If you have seen an ad promising exclusive share tips from a familiar face on the Australian finance scene, you have met one of the most effective scams operating in the country right now. It borrows the credibility of a genuine, trusted market commentator, wraps it in an AI-generated image or video, and funnels people into a fake "trading" group. The person whose face is used is not behind it. He is a victim of it — and he has been trying to warn people. This is how the scam works, why it is so convincing, and what the institutions in the payment chain can actually do about it.
In this guide
Whose face is being used — and why it matters
The scam depends on borrowing someone the audience already trusts. In Australia, one of the most heavily impersonated figures has been Tom Piotrowski, for years a recognisable market analyst on television and, more recently, Head of Market Insights at nabtrade after a long stint at CommSec. That familiarity is precisely what the criminals are stealing.
It matters — legally and ethically — to be exact about his role. He is the target of the impersonation, not its author. In NAB's own warning, Piotrowski put it plainly: "I will never contact you directly about an investment opportunity. If you are contacted directly by 'me' on social media or via WhatsApp, it is a scam." A licensed market commentator cannot lawfully cold-message the public with tips to buy particular shares, and he does not. The Australian Securities and Investments Commission has likewise identified him as one of several well-known people — alongside financial author Scott Pape and businessman Andrew "Twiggy" Forrest — whose likeness is being misused in these frauds.
So when this article refers to "the Piotrowski scam", it means a scam that abuses his identity. The distinction is the whole point: the trust people place in a real person is the raw material the criminals are mining.
How the scam works, step by step
These scams are engineered as a funnel. Each stage is designed to move the victim one step further from anyone who could interrupt them, and one step closer to an irreversible payment. Drawing the mechanics together from ASIC's and the banks' public warnings, the chain looks like this.
- The lure — a paid social ad or post. It appears in a feed, usually on Facebook or Instagram, often as a paid ad so it reaches a wide, targeted audience. It carries an AI-generated image or deepfake video of a trusted financial figure appearing to share a "can't-miss" opportunity or a secret tip. The production quality is deliberately good enough to pass a glance.
- The click-through. The ad links to a fabricated news article, a fake "CommSec" or brokerage page, or a sign-up form. The victim enters a name and phone number — the moment the criminals capture a live lead.
- The move off-platform. The victim is invited into a private group on WhatsApp or Telegram. This is the pivotal step: encrypted messaging takes the conversation off the advertising platform, away from moderation, and into a space the victim experiences as exclusive and trusted.
- The coaching. Inside the group, an "analyst" or "assistant" — impersonating the trusted figure or claiming to work with them — issues specific stock recommendations, frequently obscure shares on domestic or foreign exchanges. Other "members", who are fake, post screenshots of their gains. The social proof is entirely manufactured.
- The buy signal. The group is told to buy a named stock at a set time. Because everyone buys together, the price genuinely moves up — which the victim reads as proof the tips work. In reality they are supplying the very demand the scheme was built to create.
- The dump. The organisers, who accumulated the stock beforehand, sell into that spike at the inflated price. The share price falls back, and the victims — who bought near the top — are left holding losses.
A common variant swaps the share-market angle for a fake trading platform. There, the victim deposits an initial amount, a slick dashboard shows the balance climbing, and the fake "profits" are used to justify larger and larger deposits. When the victim tries to withdraw, they are locked out or hit with "fees" and "taxes" that must be paid first. Either way, the money is gone.
The pump and dump underneath it
Strip away the deepfake gloss and the engine is an old market-manipulation play: the pump and dump. ASIC warned in July 2026 of a sharp increase in these scams, with older Australians appearing to be the primary target. As ASIC Commissioner Alan Kirkland put it, "We suspect scammers are deliberately targeting Australians nearing retirement" — the cohort most likely to hold investable savings and to be actively thinking about how to grow them.
The choice of stock is deliberate. CommSec's own guidance notes that scammers often target low-liquidity shares — thinly traded stocks where even modest coordinated buying can move the price sharply. That thin float is what makes the "pump" visible enough to feel real, and it is what lets the organisers exit into the spike before the price gives way. The victim never had a chance: they were the exit liquidity, not the beneficiary.
Why people fall for it — the psychology and the design tricks
It is tempting to assume only the careless get caught. That is wrong, and believing it is part of why the scam keeps working. The design is a deliberate stack of well-understood psychological levers.
Borrowed authority
The scam does not ask the victim to trust a stranger. It borrows the credibility of someone they already trust — a familiar market commentator they have seen giving measured, sensible analysis for years. Authority is one of the strongest compliance triggers we have, and a deepfake hijacks it directly.
Manufactured social proof
Inside the group, dozens of "members" post profits, ask beginner questions, and thank the "analyst". Every one of them can be fake. Humans calibrate risk by watching others; a room that appears full of ordinary people succeeding is enormously persuasive, and it is trivial to fabricate.
The small win that hooks
The first tip often does go up, because the group's own coordinated buying pushes it up, or the fake platform simply shows a gain on the dashboard. That early "proof" converts scepticism into belief and belief into a larger commitment. It is the same mechanism a fraudster uses when they let a victim make a small successful withdrawal early on.
Exclusivity and urgency
"Limited spots." "The window closes at 10am." "Members only." Scarcity and time pressure are engineered to stop the one thing that reliably kills the scam — pausing to check. The private group reinforces this: it feels like inside access, not an open advertisement.
Isolation from interruption
Moving the victim onto encrypted messaging is not incidental. It removes them from public comment threads where someone might shout "scam", from an advertising platform that might take the post down, and often from friends and family who might ask an awkward question. By the time money moves, the victim has spent days inside a closed world built entirely by the criminals.
None of this requires the victim to be foolish. It requires them to be human, at a moment when a trusted face, a rising number and a ticking clock all point the same way.
The red flags — for individuals and for frontline staff
Whether you are a member of the public or a banker taking a customer's call, the tells are consistent.
- An unsolicited investment tip from a "known" figure. Genuine analysts and licensed advisers do not direct-message the public with buy signals. A tip that arrives this way is a scam by definition.
- A push onto WhatsApp or Telegram. Being moved from an ad into a private encrypted group is the single most reliable warning sign in this playbook.
- Guaranteed or "risk-free" high returns. No legitimate investment guarantees returns. Certainty is the marketing of fraud.
- Coordinated "buy now" instructions to purchase a specific, often obscure, stock at a specific time.
- On-screen profits you cannot withdraw. A dashboard showing gains is not money. Withdrawal blocks, or "fees" and "taxes" demanded before you can withdraw, mean the funds were never real.
- Pressure, secrecy and flattery. Urgency, "members-only" framing and being told not to discuss it with your bank or family are all designed to prevent the check that would end it.
- No verifiable licence. A genuine provider holds an Australian Financial Services Licence you can confirm on ASIC's registers. No licence, or a licence number that does not check out, is decisive.
What banks, brokers, fintechs and platforms should do
This is where a scam like this stops being a consumer-awareness problem and becomes an operational one. The victim is genuinely logged in and authorising the payment themselves, so it is an authorised scam — credential and imposter checks pass cleanly. Stopping it means acting across the whole journey, and different players own different parts of it.
Banks and brokers — the payment and trading chokepoints
- Model the customer's own baseline. The signal is deviation from normal for that person: a first-ever payment of this size, a newly added payee, a transfer to a digital-currency exchange, a sudden interest in an obscure security. Scam detection has to reason about behaviour, not just authentication.
- Make transaction scoring payee-aware. Payments to newly created accounts, to accounts with mule-like behaviour, or to beneficiaries flagged through information sharing should lift the risk score. Receiving-side intelligence is where much of the modern edge sits.
- Apply proportionate, risk-based holds and step-up checks. A short hold and a real conversation on the highest-risk payments buys the one thing the scam is engineered to deny the victim: time to reconsider before the money is irreversible.
- Deliver scam-specific warnings, not generic pop-ups. A warning that names the exact pattern — "Were you given this tip in a WhatsApp or Telegram group?" — cuts through where a boilerplate disclaimer does not.
- Watch for the brokerage footprint. On the trading side, coordinated buying of a thinly traded stock by many unrelated new accounts at the same moment is itself a manipulation signal worth surveilling.
- Invest in mule detection on the receiving side. Scam proceeds have to land somewhere. Accounts that sit dormant then suddenly receive and rapidly forward funds, or that fan out to many beneficiaries, are the destination side of every one of these schemes.
Digital and advertising platforms — cutting off the supply
- Fast takedown of impersonation ads and accounts. The lure is a paid ad. Speed of detection and removal directly determines how many people reach the funnel. Meta has said it removed a large volume of scam ads and disabled millions of accounts linked to scam operations, but the ads keep appearing — which tells you detection has to be faster and more resilient to evasion.
- Deepfake and synthetic-media detection on ad creative featuring public figures, tuned to the specific pattern of a "known finance personality endorsing a tip".
- Verified-identity signals for genuine financial figures and institutions, so that an impersonating account is easier to flag and a real one easier to confirm.
- Friction on the off-platform hop — the redirect into WhatsApp or Telegram groups — which is the moment the platform loses visibility and the victim loses protection.
Payment and e-commerce platforms — the deposit rail
Where the variant is a fake trading platform, the criminals still need to collect deposits. Payment processors and marketplaces should treat sudden inflows to newly onboarded "investment" or "brokerage" merchants, mismatches between a merchant's stated business and its transaction pattern, and clusters of small first-time deposits followed by withdrawal complaints as exactly the mule-and-boiler-room signals they are.
The controls that matter, mapped
No single row below stops the scam. The protection comes from layering them across the players who each own a slice of the journey.
| Control | What it stops | Who owns it |
|---|---|---|
| Impersonation ad takedown | The lure, at the top of the funnel | Advertising / social platforms |
| Deepfake / synthetic-media detection | Fake endorsements of trusted figures | Platforms; verification vendors |
| Behavioural, payee-aware transaction scoring | Unusual payments to new payees and exchanges | Banks & brokers |
| Risk-based holds & step-up checks | The irreversible payment, at the moment it matters | Banks & brokers |
| Scam-specific dynamic warnings | Social-engineered payments the customer can still stop | Banks & brokers |
| Market-surveillance on coordinated buying | The pump in thinly traded stocks | Brokers; market operators |
| Mule / receiving-account detection | The destination of every scam payment | Banks; payment platforms |
| Information sharing | Repeat mules and cross-institution scam flows | Whole ecosystem |
The scale of the problem
This is not a fringe threat. Investment scams were the single largest category of scam loss in Australia in 2025, with the Australian Competition and Consumer Commission and the National Anti-Scam Centre reporting investment scam losses of roughly $837.7 million, part of $2.18 billion in total reported scam losses across the year. NAB has noted that around 70 per cent of investment scam losses originate from social media or websites — the exact channels this deepfake playbook exploits — and that investment scams on social media platforms rose in the most recent six-month period it reported.
The trajectory is clear: fewer, but more sophisticated and more expensive, scams. AI has lowered the cost of a convincing lure to almost nothing, and encrypted messaging has industrialised the coaching that used to require a room full of callers. The defensive answer is not a single silver bullet. It is the same discipline that works against every modern scam — push the point of control upstream, layer the defences across everyone who touches the journey, and act before the money is gone rather than trying to claw it back afterwards.