Why the distinction matters
Australia’s Scams Prevention Framework (SPF) introduces a subtle but important shift in how organisations should think about scam prevention.
The framework doesn’t simply talk about takedowns. It talks about disruption. That difference matters because takedowns and disruption are not the same thing.
For years, organisations have focused on identifying scam websites and getting them removed. A phishing site is discovered, a report is submitted, the site is suspended, and the case is closed. The assumption is often that once the website is gone, the threat has been dealt with.
The problem is that scammers don’t operate from a single website. They operate campaigns.
A phishing website is often just one component of a broader ecosystem designed to attract victims, collect information and continue operating even when individual assets are removed. A victim might encounter a fake advertisement on social media, be directed to an impersonation website, provide their details, and then be contacted through other channels as the scam progresses.
From a consumer’s perspective, they see a single scam. From an operational perspective, we’re often looking at multiple domains, fake social media profiles, fraudulent advertisements, email infrastructure and other supporting assets working together.
That’s why a takedown should never be viewed as the objective. It’s simply one tactic used to achieve disruption.
Scammers operate campaigns, not websites
One of the biggest misconceptions about online scams is that they exist as isolated incidents.
In reality, most scam activity is made up of multiple interconnected components designed to work together.
A typical campaign might begin with a fraudulent advertisement on Meta, Google or another platform. That advertisement directs users to a phishing website impersonating a trusted organisation. The website captures credentials, payment information or personal details before directing victims to the next stage of the scam.
Behind that activity is often a network of supporting infrastructure including multiple domains, fake social media accounts, fraudulent advertising campaigns, email services, SMS capabilities and payment collection mechanisms.
The website itself is only one piece of the puzzle.
Most threat actors already expect individual assets to be removed and plan accordingly. Backup domains are registered, additional advertisements are prepared, replacement social media accounts are created and alternative infrastructure is kept ready to deploy.
As a result, removing a single asset rarely ends the campaign.
We’ve seen phishing websites replaced within hours of being suspended. Fraudulent advertisements often reappear using different accounts and slightly modified content, while fake social media profiles can be recreated almost immediately after removal.
This doesn’t mean enforcement isn’t working. It means enforcement alone isn’t enough.
The objective shouldn’t be to remove a website. The objective should be to reduce the scammer’s ability to reach victims.
Achieving that often requires coordinated action across multiple platforms and assets. The advertisement needs to be removed. The phishing domain needs to be suspended. Associated social media accounts need to be reported. Related infrastructure needs to be identified and investigated.
Most importantly, organisations need to understand what happens next. Because that’s where effective disruption begins.
Why monitoring is as important as enforcement
One of the lessons we’ve learned repeatedly is that disruption doesn’t end when an asset is removed. In many cases, that’s when the real work begins.
Take a fake advertisement directing users to a phishing website. Removing the website alone doesn’t necessarily stop the campaign. If the advertisement remains active, victims may simply be redirected to replacement infrastructure. On the other hand, removing the advertisement while leaving the phishing site online still gives the threat actor an opportunity to drive traffic through other channels.
The same principle applies across most forms of online abuse. Fake social media accounts, impersonation domains and fraudulent mobile applications rarely exist in isolation. They’re often part of a broader campaign, and removing a single component without understanding the wider activity can simply cause the threat actor to adapt and continue elsewhere.
This is why monitoring is just as important as enforcement.
The organisations achieving the strongest outcomes aren’t necessarily those submitting the highest volume of takedown requests. They’re the organisations that understand what happens after enforcement occurs.
When a phishing domain is suspended, do similar domains appear shortly afterwards?
When a fraudulent advertisement is removed, does the campaign re-emerge on another platform?
When a fake social media account is taken down, have additional accounts already been created?
Without ongoing monitoring, organisations are left reacting to incidents after they’ve occurred.
With monitoring, they can identify replacement infrastructure early, uncover related assets and respond before campaigns regain momentum.
Effective disruption requires visibility across the entire campaign, not just the individual asset currently being reported.
Disruption in practice
One example that stands out involved a well-known Australian brand that was being targeted through Meta advertisements directing users to fake online stores.
When we first started monitoring the activity, it felt relentless. Every day there were new advertisements, new social media accounts and new fake shops appearing. We’d remove one asset and another would pop up shortly afterwards.
Rather than treating each instance as an isolated takedown, we focused on disrupting the campaign as a whole. We monitored for new activity daily, reported fraudulent advertisements, removed fake social media accounts and took action against the fake shops supporting the campaign.
Over time, the volume started to decrease. A year later, the issue is largely gone.
I don’t believe that’s because of any single takedown. I believe it’s because the threat actors were consistently met with resistance. Every time they created new infrastructure, it was identified and actioned. Every time they attempted to rebuild the campaign, they were forced to start again.
Eventually, the effort required to continue targeting that brand likely outweighed the value they were getting from it.
That’s the difference between a takedown and disruption.
Disruption in practice
One of the strengths of the SPF is that it recognises scams for what they are: adaptive campaigns rather than isolated incidents.
(The unphish Threat Feed helps organisations identify and investigate scam campaigns by centralising suspected threats, brand impersonation activity and related infrastructure within a single view.)
The framework’s focus on disruption reflects the reality that reducing consumer harm requires more than responding to individual websites or domains. It requires organisations to identify threats, understand how they operate and take action against the infrastructure supporting them.
That is a far more accurate reflection of the threat landscape we see today.
One of the challenges with scam prevention is that success is often measured through activity rather than outcomes.
Takedowns are easy to count. Disruption is much harder to measure.
An organisation might remove hundreds of phishing websites over the course of a year. On paper, that sounds impressive. The more important question is whether those actions actually reduced consumer exposure and made it harder for scammers to continue operating.
Removing a single website may contribute to a successful takedown metric. Disrupting multiple parts of a scam campaign can significantly reduce its reach and impact.
Both may look similar in a report. Only one reflects a meaningful reduction in harm.
The SPF recognises that modern scams are rarely isolated websites that can be addressed through a single report and takedown request. They are coordinated, multi-platform campaigns that adapt quickly when enforcement occurs.
Organisations that approach scam prevention as a series of isolated takedowns will often find themselves reacting to the same threats repeatedly. Those that invest in intelligence, monitoring and coordinated disruption are far better positioned to reduce consumer harm over the long term.
Ultimately, that is what the SPF is trying to achieve.
Not simply more takedowns. More effective disruption.