Investment fraud is increasingly exploiting the one action banks struggle most to block: a payment the customer actively wants to make.
Deepfake advertisements, impersonated financial experts, and coordinated WhatsApp groups are now being used to steer retail investors into manipulated stock trades and fake investment platforms.
In 2025, investment scams became the largest fraud-loss category in both Australia and the United States.
Australian victims reported losses of $837.7 million, while US investment-scam losses reached $7.9 billion, illustrating the scale of a threat driven by synthetic media, social engineering and industrialised fraud infrastructure.
GoldBull uses deepfake social-media advertisements that impersonate financial professionals to create credibility and urgency.
The ads are deliberately short-lived, helping operators evade moderation while directing selected users through geo-targeted redirects into WhatsApp groups.
Inside those groups, a fake “head analyst” provides what appears to be precise trading guidance: a named small-cap stock, a target purchase price and an expected exit level.
Victims are encouraged to buy shares through legitimate brokerages, which gives the activity an appearance of authenticity and ensures victims not the criminals execute the transactions.
The operational goal is a coordinated pump-and-dump. Group-IB documented a case in which members were instructed on November 6, 2025, to purchase a NASDAQ-listed stock at $24.79 with a target of $29.
The stock later peaked at $27.87, a 12.4% rise, before the operators allegedly sold pre-positioned holdings. By February, the stock had fallen to $14.27 42% below the victims’ entry price.
A handful of WhatsApp groups, each with roughly 1,000 participants, can create enough concentrated buying pressure to move thinly traded equities. Group-IB estimates victim capital of $1.5 million to $3 million per campaign.
Victims reach fraudulent investment sites through SEO-optimised content, paid social advertising, or romance-scam grooming, then encounter a polished onboarding flow featuring registration, counterfeit KYC checks, trial funds, and tiered investment plans.
Once deposits have been made, withdrawals are blocked through scripted friction.
Victims may be told they need to meet a minimum balance, pay 10% to 30% in supposed taxes or insurance, upgrade their account, or wait through an indefinite “technical issue” or compliance freeze.
In some cases, the same network later reappears as a recovery service and requests another upfront payment.
Group-IB’s research highlights two distinct operations GoldBull and CoinLure that demonstrate how scammers are combining deepfake advertising with trusted platforms, social channels and increasingly professional fraud workflows.
The critical defensive insight is that these fraud rings may be difficult to stop at the payment stage but remain exposed through their infrastructure.
Shared hosting, cloned templates, recurring contact details, reused wallets, beneficiary accounts, redirect chains and WhatsApp-number patterns create linkable indicators across campaigns.
Fraudsters rely on scale to profit, but scale also creates a graph for defenders to map.
Deepfake Investment Scam
Group-IB found that one confirmed CoinLure platform was connected to 208 domains using 23 shared templates, common hosting and repeated contact details; the network’s estimated revenue was $187 million.

That means detection teams should treat an impersonation ad or malicious domain as an entry point, not an isolated incident.
Correlating ad creatives, landing pages, domain-registration data, infrastructure fingerprints, payment destinations and analyst personas can expose a broader ecosystem.
Automated disruption can then reduce a campaign’s available victim-exposure time from hours to minutes.
Financial institutions also need earlier signals. Scam victims may exhibit changes in banking-app usage, including unusual sessions or altered transaction behaviour, before high-value transfers occur.
On their own, these anomalies can be noisy. Combined with external intelligence on an active scam network, they can become a practical pre-payment intervention trigger.
Cross-bank intelligence sharing is central to detecting mule accounts and beneficiary infrastructure that would otherwise appear benign at a single institution.
Group-IB’s Cyber Fraud Intelligence Platform uses distributed tokenisation to let participants correlate suspicious identifiers without sharing raw personally identifiable information.
The company says tokenisation occurs inside each participant’s environment, while shared tokens enable detection of connected risks across organisations.
The platform describes a typical fraud warm-up period of four to eight weeks, during which mule accounts may conduct low-value probe payments before large-scale fraud begins.
Detecting these behaviours across institutions can enable blocks, holds or customer interventions before an authorised payment is sent.
Deepfake investment scams will continue to exploit consumer trust, legitimate brokerages and the perceived authority of financial analysts.
But the same repeatable infrastructure that makes these operations scalable also gives defenders the evidence needed to identify, disrupt and trace the networks behind them.
★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide





