Skip to content

Global payments intelligence

Updated Aug 24, 2026 · 23:34 UTC

Now tracking SEC Proposes Crypto Offering Exemptions and Conditional Safe Harbor
Payments intelligence
Risk, Fraud & Controversies

ASIC Reports 19,400 Scam Takedowns as Deepfake Investment Fraud Expands

Australia’s securities regulator says scammers are building networks of deepfake endorsements, fake news, reviews and investment platforms to deceive victims.

Australia’s securities regulator says criminals are using generative AI to build interconnected networks of deepfake endorsements, fake news articles, reviews and investment platforms that can make fraudulent opportunities appear legitimate.

The Australian Securities and Investments Commission said it removed more than 19,400 online scams in the financial year ended June 2026, an increase of 182% from 6,915 in the previous year. The total covered fake websites, social media advertisements, phishing links and cryptocurrency investment scams.

ASIC did not say that all 19,400 items were AI-generated, that every takedown represented a distinct criminal organization or that each item produced a victim loss. The regulator’s figures measure content and sites removed, not the value or number of payments that reached scammers.

Scammers are manufacturing the evidence victims look for

The control problem extends beyond detecting a single deceptive advertisement. ASIC said scammers create brands and distinctive phrases, then surround them with supportive search results, fabricated news coverage, positive reviews and AI-generated videos. A potential victim may move from an advertisement on a familiar platform to a fake article featuring a public figure and then to a fraudulent investment platform.

After collecting a person’s details, criminals may use scripted phone calls and show a fake account interface. ASIC said some scammers even make small purported profit payments to build trust before seeking more money. The regulator warned that the promoted investment may not exist and that funds can instead go to overseas criminals.

This structure weakens a common anti-fraud message: telling customers simply to search the web before paying. When criminals control several apparent sources of confirmation, a search can reproduce the scam’s own manufactured evidence. ASIC Chair Sarah Court said polished content, familiar branding and convincing testimonials do not establish legitimacy.

Takedowns rose across several scam channels

ASIC said it removed 5,476 phishing hyperlinks during FY2026, a 279% increase from the previous financial year. It also reported taking down 7,051 fake investment platforms, up 151%, and 3,106 cryptocurrency investment scams, an increase of almost 30%.

Those categories describe material removed through ASIC’s takedown capability. The release does not provide a mutually exclusive reconciliation of every category to the overall total, so the figures should not be added together to estimate a separate scam count.

Reports to Scamwatch also linked impersonations of well-known Australians to A$7.4 million in losses during FY2026, ASIC said. The regulator listed Anthony Albanese, market commentators Tom Piotrowski and Alan Kohler, economist Stephen Koukoulas, politicians Jacqui Lambie and Angus Taylor, entrepreneur Dick Smith, mining executive Gina Rinehart, economist Alan Oster, politician Pauline Hanson and broadcaster John Laws among the most impersonated public figures. The named people are impersonation victims, not participants in the schemes.

Payment controls need independent verification

For banks, payment providers and crypto platforms, the warning illustrates why customer authorization alone is an incomplete scam control. A victim can initiate a genuine payment after being deceived by a false investment journey. Authentication can prove who sent the instruction without proving that the beneficiary or investment is legitimate.

ASIC urged consumers to check whether an investment is associated with a verified Australian financial services licence and to match the licence holder’s name and number against its professional registers. It also warned that scammers may copy another business’s licence number or impersonate a licensed firm, meaning the existence of a number is not sufficient.

Payment and compliance teams can apply the same principle operationally: verification should use independently sourced identity and contact data rather than information supplied inside an advertisement, message or receiving website. Beneficiary-risk signals, account history, rapid changes in incoming payment patterns and links to previously identified scam infrastructure can provide additional context. These are industry control considerations, not findings that ASIC attributed to a particular bank or payment company.

The release does not identify the payment rails, banks, digital-asset exchanges or beneficiary institutions used in the reported schemes. It also does not allocate the A$7.4 million loss figure by payment method. Those omissions prevent conclusions about which providers carried the funds or whether any specific firm’s controls failed.

Takedowns address distribution, not the full money trail

ASIC said it has removed more than 33,400 scam websites, advertisements and phishing items since launching its takedown capability three years ago. Removing fraudulent content can disrupt victim acquisition, but the regulator’s release shows why takedown work and payment intervention need to be treated as complementary controls.

Scam networks can replace a website or advertisement while retaining scripts, beneficiary accounts and fake investment interfaces. Financial institutions therefore need processes that connect customer reports and recipient-account intelligence to rapid restriction, investigation and recovery efforts where legally appropriate. They also need clear escalation when a customer appears to be acting under manipulation even though the transaction is technically authorized.

ASIC advised consumers to stop before sharing money or personal information, independently check who they are dealing with, and report scams to their bank, Australia’s cyber-reporting service and Scamwatch. For the payments sector, the central accountability question is whether those reports are converted quickly enough into controls on the destination of funds as well as warnings at the point of payment.