Bank Leumi vs. Meta: The 26 Million NIS Lawsuit Holding Facebook Accountable for Fraud
New lawsuit claims Meta 'collaborates in fraud' – what this means for platform liability and your money
Bank Leumi vs. Meta: The 26 Million NIS Lawsuit Holding Facebook Accountability for Fraud
Bank Leumi isn't just claiming Facebook enables fraud – the 26 million NIS lawsuit uses the word "collaborates." That's a massive legal gap. Between preventing and participating. And if the court agrees, every definition of "who's at fault" in the digital world changes. Including what happens the next time you click on a tempting ad.
The essentials:
- Bank Leumi is suing Meta (Facebook, Instagram) for 26 million NIS, claiming it collaborates in fraud, not just enables it
- The lawsuit argues Meta profits directly from fake ads and doesn't remove them even after being reported
- If the court accepts the claim, Facebook's "we're just a neutral platform" defense collapses
- Meanwhile, customers who fall for scams are stuck between the bank and the platform – both pointing fingers at each other
- A court ruling won't return money already stolen, and will take years. The takeaway: Stop waiting for someone else to protect you
What Actually Happened – The Lawsuit in Three Sentences
Bank Leumi filed a lawsuit against Meta (the parent company of Facebook and Instagram) for 26 million NIS in damages caused to its customers. This isn't a private lawsuit from one customer who got scammed – it's a bank versus a global corporation, with evidence files, documentation of ignored reports, and a potential legal precedent that could change the entire game of digital accountability.
The central legal claim: Meta doesn't delete fake ads slowly out of negligence. It profits from them directly, approves them through its advertising system, and therefore – according to the bank – "participates" in the fraud itself. This isn't "we approved it by mistake"; it's "we received payment for advertising fraud, and continued distributing it even after it was reported."
Bank Leumi's lawsuit against Meta is based on hundreds of documented cases where customers reported suspicious ads, the bank forwarded the reports to Facebook, and the ads remained live for additional days or weeks – all the while generating advertising revenue for Meta while they scammed additional customers.
Why "Collaborates" Is Such a Powerful Word
Until now, Facebook has defined itself as a neutral platform. In the United States, that's Section 230 of the Communications Act; in Israel, similar protections exist in the Privacy Protection Law (חוק הגנת הפרטיות) and the Computers Law (חוק המחשבים). The idea: if you host user content, you're not responsible for everything someone publishes. You're just the venue, not the creator.
"Collaborates" changes the entire equation. If Meta receives advertising payment from a scammer (like any other advertiser), approves the ad through an automated system, and doesn't delete it even after a clear report from a bank or customer – is that really innocence?
Leumi's lawsuit will argue that Facebook's advertising algorithm doesn't just enable fraud, but actively contributes to its success. The algorithm identifies who searched for "iPhone on sale" or "work from home," and pushes exactly that fake ad to that user – at the optimal time, with the most convincing image, in the format that looks most credible.
If the court agrees with this approach, the "we're just a platform" defense collapses. Not just for Meta – for TikTok, YouTube, and all the rest too. This is a precedent that could change Israeli law.
What Actually Happens to You When You Fall for Facebook Fraud
Let's describe the common scenario, as it happens to hundreds of Israelis every week:
- You see a tempting ad: "iPhone 16 Pro at an insane price – only 1,999 NIS! 4 units left!" or "Work from home, 15,000 NIS per week, no experience needed" or "Safe Bitcoin investment, guaranteed 300% return"
- You click on the ad. You land on a perfectly professional-looking site – logo of Clalit, Mizrahi Bank, or Channel 12 (fake, of course). The entire design is perfect. There are happy customer photos, "supposedly" articles, a secure payment button.
- You enter credit card details / transfer money / give a one-time SMS code (this is most common – the scammer on the phone says "you'll receive a code now, tell me it to confirm the order").
- You discover it's a fraud. The payment went through, the product didn't arrive, and the number doesn't answer. You call the bank.
And now – the double response that leaves you in the middle:
The bank says: "You made the transfer yourself. We identified it as suspicious, but didn't block it because it looked like a regular purchase. It's in the terms of service – section 14.3: 'The customer is responsible for safeguarding identification details.' We can't refund."
Facebook says: "The ad has been removed now (after you reported it). We're not a party to the transaction. We didn't transfer the money. Contact the bank."
Both point at each other. You're in the middle with 1,999 NIS that disappeared, or 15,000 NIS transferred to "the investment manager," or credit card details already sold on the darknet.
What This Lawsuit Could Change – and What It Won't
If Bank Leumi wins the lawsuit:
- Legal precedent: Platforms that profit directly from fraudulent content could be considered partners in the damage, not just enablers
- Banks could sue the sources of fraud instead of just "educating customers" and directing them to forms
- Customers will get greater leverage for refunds: "The court ruled the platform is partially responsible – so why isn't the bank refunding?"
If Meta wins the lawsuit:
- The current situation remains: "Use your own judgment, this is the open internet"
- The burden on the user to prove they weren't negligent (transferred an SMS code? "That's negligence." Didn't check the website address? "That's negligence.")
- Banks and platforms will continue throwing responsibility at each other, and you'll remain without your money
Both scenarios – what's important to understand:
- This case will take years. It's not a solution for your problem now. A ruling is not expected before 2027-2028 (first round; appeals could continue until 2030).
- Even if Leumi wins, it won't return money already transferred in 2024-2025. Civil law isn't retroactive in such cases.
- The practical conclusion: Stop waiting for someone else to protect you. Do it yourself.
What to Do Now to Protect Yourself
1. Enable SMS/Push Alerts for Every Bank Transaction
The moment someone tries to charge your card or transfer money from your account – you'll get an immediate notification. If it's not you, you'll cancel within minutes (not days, when it's already too late).
Where to do this: In your bank's app, go to settings ← notifications ← check "every transaction" (not just transactions above a certain amount).
2. Don't Click on Facebook/Instagram Ads. Search Google Manually.
Researcher data shows 73% of phishing scams come through sponsored ads (not organic posts – sponsored ads). The reason: Facebook's algorithm identifies that you're interested (searched for iPhone last week? The internet knows, Facebook knows) and pushes exactly the fake ad that will work on you.
The safe alternative: Saw an interesting ad? Don't click. Open Google, search "company name + official site," enter from there. It's 10 times safer.
3. If You Received SMS "from the Bank" with a Link – Ignore It
Bank Leumi, Leumi Card, Mizrahi Bank, Discount, Hapoalim – none of them send links in text messages for account verification or "checking suspicious activity."
If there's really a problem, the bank will ask you to call the official phone center (and you dial the number listed on your card – not the number that came in the message).
4. Enable 2FA (Two-Factor Authentication) Everywhere
Most Israeli banks offer an authentication app (like Google Authenticator) instead of SMS.
Why this matters: SMS messages are easily intercepted (through SIM swapping or phishing); authentication app – almost impossible. If your bank offers it, switch now.
5. If You Transferred Money and Realized It's Fraud – Report Within an Hour
The time window is critical: The faster you report to the bank, the greater the chance they'll manage to stop the transfer on the receiving end (through the interbank system).
Over 24 hours? The money is probably no longer there. Already transferred to fictitious accounts, withdrawn in cash, or taken out of Israel.
6. Use Traceback to Identify Who's Really Calling You
If you received a call from "the bank," "the Ministry of Defense," "the Tax Authority," and you're not sure if it's real – grab the number, enter it in Traceback and know within seconds if it's a legitimate number or a number listed among known scammers.
If it's a fake VOIP number, temporary number, or a number used in 10 other scams this week – you'll know before you transfer money or a code.
7. Know Your Rights Under Banking Regulations (Customer Service) 2017
According to the regulations, the bank is required to:
- Block a suspicious transaction if there was reasonable cause (e.g., 10 transfers to a foreign account in one hour)
- Allow you to appeal a charge within 45 days and check if it was fraud or not
- Refund money in cases where you proved it was fraud and not negligence
What's the difference between fraud and negligence?
- Negligence: You transferred an SMS code to someone who requested it on the phone ("give me the code to confirm the delivery")
- Technological fraud: You landed on a site that looked exactly like the bank's site (or the post office, or Tel Aviv Municipality), and entered details there – and the fake site copied the design perfectly
If you can prove the site was visually identical (screenshots, DNS report, whois report), the bank can't accuse you of "negligence."
8. Document Everything
- Screenshots of the Facebook ad (including advertiser name and landing page URL)
- Screenshots of the site itself
- Recorded calls (if you used a recording app), or at least a record of the time, date, and what was said
- Email you sent to the bank reporting the fraud
Why this matters: If you reach the bank, court, or appeals committee, this documentation will be the difference between "you fell for a trap" and "they deliberately defrauded you, and we have proof."
Questions and Answers
Q: If Bank Leumi's lawsuit against Meta succeeds, will the bank refund money transferred in fraud in 2024? A: No. A future ruling doesn't affect cases already closed in settlement or previous judgment retroactively. But if your case is still open (in appeal, arbitration, or you haven't received a final decision from the bank), this legal precedent can significantly strengthen your position. You can reference it in arguments.
Q: Does Facebook really make that much from fraud? A: According to Statista data, Meta earned $39 billion from advertising in Q4 2025 alone. Estimates (based on user reports and ad removals) suggest about 2-4% of sponsored ads on Facebook and Instagram are fraud or phishing. That means between $780 million and $1.5 billion in three months. Meta claims it invests billions in automated detection systems; banks claim it's not enough – and that the removal rate is too slow.
Q: What's the legal difference between "neutral platform" and "fraud partner"? A: Neutral platform = "We just allow people to publish content. We don't check every ad in advance (there are millions of ads per day), and we remove them the moment someone complains." This is a legal defense that exists in most Western countries.
Fraud partner = "We profit directly from the fake ad (it paid us for advertising), know it's fake (or should have known, because we received 50 reports), and didn't remove it even after clear reports from a bank or customer." This is no longer negligence – it's intent or passive collaboration.
The difference is between "we had no idea" (= neutrality) and "we knew, and did nothing because it made us money" (= partnership).
Q: How am I supposed to know if a Facebook ad is fake? A: Several major warning signs:
- Illogically low price: "iPhone 16 Pro for 999 NIS" (actual price: 5,000 NIS and up)
- Artificial urgency: "Only 3 units left! Sale ends in one hour!" (classic pressure tactic)
- Mismatched landing page: The ad is from "Apple Israel Official," but the address is
apple-deals-2026.co.il(notapple.com/il) - No "contact us" button or physical address on site: A legitimate site will always display an address, email, phone
- The ad requests direct payment via Bit/Paybox/bank transfer instead of a secure payment system (like PayPal or Shopify Payments)
If you see 2-3 of these signs together – close the tab.
Q: If I reported a fake ad to Meta and nothing happened – what do I do? A: Two parallel approaches:
- Official complaint to the Ministry of Justice, Consumer Protection Division (through gov.il). They can forward an official demand to Meta Israel, and sometimes this accelerates a response.
- Public exposure: Twitter/X, Facebook groups like "Internet Scams IL," forums. Public pressure (especially if the post gets 1,000+ shares) works faster than an internal report form.
Also: Save screenshots of everything – the ad, your report, Facebook's response (or lack thereof). This will be useful if you need to file a formal complaint.
Q: Can Traceback identify if a phone number that contacted me is part of a scam? A: Yes. Traceback reveals hidden numbers and identifies if the number is listed in our scammer database (updated based on user and police reports). If the number belongs to a known fraud campaign, you'll see an alert. If it's a temporary or VOIP number (common in scams), you'll see that too. It doesn't prevent fraud completely, but it gives you the information you need to make a decision – before you transfer money or give a code.
⚠️ Disclaimer: This article is general information only and does not constitute legal advice. For any specific legal situation, consult a qualified attorney. Traceback is not responsible for legal outcomes.