Reputation Was the Currency. Now It Can Be Forged: a person holds an Australian polymer banknote up to the office window light, checking it, by Morris Misel

Reputation Was the Currency. Now It Can Be Forged.

Back in September 2017 I was on ABC Far North with Phil Staley, talking about the sharing economy, which at the time still felt like a slightly mad idea. Strangers sleeping in strangers’ spare rooms. Strangers getting into strangers’ cars. The whole arrangement propped up by a star rating and a photograph, and not much else.

What I said in that segment was that reputation was becoming the ultimate personal currency of the near future and beyond. I also said trust had always been fragile, that once it broke it was hard and sometimes impossible to earn back, and that the rating systems we’d bolted onto the internet to carry it weren’t really doing the job. Our old ways of working out who to trust were built for people we could look in the eye. We’d taken them online and hoped for the best.

The currency part came true. The verification part never caught up. And there’s a third thing, which nobody thinks about until it happens to them, because we’re not used to treating reputation as money: currencies get counterfeited.

The year somebody else started spending it

In August this year ASIC published something that, if you tilt your head, is a list of Australians whose reputations were spent by other people.

The regulator took down more than 19,400 scams in the 2026 financial year, which is 182 per cent more than the year before, and across three years of running that operation it has removed over 33,400 scam websites, social ads and phishing setups. The people most impersonated over that year, going by reports to Scamwatch, were well-known Australians whose faces and voices pulled in $7.4 million. The Prime Minister. Jacqui Lambie. Angus Taylor. Tom Piotrowski. Alan Kohler.

None of them did anything, which is the whole point of it. Their reputations went out to work without them, earned a good deal of money, and none of it came home. Think about what that means for someone like Kohler, who has spent decades building a particular kind of credibility, the measured bloke who explains the economy without shouting, and then watch thirty seconds of video recommending something he has never heard of in a voice that is recognisably his. ASIC’s deputy chair called it an emergency in the making, which is not the sort of language regulators reach for casually.

That isn’t theft. Theft takes the thing off you. This is forgery, which leaves you holding exactly what you had while somebody else goes shopping with a copy.

The detail in ASIC’s own description is the part that stayed with me, because it isn’t one fake video. The impersonation sits inside a whole apparatus built to look real: spoof websites, invented news articles, fabricated reviews, AI-generated footage, every piece of it pointing at every other piece as proof. It’s a closed loop of evidence with nothing actual inside it, and it works because that is roughly how all of us check whether something is true, by seeing whether the other sources agree.

The number everybody reports, and the one they don’t

Australians reported $2.18 billion in scam losses last year. That comes from the National Anti-Scam Centre’s Targeting Scams report, published in March, which pulls together Scamwatch, ReportCyber, IDCARE, the Australian Financial Crimes Exchange and ASIC into one picture. There were 481,523 reports, 274,577 of them involving money that actually went. Losses were up 7.8 per cent on the year before.

That’s where most of the commentary stops, and stopping there gets the story backwards.

Because $2.18 billion is down 29.7 per cent from the peak. In 2022 the figure was $3.1 billion. Measured as a national total we are winning, and fairly clearly. The banks have got better at this, the telcos have got better at it, and the reporting infrastructure that produces this annual picture barely existed five years ago. So if the money is falling and the thing still feels worse than it did, then the money was never measuring what’s actually changing.

Look at what sits inside the total instead. Investment scams took $837.7 million. Payment redirection took $166.8 million. Romance scams $139.9 million, phishing $97.6 million, remote access $69.9 million, and those five between them account for about 60 per cent of everything lost.

Now read that list again, not as a list of crimes but as a list of relationships. An investment scam works because you believed somebody who sounded like they knew. A payment redirection works because you believed an email from a supplier you have paid forty times without incident. A romance scam works because you believed somebody cared about you. Phishing works because you believed a logo, and remote access works because you believed the bloke on the phone really was from the bank.

Not one of those is a technology failing. Every one is a relationship doing exactly what relationships are meant to do, pointed at somebody who wasn’t there.

And the money lost is almost a rounding error against the real cost, which is a thing nobody has a line item for.

What actually breaks

Somebody in a finance team takes a call from a voice they know. They’ve heard it in meetings for four years, they know how it sounds when it’s tired and how it sounds when it’s cross, and today it’s asking them to move money, and there’s a reason, and the reason makes sense.

They don’t move it. They hang up, walk down the corridor, and check.

Nothing was lost. No report was filed, no number entered that $2.18 billion, and no incident appeared in any register anywhere. But something changed permanently in that building on that morning, which is that every voice is now a maybe.

This is the part the reporting can’t see, because it isn’t looking at the transactions that went wrong. It’s in all the ones that went right, a bit slower, with a small checking step wedged into the middle of them where there didn’t used to be one.

I called that the Checking Tax when I was writing about AI adoption last year, meaning the invisible cost that turns up when people know a system can produce something plausible but nobody has told them what it’s allowed to do without a human looking at it first. It shows up as the gap between the productivity gains an organisation modelled and the ones it actually got. The work still happens, it just happens with somebody standing over it.

What’s happened since is that the Checking Tax has escaped the workflow and landed on the relationship, where it costs nothing you can measure and prices absolutely everything. A call that used to settle a matter now opens one. A message from a colleague is a draft until somebody confirms it another way. An approval isn’t really an approval until it’s been approved twice, and none of those extra steps is unreasonable, which is exactly why nobody argues with any of them.

Multiply one hesitation by every interaction in an organisation and you don’t end up with a security problem. You end up with an organisation running slower for reasons nobody can point at, and the slowness is invisible because each individual instance of it was the sensible thing to do.

Trust doesn’t wear out, it falls off a cliff

Here’s where I think organisations get this wrong, and it’s the reason the whole thing arrives without much warning.

We talk about trust eroding, which puts a slope in your head. Gradual, measurable, something you’d notice at the halfway mark and could do something about before you got to the bottom. That isn’t how it behaves at all. What I’ve watched happen in boardrooms and leadership teams over thirty-odd years is that trust holds completely and then stops completely, and what sets it off isn’t time, it’s stakes.

I call these Trust Cliffs, meaning the point where comfort with a system, or a person, or a channel, drops away the moment real money or real people or a reputation comes into the frame. There’s no gradient to it. There’s a wide flat plain, and then an edge.

You can watch it happen in a room in about four minutes. Ask a group of executives whether they’d let an AI draft a document and most of the hands go up without much thought. Ask the same room whether they’d let it decide a redundancy, and the hands don’t drift down, they drop, and the temperature in the room changes with them. Nobody slides along a spectrum. They step off a cliff they hadn’t noticed was there until they were standing at the edge of it.

Voice does the same thing now, which is why so many organisations think they’re fine. Every low-stakes call they’ve taken this year worked perfectly. The voice was the voice, the request was routine, nothing bad happened, and all of that evidence quietly accumulates into a feeling of safety that has never once been tested, because the plain is enormous and the edge is only at one end of it.

Then one call comes in with a real number attached, and the whole structure of assumption the place has been running on for years goes in an afternoon.

Underneath the cliff sits the emotional layer, the one I’ve called PTFA, past trauma and future anxiety. An organisation that got caught once carries the scar into every decision afterwards and over-verifies everything on principle. An organisation that hasn’t been caught carries an anxiety it can never quite discharge, because there’s no way to prove a negative about a voice. Neither of those is a good state to make judgments from, and both of them reliably produce more process.

What we did last time our currency was forged

In December 1966, a few months after Australia had switched to decimal currency, high quality forgeries of the brand new paper ten dollar note started turning up in volume, apparently from a single syndicate, and they were good. The tell, once somebody finally found it, was almost nothing at all: on the real note the horizontal lines of the Times Bakery building sat flush with the building’s vertical edge, and on the fakes they were a fraction out. That was it. That was the whole difference between the real currency and the counterfeit one.

The Reserve Bank did not respond by teaching the country to look harder at bakery windows.

It put together a think tank with scientists from CSIRO and asked a completely different question, which was not how do people tell these apart but what would a banknote have to be made of so that this stops working. The answer turned out to be a plastic substrate that could carry security features paper never could. The first polymer note, the commemorative ten, came out in 1988, and between 1992 and 1996 Australia became the first country in the world to move its entire currency across.

Twenty-two years from the forgery to the answer, and the answer had nothing to do with detection.

Which is the move sitting available right now, and almost nobody is making it, because pretty much everything published about voice cloning and deepfake impersonation is detection advice. Listen for the flat tone. Watch the blink rate. Ask a question only the real person would know. All of it is the 1966 equivalent of squinting at a bakery.

Detection advice has a flaw in it that no amount of improvement will ever fix, which is that it puts the whole burden on the least prepared person in the building at the worst possible moment, and it has to win every single time, while the forgery only has to get through once. We learned that lesson properly the first time and then built a national currency around it.

The old devices, including mine

For years the advice I gave people was to agree a word. Not a password, and not anything that fits the conversation. A word that makes no sense where it turns up, so that when somebody drops it into a call you know it’s really them. Pineapple, say. Somebody rings asking you to move money and you ask them what the word is, and either it arrives or it doesn’t.

I still think it’s worth having, and I’ll be honest about what it is, which is a homemade device rather than a solution. A word can be learned. It can be overheard, or sitting in an old email thread, or given up by somebody who didn’t realise what they were handing over. A determined operation that has already built a fake voice and a fake video call has probably done enough homework to have a go at the word too.

So it’s an old-fashioned thing, and I’d offer it as one of the things a family or a small team might do rather than something an organisation should write into a policy and then relax.

But notice what it actually is, because this is the bit that matters. The code word is an old trust formula. It’s the same class of device as recognising somebody’s handwriting, or knowing their knock, or the fact that your mother’s voice on the phone was proof it was your mother. In 2017 I said those old formulas didn’t quite work online and the new artificial ones didn’t either. What’s changed in the years since is only that the gap between the two has become expensive.

And this is the easy version

Voice is where we are today. It is not where this stops, and anybody planning only for voice is planning for the version of the problem that has already arrived.

The same technology that clones a voice from a few seconds of audio is getting steadily better at the face, then the face in motion, then the small things underneath the face. The pause somebody takes before they disagree with you. The way they say your name. The particular shrug they do when they’re about to say no but haven’t decided how. None of those are hard problems in principle, they’re just further down the same road, and the road is being paved quickly.

What sits at the end of it is a digital twin: a working model of a person, convincing across voice and face and manner and history, that can hold a conversation in real time. Some of those will be entirely legitimate and built with permission, because there are good reasons an organisation might want one. The trouble is that a legitimate capability and a forged one are the same capability, and the only difference is who authorised it.

Which means the question underneath all of this was never really a security question. It’s a HUMAND question, the one I keep coming back to with boards: what is a human for in this process, and what are we handing to a machine. If a machine can now be you convincingly enough to move money, then presence has stopped being proof, and everything we built on presence being proof needs looking at again.

I don’t think that’s cause for alarm so much as cause for getting in front of it. We have some time on the digital twin, less than people think but more than none, and the organisations that use it will be the ones that sort out the authority question now, while it’s still a conversation rather than an incident.

Ripple, and then ripple again

The first-order consequence of forged reputation is the money, and that’s the $7.4 million, and that’s the part that gets reported.

The second order is the Checking Tax, spreading out through an organisation uncosted, showing up as a general sense that things take longer than they used to and nobody can say quite why.

The third order is the one I’d pay attention to, because it’s the one that stays.

Watch what a sensible organisation does the moment it notices the hesitation. It writes a procedure. Callbacks on a known number, two-person authorisation above a threshold, maybe a code word. All reasonable, and I’d argue for most of them myself.

But look at what the procedure does to the person, because it moves the decision out of their judgment and into a checklist, and it does that at precisely the moment their judgment was the thing that saved the money. The finance officer who hung up and walked down the corridor did it because something felt off. That instinct is the most valuable security asset in the building, and the procedure written to honour it quietly takes its place.

It moves through the finance team, who stop reading the request and start reading the checklist.

It moves through the leadership team, who find their own voice is no longer sufficient authority for anything that matters, and start routing decisions through channels that feel more verifiable and are almost always slower.

It moves through the customer, who came looking for a relationship with a person and finds themselves inside a verification procedure instead.

And it moves through whoever started last Monday, who learns in their first week that nobody here is taken at their word, and calibrates accordingly for as long as they stay.

None of that shows up in a scam statistic, and all of it was set in motion by a phone call that didn’t even work.

Two questions, and only one of them is any use

There are two questions an organisation can ask about all of this, and most of them are asking the first one.

How do we stop being fooled? That’s a detection question, it’s endless, the sides aren’t evenly matched, and the technology moves considerably faster than the training does. You can pour money into it indefinitely and the ground keeps shifting under you.

The second question is the one the Reserve Bank asked in 1966. What decisions in this organisation can currently be set off by a voice, and which of them should never be?

That one is a design question, and the useful thing about design questions is that they’re finite. There’s an answer, you can get to it in a single meeting, and once you have it the forgery stops working whether or not anybody spots it. It also holds when the face arrives, and when the digital twin arrives, because it was never about what the forgery looked like.

It’s the same distinction I use when I take a board through Decision Trust Zones, mapping out where an organisation will and won’t let a machine make the call. The useful work is never in improving the detection at the boundary. It’s in deciding where the boundary goes, out loud, before anybody is under pressure. A control you reach for in the moment is a control that depends on a frightened person operating it correctly, and a boundary you set in advance doesn’t need anybody to be brave at four o’clock on a Friday.

The decision worth making before the pressure arrives

One meeting settles most of this.

Write down every decision in your organisation that can currently be set in motion by somebody’s voice, or their face on a screen, or a message that looks like it came from them. Payments, access, credentials, data, a change to bank details, an approval to release something, getting somebody through a door.

Then go down the list and mark the ones where a voice on its own should never be enough, whoever it belongs to, however urgent it sounds, however senior they are.

Then tell everybody, and not as a policy document. Tell them as a promise, phrased the way round that actually protects people: I will never ask you to do this on a call, so if I appear to, it isn’t me, and you have my permission to refuse me.

That last sentence is the whole thing. It costs nothing, it takes a minute, and it takes away the pressure every one of these attacks runs on, which is a junior person weighing up a bank balance against the career risk of telling somebody senior no.

You’re not making your people better at spotting a forgery. You’re making the forgery worthless.

Nine years on

The 2017 call holds up, and I want to be careful about which part of it, because the careful bit is where the useful stuff is.

Reputation did become the currency. The systems built to verify it, the stars and the reviews and the profile photos, didn’t hold, which that segment said they wouldn’t. Neither of those was especially hard to see at the time if you were watching how many strangers were being asked to trust strangers at a scale nobody had tried before.

Where I’d put it differently now is what breaks first. Fragile, easy to break, hard to rebuild is true of a person. Inside an organisation it works differently, because institutional trust doesn’t crack. It holds absolutely, right up to the stakes that matter, and then it’s gone in an afternoon, and what’s left behind isn’t distrust exactly. It’s a verification step, on everything, from now on.

That’s why trust collapses in organisations the way it does. Not because it wore thin, but because it was never being tested anywhere near the altitude where it counts, and the first real test turned out to be the last one.

You don’t get to choose whether your reputation can be forged. A technology neither you nor I have any say over settled that, and it has already finished arriving. The face and the gestures and the twin are on their way behind it.

What you do get to choose is what your reputation is still allowed to authorise, and that decision is yours, it’s available this week, and it’s worth considerably more than every detection tool on the market.

Choose Forward.

Frequently Asked Questions

Why does trust collapse suddenly in organisations rather than fading gradually?

Because what triggers the collapse is stakes, not time. Trust in a person, a system or a channel holds completely across every low-stakes interaction, and then drops away entirely the moment real money, real people or a reputation enters the frame. Morris Misel calls this a Trust Cliff. The reason organisations are caught out is that a long run of successful low-stakes interactions feels like evidence of safety, when it has never tested the thing that matters.

What is the Checking Tax?

The Checking Tax is the invisible verification cost that appears when people know a system can produce something plausible but nobody has told them what it is allowed to do without a human reviewing it. It was coined by Morris Misel to describe the gap between the productivity gains an organisation modelled from AI and the gains it actually got. With voice cloning, the same overhead has moved from workflows onto relationships, so a call that used to settle a matter now opens one.

How much are AI impersonation scams costing Australians?

Australians reported $2.18 billion in scam losses in 2025, according to the National Anti-Scam Centre’s Targeting Scams report published in March 2026. Separately, ASIC reported that impersonations of well-known Australians drew $7.4 million in the 2026 financial year, and that it removed more than 19,400 scams over that period, up 182 per cent. The national total is falling, down 29.7 per cent from the 2022 peak, which is why the dollar figure is a poor guide to what is changing.

Does a code word protect against voice cloning?

Partly, and it is worth having, but it is a homemade device rather than a solution. A shared nonsense word can be learned, overheard, found in an old email thread, or given up by somebody who did not realise what they were handing over. It suits a family or a small team better than an organisational policy. The more durable answer is deciding in advance which decisions a voice should never be able to authorise at all.

Why is detection training the wrong answer to deepfakes?

Because detection puts the burden on the least prepared person at the worst moment, and it has to succeed every time while the forgery only has to succeed once. Australia already learned this with currency. After high quality forgeries of the paper ten dollar note appeared in December 1966, the Reserve Bank did not train the public to spot fakes. It worked with CSIRO on a banknote the forgery could not reproduce, which became the world’s first polymer note in 1988.

What should a leadership team actually decide about AI impersonation?

List every decision that can currently be set in motion by somebody’s voice, face on a screen, or a message that appears to come from them, then mark the ones a voice alone should never authorise regardless of who it belongs to or how urgent it sounds. Then say so openly, as a promise: I will never ask you to do this on a call, so if I appear to, it is not me. That removes the pressure these attacks rely on, and it holds when face cloning and digital twins arrive, because it was never about what the forgery looked like.


Before the pressure arrives

Deciding where a voice stops being sufficient authority is a boardroom conversation, not a security one, and it goes far better before an incident than after. Mapping those boundaries with leadership teams is part of the work I do, alongside keynotes on what is already arriving and what it asks of the people who have to decide.

Book Morris for a keynote, board session or workshop

Every week I publish Glimpses from the Future, short reads on the signals already arriving and what they ask of leaders. Subscribe here.


About Morris Misel

Morris Misel is a foresight strategist and keynote speaker based in Melbourne, Australia. With 30+ years of experience working with leaders, boards, associations, and organisations across Australia and internationally, Morris works with people to prepare for uncertainty, interpret signals, and make better strategic choices.

His work is grounded in several proprietary frameworks including HUMAND (a decision model for human-machine-AI work allocation), PTFA (Past Trauma, Future Anxiety), Ripple Effects (second and third-order consequence mapping), Trust Cliffs (why confidence collapses suddenly rather than gradually), and Immediate Futures (what is already arriving and needs attention now).

Morris speaks regularly on the future of work, leadership in uncertainty, AI strategy, and organisational foresight. He is a regular guest on RTHK Radio 3 (Hong Kong) and has appeared across Australian and international media.

Learn more: morrisfuturist.com | morrismisel.com

Leave a comment