We spent twenty years training people to check before they buy. Search the company. Read the reviews. See if the press covered it. Look for a real address.
Scammers read the same advice and built for it.
What the takedown numbers describe
Australia’s corporate regulator published its scam takedown figures on 17 August. In FY26, ASIC removed more than 19,400 online scams, up 182% on the previous year’s 6,915. Fake investment platforms accounted for 7,051 of those, up 151%. Phishing hyperlink takedowns rose 279% to 5,476. Crypto investment scams rose about 30%, to 3,106. Across three years of running the capability, the total is over 33,400.
Those are enforcement numbers, but read as marketing data they describe something specific. This is not a spray of crude fake pages. ASIC’s description of the method is that scammers create scam brands with unique phrases and a supporting online footprint: news articles, positive reviews, ads and websites that reinforce each other. Deepfake video of a recognisable person sits on top. Then scripted phone calls, a convincing fake platform, and small early payouts to build trust.
In Australia the impersonated names included the Prime Minister, a former senator, a well-known finance presenter and several business figures. Scamwatch tied $7.4 million in reported losses to those impersonations in a single year. ASIC also notes the roster changes with the news cycle, which tells you the operation is being actively managed rather than set and forgotten.
The uncomfortable part for marketers
Every trust signal in that list is one your own marketing team is trying to build. Consistent brand language. Third-party coverage. Reviews. A recognisable face. Ads on platforms people already trust. Enough surface area that a search returns a coherent picture.
The attacker’s advantage is that generating all of it now costs almost nothing, and they do not need it to survive scrutiny for years. They need it to survive one anxious evening of Googling.
Which means the “do your own research” step, the one every consumer education campaign ends on, has quietly become the moment of maximum vulnerability. The victim is not careless. The victim is being careful in exactly the way we taught them, against a target built to reward that behaviour.
You cannot out-content someone who can generate content faster than you can.
What actually works, and it is not what most brands try
The instinct when a brand finds a fake version of itself is to publish a warning post. It helps a little. It also ranks below the scam’s ad spend, and it only reaches people already on your properties, who are not the ones at risk.
The thing buried in ASIC’s release is far more useful. The regulator is asking licensed financial businesses to register their real website addresses on ASIC’s public registers so consumers can verify a site against an official source. That is the actual defence, and the principle generalises well beyond financial services: put the verifiable version of your identity somewhere a scammer cannot publish to.
For most businesses that means being deliberate about a small number of channels nobody else can write into. Your entry on an official register or licensing body. A verified profile on a platform that checks identity. A domain that matches your legal name, held for years, easy to say out loud on a phone call. A single canonical “how we will and will not contact you” page you can point people to.
The test is simple. If a customer rang you tomorrow and said someone was selling your product at half price on a site that looked exactly like yours, what would you tell them to check that a scammer could not fake within a day? If the answer is your reviews, your press mentions, or your social following, you do not currently have an answer.
The takedown sequence, before you need it
Small teams discover impersonation on a Friday and then lose a weekend working out who to email. Write this down now, while it is theoretical.
- Evidence first. Screenshots with visible URLs and timestamps, the ad if there is one, and the platform’s ad library entry. Takedown forms ask for this and stall without it.
- Registrar and host, not just the platform. A WHOIS lookup and an abuse report to the host often moves faster than a platform’s brand form, and it kills the destination rather than one ad.
- Platform brand-protection channels. Most large ad platforms have a separate, faster route for trademark and impersonation complaints than the general report button. Find the link before you need it.
- Your own customers, quickly and calmly. One email, one pinned post, one line on the site. Say what the real domain is. Do not link to the fake one.
- The relevant regulator. In financial services, telecoms and health this genuinely accelerates removal. In other sectors it may do nothing, so set expectations accordingly.
This may not be worth building out if you are a local business with no public profile and no advertising spend, because impersonation follows recognition. The moment it becomes worth building is the moment your founder starts appearing on camera or your ads start running at scale. Those are the same conditions that make you worth copying.
The part that will not be solved by process
There is a real limit here and it is worth saying plainly. A takedown removes one site. The operation spins up another. ASIC removed 19,400 in a year and the honest interpretation of a 182% increase is not that enforcement is winning, it is that supply is growing faster than removal.
So the defensive posture that scales is not detection. It is making verification cheap for your customer. A brand that has told its audience, repeatedly and boringly, “we will only ever contact you from this domain, we will never ask for payment by transfer, check us on this register” is harder to impersonate profitably than a brand with twice the following and no such habit.
Boring, repeated, specific. It is the least exciting brand work there is, and it is the only kind an AI-generated clone cannot copy faster than you can publish it.
Editor’s note: This area changes quickly, so check the latest platform policy before making compliance decisions.
