agent sits between your audience and your brand, shifting the control layer in social marketing. Education campaigns face a similar challenge. They're asking users to add friction to their login flow to prevent a problem most people haven't personally experienced yet.

99.9% of automated attacks blocked by multi-factor authentication Microsoft Digital Defense Report 2025

The fragmentation problem in anti-scam education

Campaigns are fragmented across government agencies and industries, often one-shot appeals that communicate different approaches and advise actions which are outdated and largely ineffective. Their impact is usually not evaluated scientifically, and therefore, their impact remains unknown.

One Step Ahead is attempting to solve that fragmentation by unifying messaging across 18 countries and standardising the core advice. But research emphasizes the importance of interactivity (gamification), contact with the user, focus on a specific type of scam, and continuous education as the features that actually work. Mass awareness campaigns, even well-designed ones, struggle to deliver all four.

A meta-analysis of social engineering interventions found that awareness campaigns, while sometimes helpful, are generally less effective than more interactive and targeted approaches. The tension for Meta is that interactive, personalised education doesn't scale the way 1.3 billion impressions do.

Where this fits in the wider scam infrastructure fight

Meta's anti-scam work in Asia-Pacific isn't just about the education campaign. Based on information shared by law enforcement partners, Meta disabled over 150,000 accounts involved in or supporting scam center networks in March 2026, and the Royal Thai Police Anti-Cyber Scam Center arrested 21 individuals. In May and June 2026, the US Department of Justice's Scam Center Strike Force brought together Meta, Microsoft, Coinbase, Starlink and law enforcement partners across six countries, resulting in more than a million online assets disrupted and 63 arrests by the Royal Thai Police.

The education layer matters most when it sits on top of coordinated enforcement and intelligence sharing. Effective intelligence sharing depends on identifying the signals that can help partners act earlier, which may include scam domains, phone numbers, account indicators, behavioural patterns, typologies, infrastructure signals or information about how criminal activity is moving between platforms, telecoms and financial services.

The Australian government responded to record scam losses in 2022 with a national anti-scam strategy, allocating AUD $58 million in the 2023-24 budget, with the National Anti-Scam Centre launched in July 2023 within the Australian Competition and Consumer Commission, centralising prevention, public education, data sharing, and enforcement. That model, a unified national hub coordinating cross-sector response, is what Meta's regional partnerships are trying to replicate at platform scale.

Our breakdown of how Snapchat hands campaign bidding to advertiser measurement partners showed how platforms are opening up infrastructure to trusted third parties. Meta's scam partnerships follow a similar pattern: share intelligence, coordinate enforcement, and let the local authority carry the trust.

What social media marketers should take from this

If you're running campaigns in Asia-Pacific, assume your audience is seeing scam content that looks like your brand. When scammers successfully imitate the brands of merchants, the trust that consumers have in those brands begins to decline, with victims of a scam less inclined to click on links, which could include legitimate marketing outreach from merchants to which they were once loyal, leading to fewer purchases and less revenue for oft-imitated merchants.

The One Step Ahead campaign's 1.2 million link clicks represent people actively seeking scam protection resources. That's your audience learning to be more cautious, which means legitimate brands need to work harder to signal trust. Verified badges, consistent visual identity, and transparent landing pages are no longer just brand hygiene. They're friction reducers in an environment where caution is rising.

If your brand operates in retail, finance, or e-commerce in the region, check whether you're listed as a partner or resource in the local version of the campaign. If you're not, consider whether that's a missed opportunity to associate your brand with the trusted source layer Meta's building. Public sector campaigns like South Yorkshire Fire & Rescue's Fire Safety Dance show how government partnerships can amplify reach and borrow trust. The same logic applies to corporate participation in anti-scam infrastructure.

The measurement gap

Meta reports reach, impressions, and link clicks, but not behaviour change. We don't know how many of those 303 million people turned on two-factor authentication, how many stayed protected after initial setup, or how many avoided a scam because of the campaign. That's standard for awareness campaigns, but it leaves the question of effectiveness unanswered.

A Global Anti-Scam Alliance 2025 survey shows that 79% of Southeast Asian adults were exposed to scams in the past year. If exposure remains at that level after a 1.3 billion impression campaign, the problem isn't reach. It's conversion from awareness to action.

The campaign's real test will be whether enforcement data shows a drop in successful account compromises in the markets where the campaign ran hardest. Meta hasn't published that yet. Until it does, One Step Ahead is a promising structure built on solid principles, but with impact that's still being proven.

What's transferable

The co-design model is the most portable element. If you're building a campaign that asks your audience to change behaviour in response to a trust or safety threat, bring the trusted local authority into the creative process early. Don't just co-brand the final asset. Let them shape the message, the tone, and the call to action. That's what Meta did with 25 partners across 18 countries, and it's why the campaign feels less like a platform pushing self-interest and more like a coordinated public safety effort.

The emphasis on actionable, simple steps matters too. "Turn on two-factor authentication" is a single, clear ask. It's not "be more vigilant" or "stay safe online." The specificity makes it easier to act on and easier to measure. If your campaign struggles to define one concrete behaviour change, you're probably asking for too much at once.

Finally, the enforcement-education pairing is critical. Education without enforcement looks like responsibility offloading. Enforcement without education looks authoritarian. Together, they create a credible case that the platform is doing its part and asking users to do theirs. That balance is what makes the campaign defensible, and it's what social media marketers should replicate when asking audiences to take protective action in high-risk environments.