On 20 August 2026 ABC News, working with OCCRP, Swedish broadcaster SVT, Qurium and amaBhungane, traced the money behind cloned ABC News scam pages to a group it names the Sapphire Network — run from central Tel Aviv, active since at least 2021, with call centres linked to six countries. More than 4,000 Australians appear in the network’s own internal spreadsheets, and investigators put losses in the hundreds of millions of dollars.
The synthetic media was documented two months earlier: Facebook advertisements carrying AI-generated images of named Australian public figures, including ABC’s own presenters, funnelling readers into an almost-perfect clone of the ABC News website. That operation is estimated to have stolen at least $350 million globally across more than 3,000 fake investment brands.
Read together, the two investigations describe something more useful than a scam: a four-stage supply chain with a first stage. Every enforcement action in the reporting fires at the last one.
- The attribution is what is new. ABC and OCCRP name the Sapphire Network, place it in central Tel Aviv, and trace payments through registered entities including Trigo XO, Allegiant Holdings Ltd and Finterex Capital. More than 4,000 Australians appear in the network’s own spreadsheets.
- The synthetic media sits at the top of the funnel, not at the transaction. AI-generated images of ABC presenter Sarah Ferguson, Angus Taylor, Jacqui Lambie, Gina Rinehart and others earned the click; a cloned ABC News site earned the trust; call centres in six countries closed the sale.
- Takedown scales with the attack instead of suppressing it. ASIC removed more than 19,000 scams in twelve months, up 182 per cent, and the pipeline kept running. Alan Kohler, reporting his own deepfakes to Meta, called it “whack-a-mole… it just kept coming back”.
- Stage 1 is the only pre-victim control point. The ad creative is the sole stage that exists as a file, in someone else’s system, before any victim has clicked — and the only stage where detection is even possible.
- Nothing here is settled law. No regulator has confirmed an investigation, and Shefi Goldberg, named in the reporting, denies any fraudulent activity.
On 20 August 2026 the Australian Broadcasting Corporation, working with the Organised Crime and Corruption Reporting Project, Swedish broadcaster SVT, the media foundation Qurium and the South African investigative centre amaBhungane, traced the money behind cloned ABC News scam pages to a group it names the Sapphire Network. The network is described as running from central Tel Aviv, active since at least 2021, with call centres linked to Bulgaria, Ukraine, Cyprus, Macedonia, Israel and South Africa. More than 4,000 Australians appear in its own internal spreadsheets. Investigators put total losses in the hundreds of millions of dollars.
The synthetic-media half of this story was already documented. In June, ABC published an investigation into Facebook advertisements carrying AI-generated images of named Australian public figures — its own presenter Sarah Ferguson among them — which led to what it called an almost-perfect clone of the ABC News website. That operation, ABC reported, is estimated to have stolen at least $350 million globally across more than 3,000 fake investment brands.
What changed in August is attribution. For most of the past three years, deepfake investment fraud has been reported as weather: a rising volume of bad advertisements, a rising count of takedowns, a rising loss total. The August investigation reports something structurally different. It describes a deepfake ad supply chain — synthetic creative, a cloned newsroom, offshore call centres, and a chain of registered payment entities — operated as one commercial pipeline with identifiable parts. That is worth reading carefully, because a pipeline has a first stage, and every enforcement action described in three years of this reporting fires at the last one.
An ABC News investigation published on 20 August 2026, with OCCRP, Swedish broadcaster SVT, Qurium and amaBhungane, traced the money behind cloned ABC News scam pages to a group it names the Sapphire Network, run from central Tel Aviv and active since at least 2021. The synthetic-media stage of that operation had already been documented in June. What is new is the attribution: for the first time, the AI-generated ad creative, the cloned newsroom and the payment plumbing are described as one accountable supply chain rather than as separate nuisances.
What the investigation found
Stripped to its findings, the reporting establishes five things.
- A named network with an internal victim ledger. ABC found one victim’s contact details and a specific payment logged in the Sapphire Network’s own spreadsheets, alongside those of another 4,000 Australians. This is not an estimate derived from complaint volumes; it is the operation’s own record-keeping.
- Named corporate plumbing. Payments were traced through registered entities including Trigo XO, GoBe Marketing, MSG Marketing, USC Market Place, Smart Pay, Allegiant Holdings Ltd, Finterex Capital and Ambit Capital.
- A named individual, who denies involvement. Israeli businessman Shefi Goldberg, 43, is identified in the reporting as co-managing director of GoBe Marketing and owner of the Cyprus-registered payment processor Allegiant Holdings. He told reporters “We didn’t have any fraudulent activity” and “I have no ownership, control, or any corporate involvement of any kind with Trigo XO Pty Ltd”, adding of the Cypriot company that he is “merely registered in connection with” it and not involved in its management. Ynetnews reported the same denials.
- Hard individual losses. Two Australian victims named in the reporting as Rodger and Toby lost approximately $125,000 and more than $500,000 respectively.
- No confirmed investigation. An Australian accountant said he had already complained to AUSTRAC because he had “no way to check” that invoices arriving through Trigo XO were legitimate. AUSTRAC said it could not comment on or confirm investigations into individual businesses. No regulator, in any jurisdiction named in the reporting, has confirmed an investigation into any named entity.
That last point matters for how this article is written, and it is worth stating plainly rather than burying: what follows analyses a pipeline described by journalists, not findings established by a court. The denials are part of the record.
Timeline: from cloned newsroom to named network
The two ABC investigations were published two months apart and are usually read separately — one as a media-integrity story, one as a financial-crime story. Read in sequence they describe the same funnel from opposite ends.
Table 1: Timeline of the ABC and OCCRP reporting, from cloned newsroom to named network.
The interesting gap in that timeline is between June and August. In June, ABC could describe the creative and the clone but not the operators. In August it could name the operators and the money but treated the creative as established background. Nobody, in either piece, had commercial reason to ask the question that sits between them: if this is a pipeline, which stage is cheapest to break?
What Is a Deepfake Ad Supply Chain?
A deepfake ad supply chain is a fraud operation in which synthetic media is one specialised input among several, produced and consumed at industrial scale rather than crafted per victim. It is distinguishable from the more familiar single-artefact deepfake attack — the cloned CFO on a video call, the voice-cloned instruction to a treasury team — by division of labour. In a single-artefact attack, one artefact is made for one target and the fraud succeeds or fails on that artefact. In a supply chain, the artefact is advertising inventory: generated in volume, tested against click-through, discarded and regenerated when removed.
The economics of the two are opposites. A bespoke deepfake attack is expensive to produce and catastrophic when it lands, so detection is worth paying for at the moment of the transaction. Industrial synthetic ad creative is nearly free to produce and individually worthless, which means removing any single instance costs the operator almost nothing. Detection that fires per instance, after publication, is therefore competing on the one axis where the attacker has an unlimited budget.
This is a different problem from the one most detection deployments are built for, and it is closer in shape to the injection-attack problem than to the presentation-attack problem — a distinction we set out in our analysis of liveness detection versus deepfake detection. In both cases the control has to sit where the media enters the system, not where a human eventually looks at it.
Reconstructed from the ABC / OCCRP investigation into the group it names the Sapphire Network, and from ABC's earlier reporting on the cloned ABC News site that fed it. Each stage is a separate specialism run by separate operators. Only the first stage is upstream of the victim.
Stage 1: the synthetic creative is the only part that exists before the victim does
ABC’s June reporting identified AI-generated images of ABC presenter Sarah Ferguson, Commonwealth Bank chief executive Matt Comyn, Gina Rinehart, Opposition Leader Angus Taylor, Tasmanian senator Jacqui Lambie, David Koch, Dick Smith and Andrew Forrest. The compositions were specific rather than generic: Taylor with personal bank details displayed by hackers while appearing on Insiders; Taylor confronted by Lambie for talking down to everyday people. The staging mimics a photograph taken from behind the scenes of a television set — the visual grammar of a leak.
Two things follow from that choice of subject matter. The first is that the creative is not trying to deceive a verification system; it is trying to deceive a scroll. It has to survive about a second of attention in a feed, which is a far lower bar than surviving a KYC check, and it explains why the artefacts do not need to be good. The second is that the creative is the only stage of the four that exists before a victim is involved at all. The clone site needs a click. The call centre needs a phone number. The payment chain needs a transfer. The image exists, as a file, in an advertising system, before any of that — held by a party that has already decided to serve it and to charge for it.
Synthetic images produced at this volume also tend to carry the generator-side regularities that make the traces generators leave behind tractable at scale, precisely because nobody is hand-finishing 3,000 brands’ worth of ad creative. Volume is the attacker’s advantage at stage 4 and their weakness at stage 1.
Stage 2: the cloned masthead does the work the deepfake cannot
It would be a misreading of this campaign to say the deepfakes convinced anybody. They did not have to. The advertisement’s job was to earn a click; the conversion happened on a page that had borrowed the ABC’s masthead, layout and typography. ABC described its own clone as almost perfect.
This is the part of the funnel that most cleanly explains why victims in the reporting are not credulous outliers. A reader who correctly distrusts a Facebook advertisement can still extend trust to what appears to be a national broadcaster’s news page, because that is a reasonable thing to do. The fraud is not exploiting a failure of scepticism; it is exploiting the fact that scepticism is applied at the ad and not renewed at the destination. ABC’s earlier reporting on foreign Facebook accounts using AI-generated Pauline Hanson content documents the same borrowing of a trusted identity to carry a claim that could not stand on its own.
Institutionally, the consequence is awkward: the asset being stolen belongs to the publisher, the money is lost by the consumer, the distribution is sold by the platform, and none of those three parties owns the control that would stop it.
Stages 3 and 4: the human end, where all the enforcement lives
From the click onward there is no synthetic media in the reporting at all. Victims were handed to operators posing as professional brokers, shown fabricated profit screens, moved from a small opening deposit to progressively larger transfers, and then met with new fees when they tried to withdraw. Ynetnews reports typical opening registration fees of around $250. The pattern is ordinary boiler-room fraud, executed by people, in call centres, in six named jurisdictions.
Stage 4 is corporate. Payments moved through registered entities in multiple jurisdictions, including a Cyprus-registered payment processor. This is where the fraud becomes legible to the financial system, and also where it becomes hardest to act on: the accountant in ABC’s account was not confused about whether something was wrong, he was unable to verify invoices, which is a different and less actionable problem.
Table 2: The four stages of the funnel, the evidence for each, and the nearest control currently available at that stage.
Set out this way, one asymmetry is hard to miss. Three of the four stages are labour, geography and corporate registration — expensive to build, slow to move, but well outside the reach of any detection technology. The one stage that is a media file, and therefore the one stage where detection is even possible, is also the one stage that sits before the victim. It is the only place in the pipeline where a control would be cheap and preventative rather than expensive and remedial. It is also, on the evidence of the reporting, the only stage nobody is inspecting.
Why takedown is structurally the wrong control point
Australia has an unusually good natural experiment running on this question, because the enforcement effort is real and the numbers are published. ASIC reported on 17 August 2026 that it had removed more than 19,000 scams in twelve months, a 182 per cent increase on the previous year, and more than 33,400 over three years. ASIC chair Sarah Court said “AI is significantly exacerbating the challenges in a range of ways”. Australians lost more than $2 billion to scams in 2025, of which investment scams were more than 38 per cent — $837.7 million.
A 182 per cent increase in removals is a serious operational achievement. It is also, read as a control-effectiveness measure, evidence of the opposite of what it appears to show. Takedown volume is a function of how much material is published, not of how much reaches a victim. A control that scales with the attack rather than suppressing it is a cost centre, not a defence.
The most useful testimony on this comes from someone who ran the experiment personally. ABC finance presenter Alan Kohler, whose likeness was used in deepfake videos promoting fake schemes, described reporting removals to Meta as “like whack-a-mole… it just kept coming back”, and said the situation is “really potentially an emergency in the making”. Kohler is a well-known public figure with direct access to the platform’s reporting channels, acting on his own likeness with maximum motivation. That is the strongest possible test case for per-instance removal, and it failed. If the best-resourced complainant in the country cannot outpace regeneration, the mechanism is not under-used; it is mis-sited.
Table 3: Where each available control fires relative to the synthetic creative, and what the reporting shows about its effect.
The regeneration asymmetry is the whole argument. Removing one advertisement costs the operator the marginal cost of generating another, which for synthetic creative rounds to zero. Screening the same advertisement before it is served costs the operator the entire campaign, because the pipeline behind it — the clone site, the call centre shift, the payment entity — is idle without traffic. Same detection capability, applied at two points, with completely different economics for the attacker.
None of which requires new legal ground to be plausible. The Warsaw Court of Appeal, in the Meta litigation over fraudulent advertisements using Rafał Brzoska’s likeness, reasoned that platforms inspect advertising content before publication, approve campaigns, supply targeting and take payment. Whatever one makes of the liability conclusion, the factual premise is the one that matters here: a pre-publication stage exists, it holds the creative, and it already decides whether the creative runs. The question this campaign puts is not whether such a stage could screen for synthetic media. It is why it does not.
What this means for platforms, publishers and financial institutions
For platforms. Ad review is already a pre-publication inspection stage that holds the artefact. Adding synthetic-media analysis to a stage that exists is a different proposition from building a new one, and it is the only intervention in this pipeline that touches the attacker’s unit economics instead of their inventory. Meta did not respond to ABC’s multiple requests for comment in June, and whether platform ad review performs any synthetic-media analysis today is not public.
For publishers. The masthead is the asset under attack, and the publisher is the party with no control surface at all — it neither serves the advertisement nor hosts the clone. Practically, that argues for treating brand-clone detection and synthetic-likeness monitoring of on-air staff as a security function rather than a communications one. ABC’s own presenters were the creative.
For banks and payment firms. Stage 4 is where these losses currently surface, which means they arrive as disputes rather than as preventable events. The accountant’s complaint to AUSTRAC is the shape of the problem: the signal existed, the verification capability did not. Institutions worried about the same funnel arriving through their own onboarding — rather than through a call centre — should read this alongside how injection attacks feed deepfakes into verification and what happens when deepfakes enter remote verification flows, because the same synthetic-media supply that fills an ad account also fills an onboarding queue.
DuckDuckGoose builds detection for exactly this class of artefact: Phocus analyses AI-generated still images, which is what stage 1 of this pipeline consists of, and the analysis is designed to be explainable enough to support an accept-or-reject decision at machine speed rather than a human review afterwards. That distinction — a decision at the gate versus an opinion after the fact — is the difference between the two rows at the bottom of Table 3.
What we have not verified
Several things in this account are reported rather than established, and it is worth being explicit about which.
- ABC’s June reporting documents the AI-generated ad creative and the cloned site; its August reporting traces the money from those scam pages to the Sapphire Network. The reporting does not state that the Sapphire Network itself produced the synthetic images. The pipeline described here follows ABC’s own sequencing of the two investigations, not a stated finding of common production.
- The $350 million figure is ABC’s estimate for the wider fake-ABC-News scam operation, and the “hundreds of millions” figure is attributed to investigators assessing the Sapphire Network. They are different scopes, they are not additive, and the currency of the $350 million global figure is not specified in the reporting.
- No court has ruled on any allegation described here, and no regulator has confirmed an investigation into any named individual or entity. Shefi Goldberg denies any fraudulent activity and denies ownership or control of Trigo XO Pty Ltd.
- Whether platform advertising review performs any synthetic-media analysis is not publicly documented. The argument made here concerns where a control would sit, not what any platform currently does.
Frequently Asked Questions
What is the Sapphire Network?
The Sapphire Network is the name ABC News gave, in a 20 August 2026 investigation with OCCRP, SVT, Qurium and amaBhungane, to an alleged investment-fraud operation run from central Tel Aviv and active since at least 2021. More than 4,000 Australians appear in its internal spreadsheets, and investigators estimate losses in the hundreds of millions of dollars. Call centres have been linked to Bulgaria, Ukraine, Cyprus, Macedonia, Israel and South Africa. No court has ruled on the allegations.
Were deepfakes used in the Sapphire Network scam?
ABC documented AI-generated images of named Australian public figures in the Facebook advertising that led victims to a cloned ABC News website, and separately traced the money from those scam pages to the Sapphire Network. The reporting does not state that the network produced the images itself. The synthetic media is at the top of the funnel; from the phone call onward, the reporting describes conventional boiler-room fraud carried out by people.
Why does removing deepfake scam ads not stop the fraud?
Because removal fires after publication and costs the operator only the price of generating a replacement, which for synthetic ad creative is close to nothing. ASIC removed more than 19,000 scams in twelve months, up 182 per cent, and the funnel kept running; ABC presenter Alan Kohler described reporting his own deepfakes to Meta as “whack-a-mole… it just kept coming back”. Screening the same creative before it is served denies the whole campaign its traffic instead of denying one advertisement its slot.
How much have deepfake investment scams cost Australians?
Australians lost more than $2 billion to scams in 2025, of which investment scams accounted for more than 38 per cent, or $837.7 million, according to figures reported by ABC News on 17 August 2026. Separately, ABC estimated in June 2026 that the fake-ABC-News scam operation had stolen at least $350 million globally across more than 3,000 fake investment brands. These figures cover different scopes and should not be added together.
Who is responsible for stopping fraudulent ads that use a real person’s face?
No single party currently holds the control. The publisher owns the impersonated brand but neither serves the advertisement nor hosts the clone site; the consumer bears the loss; the platform sells the distribution and operates the only pre-publication stage that holds the creative. For the regulatory dimension of that question, see our analysis of what is changing in deepfake regulation in 2026 and of AI Act Article 50 and explainable detection.
Methodology
This analysis is built on primary reporting read directly rather than on syndicated summaries. The core sources are three ABC News investigations — the 20 August 2026 attribution piece produced with OCCRP, SVT, Qurium and amaBhungane; the 23 June 2026 investigation into the cloned ABC News site and its Facebook advertising; and the 17 August 2026 report on ASIC’s impersonation-scam findings — corroborated against independent pickup in the Jerusalem Post, Ynetnews and Finance Magnates.
Figures are quoted at the scope the original source gave them, and where two figures describe different scopes they are kept separate rather than combined. Where a source qualified a number as an estimate, that qualification is carried through. Allegations against named individuals and companies are presented as allegations, with denials included. The structural argument about control points is ours; the facts it rests on are attributed. No media artefact from this campaign was obtained or analysed for this article, and no detection output is reported here.
Sources
- ABC News — Fake ABC News articles are promoting scams. The money leads to an international fraud network (20 August 2026)
- ABC News — The fake ABC News articles trying to sell you a scam (23 June 2026)
- ABC News — AI deepfake scams ‘an emergency in the making’ as ASIC reports rise in false investment endorsements (17 August 2026)
- The Jerusalem Post — Australian investigation uncovers alleged Israeli investment fraud network
- Ynetnews — Thousands of Australians targeted in investment scam network allegedly operating from Tel Aviv
- Finance Magnates — Fake News Articles, Over 4,000 Aussie Victims: An Israeli Network Behind Investment Fraud
- ABC News — Foreign Facebook accounts using AI Pauline Hanson to manipulate Australians (11 March 2026)
DuckDuckGoose AI builds explainable deepfake detection for images, video and audio. If you are assessing where synthetic-media screening should sit in an advertising, onboarding or verification pipeline, see duckduckgoose.ai.
Last update: Q3 2026.














