Fake ABC News Website Scam Using Facebook Ads to Defraud Australians of Hundreds of Thousands of Dollars
Five Eyes Cyber Chiefs Issue Urgent Joint Warning: AI Is Reshaping Cyber Risk Faster Than Anyone Anticipated
Anthropic’s Mythos AI Model Found Vulnerabilities in Classified US Government Systems Within Hours
WhatsApp Phishing Attack Uses Fake Business Documents to Compromise PCs
New macOS ClickFix Attack Silently Mounts Disk Images to Deploy Information-Stealing Malware
https://www.abc.net.au/news/2026-06-23/fake-abc-website-scam-facebook-ads/106653690
Scammers are running an industrial-scale operation using pixel-perfect clones of the ABC News website, promoted through Facebook advertising, to convince Australians to pour money into fraudulent investment platforms, with some victims losing hundreds of thousands of dollars to the scheme. The operation, which has been traced to criminal networks spanning Europe and Israel and is estimated to have stolen at least $350 million globally, begins with a Facebook advertisement depicting a dramatic fictional confrontation between well-known Australian public figures, frequently featuring senior ABC journalists and prominent politicians rendered through AI-generated imagery. Clicking the advertisement directs the target to a near-perfect replica of the ABC News website, complete with accurate reproductions of navigational elements including the iview and Listen tabs, where a fabricated news article awaits them written in the punchy, short-sentenced style characteristic of generative AI and laced with genuine biographical details about real public figures to lend it an air of credibility.
The fake articles follow a consistent formula, depicting scenes in which a celebrity or politician is caught revealing or being confronted about a secret investment approach, with AI-generated photographs styled to resemble candid behind-the-scenes television footage. In one variation, Opposition Leader Angus Taylor appears to have his personal banking details exposed by hackers during a live appearance on Insiders, while another portrays him being publicly confronted by Tasmanian senator Jacqui Lambie. The dramatic narrative exists solely to introduce the actual purpose of the scam, which is the promotion of a fraudulent investment platform such as Hexonix 365, endorsed near the bottom of the article by a fabricated editor’s note claiming the platform has been investigated and verified as legitimate by ABC journalists. Urgency tactics warning that the investment opportunity is time-limited are deployed to encourage impulsive decision-making, and those who click through to the fake investment platform and submit their contact details are subsequently called by scammers who work to extract as much money as possible from their targets.
At least one Australian man told the ABC he lost more than $500,000 to the scheme, describing the experience by saying his world ended as he knew it, while another lost more than $100,000 to an earlier iteration of the same operation in 2024. The ABC, with digital forensics assistance, identified more than 3,000 fake investment brands created by the scammers, with near-identical campaigns targeting victims in Canada, the United Kingdom, and across Europe, confirming the operation’s global reach and sophistication. Researchers found the scam advertisements running consistently across Facebook throughout April, May, and June of 2026, with new advertising accounts rapidly replacing those taken down by the platform, while Meta did not respond to multiple requests for comment. The scale of Meta’s complicity in facilitating the scam has drawn sharp criticism, with a Reuters investigation citing internal documents reportedly showing Meta had projected that ten per cent of its 2024 revenue would derive from advertisements for scams and banned goods, averaging approximately 15 billion scam advertisements per day and generating an estimated $10 billion Australian dollars in annual revenue, meaning the money extracted from victims is being recycled back into reaching further victims with Meta profiting at every step.
The ACCC has called on all digital platforms including Meta to do significantly more to protect their users from the dangers present on their sites, while security experts note that sophisticated cloaking techniques used by scammers to evade platform detection do not absolve platforms of responsibility to act more decisively against the abuse of their advertising infrastructure.
The heads of the Five Eyes cybersecurity agencies have issued a rare joint statement declaring that artificial intelligence is reshaping cyber risk in months rather than years, delivering a blunt and unambiguous message to business and government leaders across Australia, the United States, Britain, Canada, and New Zealand to act immediately rather than treat the threat as a future consideration. The statement, released on Monday night, warns that frontier AI models are expected to exceed industry expectations and will fundamentally transform both the attack and defence sides of cybersecurity, and that the window between a vulnerability being discovered and actively exploited is closing at a pace that existing patching and response cycles were never designed to accommodate. Among the signatories is the head of the Australian Cyber Security Centre at the Australian Signals Directorate, who expressed cautious optimism that Australia is well positioned to meet the challenge provided organisations treat it with the seriousness it demands.
The urgency of the statement is underscored by a recent and striking demonstration of how quickly frontier AI capabilities are advancing. On 13 June, Anthropic suspended worldwide access to its two most powerful AI models, Fable 5 and Mythos 5, following a United States export control directive tied to security concerns, leaving Australian users without access and without prior notice. Testing conducted by Britain’s AI Security Institute had found that one of the models could successfully break into computer systems approximately 73 per cent of the time, a finding that has been described as representing a step change in capability rather than an incremental improvement. The agencies noted that this kind of rapid capability uplift means that cyber risk assumptions that were considered sound can become dangerously outdated within months, creating an environment in which organisations that delay action face compounding and increasingly avoidable exposure.
The joint statement makes clear that cyber risk can no longer be treated as a purely technical matter to be managed by IT departments, characterising it instead as a core business risk and a direct leadership responsibility requiring boards and executives to be genuinely confident their defences would hold during a real attack rather than simply having controls nominally in place.
Practical steps outlined by the agencies include reducing the number of systems exposed to the internet, accelerating the patching of known vulnerabilities, retiring unsupported legacy systems, and tightening access controls over critical networks, with particular emphasis on the danger that AI-shortened exploitation timelines pose to operational systems with long update cycles. The agencies also strongly urged organisations to deploy AI actively in their own defences, noting that adversaries are already leveraging the technology and that organisations integrating AI into their security operations will be better positioned to detect weaknesses earlier, identify unusual behaviour, and contain incidents before they escalate into operational and financial crises. ASCS reinforced this message directly, stating that defenders must learn from and adopt emerging technology including AI, because adversaries are already doing so and the tools and capabilities to respond effectively are available to those willing to act.
A United States government official has confirmed to the Associated Press that Anthropic’s Mythos artificial intelligence model identified vulnerabilities in highly sensitive and classified US government computer systems during a controlled testing exercise, with the model locating certain weaknesses within hours rather than the days or weeks that conventional security testing might require. The official, who spoke on the condition of anonymity given the sensitive nature of the subject matter, clarified that while the model identified the vulnerabilities within that compressed timeframe, this did not necessarily mean it was able to actively exploit them within the same period. The disclosure represents one of the most significant public confirmations to date of the capability gap that frontier AI models are opening in the domain of offensive cybersecurity, and arrives at a moment of intense scrutiny over how governments and technology companies should manage the proliferation of AI systems with capabilities that touch directly on national security.
The testing was conducted through an Anthropic initiative called Project Glasswing, which brought together technology companies and other industry partners with the explicit goal of securing the world’s critical software infrastructure against the severe risks that the Mythos model could pose to public safety, national security, and economic stability. The programme reflects a growing recognition within both the technology industry and the US intelligence community that the most capable AI models must be stress-tested against real-world critical systems before they are widely deployed, and that the organisations developing these systems bear a direct responsibility for understanding and mitigating their potential for harm. The involvement of US intelligence agencies in the testing exercise underscores the degree to which frontier AI capability has become a matter of national security concern rather than simply a commercial or academic question.
The findings had been briefly referenced in a Senate hearing on 11 June before the Senate Committee on Banking, Housing, and Urban Affairs, where it was disclosed that the tool had broken into almost all classified systems tested, not in weeks but in hours. The National Security Agency declined to comment when contacted, and an Anthropic spokesman also declined to provide a response, leaving the official who spoke to the Associated Press as the sole confirmed source for the specific details of what the testing revealed. The disclosure lands in the context of significant recent turbulence surrounding Anthropic’s most powerful models, with the company having suspended worldwide access to both Mythos and its companion model Fable 5 on 13 June following a US export control directive tied to security concerns, a decision that cut off Australian and other international users without prior warning and that has drawn fresh attention to the question of how export controls and national security considerations will increasingly shape global access to frontier AI systems.
https://securelist.com/whatsapp-vbs-rmm-campaign/120290/
A phishing campaign targeting WhatsApp users has been uncovered, in which attackers are distributing fake business documents through the platform to trick recipients into executing malware that compromises their Windows computers. The attack exploits the inherent trust that users place in document attachments received through WhatsApp, a platform increasingly used for professional and business communication alongside its more traditional personal messaging role, making recipients significantly less likely to apply the same level of scrutiny they might bring to an unexpected email attachment from an unknown sender. The campaign represents a continuation of a broader trend in which threat actors have shifted their initial access operations away from email-based phishing, where detection and filtering capabilities have matured considerably, towards messaging platforms where enterprise security controls are far less consistently applied and where the casual conversational context encourages faster and less cautious interaction with received files.
The attack chain begins when a target receives what appears to be a legitimate business document through WhatsApp, potentially styled as an invoice, contract, purchase order, or other commercially plausible file type designed to prompt the recipient to open it without undue suspicion. Once the victim opens or interacts with the document, malicious code is executed on their machine, establishing a foothold that gives the attacker varying degrees of control over the compromised system depending on the specific payload deployed. The use of business-themed lures is a deliberate social engineering choice, as professionally formatted documents carry an implicit legitimacy that personal or casual content does not, and recipients in workplace environments are conditioned to open and review business documents as a routine part of their daily responsibilities, lowering their defensive instincts at precisely the moment the attack relies upon them being lowered.
Individuals and organisations should treat document attachments received through WhatsApp with the same level of caution they would apply to email attachments, regardless of whether the sender appears to be known or trusted, as attackers frequently compromise or spoof legitimate accounts to add credibility to their lures. Organisations that permit or encourage the use of WhatsApp for business communication are being advised to implement clear policies around the handling of file attachments received through consumer messaging platforms, and to ensure that endpoint security controls are capable of detecting and blocking malicious payloads delivered through non-email channels. The broader lesson from campaigns of this nature is that as defenders have hardened traditional attack vectors, threat actors have demonstrated consistent agility in migrating to the communication channels where users are least prepared to encounter and recognise malicious content, making user awareness and cross-platform security hygiene increasingly essential components of any effective organisational defence posture.
A newly identified attack campaign targeting macOS users has adapted the increasingly prevalent ClickFix social engineering technique to Apple’s desktop operating system, silently mounting disk image files in the background to deliver information-stealing malware without triggering the level of user suspicion that more overt installation methods typically provoke. ClickFix, which originally emerged and proliferated as a Windows-focused attack vector, instructs victims to copy and paste malicious commands into their own systems under the pretence of fixing a technical problem, verifying they are human, or completing a routine software update, exploiting the user’s own actions to bypass security controls that would otherwise block an unsolicited installation. The adaptation of this technique to macOS is a significant development that challenges the widely held but increasingly outdated perception among Apple users that their platform offers inherent protection against the kinds of social engineering attacks that routinely compromise Windows environments, and reflects a broader shift among threat actors towards targeting the growing macOS user base with purpose-built campaigns rather than treating it as an afterthought.
The macOS variant of the attack introduces a technically noteworthy twist by silently mounting a disk image file, a DMG, as part of the infection chain, a method that takes advantage of macOS’s native ability to mount such files automatically and that can occur without producing the visible indicators a cautious user might otherwise notice and question. Disk image files are a familiar and trusted format for macOS users, routinely used for legitimate software distribution by Apple and third-party developers alike, meaning their appearance in an attack chain carries a degree of inherent plausibility that more obviously suspicious file types would lack. By leveraging a trusted and familiar file format in combination with the psychological manipulation central to the ClickFix approach, attackers have constructed an infection pathway that is difficult for victims to identify as malicious in the moment they are most vulnerable to it, which is when they are actively following what they believe to be legitimate instructions to resolve a problem or complete a task.
The payload delivered through this campaign is an infostealer, a category of malware specifically designed to harvest credentials, browser cookies, saved passwords, cryptocurrency wallet data, and other sensitive information from the compromised machine and transmit it silently to attacker-controlled infrastructure. Infostealers have become one of the most commercially significant categories of malware in the current threat landscape, with stolen credential data routinely sold through criminal marketplaces and used to facilitate follow-on intrusions into corporate networks, cloud environments, and financial accounts. macOS users should treat any web page or pop-up that instructs them to open Terminal, run a command, or manually execute any file with extreme scepticism regardless of how legitimate the surrounding context appears, and to ensure their systems are running current macOS security updates and reputable endpoint protection capable of detecting infostealer behaviour.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.