<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>privacy Archives &#8211; Mark8ng.com</title>
	<atom:link href="https://www.mark8ng.com/tag/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.mark8ng.com/tag/privacy/</link>
	<description>Entertainment, Research, Current Affairs.</description>
	<lastBuildDate>Tue, 18 Aug 2026 19:47:08 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Scammers Now Build a Whole Brand Before They Steal Anything</title>
		<link>https://www.mark8ng.com/deepfake-brand-impersonation-defence/</link>
		
		<dc:creator><![CDATA[Mark8ng Editorial]]></dc:creator>
		<pubDate>Tue, 18 Aug 2026 19:47:08 +0000</pubDate>
				<category><![CDATA[Responsible AI]]></category>
		<category><![CDATA[brand protection]]></category>
		<category><![CDATA[deepfakes]]></category>
		<category><![CDATA[marketing operations]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[scams]]></category>
		<guid isPermaLink="false">https://www.mark8ng.com/deepfake-brand-impersonation-defence/</guid>

					<description><![CDATA[<p>We spent twenty years training people to check before they buy. Search the company. Read the reviews. See if the press covered it. Look for a real address. Scammers read</p>
<p>The post <a href="https://www.mark8ng.com/deepfake-brand-impersonation-defence/">Scammers Now Build a Whole Brand Before They Steal Anything</a> appeared first on <a href="https://www.mark8ng.com">Mark8ng.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>We spent twenty years training people to check before they buy. Search the company. Read the reviews. See if the press covered it. Look for a real address.</p>
<p>Scammers read the same advice and built for it.</p>
<h2>What the takedown numbers describe</h2>
<p>Australia&#8217;s corporate regulator published its scam takedown figures on 17 August. In FY26, ASIC removed more than 19,400 online scams, up 182% on the previous year&#8217;s 6,915. Fake investment platforms accounted for 7,051 of those, up 151%. Phishing hyperlink takedowns rose 279% to 5,476. Crypto investment scams rose about 30%, to 3,106. Across three years of running the capability, the total is over 33,400.</p>
<p>Those are enforcement numbers, but read as marketing data they describe something specific. This is not a spray of crude fake pages. ASIC&#8217;s description of the method is that scammers <a href="https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-195mr-asic-warns-scammers-are-using-ai-to-spin-vast-webs-of-deception" target="_blank" rel="noopener noreferrer" style="color:#DD3333;text-decoration:underline;">create scam brands with unique phrases and a supporting online footprint</a>: news articles, positive reviews, ads and websites that reinforce each other. Deepfake video of a recognisable person sits on top. Then scripted phone calls, a convincing fake platform, and small early payouts to build trust.</p>
<p>In Australia the impersonated names included the Prime Minister, a former senator, a well-known finance presenter and several business figures. Scamwatch tied $7.4 million in reported losses to those impersonations in a single year. ASIC also notes the roster changes with the news cycle, which tells you the operation is being actively managed rather than set and forgotten.</p>
<h2>The uncomfortable part for marketers</h2>
<p>Every trust signal in that list is one your own marketing team is trying to build. Consistent brand language. Third-party coverage. Reviews. A recognisable face. Ads on platforms people already trust. Enough surface area that a search returns a coherent picture.</p>
<p>The attacker&#8217;s advantage is that generating all of it now costs almost nothing, and they do not need it to survive scrutiny for years. They need it to survive one anxious evening of Googling.</p>
<p>Which means the &#8220;do your own research&#8221; step, the one every consumer education campaign ends on, has quietly become the moment of maximum vulnerability. The victim is not careless. The victim is being careful in exactly the way we taught them, against a target built to reward that behaviour.</p>
<p>You cannot out-content someone who can generate content faster than you can.</p>
<h2>What actually works, and it is not what most brands try</h2>
<p>The instinct when a brand finds a fake version of itself is to publish a warning post. It helps a little. It also ranks below the scam&#8217;s ad spend, and it only reaches people already on your properties, who are not the ones at risk.</p>
<p>The thing buried in ASIC&#8217;s release is far more useful. The regulator is asking licensed financial businesses to register their real website addresses on ASIC&#8217;s public registers so consumers can verify a site against an official source. That is the actual defence, and the principle generalises well beyond financial services: put the verifiable version of your identity somewhere a scammer cannot publish to.</p>
<p>For most businesses that means being deliberate about a small number of channels nobody else can write into. Your entry on an official register or licensing body. A verified profile on a platform that checks identity. A domain that matches your legal name, held for years, easy to say out loud on a phone call. A single canonical &#8220;how we will and will not contact you&#8221; page you can point people to.</p>
<p>The test is simple. If a customer rang you tomorrow and said someone was selling your product at half price on a site that looked exactly like yours, what would you tell them to check that a scammer could not fake within a day? If the answer is your reviews, your press mentions, or your social following, you do not currently have an answer.</p>
<h2>The takedown sequence, before you need it</h2>
<p>Small teams discover impersonation on a Friday and then lose a weekend working out who to email. Write this down now, while it is theoretical.</p>
<ul>
<li><strong>Evidence first.</strong> Screenshots with visible URLs and timestamps, the ad if there is one, and the platform&#8217;s ad library entry. Takedown forms ask for this and stall without it.</li>
<li><strong>Registrar and host, not just the platform.</strong> A WHOIS lookup and an abuse report to the host often moves faster than a platform&#8217;s brand form, and it kills the destination rather than one ad.</li>
<li><strong>Platform brand-protection channels.</strong> Most large ad platforms have a separate, faster route for trademark and impersonation complaints than the general report button. Find the link before you need it.</li>
<li><strong>Your own customers, quickly and calmly.</strong> One email, one pinned post, one line on the site. Say what the real domain is. Do not link to the fake one.</li>
<li><strong>The relevant regulator.</strong> In financial services, telecoms and health this genuinely accelerates removal. In other sectors it may do nothing, so set expectations accordingly.</li>
</ul>
<p>This may not be worth building out if you are a local business with no public profile and no advertising spend, because impersonation follows recognition. The moment it becomes worth building is the moment your founder starts appearing on camera or your ads start running at scale. Those are the same conditions that make you worth copying.</p>
<h2>The part that will not be solved by process</h2>
<p>There is a real limit here and it is worth saying plainly. A takedown removes one site. The operation spins up another. ASIC removed 19,400 in a year and the honest interpretation of a 182% increase is not that enforcement is winning, it is that supply is growing faster than removal.</p>
<p>So the defensive posture that scales is not detection. It is making verification cheap for your customer. A brand that has told its audience, repeatedly and boringly, &#8220;we will only ever contact you from this domain, we will never ask for payment by transfer, check us on this register&#8221; is harder to impersonate profitably than a brand with twice the following and no such habit.</p>
<p>Boring, repeated, specific. It is the least exciting brand work there is, and it is the only kind an AI-generated clone cannot copy faster than you can publish it.</p>
<p><em>Editor&#8217;s note: This area changes quickly, so check the latest platform policy before making compliance decisions.</em></p>
<p>The post <a href="https://www.mark8ng.com/deepfake-brand-impersonation-defence/">Scammers Now Build a Whole Brand Before They Steal Anything</a> appeared first on <a href="https://www.mark8ng.com">Mark8ng.com</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1226</post-id>	</item>
		<item>
		<title>A Regulator Just Ruled on the Design of a Consent Box. Read Your Cookie Banner Again.</title>
		<link>https://www.mark8ng.com/apple-consent-prompt-ruling-marketers/</link>
		
		<dc:creator><![CDATA[Mark8ng Editorial]]></dc:creator>
		<pubDate>Tue, 18 Aug 2026 19:46:36 +0000</pubDate>
				<category><![CDATA[Tech Industry News]]></category>
		<category><![CDATA[advertising regulation]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[consent]]></category>
		<category><![CDATA[marketing operations]]></category>
		<category><![CDATA[privacy]]></category>
		<guid isPermaLink="false">https://www.mark8ng.com/apple-consent-prompt-ruling-marketers/</guid>

					<description><![CDATA[<p>A competition regulator spent four years arguing about a pop-up. Not whether consent was collected. Whether the box was designed to make you say yes. On 17 August the Bundeskartellamt,</p>
<p>The post <a href="https://www.mark8ng.com/apple-consent-prompt-ruling-marketers/">A Regulator Just Ruled on the Design of a Consent Box. Read Your Cookie Banner Again.</a> appeared first on <a href="https://www.mark8ng.com">Mark8ng.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A competition regulator spent four years arguing about a pop-up. Not whether consent was collected. Whether the box was designed to make you say yes.</p>
<p>On 17 August the Bundeskartellamt, Germany&#8217;s competition authority, closed its case against Apple&#8217;s App Tracking Transparency Framework after accepting binding commitments. The finding underneath it is the part marketers should copy out and keep, because it has almost nothing to do with Apple.</p>
<h2>What the regulator actually objected to</h2>
<p>Apple&#8217;s framework requires third-party apps to get an extra layer of consent, on top of data protection consent, before using cross-company data for personalised ads. Apple&#8217;s own apps sit outside that framework and use their own prompt.</p>
<p>The authority&#8217;s assessment was that the two prompts were not equivalent, and that the gap was bigger than the underlying data processing could justify. In its words, the wording, design and selection options in Apple&#8217;s own request had the potential to encourage consent, while the request Apple wrote for everyone else had the potential to discourage it. Third-party apps also had to ask more than once in some cases, even where valid data protection consent already existed.</p>
<p>So Apple will now remove what the regulator called possibly discouraging symbols and wording, and the prompts will be, in the <a href="https://www.bundeskartellamt.de/SharedDocs/Meldung/EN/Pressemitteilungen/2026/08_17_2026_Apple_ATTF.html" target="_blank" rel="noopener noreferrer" style="color:#DD3333;text-decoration:underline;">Bundeskartellamt&#8217;s phrasing</a>, neutral in terms of content, wording and layout. Apple has four months to implement. The commitments run for seven years with an independent monitoring trustee, and although this was a German case, the changes are expected to reach most of the EU.</p>
<p>Worth noting the price of getting there ahead of Germany: French and Italian authorities fined Apple 150 million and 98.6 million euros respectively over the same framework.</p>
<h2>What most marketers will take from this, and why it is the wrong lesson</h2>
<p>The obvious read is &#8220;iOS opt-in rates might improve, so app install campaigns get cheaper.&#8221; Maybe. Nobody should build a Q4 plan on it. Apple has four months, testing happens with app publishers first, and consent behaviour is stubborn in ways that survive prompt redesigns.</p>
<p>The lesson worth having is the standard itself. A regulator has now written down, in a binding decision, that asymmetric consent design is the problem. Not missing consent. Not unlawful processing. The symbols. The wording. The layout. The number of times you ask.</p>
<p>Now go and look at your own cookie banner.</p>
<p>Most small business sites are running a banner where Accept All is a filled button in the brand colour and Reject is grey text, or a link, or one layer down behind Manage Preferences. That is the exact shape of the thing Apple just spent four years defending and lost. The German case was argued under competition law rather than data protection law, so it does not directly create a new obligation for your site. But regulators read each other, and Andreas Mundt was explicit about the goal: users who do not want their data used must be able to make an equally free and informed decision as users who do.</p>
<p>Consent design is now a documented enforcement target, not a dark pattern that everyone quietly tolerates.</p>
<h2>The bit that is actually good news</h2>
<p>Buried in the commitments is something publishers have wanted for years. App publishers and content providers will get more scope inside the prompt to explain what personalised advertising means for their offering and their business model. Apple will also let publishers combine its required consent request with the ones required under data protection law, instead of stacking them.</p>
<p>That turns a compliance screen into a piece of copy. Someone has to write it.</p>
<p>This is a genuinely unusual opportunity, and I expect most teams to waste it. The instinct will be to write something manipulative, because the metric on the dashboard is consent rate. The regulator has pre-emptively closed that door: Mundt said plainly that the aim is not to achieve the highest possible levels of consent. Push too hard on the wording and you rebuild the problem from the other side.</p>
<p>The version that works is boring and specific. Not &#8220;we value your privacy&#8221; but &#8220;ads pay for this app, personalised ads pay roughly twice as much, and that is the difference between free and a subscription.&#8221; People respond to a real trade-off explained honestly far better than they respond to reassurance.</p>
<h2>A simple action plan</h2>
<p>Three things, in order, none of which require a lawyer to start.</p>
<ol>
<li><strong>Screenshot your consent banner and look at it as a stranger.</strong> Are the two options equally easy to see, equally easy to click, equally weighted in colour and size? If a reasonable person would say the design is steering, it is steering.</li>
<li><strong>Count the asks.</strong> If a user has already consented once, does something ask them again on the next page or the next session? Repeat prompting was one of the specific complaints in this case.</li>
<li><strong>Write the honest explanation now.</strong> One or two sentences on why you want the permission and what the user gets. You will need it for app prompts within four months, and it improves your web banner today.</li>
</ol>
<p>If everything is optimised for the yes, nothing is really consented. That is the direction the enforcement is moving, and the teams that get there voluntarily will spend a lot less on the retrofit than the ones who wait.</p>
<p>For advertisers, this sits alongside a broader pattern of platforms controlling the interface between you and your customer, which is the same tension behind <a href="https://www.mark8ng.com/google-ai-ad-labels-advertisers/">Google labelling AI ads without an opt-out</a>. You do not own the box your message appears in. You only own what it says.</p>
<p><em>Editor&#8217;s note: This area changes quickly, so check the latest platform policy before making compliance decisions.</em></p>
<p>The post <a href="https://www.mark8ng.com/apple-consent-prompt-ruling-marketers/">A Regulator Just Ruled on the Design of a Consent Box. Read Your Cookie Banner Again.</a> appeared first on <a href="https://www.mark8ng.com">Mark8ng.com</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1225</post-id>	</item>
	</channel>
</rss>
