Bank Leumi's 26.6 million shekel lawsuit against Meta raises a critical question: can platforms be held liable for knowingly hosting fraudulent advertisements that steal customer credentials and drain bank accounts? An analysis of Israeli criminal and civil law.
Bank Leumi filed a 26.6 million shekel lawsuit against Meta in 2026, alleging the social media platform knowingly approved fraudulent advertisements impersonating the bank, collected payments for their placement, and ignored obvious warning signs while criminals harvested customer credentials. The lawsuit represents a turning point in how Israeli law treats platform liability for paid content that facilitates financial crime.
What exactly is the fraud scheme behind the headlines?
From a criminal law perspective, this is not a novel offense but rather a technologically sophisticated version of time-tested crimes: obtaining property by deception (sections 415 and 441 of the Israeli Penal Code), theft (section 384), and in some cases computer crimes when unauthorized account access occurs.
The mechanics are straightforward. A fake advertisement displays a bank logo and official visual branding, offers a non-existent customer benefit or reward program, and directs the victim to a counterfeit website. When the victim enters their authentication codes and access credentials, the fraudster gains entry to the real bank account. Within hours, money leaves the account through wire transfers, cryptocurrency transfers, or intermediary accounts designed to obscure the trail.
The advertisement served as the lure in a classic three-stage fraud sequence. Stage one is the deception: a visual and verbal pretense that tricks the victim into believing they are interacting with a legitimate bank. Stage two is account intrusion: using stolen credentials to access systems without authorization. Stage three, often overlooked in initial police reports, is money laundering through cryptocurrency wallets, mule accounts, or informal value-transfer networks.
What distinguishes the Bank Leumi case is not the fraud itself but who profited and who ignored the warnings.
Could a platform be held criminally liable for knowingly hosting fraud-for-payment?
Israeli criminal law recognizes corporate criminal liability and, under certain conditions, liability for parties who knowingly assist or enable a crime when they are aware of or deliberately ignore clear warning signs. This is the legal hinge the Bank Leumi complaint turns on.
The bank's statement of claim emphasizes a specific detail: the fraudulent indicators were "plainly visible" on the advertisements themselves. Garbled spelling, broken grammar, mismatched domain names, unverified accounts, and requests for access codes all violated Meta's own stated advertising standards. Yet Meta approved the ads, collected payment, and displayed them to targeted audiences.
A platform's knowledge of fraud markers creates potential criminal exposure under several theories. First, there is passive tolerance of crime. If a platform knowingly ignores a pattern of fraudulent activity in exchange for advertising revenue, criminal prosecutors can argue the platform has effectively agreed to benefit from the proceeds of fraud, potentially violating money laundering statutes (sections 53 and 54 of the Israeli Money Laundering Law, 5760-2000). Second, there is the theory of complicity or aiding and abetting. If Meta's systems are designed to make approval easy and challenge difficult, and if financial incentive aligns the platform with the fraudster's success, a prosecutor can argue Meta acted with the requisite mens rea (guilty mind) to be a partner in crime.
The difference between a platform that is a neutral conduit and a platform that is an active participant lies in knowledge and economic incentive. A platform that receives a report of fraud, investigates, and removes the content quickly bears no criminal exposure. A platform that receives hundreds of reports, sees a pattern, and continues to approve variants of the same fraudulent ad for payment is building a prosecutorial case against itself.
What does Israeli corporate liability law actually require to trigger criminal prosecution?
Israeli law imposes criminal liability on corporations when a senior officer commits a crime in the scope of their employment and for the benefit of the company (section 259 of the Israeli Penal Code, read with the 1997 Corporate Liability Law). "Senior officer" is defined narrowly: C-level executives with policy-setting authority. However, this is paired with a second pathway: the corporation itself may be liable if a crime is committed for the company's benefit, even without proving a specific senior officer's intent.
Meta's design and compensation structure create a fact pattern that invites this second pathway. Advertisers pay per impression and per click. The more ads are shown, the more revenue flows. If Meta's review process can be gamed, and if the reputational cost of hosting fraudulent ads against a single bank is lower than the financial benefit of ad volume, the company's own economic incentives may satisfy the "for the benefit of the company" requirement.
Moreover, Israeli courts have begun to accept arguments that a corporation's negligent architecture can amount to tacit knowledge. If a platform builds moderation systems that are deliberately understaffed, if detection algorithms are tuned to flag only the most obvious fraud to reduce labor costs, or if executives are insulated from fraud reports, courts can infer that the corporation knew or should have known of the pattern. This is called willful blindness under Israeli law: a company actively choosing not to see what it has reason to know is occurring.
Bank Leumi's complaint alleges exactly this. The bank claims that the fraud indicators were so obvious that Meta could not claim ignorance, and that Meta's continued approval for payment demonstrates not just negligence but deliberate indifference.
What happens to victims caught in the middle of a fraud-enabled platform?
A customer who falls victim to this type of fraud occupies an uncomfortable legal position, straddling civil banking procedure and criminal investigation. On one side, they must file a police report alleging fraud and theft. On the other side, they must assert claims against the bank under banking regulations that require the bank to prevent unauthorized access and reimburse customers for losses under certain conditions.
The Israel Banking Supervision Department and the Bank of Israel have issued guidelines requiring banks to conduct fraud investigations within defined timeframes and to restore funds to customers who can demonstrate they did not voluntarily disclose their credentials. However, banks often argue that victims were negligent for clicking a link or entering a code without verifying the URL, and the law is not uniform on whether this negligence bars recovery.
In practice, successful recovery depends on speed and documentation. A victim who immediately reports the fraudulent advertisement to Meta, preserves screenshots before the ad is removed, files a bank report within 24 hours of discovering the unauthorized transactions, and submits all of this evidence to the bank stands a better chance of reimbursement. A victim who waits weeks or who cannot produce the advertisement itself faces an uphill battle, because the bank will argue it cannot verify that the specific advertisement caused the loss.
This is why parallel action is essential: contact the bank, document the Meta advertisement directly (with timestamps and full URL), file a police report with the Cyber Unit (Unit 433) of the Israel Police that cites the specific advertisement and traces the flow of funds, and provide the bank with all three documents bundled together. The more evidence chains criminal fraud to a specific platform, the stronger the victim's negotiating position with the bank.
Why does this lawsuit signal a shift in how courts will treat platform responsibility?
Bank Leumi's case reflects a broader judicial reckoning with digital platforms' economic and behavioral incentives. For years, courts in Israel and elsewhere treated platforms as neutral infrastructure providers, immune from liability for user-generated content under the logic of the Communications Decency Act (CDA) framework, which influenced Israeli jurisprudence even though Israel has no direct equivalent statute.
That immunity was always weaker when platforms exercised editorial judgment. If Meta approves an advertisement, collects payment, targets it to specific demographics, and places it in prioritized ad slots, Meta is not a neutral conduit anymore. It is a publisher making editorial and financial decisions. Once a platform crosses that line, courts have begun to argue, it cannot simultaneously enjoy liability protections designed for neutral infrastructure.
Israeli courts have begun following this logic in cases involving intellectual property infringement and coordinated harassment. The next frontier is financial fraud. If Bank Leumi's claims prevail, Israeli courts may establish that a platform's repeated approval of fraudulent ads, despite clear warning signs, constitutes either criminal complicity or a breach of duty under tort law that allows victims to sue the platform directly, not just the fraudster.
This would alter the incentive structure for platforms. Currently, Meta faces essentially no financial consequence for hosting fraud ads: advertiser disputes and account suspensions are routine business costs, and the company's scale allows it to absorb them. But if platforms become jointly liable for fraud losses or face statutory damages for reckless approval, the calculus changes. Better moderation becomes a cost of doing business, not an optional luxury.
What would stronger platform accountability rules actually require?
The Bank Leumi lawsuit does not ask Meta to screen all advertisements perfectly. It asks Meta to do what Meta claims it already does: verify advertiser identity, flag suspicious content patterns, and remove ads that impersonate financial institutions. These steps are technically feasible. Advertiser verification can be performed using document scans and cross-reference checks against registered business databases. Pattern detection can be automated: any advertisement that combines a bank logo with urgency language and requests for credentials can be flagged for manual review.
The cost of these measures is real but not prohibitive. The financial gain from allowing a single fraudulent ad to run unchecked is small relative to the reputational and legal risk. Yet empirically, fraudulent bank-impersonation ads continue to run on Meta, Instagram, and other platforms, suggesting that either detection is inadequate or enforcement is inconsistent.
Stronger rules would likely include a statutory requirement that platforms maintain advertiser registries, conduct periodic audits of financial-services ads, and publish transparency reports on fraud takedowns. Several countries, including the United Kingdom and the European Union, have begun requiring this. If Israeli regulation moves in that direction, platforms will have no choice but to comply.
For now, however, platforms operate in a gray zone: they claim to enforce standards they do not consistently apply, and they benefit financially from the friction that makes enforcement costly. The Bank Leumi case may not change that immediately, but it puts the question in front of courts in a way that previous complaints have not.
Bank Leumi's lawsuit is a reminder that online financial fraud is not merely a cybersecurity risk or a technology problem. It is a legal question about who bears the costs and who bears the responsibility when a paid platform knowingly enables crime. The answer Israeli courts give will shape how platforms operate not just in Israel but across the region, and will determine whether victims have any recourse beyond their banks.








