Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.
Alan Kohler, the ABC's veteran finance presenter, has watched his own face sell cryptocurrency he has never touched. When he asked Meta to take the accounts down they came down, and then they came back. He described the experience to ABC News as "whack-a-mole".
That complaint is familiar enough. What arrived on 17 August 2026 was the accounting behind it, and buried in the numbers is a change in what generative AI actually contributes to investment fraud. It is not a better fake video. It is that the fake video now arrives with corroboration attached.
The Australian Securities and Investments Commission (ASIC, the country's corporate and financial regulator) removed more than 19,400 online scams in the 2026 financial year, up 182 percent on the 6,915 it took down the year before. Fake investment platforms made up 7,051 of them, a rise of 151 percent. Phishing links jumped 279 percent to 5,476. Cryptocurrency scam takedowns climbed almost 30 percent to 3,106. Separately, reports to Scamwatch attributed 7.4 million Australian dollars of losses to scams impersonating just ten well-known Australians, including Prime Minister Anthony Albanese, the politicians Jacqui Lambie and Angus Taylor, the mining billionaire Gina Rinehart, and Kohler himself.
The design is the part worth following. A target sees a social media advertisement carrying a deepfaked endorsement, meaning a video or audio clip of a real person, generated by AI, saying something they never said. Clicking does not lead to a payment page. It leads to what looks like a news article, frequently a close copy of a real masthead, carrying fabricated reader comments that agree the scheme works. From there the target reaches an investment platform that may quote a genuine Australian Financial Services licence number belonging to a completely different company. Only once details have changed hands do humans enter the process: scripted phone calls, one or two small payouts to prove the returns are real, and then the request for the deposit that matters. ASIC's own description of the architecture is the sharpest sentence in the release. Scammers, it wrote, are targeting the very places online that consumers use to check whether an investment is genuine.
Nearly every awareness programme carries some version of the same instruction: do not act on the advertisement, go and look it up. That instruction rested on an assumption that held for as long as the web has existed. Manufacturing a dozen independent-looking sources cost real money and real time, so a scheme with a thin footprint was probably a scheme. Generative AI removed the cost. One operator can now produce the brand, the reviews, the news article, the forum thread and the comparison site in an afternoon, and tune each of them to the exact phrase a cautious person is most likely to type into a search box. Sarah Court, who chairs ASIC, stated the consequence plainly. A simple online search, she said, is not enough to verify whether an opportunity is legitimate.
For your own organisation the exposure runs in two directions. If you employ anyone whose face or voice carries public authority, a chief executive, a fund manager, a chief economist, that person is raw material, and you will usually learn about it from a customer asking whether the endorsement was real. Alan Oster, formerly chief economist at NAB, was fielding ten such messages a week at the peak. The wider shift should trouble anyone who has built verification into a process, because cross-referencing was never really a test of truth. It was a test of effort, and effort has stopped being scarce.
Nobody was hacked in any of this. No credential was stolen and no system was breached. Criminals simply built the evidence a careful person goes looking for, and a regulator spent a year pulling down 19,400 instances of it. Take the shape of that to your next security meeting, because it does not stay in consumer finance. Any control that works by asking somebody to go and corroborate something on the open internet is now resting on an assumption a generative model has quietly retired. ASIC's release sets out the full takedown figures and the list of impersonated figures.


