Australia’s corporate regulator has put a number on deepfake investment fraud. Reports to Scamwatch involving the eleven public figures ASIC named as most impersonated in FY26 — led by Prime Minister Anthony Albanese, and including two sitting senators, the Leader of the Opposition and ABC finance journalist Alan Kohler — are associated with A$7.4 million in losses. ASIC removed more than 19,400 online scams over the same year, a 182% increase.
The regulatory story has been widely covered. A narrower question has not been: what kind of fake are these? Reporting describes the Albanese clips as authentic broadcast footage with only the audio replaced by a synthesised voice. If that is right, then the public guidance issued alongside these warnings — check the blinking, check the lip-sync, check the skin texture — is aimed entirely at the one layer of these clips that was never touched. This is an analysis of that mismatch, and of why every enforcement point in the scam funnel sits downstream of the transfer.
- A$7.4 million in FY26 Scamwatch-reported losses is tied to the eleven public figures ASIC named as most impersonated (ASIC 26-195MR, 17 August 2026).
- 19,400 scams removed by ASIC in FY26, up 182% from 6,915 — including 7,051 fake investment platforms and 5,476 phishing links.
- The eleven names cluster in financial and governmental authority: Albanese, Piotrowski, Kohler, Koukoulas, Lambie, Taylor, Smith, Rinehart, Oster, Hanson, Laws.
- Three loss figures are circulating — A$7.4m, A$837.7m and A$2bn — measuring different things over different periods. They should not be merged.
- The clips are reported as audio grafts: authentic video, synthesised voice. No pixels generated means no visual artefacts to find.
- Visual-cue advice returns a clean result here, correctly — the video really is untampered. The check is aimed at the wrong layer.
- Only one control is preventive: screening paid ads before they are served. Every later stage sits downstream of the transfer.
- No detector output is claimed. DuckDuckGoose has not analysed the clips; the argument is methodological and its limits are stated in the article.
Australia’s corporate regulator has put a number on deepfake investment fraud: reports to Scamwatch involving the eleven public figures it named as most impersonated in FY26 are associated with A$7.4 million in losses, and ASIC removed more than 19,400 online scams over the same year — a 182% increase on the 6,915 it took down the year before. The list of impersonated figures is led by Prime Minister Anthony Albanese, and includes two sitting senators, the Leader of the Opposition, and the ABC finance journalist Alan Kohler. The figures come from ASIC media release 26-195MR, published 17 August 2026.
The regulatory story is straightforward and has been widely reported. The more useful question for anyone running an identity or content-integrity pipeline is narrower, and it has had almost no attention: what kind of fake are these, and does the detection advice being issued alongside the warning actually apply to them?
On the reporting available, the answer appears to be no. Coverage of the campaign describes the Albanese clips as authentic broadcast footage with a synthesised voice track — real video, replaced audio. If that description is accurate, then the standard public guidance for spotting a deepfake, which is overwhelmingly a list of visual tells, is being aimed at the one layer of these clips that was never manipulated. That is the subject of this analysis.
Australia's corporate regulator, ASIC, reported on 17 August 2026 that deepfake videos of eleven named public figures — Prime Minister Anthony Albanese among them — were used to promote fake investment platforms. Reports to Scamwatch involving those figures are associated with $7.4 million in losses for FY26.
What ASIC actually reported
ASIC’s FY26 release documents a takedown programme and a rise in AI-assisted impersonation. ASIC Chair Sarah Court is quoted directly: “AI is making investment scams more convincing and harder to detect,” and, on the signals consumers are told to trust, “The presence of polished content, familiar branding or convincing testimonials does not mean an investment is legitimate.” In separate remarks reported by FX News Group, Court added that Australians “should be especially cautious if they see a celebrity or influencer promoting an investment opportunity online.”
The eleven named figures are not a random sample of the famous. They are, almost without exception, people whose public credibility is specifically financial or governmental — a prime minister, an opposition leader, two senators, three economists and market commentators, a finance journalist. The impersonation is not borrowing fame. It is borrowing authority over exactly the subject the scam is about.
Table 1: The eleven public figures ASIC named as most impersonated in FY26 investment scams. Ranking as published by Bitdefender from ASIC and National Anti-Scam Centre data; Lambie and Taylor share a position.
Four numbers, four different things
Coverage of this story has put several large figures into circulation, and they measure different quantities over different periods. They are not competing estimates and should not be merged. ABC News reports A$837.7 million in investment scam losses and A$2 billion in total scam losses for calendar 2025, both attributed to the National Anti-Scam Centre and both covering all scam types. ASIC’s A$7.4 million is a much narrower figure: FY26 Scamwatch reports that involved these eleven specific people. The smaller number is not a correction of the larger ones.
Table 2: The four loss and removal figures in circulation, and what each one actually counts. These are not alternative estimates of the same quantity.
One limitation applies to all of them, and it runs in a single direction. Every figure here derives from reports voluntarily filed by victims. Investment fraud is among the most under-reported categories of crime, because the victim has to volunteer that they were persuaded. A$7.4 million is a floor on the losses tied to these eleven names, not an estimate of them.
Table 3: ASIC's FY26 takedown volumes by category. The sub-categories are drawn from the same media release as the headline figure and do not sum to it.
What Is an Audio-Grafted Deepfake?
An audio-grafted deepfake is a video in which the visual track is genuine, unmodified footage of a real person, and only the audio has been replaced with synthesised speech in that person’s cloned voice. Nothing about the image is generated. The frames are the original camera capture, with the original lighting, the original compression history and the original sensor characteristics. What has changed is what the person appears to be saying.
This is a different object from what most people picture when they hear “deepfake.” The familiar form is a face swap or a fully generated video, where a generative model has produced or altered the pixels themselves. That process is lossy and leaves evidence: blending seams at the jaw and hairline, texture that is too smooth or too uniform, blink patterns that do not match human distributions, lighting that disagrees with the scene, frequency-domain artefacts characteristic of the generator. Our analysis of the artefacts generators leave behind covers those traces in detail, and why some generators are harder to detect than others covers how much they vary between models.
An audio graft skips that entire attack surface. There is no generator touching the video, so there are no generator artefacts in the video. The manipulation is real, complete and entirely confined to one track — and it is the track that almost none of the public guidance addresses.
The Layer Mismatch: Why “Spot the Fake” Advice Returns a Clean Result
Public deepfake guidance is remarkably consistent, and remarkably visual. Look for unnatural blinking. Check whether the lips match the words. Watch for waxy or overly smooth skin. Look at the edges of the face. Check whether the lighting on the face matches the background. Every one of those instructions is a test of the video track.
Two ways to fake a video of a public figure — and only one of them leaves the artefacts the public is told to look for
Reporting on the ASIC campaign describes the Albanese clips as authentic news footage with a synthesised voice track. If that holds, the video layer is genuine, and every visual cue in the standard “spot the deepfake” checklist is being applied to a layer that was never edited.
Panel B is a description of the construction reported in coverage of the ASIC campaign, not a measurement of a specific clip. DuckDuckGoose has not obtained or analysed the circulating videos.
Run that checklist against an audio-grafted clip and it returns a clean result on every item, correctly, because the video is clean. The viewer is not being fooled by a good forgery of a video. They are inspecting a real video, finding — accurately — that it has not been tampered with, and drawing the wrong conclusion from a correct observation. The checklist has not failed to detect a manipulation. It has been pointed at the wrong layer.
Table 4: Which cues survive each construction. The right-hand column is why a checklist aimed at the video layer returns a clean result on an audio-grafted clip.
Lip-sync deserves a specific note, because it is the one cue that might survive, and it is less reliable than it looks. Whether an audio graft produces visible desynchronisation depends almost entirely on shot framing. In a tight head-on shot it may be detectable. But broadcast footage of politicians and economists is not mostly tight head-on shots — it is wide shots, cutaways to an interviewer, over-the-shoulder framing, B-roll of the subject walking or seated while a voice runs over the top. A scammer selecting source footage does not need to defeat lip-sync analysis. They only need to choose a clip where the mouth is not clearly visible, which is most of them. Our guide to how to spot a deepfake sets out the visual cues in full; this incident is a clear illustration of the case where those cues are not the right instrument, and where the audio track has to be examined on its own terms.
The practical consequence is that the detection question has to be asked per-track rather than per-file. A verdict of “the video is authentic” is not a verdict of “the recording is authentic.” A pipeline that analyses video and image content — the problem DuckDuckGoose’s DeepDetector is built for — and a pipeline that analyses voice for synthesis, which is what Waver addresses, are answering two different questions, and on this construction only the second one is being asked about the part that was actually changed. Treating a media-integrity check as a single pass/fail verdict on a file is what allows a clip like this through.
The Funnel: Every Enforcement Point Is Downstream of the Money
The deepfake is the entry point of a staged operation, not the whole of it. ASIC describes the sequence: a social advertisement carrying the fabricated endorsement, a click through to a spoofed news article with invented reader comments and reviews, a counterfeit investment platform with a working dashboard showing fabricated returns on a small initial deposit, then scripted follow-up calls. Bitdefender Labs tracked these campaigns running across Facebook, Instagram, TikTok, X and YouTube.
Every step ASIC can act on happens after the transfer
ASIC describes a staged funnel: a deepfake advertisement, a fabricated news page carrying the endorsement, a counterfeit investment platform, then scripted calls. Removal is a response to infrastructure that has already done its work.
ASIC removed 19,400 scams in FY26, up 182%. That figure is usually presented as evidence of an effective enforcement programme, and as a measure of reach it is. It is also, read the other way, a count of how much fraudulent infrastructure went live and stayed live long enough to require removal. Takedown is a lagging control. It operates on the advertisement after it has been served, on the spoofed article after it has converted, on the fake platform after the deposit has cleared. The 182% growth rate is the more informative number, because it indicates that supply is scaling faster than removal.
Alan Kohler, who is on ASIC’s list, described the experience of trying to get his own likeness removed to ABC News as “like whack-a-mole… it just kept coming back,” and said of the reputational cost: “It’s taken a lifetime to build trust, and it’s so easily lost.” He argued for regulatory intervention, calling the situation “potentially an emergency in the making.” That is a person named on the regulator’s own list describing the removal process as ineffective at the individual level.
There is exactly one point in this funnel where a detection check changes an outcome rather than documenting it: ad review, before the advertisement is served. That is a platform-side control, not a regulator-side one, and not a consumer-side one. Screening paid advertising that features a recognisable public figure making a financial claim is a bounded, tractable problem — a finite set of high-profile faces and voices, checked at submission rather than after complaint. Everything downstream of that gate is cleanup.
What This Means for Platforms, Institutions and Verification Providers
For platforms: the screening question for paid political and financial advertising has to include the audio track independently. A clip whose video passes every authenticity check is not thereby cleared, and a policy written around “manipulated media” that operationalises only visual manipulation will not catch this construction.
For financial institutions: the loss event is a customer-initiated transfer, which means it presents as legitimate. The detection surface is behavioural rather than synthetic-media analysis: a first transfer to a new investment platform, unusual for the account, often following a phone conversation. The deepfake is upstream and invisible from inside the bank.
For identity verification providers: the direct lesson is about layer coverage, and it is the same structural error we have documented elsewhere. A control certified against one attack class is routinely treated as coverage of a category it was never tested for — the pattern described in our comparison of liveness detection versus deepfake detection, and in the analysis of how injection attacks feed deepfakes into verification, where an iBeta-certified system can be transparent to the dominant attack vector. Audio grafting is the same failure in a different domain: a video-integrity check standing in for a media-integrity check. Providers running remote onboarding should also read this alongside how deepfakes enter remote verification flows, since a voice-only manipulation is directly relevant to any verification step conducted over a call.
For regulators: the FY26 numbers make the case that removal volume is the wrong headline metric. Time-to-removal, and the proportion of scam advertising stopped before first impression, describe whether the intervention is working. 19,400 removals and a 182% increase are compatible with a programme that is losing ground.
What We Have Not Verified
Being explicit about the boundary of this analysis, because the argument above depends on one characterisation we have not independently confirmed:
- We have not obtained or analysed the circulating clips. DuckDuckGoose has run no detection process on this material. There are no confidence scores, per-frame findings or artefact observations in this article, because we have not examined the artefacts. The argument here is methodological: if a clip is constructed this way, then visual-cue analysis cannot detect it. That reasoning stands on its own, but it is reasoning, not measurement.
- The audio-graft characterisation comes from secondary reporting. The description of authentic footage with a replaced audio track, and the specific claim that a clip pitched turning A$4,000 into A$40,000 a month on a platform described as “official” and government-guaranteed, is attributed to Guardian reporting and reproduced in secondary coverage. We were not able to retrieve the Guardian article directly. ASIC’s own release does not characterise the clips at this level of technical detail. If some clips in this campaign are fully synthetic rather than audio-grafted, the visual cues would apply to those — the point is that they cannot be relied on to apply to all of them.
- Attribution and infrastructure are unknown to us. We make no claim about who operated this campaign, what tools generated the voice, or where the infrastructure was hosted. Pindrop-style generator attribution requires the artefact.
Frequently Asked Questions
How much did the ASIC deepfake investment scams cost Australians?
Reports to Scamwatch involving the eleven most-impersonated public figures are associated with A$7.4 million in losses during FY26, according to ASIC media release 26-195MR. This is narrower than the A$837.7 million in all investment scam losses reported for calendar 2025, which covers every scam type rather than deepfake impersonation specifically. Because both rest on voluntarily filed reports, they are floors rather than estimates.
Which public figures were impersonated in the ASIC deepfake scams?
ASIC named eleven: Anthony Albanese, Tom Piotrowski, Alan Kohler, Stephen Koukoulas, Jacqui Lambie, Angus Taylor, Dick Smith, Gina Rinehart, Alan Oster, Pauline Hanson and John Laws. The list is concentrated in people with financial or governmental authority rather than general celebrity.
What is an audio-grafted deepfake?
A video where the visual track is genuine, unmodified footage and only the audio has been replaced with synthesised speech in the subject’s cloned voice. Because no pixels are generated, the video carries none of the artefacts that visual deepfake detection and public “spot the fake” advice look for.
Why doesn’t standard deepfake-spotting advice work on these clips?
Nearly all public guidance tests the video track — blinking, lip-sync, skin texture, edge blending, lighting. On an audio-grafted clip the video track is authentic, so those checks pass correctly and the viewer concludes the clip is genuine. Lip-sync is the only cue with any chance of surviving, and whether it shows depends on shot framing, which the attacker chooses.
Did ASIC say the clips were audio-grafted?
No. ASIC’s release describes a rise in deepfake videos of celebrities and politicians without characterising the construction. The audio-graft description comes from press coverage of the campaign, principally Guardian reporting. We flag it as a reported characterisation rather than a verified technical finding.
Has DuckDuckGoose analysed these videos?
No. We have not obtained the circulating clips and have run no detection process on them. This article deliberately contains no detection scores or artefact findings. The analysis is about what the reported construction implies for detection method.
Where in the scam funnel can detection actually prevent a loss?
At ad review, before the advertisement is served. Every later stage — the spoofed news page, the fake platform, the scripted call — sits downstream, and ASIC’s takedown powers operate as removal after the infrastructure has run. That is why 19,400 removals at 182% growth is compatible with the problem getting worse.
Methodology
The figures in this article are drawn from ASIC media release 26-195MR of 17 August 2026 as the primary source, corroborated against ABC News, Bitdefender, FX News Group, Finextra and Finance Magnates. Eight distinct publishers covering this story were identified, including The Guardian. Where sources report different quantities, each is presented separately with its measurement basis and period stated rather than reconciled into a single number. Loss figures derived from voluntary victim reports are treated as lower bounds. Technical characterisations that we could not confirm in a primary or high-authority source are labelled as reported claims in the section above, and no detection findings are asserted, because no detection process was run.
Sources
- ASIC — 26-195MR: ASIC warns scammers are using AI to spin vast webs of deception (primary)
- ABC News — AI deepfake scams an emergency in the making as ASIC reports rise in false investment endorsements
- The Guardian — Deepfake Anthony Albanese used in celebrity scams duping Australians out of $7.4m, Asic warns
- Bitdefender — Top Aussie public figures impersonated in investment scams
- FX News Group — Australian regulator warns public of scammers increasingly using AI for investment fraud
- Finextra — Asic warns of surge in deepfake scams
- Finance Magnates — ASIC Removes Over 19,400 Scams as AI Deepfakes Target Investors
- UA.NEWS — In Australia, scammers are using deepfakes of the prime minister for investment scams
DuckDuckGoose builds deepfake detection for organisations that need to know whether media is synthetic before acting on it — DeepDetector for video and image, Waver for voice. See duckduckgoose.ai for how the detection stack is structured.
Last update: Q3 2026.














