Deepfake Albanese Ads Cost Australians A$7.4M

ASIC linked deepfakes of eleven named public figures to A$7.4 million in FY26 losses and removed 19,400 scams. The clips are reported to keep the real video and replace only the voice — which breaks the detection advice Australians are being given.
By Sukrit Bhatia
August 19, 2026
l
17
 min read
What are deepfakes — business risk overview article
Table of Content
No items found.

Australia’s corporate regulator has put a number on deepfake investment fraud. Reports to Scamwatch involving the eleven public figures ASIC named as most impersonated in FY26 — led by Prime Minister Anthony Albanese, and including two sitting senators, the Leader of the Opposition and ABC finance journalist Alan Kohler — are associated with A$7.4 million in losses. ASIC removed more than 19,400 online scams over the same year, a 182% increase.

The regulatory story has been widely covered. A narrower question has not been: what kind of fake are these? Reporting describes the Albanese clips as authentic broadcast footage with only the audio replaced by a synthesised voice. If that is right, then the public guidance issued alongside these warnings — check the blinking, check the lip-sync, check the skin texture — is aimed entirely at the one layer of these clips that was never touched. This is an analysis of that mismatch, and of why every enforcement point in the scam funnel sits downstream of the transfer.

  • A$7.4 million in FY26 Scamwatch-reported losses is tied to the eleven public figures ASIC named as most impersonated (ASIC 26-195MR, 17 August 2026).
  • 19,400 scams removed by ASIC in FY26, up 182% from 6,915 — including 7,051 fake investment platforms and 5,476 phishing links.
  • The eleven names cluster in financial and governmental authority: Albanese, Piotrowski, Kohler, Koukoulas, Lambie, Taylor, Smith, Rinehart, Oster, Hanson, Laws.
  • Three loss figures are circulating — A$7.4m, A$837.7m and A$2bn — measuring different things over different periods. They should not be merged.
  • The clips are reported as audio grafts: authentic video, synthesised voice. No pixels generated means no visual artefacts to find.
  • Visual-cue advice returns a clean result here, correctly — the video really is untampered. The check is aimed at the wrong layer.
  • Only one control is preventive: screening paid ads before they are served. Every later stage sits downstream of the transfer.
  • No detector output is claimed. DuckDuckGoose has not analysed the clips; the argument is methodological and its limits are stated in the article.

Australia’s corporate regulator has put a number on deepfake investment fraud: reports to Scamwatch involving the eleven public figures it named as most impersonated in FY26 are associated with A$7.4 million in losses, and ASIC removed more than 19,400 online scams over the same year — a 182% increase on the 6,915 it took down the year before. The list of impersonated figures is led by Prime Minister Anthony Albanese, and includes two sitting senators, the Leader of the Opposition, and the ABC finance journalist Alan Kohler. The figures come from ASIC media release 26-195MR, published 17 August 2026.

The regulatory story is straightforward and has been widely reported. The more useful question for anyone running an identity or content-integrity pipeline is narrower, and it has had almost no attention: what kind of fake are these, and does the detection advice being issued alongside the warning actually apply to them?

On the reporting available, the answer appears to be no. Coverage of the campaign describes the Albanese clips as authentic broadcast footage with a synthesised voice track — real video, replaced audio. If that description is accurate, then the standard public guidance for spotting a deepfake, which is overwhelmingly a list of visual tells, is being aimed at the one layer of these clips that was never manipulated. That is the subject of this analysis.

At a glance

Australia's corporate regulator, ASIC, reported on 17 August 2026 that deepfake videos of eleven named public figures — Prime Minister Anthony Albanese among them — were used to promote fake investment platforms. Reports to Scamwatch involving those figures are associated with $7.4 million in losses for FY26.

A$0M
Reported losses
Scamwatch reports tied to the 11 most-impersonated figures, FY26
0
Scams removed
Taken down by ASIC in FY26, across all scam categories
+0%
Year on year
Up from 6,915 removals in FY25
0
Named figures
Politicians, economists and broadcasters impersonated

What ASIC actually reported

ASIC’s FY26 release documents a takedown programme and a rise in AI-assisted impersonation. ASIC Chair Sarah Court is quoted directly: “AI is making investment scams more convincing and harder to detect,” and, on the signals consumers are told to trust, “The presence of polished content, familiar branding or convincing testimonials does not mean an investment is legitimate.” In separate remarks reported by FX News Group, Court added that Australians “should be especially cautious if they see a celebrity or influencer promoting an investment opportunity online.”

The eleven named figures are not a random sample of the famous. They are, almost without exception, people whose public credibility is specifically financial or governmental — a prime minister, an opposition leader, two senators, three economists and market commentators, a finance journalist. The impersonation is not borrowing fame. It is borrowing authority over exactly the subject the scam is about.

FigurePublic roleRanking in ASIC's FY26 list
Anthony AlbanesePrime Minister of Australia1
Tom PiotrowskiMarket commentator2
Alan KohlerFinance journalist, ABC3
Stephen KoukoulasEconomist4
Jacqui LambieSenator for Tasmania5 (tied)
Angus TaylorLeader of the Opposition5 (tied)
Dick SmithBusinessman6
Gina RinehartMining executive7
Alan OsterEconomist, National Australia Bank8
Pauline HansonSenator for Queensland9
John LawsBroadcaster10

Table 1: The eleven public figures ASIC named as most impersonated in FY26 investment scams. Ranking as published by Bitdefender from ASIC and National Anti-Scam Centre data; Lambie and Taylor share a position.

Four numbers, four different things

Coverage of this story has put several large figures into circulation, and they measure different quantities over different periods. They are not competing estimates and should not be merged. ABC News reports A$837.7 million in investment scam losses and A$2 billion in total scam losses for calendar 2025, both attributed to the National Anti-Scam Centre and both covering all scam types. ASIC’s A$7.4 million is a much narrower figure: FY26 Scamwatch reports that involved these eleven specific people. The smaller number is not a correction of the larger ones.

FigureWhat it measuresPeriodSource
A$7.4 millionLosses in Scamwatch reports involving the eleven most-impersonated public figuresFY26ASIC 26-195MR
A$837.7 millionAll investment scam losses reported nationally, across every scam type — not only deepfake or impersonation casesCalendar 2025ABC News, citing the National Anti-Scam Centre
A$2 billionAll scam losses of every category reported nationallyCalendar 2025ABC News, citing the National Anti-Scam Centre
19,400Online scams removed by ASIC, all categoriesFY26ASIC 26-195MR
6,915Online scams removed by ASIC in the preceding year, the base for the 182% riseFY25FX News Group
33,400Cumulative scam websites, social media ads and phishing scams removed by ASICSince launch, three yearsASIC 26-195MR

Table 2: The four loss and removal figures in circulation, and what each one actually counts. These are not alternative estimates of the same quantity.

One limitation applies to all of them, and it runs in a single direction. Every figure here derives from reports voluntarily filed by victims. Investment fraud is among the most under-reported categories of crime, because the victim has to volunteer that they were persuaded. A$7.4 million is a floor on the losses tied to these eleven names, not an estimate of them.

Scam categoryRemoved in FY26Change on prior yearSource
Fake investment platforms7,051Up 151%ASIC 26-195MR
Phishing hyperlinks5,476Up 279%ASIC 26-195MR
Cryptocurrency investment scams3,106Up almost 30%ASIC 26-195MR
All categories combined19,400Up 182%ASIC 26-195MR

Table 3: ASIC's FY26 takedown volumes by category. The sub-categories are drawn from the same media release as the headline figure and do not sum to it.

What Is an Audio-Grafted Deepfake?

An audio-grafted deepfake is a video in which the visual track is genuine, unmodified footage of a real person, and only the audio has been replaced with synthesised speech in that person’s cloned voice. Nothing about the image is generated. The frames are the original camera capture, with the original lighting, the original compression history and the original sensor characteristics. What has changed is what the person appears to be saying.

This is a different object from what most people picture when they hear “deepfake.” The familiar form is a face swap or a fully generated video, where a generative model has produced or altered the pixels themselves. That process is lossy and leaves evidence: blending seams at the jaw and hairline, texture that is too smooth or too uniform, blink patterns that do not match human distributions, lighting that disagrees with the scene, frequency-domain artefacts characteristic of the generator. Our analysis of the artefacts generators leave behind covers those traces in detail, and why some generators are harder to detect than others covers how much they vary between models.

An audio graft skips that entire attack surface. There is no generator touching the video, so there are no generator artefacts in the video. The manipulation is real, complete and entirely confined to one track — and it is the track that almost none of the public guidance addresses.

The Layer Mismatch: Why “Spot the Fake” Advice Returns a Clean Result

Public deepfake guidance is remarkably consistent, and remarkably visual. Look for unnatural blinking. Check whether the lips match the words. Watch for waxy or overly smooth skin. Look at the edges of the face. Check whether the lighting on the face matches the background. Every one of those instructions is a test of the video track.

Detection layer mismatch

Two ways to fake a video of a public figure — and only one of them leaves the artefacts the public is told to look for

Reporting on the ASIC campaign describes the Albanese clips as authentic news footage with a synthesised voice track. If that holds, the video layer is genuine, and every visual cue in the standard “spot the deepfake” checklist is being applied to a layer that was never edited.

Fully synthetic videoFace swap or generated frames
Video track: generated
Frames are synthesised or a face is swapped in, so pixel-level statistics differ from a camera capture.
Audio track: generated
Cloned or text-to-speech voice, produced alongside the video.
Lip-sync coupling: modelled
Mouth movement is driven by the generator, so it can drift out of alignment with the speech.
Visual cues available
Blink irregularity, edge blending, texture inconsistency and lip-sync drift can all be present, because the video itself was manipulated.
Standard public advice
Check for unnatural blinking
Check lip-sync alignment
Check skin texture and edges
Audio-grafted clipReal footage, replaced voice
Video track: authentic
Genuine broadcast footage, unedited. Pixel statistics are those of a real camera, because it was one.
Audio track: synthesised
The only manipulated layer. A cloned voice delivers a script the speaker never said.
Lip-sync coupling: incidental
Mismatch depends on framing. Wide shots, cutaways, voiceover segments and B-roll hide it entirely.
The mismatch
There are no video artefacts to find, because no video was generated. A viewer following the checklist inspects a real recording, finds nothing wrong, and concludes the clip is genuine.
Same advice, applied here
Check for unnatural blinking
Check lip-sync alignment
Check skin texture and edges

Panel B is a description of the construction reported in coverage of the ASIC campaign, not a measurement of a specific clip. DuckDuckGoose has not obtained or analysed the circulating videos.

Run that checklist against an audio-grafted clip and it returns a clean result on every item, correctly, because the video is clean. The viewer is not being fooled by a good forgery of a video. They are inspecting a real video, finding — accurately — that it has not been tampered with, and drawing the wrong conclusion from a correct observation. The checklist has not failed to detect a manipulation. It has been pointed at the wrong layer.

Detection cueFully synthetic videoAuthentic video, synthesised audio
Blink rate and eye behaviourMay be irregularNormal — it is a real recording
Skin texture and edge blendingMay show generator artefactsClean — no pixels were generated
Lip-sync alignmentOften driftsDepends entirely on shot framing; absent in cutaways, wide shots and voiceover
Lighting and shadow consistencyMay be inconsistentPhysically correct
Compression and frequency artefactsOften present in the video streamPresent only in the audio stream
Voice timbre, prosody and breathSyntheticSynthetic

Table 4: Which cues survive each construction. The right-hand column is why a checklist aimed at the video layer returns a clean result on an audio-grafted clip.

Lip-sync deserves a specific note, because it is the one cue that might survive, and it is less reliable than it looks. Whether an audio graft produces visible desynchronisation depends almost entirely on shot framing. In a tight head-on shot it may be detectable. But broadcast footage of politicians and economists is not mostly tight head-on shots — it is wide shots, cutaways to an interviewer, over-the-shoulder framing, B-roll of the subject walking or seated while a voice runs over the top. A scammer selecting source footage does not need to defeat lip-sync analysis. They only need to choose a clip where the mouth is not clearly visible, which is most of them. Our guide to how to spot a deepfake sets out the visual cues in full; this incident is a clear illustration of the case where those cues are not the right instrument, and where the audio track has to be examined on its own terms.

The practical consequence is that the detection question has to be asked per-track rather than per-file. A verdict of “the video is authentic” is not a verdict of “the recording is authentic.” A pipeline that analyses video and image content — the problem DuckDuckGoose’s DeepDetector is built for — and a pipeline that analyses voice for synthesis, which is what Waver addresses, are answering two different questions, and on this construction only the second one is being asked about the part that was actually changed. Treating a media-integrity check as a single pass/fail verdict on a file is what allows a clip like this through.

The Funnel: Every Enforcement Point Is Downstream of the Money

The deepfake is the entry point of a staged operation, not the whole of it. ASIC describes the sequence: a social advertisement carrying the fabricated endorsement, a click through to a spoofed news article with invented reader comments and reviews, a counterfeit investment platform with a working dashboard showing fabricated returns on a small initial deposit, then scripted follow-up calls. Bitdefender Labs tracked these campaigns running across Facebook, Instagram, TikTok, X and YouTube.

Takedown versus prevention

Every step ASIC can act on happens after the transfer

ASIC describes a staged funnel: a deepfake advertisement, a fabricated news page carrying the endorsement, a counterfeit investment platform, then scripted calls. Removal is a response to infrastructure that has already done its work.

01Deepfake advertisement on a social platform
A clip of a recognised public figure endorsing an investment scheme is served as paid social advertising. Bitdefender Labs tracked these campaigns across Facebook, Instagram, TikTok, X and YouTube.
02Fabricated news article with fake comments
The click lands on a spoofed news page carrying the endorsement, invented reader comments and positive reviews — an entire manufactured footprint for a brand that does not exist.
03Counterfeit investment platform
A working dashboard shows fabricated gains against a small initial deposit. ASIC removed 7,051 fake investment platforms in FY26, a 151% rise.
04Scripted follow-up call
Victims who submit contact details receive scripted calls that convert an interested reader into a larger transfer. The human layer closes what the synthetic layer opened.
05Funds extracted
Money leaves the victim's control. Reports to Scamwatch involving the eleven most-impersonated figures are associated with A$7.4 million in losses across FY26.
Where enforcement arrives
ASIC's takedown capability engages at steps 1 to 3 — but as removal, after the advertisement has run and the page has converted. Removing 19,400 scams in a year is evidence of reach; it is also evidence that 19,400 pieces of infrastructure were live long enough to need removing.
The missing gate
Screening at step 1, before the advertisement is served
The only point in this funnel where a detection check changes the outcome rather than documenting it is at ad review, on the platform side. Everything after step 1 is cleanup.
19,400
Scams removed by ASIC in FY26, up 182% year on year
7,051
Fake investment platforms removed, up 151%
5,476
Phishing hyperlinks removed, up 279%

ASIC removed 19,400 scams in FY26, up 182%. That figure is usually presented as evidence of an effective enforcement programme, and as a measure of reach it is. It is also, read the other way, a count of how much fraudulent infrastructure went live and stayed live long enough to require removal. Takedown is a lagging control. It operates on the advertisement after it has been served, on the spoofed article after it has converted, on the fake platform after the deposit has cleared. The 182% growth rate is the more informative number, because it indicates that supply is scaling faster than removal.

Alan Kohler, who is on ASIC’s list, described the experience of trying to get his own likeness removed to ABC News as “like whack-a-mole… it just kept coming back,” and said of the reputational cost: “It’s taken a lifetime to build trust, and it’s so easily lost.” He argued for regulatory intervention, calling the situation “potentially an emergency in the making.” That is a person named on the regulator’s own list describing the removal process as ineffective at the individual level.

There is exactly one point in this funnel where a detection check changes an outcome rather than documenting it: ad review, before the advertisement is served. That is a platform-side control, not a regulator-side one, and not a consumer-side one. Screening paid advertising that features a recognisable public figure making a financial claim is a bounded, tractable problem — a finite set of high-profile faces and voices, checked at submission rather than after complaint. Everything downstream of that gate is cleanup.

What This Means for Platforms, Institutions and Verification Providers

For platforms: the screening question for paid political and financial advertising has to include the audio track independently. A clip whose video passes every authenticity check is not thereby cleared, and a policy written around “manipulated media” that operationalises only visual manipulation will not catch this construction.

For financial institutions: the loss event is a customer-initiated transfer, which means it presents as legitimate. The detection surface is behavioural rather than synthetic-media analysis: a first transfer to a new investment platform, unusual for the account, often following a phone conversation. The deepfake is upstream and invisible from inside the bank.

For identity verification providers: the direct lesson is about layer coverage, and it is the same structural error we have documented elsewhere. A control certified against one attack class is routinely treated as coverage of a category it was never tested for — the pattern described in our comparison of liveness detection versus deepfake detection, and in the analysis of how injection attacks feed deepfakes into verification, where an iBeta-certified system can be transparent to the dominant attack vector. Audio grafting is the same failure in a different domain: a video-integrity check standing in for a media-integrity check. Providers running remote onboarding should also read this alongside how deepfakes enter remote verification flows, since a voice-only manipulation is directly relevant to any verification step conducted over a call.

For regulators: the FY26 numbers make the case that removal volume is the wrong headline metric. Time-to-removal, and the proportion of scam advertising stopped before first impression, describe whether the intervention is working. 19,400 removals and a 182% increase are compatible with a programme that is losing ground.

What We Have Not Verified

Being explicit about the boundary of this analysis, because the argument above depends on one characterisation we have not independently confirmed:

  • We have not obtained or analysed the circulating clips. DuckDuckGoose has run no detection process on this material. There are no confidence scores, per-frame findings or artefact observations in this article, because we have not examined the artefacts. The argument here is methodological: if a clip is constructed this way, then visual-cue analysis cannot detect it. That reasoning stands on its own, but it is reasoning, not measurement.
  • The audio-graft characterisation comes from secondary reporting. The description of authentic footage with a replaced audio track, and the specific claim that a clip pitched turning A$4,000 into A$40,000 a month on a platform described as “official” and government-guaranteed, is attributed to Guardian reporting and reproduced in secondary coverage. We were not able to retrieve the Guardian article directly. ASIC’s own release does not characterise the clips at this level of technical detail. If some clips in this campaign are fully synthetic rather than audio-grafted, the visual cues would apply to those — the point is that they cannot be relied on to apply to all of them.
  • Attribution and infrastructure are unknown to us. We make no claim about who operated this campaign, what tools generated the voice, or where the infrastructure was hosted. Pindrop-style generator attribution requires the artefact.

Frequently Asked Questions

How much did the ASIC deepfake investment scams cost Australians?
Reports to Scamwatch involving the eleven most-impersonated public figures are associated with A$7.4 million in losses during FY26, according to ASIC media release 26-195MR. This is narrower than the A$837.7 million in all investment scam losses reported for calendar 2025, which covers every scam type rather than deepfake impersonation specifically. Because both rest on voluntarily filed reports, they are floors rather than estimates.

Which public figures were impersonated in the ASIC deepfake scams?
ASIC named eleven: Anthony Albanese, Tom Piotrowski, Alan Kohler, Stephen Koukoulas, Jacqui Lambie, Angus Taylor, Dick Smith, Gina Rinehart, Alan Oster, Pauline Hanson and John Laws. The list is concentrated in people with financial or governmental authority rather than general celebrity.

What is an audio-grafted deepfake?
A video where the visual track is genuine, unmodified footage and only the audio has been replaced with synthesised speech in the subject’s cloned voice. Because no pixels are generated, the video carries none of the artefacts that visual deepfake detection and public “spot the fake” advice look for.

Why doesn’t standard deepfake-spotting advice work on these clips?
Nearly all public guidance tests the video track — blinking, lip-sync, skin texture, edge blending, lighting. On an audio-grafted clip the video track is authentic, so those checks pass correctly and the viewer concludes the clip is genuine. Lip-sync is the only cue with any chance of surviving, and whether it shows depends on shot framing, which the attacker chooses.

Did ASIC say the clips were audio-grafted?
No. ASIC’s release describes a rise in deepfake videos of celebrities and politicians without characterising the construction. The audio-graft description comes from press coverage of the campaign, principally Guardian reporting. We flag it as a reported characterisation rather than a verified technical finding.

Has DuckDuckGoose analysed these videos?
No. We have not obtained the circulating clips and have run no detection process on them. This article deliberately contains no detection scores or artefact findings. The analysis is about what the reported construction implies for detection method.

Where in the scam funnel can detection actually prevent a loss?
At ad review, before the advertisement is served. Every later stage — the spoofed news page, the fake platform, the scripted call — sits downstream, and ASIC’s takedown powers operate as removal after the infrastructure has run. That is why 19,400 removals at 182% growth is compatible with the problem getting worse.

Methodology

The figures in this article are drawn from ASIC media release 26-195MR of 17 August 2026 as the primary source, corroborated against ABC News, Bitdefender, FX News Group, Finextra and Finance Magnates. Eight distinct publishers covering this story were identified, including The Guardian. Where sources report different quantities, each is presented separately with its measurement basis and period stated rather than reconciled into a single number. Loss figures derived from voluntary victim reports are treated as lower bounds. Technical characterisations that we could not confirm in a primary or high-authority source are labelled as reported claims in the section above, and no detection findings are asserted, because no detection process was run.

Sources

  1. ASIC — 26-195MR: ASIC warns scammers are using AI to spin vast webs of deception (primary)
  2. ABC News — AI deepfake scams an emergency in the making as ASIC reports rise in false investment endorsements
  3. The Guardian — Deepfake Anthony Albanese used in celebrity scams duping Australians out of $7.4m, Asic warns
  4. Bitdefender — Top Aussie public figures impersonated in investment scams
  5. FX News Group — Australian regulator warns public of scammers increasingly using AI for investment fraud
  6. Finextra — Asic warns of surge in deepfake scams
  7. Finance Magnates — ASIC Removes Over 19,400 Scams as AI Deepfakes Target Investors
  8. UA.NEWS — In Australia, scammers are using deepfakes of the prime minister for investment scams


DuckDuckGoose builds deepfake detection for organisations that need to know whether media is synthetic before acting on it — DeepDetector for video and image, Waver for voice. See duckduckgoose.ai for how the detection stack is structured.

Last update: Q3 2026.

By Sukrit Bhatia
DuckDuckGoose AI

About the author

By Sukrit Bhatia
DuckDuckGoose AI

Discover the Power of Explainable AI (XAI) Deepfake Detection

Schedule a free demo today to experience how our solutions can safeguard your organization from fraud, identity theft, misinformation & more