Scam comments follow ad spend. The moment a campaign scales, the comment section attracts fake support accounts telling your customers to message them, lookalike profiles running giveaway bait, and phishing links dressed up as discount codes. Your ad paid for the audience; the scammer is harvesting it — and every victim blames your brand.
The patterns worth automating first
- Links and shortened URLs: almost never legitimate under an ad, and the single highest-value auto-hide rule.
- Contact-detail bait: comments pushing phone numbers, emails, or messaging handles pretending to be support.
- Impersonation phrasing: variations of 'contact our support team', 'you have won', and 'claim your prize'.
- Payment and crypto lures: cash-app handles, wallet addresses, investment pitches.
Hide fast, and keep the evidence
Speed is the defense: a scam comment that sits under an ad overnight has done its damage. Automated rules act within seconds of the comment arriving, around the clock, and the median time-to-protection number tells you exactly how fast. Hiding rather than deleting keeps the comment invisible to your audience while preserving it — with the rule that caught it and a timestamp — in your action log.
What hiding does on Meta
A hidden Facebook comment stays visible to the commenter and their friends, so scammers rarely notice they have been neutralized and simply move on. Blocking the account outright is a Page-level action in Meta's own tools — worth doing for repeat offenders, but the per-comment hide is what protects each campaign in real time. Instagram enforcement has platform limits a serious tool should state plainly rather than hide.
Layer human review on top
New scam variants appear constantly. Route borderline matches to a review queue instead of auto-hiding them, check the queue daily during active campaigns, and promote confirmed patterns into keyword rules. The rule set you accumulate — trained by your own traffic — becomes the asset that protects the next campaign from day one.