Faking a trusted brand is easier than ever, defending against impersonation isn’t


By Scott Morris*
Tuesday, 11 August, 2026


Faking a trusted brand is easier than ever, defending against impersonation isn’t

Impersonating popular, trusted brands and goods isn’t a new phenomenon. You’ve likely seen the newest Nike sneakers at a price that seems much too good to be true, or Apple Watches sold on an online marketplace you’ve never heard of.

The world’s most well-known brands — Apple, Google, AWS and major banks — are all regularly impersonated. Once upon a time, these impersonations were easy to spot and avoid, but new technologies are changing the game. Cybercriminals have taken advantage of brand impersonation, using AI-created content to quickly and easily set up counterfeit websites and copy the branding, logos, advertisements and even marketing campaigns of trusted brands within minutes.

Some of Australia’s most iconic brands are impersonated by scammers every day — from banks to postal services, healthcare and insurance. This isn’t a new phenomenon. The issue is that the scams are getting more convincing, and finding the differences between legitimate advertising campaigns and nefarious actors is like a game of ‘Where’s Wally’.

That should be a real concern for brands at home and around the world. With the proliferation of misinformation and an increasingly competitive business environment, a strong, trusted brand is more important than ever.

In the words of Warren Buffett, “It takes 20 years to build a reputation and five minutes to ruin it.” With AI impersonations, and a world now crawling with cybercriminals, that five minutes might now be less than two. A recent study found that disinformation is now costing the global economy US$78 billion annually, with erosion of trust now a financial risk that organisations cannot ignore.

In Australia, the National Anti-Scam Centre reported that online contact methods — including fake websites, advertisements, social media and mobile apps — accounted for around half of all reports during the quarter. These websites, advertisements and social media posts look eerily similar to legitimate brands. There are also certain brands that are more often impersonated than others. In Australian retail, counterfeit websites mimicking luxury brands jumped 45%, particularly for handbags, footwear and special releases.

There are brand-abusing threat actors that routinely create these threats, like the prolific Hazy Hawk, a DNS-savvy operator that routinely hijacks subdomains of well-known organisations like UNICEF, Deloitte and even the Centers for Disease Control.

But perhaps the most relevant example is the 2026 FIFA World Cup: amongst the joy and fanfare of the tournament, there are always those looking to use the major sporting event as an opportunity for nefarious activities. Unfortunately, it’s one of the busiest times for cybercriminals, leading the NSW government to even issue a warning about fake FIFA World Cup websites.

Given the surge in online traffic looking for FIFA World Cup streaming sites, or even legal sports betting pages, it’s no surprise threat actors were leveraging these pages for scam purposes.

While events like these create opportunities for threat actors, brand impersonation happens consistently throughout the year. In the last quarter, the National Anti-Scam Centre disrupted thousands of scam operations during this period, with 5834 scam websites taken down, including 1960 fake online gambling websites.

Due to the quantity of scam websites, we can’t rely on public organisations alone to take these threat actors down. Lookalike attacks are so difficult to address because of their inherent ambiguity. A domain embedding a well-known brand name could just as easily belong to a legitimate content delivery network or third-party provider as to an attacker preparing a phishing campaign.

There's often no way for a user to discern a scam, and attackers deliberately exploit that to maintain plausible deniability for as long as possible. So perhaps ‘Where’s Wally’ is the wrong analogy. Think of looking for a needle in a haystack; except you’re trying to find one specific needle in a pile of almost-identical needles.

While AI is exacerbating these threats, there is also an opportunity to use AI as a defensive tool. For example, Digital Risk Protection Services (DPRS) use AI-driven analysis to discover and disrupt active threats outside the enterprise perimeter — phishing, impersonation, fraud and credential exposure — before they reach customers or employees. External Attack Surface Management (EASM) compliments this by providing continuous, outside-in visibility into an organisation’s internet-facing assets, identifies the exposures attackers can actually leverage and prioritises them, so teams know exactly what to fix and how.

In a world of luxury knock offs and counterfeit websites, trusted branding is a company’s greatest asset. Protecting this should be a top priority, as any potential erosion of this trust should be taken seriously.

Organisations must defend their brand with renewed vigour, investing in tools that discovering external threats before the damage is done. Otherwise, a company’s most important asset — its reputation — could be on the line.

*Scott Morris is Managing Director for ANZ at Infoblox.

Top image credit: iStock.com/Pheelings Media

Related Articles

How Mythos changes the assumptions underpinning Australia's banking regulations

The advent of frontier AI models invalidates many of the cybersecurity assumptions implicit in...

Securing the new financial year: prioritising autonomous cyber defence

As Australian businesses enter a new financial year, they need to evaluate their security...

Australia is building AI faster than it can secure it

The pace of AI adoption is being set by competitive pressure and internal demand, and security is...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd