unphish
unphish unphish

How the SPF Turns Brand Impersonation Into a Compliance Issue

How the SPF Turns Brand Impersonation Into a Compliance Issue

Brand impersonation has long been one of the most common tactics used in online scams. Fake websites, lookalike domains, fraudulent social media profiles and impersonated brands are routinely used to deceive consumers and build trust in scam campaigns.

Under Australia’s draft Scams Prevention Framework (SPF) Codes, brand impersonation is no longer simply a cybersecurity or brand protection issue. The draft introduces explicit expectations for regulated entities to have systems and processes in place to help prevent their brands from being used to facilitate scams.

That represents an important shift. Rather than responding only after consumers report a scam, organisations may be expected to actively monitor for brand impersonation, protect their official communication channels and take steps to reduce opportunities for scammers before harm occurs.

Brand impersonation has traditionally been treated as a security issue

According to Scamwatch, Australians have reported more than 61,400 scams in 2026, with phishing among the highest-loss scam types, resulting in almost $6 million in reported losses. Many of these scams rely on impersonating trusted organisations through fake websites, fraudulent emails, lookalike domains or cloned social media accounts.

Historically, incidents like these have been treated as operational issues. Responsibility has typically sat across cybersecurity, brand protection, legal or marketing teams, with action often taken only after suspicious activity was identified internally or reported by customers.

While many organisations already invest in brand protection activities, these efforts have generally been driven by risk management and customer protection rather than regulatory compliance.

The draft SPF Codes begin to change that.

The draft SPF Codes change that

Section 2-7 of the draft SPF Codes introduces one of the clearest examples of how the SPF shifts brand protection into a compliance obligation.

The draft requires regulated entities to have reasonable systems and processes to prevent their brand, brand assets or likeness from being used to facilitate scams.

To support this obligation, the draft Codes state that organisations should:

Importantly, the draft Codes don’t prescribe a single approach that every organisation must follow. Instead, they recognise that what is considered “reasonable” will depend on factors such as the organisation’s size, the services it provides, the scam risks it faces, the threat landscape, the use of contemporary technologies, continuous improvement, industry practices and the potential harm to consumers.

This represents a significant shift. Proactive monitoring for brand impersonation is no longer presented simply as a security best practice. Under the draft SPF Codes, it becomes part of demonstrating that an organisation has reasonable systems and processes in place to help prevent scams.

Prevention requires visibility

One of the reasons Treasury has included brand impersonation under the prevent principle, rather than detect, is because organisations are expected to reduce opportunities for scammers before harm occurs.

That means waiting until customers report a phishing website, a fake social media profile, or consumers begin losing money is no longer enough.

Instead, organisations need visibility across the digital channels where brand impersonation commonly occurs, including lookalike domains, phishing websites, fake social media accounts, scam advertisements and other online content that misuses their brand.

Visibility isn’t valuable simply because it helps organisations identify threats. It helps demonstrate that reasonable systems and processes are in place to monitor for brand impersonation and take action before scams reach consumers.

This reflects one of the most significant shifts introduced by the draft SPF Codes: proactive monitoring is no longer just a security best practice. It becomes an important part of helping organisations meet their broader scam prevention obligations.

What this means in practice

For many organisations, the draft SPF Codes raise practical questions rather than technical ones.

These aren’t simply cybersecurity questions. Increasingly, they’re compliance questions.

As organisations prepare for the SPF, the focus is likely to shift from whether brand monitoring is a worthwhile investment to whether existing systems and processes are sufficient to demonstrate compliance with the framework’s scam prevention expectations.

unphish centralises every investigation into a single case file, bringing together evidence and screenshots

(unphish centralises every investigation into a single case file, bringing together evidence and screenshots.)

Assess Your SPF Readiness with us

Complete the form below and one of our specialists will be in touch.

    About unphish

    Protect Your Brand with unphish

    unphish is a threat detection and disruption platform built to identify and take down phishingscams, and digital impersonation at scale. We combine intelligence-led detection with automated enforcement to help organisations protect their brand, customers, and digital ecosystem.

    See unphish in Action

    Detect, Validate, and Take Down Threats Automatically

    unphish combines intelligence-led detection with automated enforcement so you can protect your brand, customers, and digital ecosystem without the manual effort.

    Create your account