Skip to main content

17 July 2026

AI Safety

How to Spot AI Deepfake Scams: An Australian Guide

A practitioner's guide to deepfake scams in Australia: the video, voice, and investment-ad tells, why detection is getting harder, and the process that actually protects you.

How to Spot AI Deepfake Scams: An Australian Guide, AI Safety, Deepfakes analysis by Amjid Ali.

Nearly nine in ten Australians reckon they can spot an AI scam. When they were actually tested, they got it right 42% of the time. That gap is exactly where the money is being lost.

I work with organisations across Melbourne on AI safety and security, and the question I get most from clients, family, and friends this year is some version of “how would I even know?” So let me give you the honest answer up front.

You spot an AI deepfake scam not by trusting your eyes or ears, but by treating any urgent, unexpected request for money or personal information as a fake until you have verified the person through a second channel you already trust. Everything else in this guide supports that one habit.

How bad is the deepfake scam problem in Australia?

The scale is genuinely confronting. Australians reported $2.18 billion in scam losses in 2025, and a huge slice of that, $837.7 million, went to investment scams, many of them fronted by AI deepfakes of people you would recognise. What worries me more is that reported losses are falling while dollar losses rise, which usually means the scams are getting more targeted and more convincing, not less common.

Then there is the detection gap. Commonwealth Bank ran research where nearly nine in ten Australians said they were confident they could recognise an AI-generated scam, yet when they were shown real and AI-generated images and asked to tell them apart, they were correct only 42% of the time. That is worse than guessing. Over-65s did only marginally worse than younger people, so please do not assume this is a problem that only affects your parents. It affects all of us.

The uncomfortable takeaway: confidence in spotting deepfakes is not a defence. It is a liability, because it makes you act instead of verify.

What are the main types of deepfake scams?

Deepfakes are not one thing. They show up in four distinct shapes, and each has its own tell and its own defence. Here is the quick reference I give clients.

Deepfake typeHow it targets youTell-tale signsYour defence
Celebrity investment adA fake video of a well-known Australian spruiking a trading bot or crypto platformToo-good returns, pressure to act now, off-platform links, odd lip syncNever invest from an ad. Check the person’s real, verified channels
Voice-cloning callA cloned voice of family in “trouble” or a boss ordering a paymentUrgency, secrecy, unusual payment method, refusal to verifyHang up. Call back on a known number. Use a family safe word
Fake video callA live meeting where colleagues on screen are AI-generatedRequests to bypass normal approvals, no small talk, camera “glitches”Confirm through a separate, trusted channel before any transfer
Romance deepfakeAn AI persona builds a relationship, then asks for moneyWon’t meet in person, video is brief or evasive, escalating requestsReverse-image search, insist on a live unscripted video call

Celebrity investment scams

This is where the biggest money goes. Andrew “Twiggy” Forrest has spent millions fighting deepfake ads that make it look like he is urging people to sign up for automated trading bots. ASIC coordinated the removal of nearly 12,000 scam websites in 2025, a 90% jump on the year before, and they are still losing the takedown race because the ads regenerate faster than they can be pulled. The rule here is simple and absolute: no legitimate investment comes to you through a social media video ad. None.

Voice-cloning “family emergency” and CEO-fraud calls

This is the one that keeps me up at night, because the barrier to entry has collapsed. Scammers need as little as three seconds of audio to clone a voice, and they pull that sample from a public TikTok, Instagram Reel, or YouTube clip. Australians lost about $25.8 million to AI voice scams in the first half of 2025.

The business version is worse in dollar terms. In the now-infamous Arup case, a finance worker joined a video call with what looked like the CFO and colleagues and authorised roughly $25 million in transfers. Every person on that call was a deepfake. Closer to home, Noosa Council paid more than $2 million to a fraudulent account after staff were convinced to update a contractor’s bank details. If you run finance or ops for an Australian business, this is a training and process problem you need to solve this quarter, not next year.

How can you tell if a video or voice is a deepfake?

You can sometimes catch a low-effort fake by eye, but you can never confirm a good one, which is why the visual tells are the least important part of your defence. Let me give you the tells anyway, then explain why they are the junior partner.

For video, look for:

For voice, listen for flat emotional tone, odd pacing, no background noise where you would expect some, and a strange reluctance to answer a specific personal question.

Here is the honest caveat, and it matters. The classic advice to “watch the blinking” is outdated: that was a real tell around 2018, and modern models fixed it. The tells are a moving target, and they are moving fast. Detection is genuinely getting harder, which is the whole reason I keep steering people away from eyeballing and toward process. I dig into why automated tools are not a rescue in do AI detectors work, but the short version is below.

Do deepfake detector apps solve this?

No. Automated detectors are useful for triage, but they are nowhere near reliable enough to make a “send the money” decision on. A 2024 meta-analysis of 56 studies found detectors averaged around 55.5% accuracy, barely better than a coin toss, and new generative models are trained specifically to defeat the detectors that exist. Tools like content-provenance checkers and mobile scam-check apps can flag obvious fakes, but none of them are foolproof. Treat a “looks genuine” result from any detector as no result at all.

What is the single best defence against deepfake scams?

Verify through a second channel, every time, no exceptions. If you get a call, hang up and ring the person back on the number you already have saved. If you get a video message from your CEO, walk to their desk or message them on the internal system you normally use. If an “investment opportunity” arrives, go to the institution’s official website that you typed in yourself. The scammer controls the channel they contacted you on. Your safety comes from leaving that channel entirely.

Set up a family safe word

This is the cheapest, most effective control I recommend, and almost nobody has done it. Agree on a private safe word or phrase known only to your family. If someone calls claiming to be a loved one in crisis, ask for the safe word before you do anything. Choose something that would never appear on social media: not a pet’s name, not a birthplace, not a school. A random word or an inside joke works best. Then actually tell the vulnerable people in your life about it, because CommBank found 67% of Australians had never discussed AI scams with family. That conversation is worth more than any app.

For businesses: build verification into the process

If you run a team, do not rely on staff spotting a deepfake in the moment, because the research says they will not. Instead, make dual authorisation mandatory for payments and for any change of bank details, require a callback to a pre-verified number for urgent transfer requests, and give junior staff explicit permission to slow down a “CEO” without fear of consequences. The Arup employee was not foolish. The process just did not force a second check. I cover the organisational angle for Australian firms in is ChatGPT safe for Australian business, and the national-security dimension in the Five Eyes AI security joint statement.

What should I do if I have been targeted or scammed?

Move fast, because in the first few hours money can sometimes still be recovered. Here is the order of operations I give people:

  1. Stop all contact with the scammer. Do not send “one more” payment to test them.
  2. Call your bank immediately if you sent money or shared details. Ask them to halt or attempt to recall the transfer and to secure your accounts.
  3. Report to Scamwatch, run by the National Anti-Scam Centre. Reports feed the intelligence that drives takedowns.
  4. Contact IDCARE if any identity information was exposed. They are Australia’s free national identity and cyber support service.
  5. Warn the person who was impersonated, whether that is a family member or a colleague, so they can alert others.

You now also have more backing than you did a year ago. Australia’s Scams Prevention Framework commenced in February 2025, with the first obligations on banks, telcos, and digital platforms taking effect from 1 July 2026. It forces those sectors to prevent, detect, disrupt, and report scams, and it opens a compensation pathway when they fail to meet their obligations. Penalties reach $50 million per breach. I have written a full operator’s guide to the Scams Prevention Framework for the technology leaders who have to build all of this. It is a real shift: for the first time the platforms carrying these scams carry legal responsibility for them too.

The takeaway

Deepfakes have crossed the line where your senses can be trusted. The people losing money are not gullible. They are relying on detection instincts that the technology has already beaten. So stop trying to win the spotting game. Build the habits instead: a family safe word, a callback on a known number, dual authorisation on every payment, and the flat rule that no genuine investment ever arrives through a video ad. Detection is getting harder every month. Process does not care how good the fake is.

Amjid Ali is an AI and technology leader based in Melbourne, helping Australian organisations adopt AI safely and defend against AI-enabled fraud. To talk through deepfake risk for your team, get in touch.

Frequently asked.

How can you tell if a video is an AI deepfake scam?
Look for lighting that does not match the scene, lip movements that lag or over-smooth the audio, edges that shimmer around the hairline and glasses, and blinking that feels off. But treat those as weak hints, not proof. The reliable test is process: if a video pushes urgency, money, or crypto, verify the person through a second channel you already trust before you act.
What is an AI voice-cloning scam and how does it work?
A voice-cloning scam uses AI to copy someone's voice from as little as three seconds of public audio, then plays it back in a fake 'family emergency' or a CEO instructing an urgent transfer. Scammers pull the sample from a TikTok, Reel, or YouTube clip. The defence is a family safe word and a callback on a known number before any money or data moves.
How much are Australians losing to deepfake and AI investment scams?
Australians reported $2.18 billion in scam losses in 2025, including $837.7 million to investment scams, many powered by deepfake celebrity endorsements. Australians lost about $25.8 million to AI voice scams in the first half of 2025 alone. Reported figures understate the real total, as many victims never report out of embarrassment.
What should I do if I think I have been targeted by a deepfake scam?
Stop contact with the scammer immediately. If you sent money or shared details, call your bank straight away and ask them to halt or recall the transfer. Report it to Scamwatch at scamwatch.gov.au, and contact IDCARE if your identity may be exposed. Warn the person who was impersonated. Speed matters most in the first hours.
Do AI deepfake detector tools actually work reliably?
Not reliably enough to bet money on. A 2024 meta-analysis of 56 studies found automated detectors averaged about 55.5% accuracy, barely better than a coin toss, and generative models are trained specifically to beat them. Detectors can flag low-effort fakes, but they miss the best ones. This is why verification through a trusted second channel beats staring at the screen.

Picked by shared topic. The through-line is agentic AI shipped into production, not the pilot theatre.

Read another.