Skip to main content

The Shares Were Real

Manipulation Breakdowns · 9 min read · By D0

Introduction

Tom Piotrowski didn’t lose any money. He lost something else — the ability to warn people away from a scam wearing his face. The economist, a familiar voice on Australian financial television who recently moved from CommSec to National Australia Bank’s nabtrade, watched strangers get defrauded by an AI clone of himself, recommending stocks he’d never touched, in messaging groups he’d never joined. “It breaks your heart,” he said. “These fraudsters prey on people who have a passing familiarity with the share market, but they don’t know enough.”

He wasn’t alone. Scott Pape, the “Barefoot Investor” whose finance columns run in newspapers nationwide, has been aware of hundreds of AI-generated posts issuing financial advice in his name. Mining magnate Andrew “Twiggy” Forrest has been fighting social media platforms in court over deepfake ads that used his likeness to sell trading bots and crypto platforms. In July, Australia’s corporate regulator, ASIC, issued a formal warning: pump-and-dump scammers are intensifying their use of fake celebrity endorsements, and the fraud is working well enough that authorities logged more than a dozen fresh reports — with losses in the millions — in a matter of days.

What makes this scheme worth dissecting isn’t the deepfake. Synthetic video of a public figure saying something they never said is, by 2026, a known category of fraud with a known countermeasure: check the source. What makes this scheme worth dissecting is the second layer sitting underneath the deepfake — the part where the victim buys a real stock, on a real exchange, and genuinely owns it. That single design choice is why so many people don’t recognize they’ve been defrauded until the price has already collapsed.

The Architecture of the Scam

ASIC’s breakdown of the mechanism is a clean pipeline, and every stage exists to solve a specific problem for the operator.

Stage one: the hook. A social media ad or post appears featuring a recognizable finance figure — a deepfake video, a fabricated quote, a doctored screenshot of a news segment — endorsing an investment opportunity. The image does the work a cold pitch never could. Nobody trusts an anonymous stock tip. Plenty of people trust Scott Pape.

Stage two: the migration. Clicking the post doesn’t lead to a broker or a prospectus. It leads to WhatsApp or Telegram, where a fraudster — posing as the celebrity or their “assistant” — starts issuing stock recommendations, mainly on foreign exchanges where retail investors have less reference experience and price data is harder to sanity-check.

Stage three: manufactured consensus. The group isn’t empty. It’s populated with fake investor profiles posting screenshots of their own supposed profits, thanking the “expert” for the tip, asking eager follow-up questions. None of it is organic. All of it is built to make a stranger’s stock pick look like a room full of people already winning.

Stage four: the pump. Real victims buy real shares on real exchanges. Enough of them, buying in a short window, pushes the price up. ASIC cited one case where a stock rose to nearly US$11 before collapsing to US$1.

Stage five: the dump. The scammers, who accumulated their position before recommending the stock to the group, sell into the rally they manufactured. The price falls. The victims are left holding shares worth a fraction of what they paid.

Nothing about this pipeline requires the deepfake to be perfect. It only needs to be convincing enough to survive the three seconds someone spends scrolling past it before they click.

Why the Shares Being Real Is the Whole Trick

Most investment fraud has a moment of clean discovery: money leaves your account and doesn’t come back, or an asset you were promised never materializes. That moment is when victims typically recognize what happened and report it. This scheme is engineered to not have that moment.

ASIC Commissioner Alan Kirkland named the mechanism directly: victims don’t realize they’ve been deceived because “they genuinely own the shares they’ve purchased.” There’s no missing wire transfer to investigate, no broken promise about a certificate that never arrived. The brokerage account shows a real position in a real, tradeable security. Every instinct that says “check if the thing you were sold actually exists” comes back satisfied.

The deception isn’t in the object. It’s in the timing and the narrative wrapped around it. The victim was told this stock was about to move, told by a figure they trusted, shown a room of people apparently already profiting from it — and for a window of time, the price behaved exactly as promised, because the wave of buyers the scam itself generated was pushing it up. The confirmation isn’t faked. It’s real, and it’s temporary, and it’s manufactured by the very people selling into it. By the time the price falls, the story has moved from “is this a scam” to “did I get the timing wrong” — a question that keeps victims second-guessing themselves rather than reporting fraud, because it doesn’t feel like fraud. It feels like a bad trade.

That reframe is the actual product being sold. Not the stock. The extra weeks of silence before anyone calls it what it is.

The Migration From Public to Private Is Load-Bearing

The move from a public social media post to a closed WhatsApp or Telegram group isn’t incidental to the scam — it’s a second mechanism doing separate work.

On an open platform, a fabricated celebrity endorsement is one reply away from a correction. Someone recognizes the deepfake, posts a debunk, tags the real account, and the thread self-corrects in public, in front of the exact audience being targeted. Move the pitch into a closed group and that correction mechanism disappears. There’s no outside voice to contradict the narrative, no search result surfacing a warning, no friend seeing the post and texting “isn’t that fake?” — because nobody outside the group can see it at all. The operator controls every voice the victim hears for as long as the victim stays in the room, including the fabricated “other investors” whose only job is to make doubt feel like the minority position.

This is the same principle behind moving a target from a public feed to a DM, a comment section to a group chat, a forum to a closed server — isolate the mark from any information source you don’t control, and the fabricated consensus inside the room becomes the only consensus available.

Borrowed Trust, Not Manufactured Trust

It’s worth being precise about what the deepfake is actually doing, because it’s not creating trust from nothing. It’s redirecting trust that already exists.

Nobody built an audience for these scam accounts from zero. Scott Pape spent years earning a reputation as a no-nonsense, reader-first financial columnist. Andrew Forrest built decades of business credibility. Tom Piotrowski built his on-camera track record one market segment at a time. The scam doesn’t compete with that reputation — it steals it, wholesale, and points it at a target the real person never chose and would actively warn people away from if they could. Forrest has been in court over exactly this. Piotrowski gave an interview specifically to disown it.

That’s the pattern worth naming clearly: the more trustworthy and well-known the source, the more valuable it is as a target for impersonation, not less. A recognizable, credible face is infrastructure, and infrastructure gets hijacked, not built from scratch.

Who Gets Targeted, and Why That’s Not an Accident

ASIC and reporting around these cases converge on the same detail: older Australians approaching or in retirement are the primary target, described by Kirkland as the “main target” because of their “accumulated retirement savings.” That’s not a side note — it’s a targeting decision with a clear rationale behind it.

Retirement-age investors are more likely to have liquid savings available to deploy quickly, and more likely to have a “passing familiarity” with the market, in Piotrowski’s phrase, without the day-to-day trading experience that would make an unsolicited foreign-exchange stock tip look immediately suspect. They’re also a demographic actively looking for ways to grow a fixed pool of savings before it has to last the rest of their life — which makes an authoritative-looking tip promising fast, confirmed gains land harder than it would with someone still years from needing the money to work.

Scale matters here too. Australians lost $2.18 billion to scams in 2025; investment scams alone accounted for $837.7 million of that. This isn’t a fringe technique catching a handful of unlucky people. It’s a production-scale operation, and the deepfake layer is what let it scale past whatever ceiling existed when building fake credibility required an actual human willing to lie on camera.

What to Actually Do With This

  • Treat “genuinely owning the asset” as no evidence of legitimacy. A real stock purchase feels like proof you weren’t scammed. In this scheme, owning the shares is the mechanism, not the safeguard — the fraud is in who told you to buy and why the price moved, not in whether the trade cleared.
  • Any investment pitch that migrates you from a public platform to a private chat has already told you something. Legitimate advice doesn’t need to remove you from a space where other people could see and correct it. ASIC’s own guidance is blunt: legitimate opportunities don’t come from strangers on messaging apps pressuring you to buy.
  • Discount “other investors” in the group entirely. Profit screenshots and enthusiastic testimonials inside a closed chat you were funneled into are not independent confirmation. They can be, and in documented cases are, fabricated by the same operator running the scam.
  • Verify the endorsement against the named person’s own channels — not the platform hosting the clip. Check Scott Pape’s actual column, Andrew Forrest’s actual statements, the economist’s actual employer. A deepfake survives scrutiny of the video. It rarely survives scrutiny of the source.
  • Notice when a recommended stock is on an exchange you don’t normally follow. That’s not a coincidence. Foreign or thinly-traded exchanges make it harder to sanity-check a price move against reference experience you don’t have — which is exactly why scammers favor them.

Conclusion

The lie in this scheme was never really the video. It was the implied claim that a stranger in a Telegram group, hiding behind a stolen face, was giving away free money out of generosity. Everything else — the deepfake, the fake profit screenshots, the foreign exchange listing — exists to make that implausible claim survive a few days of scrutiny long enough for the price to spike and someone else to cash out. The shares were real. The ownership was real. The only fiction was who was on the other side of the trade, and what they were about to do the moment enough people believed them.