Investment Fraud: The Rise of Deepfake Scams
Investment fraud has become an increasingly sophisticated issue, particularly as scammers leverage one of the most challenging actions for banks to prevent: payments that consumers willingly authorize. This alarming trend has seen a rise in the utilization of advanced technologies, including deepfake advertisements and impersonated financial experts, merging with social engineering tactics to persuade retail investors into ill-fated stock trades and fraudulent investment platforms.
In 2025, the scale of investment scams dramatically escalated, establishing itself as the leading category for fraud-related losses in both Australia and the United States. Reports indicated that victims in Australia suffered losses totaling approximately $837.7 million, while in the United States, the figure soared to an astounding $7.9 billion. This alarming trend highlights a significant expansion of a threat fueled by synthetic media, innovative social engineering techniques, and an organized fraud infrastructure.
Among the prominent players in this nefarious landscape is GoldBull, a group known for deploying deepfake advertisements on social media platforms that impersonate reputable financial professionals. By creating a facade of credibility and urgency, these ads manipulate potential victims. Notably, these advertisements are designed to have a short lifespan, allowing the operators to skirt around performance moderation, while simultaneously directing targeted users through geo-specific links into WhatsApp groups.
Within these groups, a fictitious “head analyst” offers what appears to be precise trading recommendations, including specific small-cap stocks, target purchase prices, and anticipated exit levels. This carefully orchestrated scheme encourages victims to purchase shares through authentic brokerages, lending an air of legitimacy to the transactions and ensuring that victims, rather than scammers, execute the trades.
The operational blueprint behind this fraud is a method known as a coordinated pump-and-dump scheme. An instance documented by Group-IB showcased how, on November 6, 2025, members were directed to buy a NASDAQ-listed stock priced at $24.79, aiming for a target price of $29. Following a brief surge, where the stock peaked at $27.87—a 12.4% increase—the operators allegedly offloaded their pre-positioned shares. By February, the stock plummeted to $14.27, leaving victims with losses amounting to 42% below their initial investment.
The dynamics of these scams reveal that even a handful of WhatsApp groups, each comprising about 1,000 participants, can generate sufficient buying pressure to affect the price of thinly traded equities. Group-IB estimates that victim capital per campaign ranges from $1.5 million to $3 million, indicating the substantial financial risk involved.
Victims typically stumble upon fraudulent investment sites through a combination of search engine optimization, paid advertising, or interactions with romance scams that groom potential targets. Upon engagement, they are led through a deceptive onboarding process that includes registration, counterfeit Know Your Customer (KYC) checks, trial funds, and tiered investment plans. After victims deposit money, withdrawal requests are methodically blocked through scripted obstacles. They may be informed that they must meet a minimum balance requirement, pay fictitious taxes or insurance fees, or upgrade their accounts—often under the guise of compliance with supposed regulations.
Furthermore, in a disturbing twist, some of these fraudulent networks re-emerge as recovery services, soliciting additional upfront payments from victims in exchange for access to their lost funds.
Research by Group-IB identifies two distinct operations: GoldBull and CoinLure, demonstrating how these fraudsters are adeptly merging deepfake advertising techniques with trusted platforms and social channels, all while orchestrating increasingly professional workflows for their malicious activities.
A crucial insight is that while these fraud networks may be challenging to disrupt during the payment phase, their infrastructure remains vulnerable to detection efforts. Common traits, such as shared hosting, cloned templates, and reused wallets, provide identifiable markers across campaigns.
Interestingly, fraudsters exploit their scalability to enhance profitability, but this very scale also creates a roadmap for defenders to utilize in mapping out fraud networks. For instances, Group-IB revealed that one confirmed CoinLure platform was connected to a staggering 208 domains, utilizing 23 shared templates and common hosting services, which cumulatively amounted to an estimated revenue of $187 million.
Given the complexities surrounding deepfake investment scams—wherein consumer trust, authentic brokerages, and the perceived authority of financial analysts are often exploited—financial institutions must recalibrate their detection methodologies. Honing in on ad creatives, landing pages, and registration data as interconnected points rather than isolated incidents is vital for recognizing the broader ecosystem of these scams.
By fostering cross-bank intelligence sharing, institutions can mitigate risks associated with mule accounts and benign-looking beneficiary infrastructures that may facilitate fraudulent activities. Group-IB’s innovative Cyber Fraud Intelligence Platform introduces a fresh framework through distributed tokenization, enabling participants to correlate suspicious identifiers without compromising sensitive personal data.
Ultimately, deepfake investment scams are likely to persist, exploiting consumer trust and leveraging modern technology to ensnare victims. However, the very infrastructure that underpins these scams offers defenders critical evidence necessary for identifying, disrupting, and uncovering the networks responsible for these fraudulent schemes. As the methods employed by fraudsters continue to evolve, so too must the defenses against them, ensuring financial security in a rapidly changing landscape.

