Scammers Used a Deepfake of Australia's PM to Steal $7.4 Million — And Your Social Feed Is the Delivery Mechanism
AI audio grafted onto real PM footage fooled investors out of $7.4M AUD. Regulators call it 'an emergency in the making' — and the technique defeats standard detection advice.
The Scam That Broke Every Rule You Were Taught to Follow
You've heard the advice a hundred times: look for the blinking, check the lip-sync, watch for blurry edges around the face. That playbook is now obsolete. A new deepfake technique has arrived that leaves the real video completely intact — and replaces only the voice.
Scammers used it to steal AUD $7.4 million (~$5.3 million USD) from ordinary Australians. The face they used belonged to Prime Minister Anthony Albanese. The video was real. The words coming out of his mouth were not.
This is not a future threat. It is happening now, on your social media feed, in the same scroll between a recipe video and a friend's vacation photo.
What 'Audio Grafting' Actually Is — And Why It Matters
Traditional deepfakes swap or synthesize an entire face. That's what gave us the blurry hairlines and the uncanny valley eyes. Detection tools — and human intuition — learned to catch those tells.
Audio grafting is different. Scammers take authentic, publicly available video of a trusted person — a press conference, a TV interview, a keynote — and strip the audio track. They replace it with AI-synthesized voice that sounds almost identical to the real person. The face, the gestures, the lighting, the lip movements: all genuine footage. Only the words change.
The result passes every visual check you know. The blinking looks natural because it is natural. The face moves authentically because it is authentic. Standard detection software trained on face-swap artifacts finds nothing wrong.
Australia's financial regulator, ASIC, flagged this on August 17, 2026, calling AI-powered investment scams "an emergency in the making." The Albanese campaign was paired with deepfakes of nine other Australian public figures — all promising returns of $40,000 per month from a $4,000 entry investment. The ads ran on mainstream social media platforms, where most people lower their guard because the content looks indistinguishable from legitimate news clips.
The Numbers Are Staggering — And Accelerating
ASIC removed a record 19,400 fraudulent websites in its last fiscal year. That is up 182% year-over-year. Regulators directly attribute the acceleration to AI: it is now faster and cheaper to produce convincing scam content than it has ever been, and the volume is outpacing every takedown effort.
Think about what that means for you personally. Social media platforms serve millions of ads per day. Regulators cannot review them all. AI can generate a new scam campaign faster than a human team can shut the old one down. By the time an ad is reported, reviewed, and removed, it has already reached tens of thousands of people.
The delivery mechanism is your social feed. The trust mechanism is a face you recognize. The closing argument is a number that sounds life-changing: $40,000 a month.
Why Your Brain Is the Target
There is a reason scammers use public figures rather than inventing fictional spokespeople. Familiarity creates trust. When you see someone you recognize — a prime minister, a financial journalist, a tech CEO — your brain skips the scrutiny step. You don't evaluate the claim the same way you would if a stranger said it.
Audio grafting weaponizes that shortcut. The face is real. The credibility is borrowed. The urgency ("limited spots," "exclusive access") is engineered.
The single most dangerous sentence in any investment ad is: "I've tried it myself and it works."
When a trusted face says it, in what appears to be authentic footage, the scam becomes exceptionally hard to resist.
How to Protect Yourself — Starting Today
These are concrete steps, not vague advice.
Before You Trust Any Investment Claim Online
- Treat any "investment opportunity" in a social ad as fraudulent by default. Legitimate financial products are not sold through social media video ads featuring celebrities. Full stop.
- Search the person's name plus "scam" or "fake ad" before engaging. ASIC, the FTC, and most national financial regulators publish updated scam alerts. Take 90 seconds.
- Go to the source directly. If PM Albanese were genuinely promoting an investment platform, it would be on his official government website. If a CEO were endorsing a product, it would be in their verified social accounts and press releases — not a paid ad you stumbled across.
Harden Your Financial and Personal Security
- Enable two-factor authentication (2FA) on every financial account. If a scammer does get your details, 2FA buys time. Better yet, switch to passkeys where your bank supports them — they are phishing-resistant by design.
- Place a credit freeze with all three major bureaus (Equifax, Experian, TransUnion in the US; equivalent services exist in Australia, UK, and Canada). A freeze is free and stops anyone from opening new credit in your name even if they have your personal data.
- Use a data removal service to reduce how much personal information is available to scammers in the first place. Many run as annual subscriptions; some states have free opt-out tools for data brokers.
When Something Feels Off
- Call a real person. If someone you know shares an investment opportunity online, call them — don't message them through the same platform. Accounts get hacked; voices are harder to fake in a live call (for now).
- Report the ad immediately. Every platform has a "report ad" function. Use it. Volume of reports is one of the signals that triggers faster review.
- Never transfer money under time pressure. Urgency is a manufactured tool. A real investment opportunity does not expire in 24 hours.
Do This Now
- Do not trust investment ads on social media regardless of whose face appears in them.
- Search for scam alerts before engaging with any financial claim you see online.
- Freeze your credit if you haven't already — it takes under 10 minutes per bureau.
- Enable 2FA or passkeys on your bank, email, and brokerage accounts today.
- Report suspicious ads on every platform you see them — it takes 30 seconds and protects the next person.
The scammers who stole $7.4 million from Australians didn't need a sophisticated hack. They needed a real video clip, an AI voice tool, and a social media ad budget. The technology barrier is effectively zero. The trust barrier — the thing standing between them and your money — is you.
Know what they're doing. That knowledge is the only detection tool that still works.
Sources
Common Questions About AI Threats
What is AI voice cloning and how are criminals using it?
AI voice cloning can replicate a person's voice from as little as three seconds of audio. Criminals use it to impersonate family members in fake emergency calls, executives requesting wire transfers, or officials demanding payment. Always verify urgent calls by hanging up and calling back on a known number.
How can I tell if a video is a deepfake?
Look for unnatural blinking, blurry edges around the hairline, audio that mismatches lip movements, and inconsistent lighting between face and background. Tools like Deepware Scanner can help detect deepfakes.
Are AI-powered phishing emails harder to detect?
Yes. AI generates grammatically perfect, personalized phishing emails using details scraped from LinkedIn or social media. Verify unexpected requests involving money or passwords by calling the sender directly on a known number.
More in ai threats
Stay invisible. Follow @hack_decoded
