Fake Musk, Real Losses: Deepfake Ads Linked to $61.5M in South African Investor Losses in Banxso Scandal
Deepfakes, Data and the Banxso Scandal: A Data Governance Reading of AI-Enabled Financial Fraud | Data Governance Africa

Artificial intelligence is making financial fraud harder to recognise.

A recent South African regulatory case involving online trading platform Banxso shows how deepfake technology, misleading advertising, personal data and digital financial services can combine to create a sophisticated fraud pipeline.

The case is bigger than one company or one trading platform. It raises a fundamental question for regulators and digital businesses across Africa: who is responsible when artificial intelligence is used to manufacture trust and move people’s money?

From Deepfake Ads to Trading Accounts

The scheme began with online advertisements operating under the name “Immediate Matrix.” The adverts used manipulated videos and voices of prominent figures, including Elon Musk and Johann Rupert, to create the impression that these individuals were endorsing an investment opportunity.

The advertisements promised extraordinary returns. Potential investors were told that an initial deposit of about R4,700 could generate monthly earnings of up to R300,000.

The attraction was not simply the promise of money. It was the manufactured credibility behind the promise.

Users who interacted with the advertisements were funnelled towards representatives connected to Banxso, where they were encouraged to deposit funds and trade Contracts for Difference (CFDs), complex and high-risk financial products.

This illustrates an important evolution in online fraud: AI is increasingly being used not merely to impersonate people, but to manufacture the entire appearance of legitimacy.

The Money Trail

According to findings by South Africa’s Financial Sector Conduct Authority (FSCA), the consequences went far beyond misleading advertising.

Almost R1 billion in client money was allegedly siphoned through the platform.

The regulator found that client funds were commingled, transferred through accounts that were not designated for the relevant purpose and used for corporate and personal expenses.

The FSCA also found that client money was not being transferred to authorised over-the-counter derivative providers or legitimate liquidity providers as expected. Instead, trading was handled internally.

That distinction matters.

A customer may believe they are participating in a genuine financial market while the underlying system operates very differently from what the customer has been led to believe.

In other words, the fraud was not limited to the advertisement. The deceptive marketing formed part of a broader digital and financial infrastructure through which customers were acquired, persuaded and exposed to financial loss.

The Regulator’s Response

The FSCA imposed severe sanctions.

A R2 billion joint administrative penalty was imposed against Banxso and executives Harel Adam Sekler and Warwick David Sneider.

Additional penalties included:

  • R16 million against Banxso;
  • R20 million against Manuel de Andrade;
  • R10 million against Mohammed Bux; and
  • R5 million against Henry James Simpson.

Sekler, Sneider, De Andrade and Bux were handed 30-year debarments, while Simpson received a 10-year debarment.

Banxso’s financial services provider licence was also permanently withdrawn.

The matter was further referred to South Africa’s Directorate for Priority Crime Investigation, commonly known as the Hawks, for potential criminal prosecution.

The Western Cape High Court subsequently placed Banxso into final liquidation after finding its trading framework illegal.

The “Hacked by Someone Else” Defence

One of the most significant aspects of the case concerns responsibility for the deepfake advertising.

Banxso argued that it had been the victim of third-party hacking or what it described as “parasitic” marketing.

The FSCA and the High Court rejected this explanation.

Their findings pointed towards a more important principle: a company cannot necessarily distance itself from a fraudulent customer-acquisition system simply because the deception was carried out through third parties.

Where a business benefits from the leads generated by deceptive advertising, questions arise about what it knew, what it should have known, what controls it had in place and whether it took reasonable steps to prevent the abuse.

This principle becomes increasingly important as companies rely on advertising networks, influencers, affiliates, automated systems and AI-generated content to acquire customers.

Why This Is a Data Governance Issue

At first glance, the Banxso case appears to be primarily about financial regulation and consumer fraud.

But there is also a significant data governance dimension.

Deepfake fraud depends on data.

Images, voices, names, professional profiles and publicly available information about individuals can be collected and manipulated to create convincing synthetic identities or endorsements.

At the other end of the process, prospective investors provide their own personal and financial information to platforms that promise investment opportunities.

The result is a chain involving:

data collection, AI manipulation, targeted advertising, customer profiling, financial onboarding, transactions, financial records.

Weak governance at any point in that chain can create serious consequences.

The case therefore demonstrates why data governance cannot be treated as an internal compliance exercise disconnected from product design, marketing, cybersecurity and financial risk.

The African AI Governance Question

For African regulators, the lesson is particularly relevant.

Deepfakes are becoming cheaper and easier to produce. At the same time, digital financial services are expanding rapidly across African markets.

That combination creates an attractive environment for fraudsters.

A fabricated endorsement from a famous entrepreneur, politician, celebrity or financial expert can be distributed to thousands or millions of people through social media and digital advertising. Once a user clicks, automated systems and human agents can take over the conversion process.

Traditional fraud controls may struggle because the deception occurs before the customer reaches the regulated financial institution.

This creates a regulatory gap worth addressing: who monitors the advertising layer? Who verifies claims made by affiliates? Who is responsible for AI-generated endorsements? And what happens when a regulated entity benefits from customers acquired through fraudulent means?

From AI Safety to AI Accountability

The Banxso case also illustrates why discussions about AI governance need to move beyond abstract principles.

It is not enough to ask whether an AI system is accurate or whether a company has an AI policy.

Organisations should also ask:

  • Can our systems be used to impersonate people?
  • Can our advertising partners generate synthetic endorsements?
  • Do we know where our customer leads originate?
  • Can we trace the data and decisions involved in customer acquisition?
  • Are financial promotions being independently verified?
  • What happens when an affiliate or third party violates the law?
  • Can we demonstrate who was responsible for approving a campaign?

These are governance questions as much as they are technology questions.

The Real Warning

The most important lesson from the Banxso scandal is that AI can industrialise trust as easily as it can industrialise deception.

A deepfake does not need to be perfect to work. It only needs to be convincing enough to make someone click, deposit money or surrender personal information.

Once that happens, the technology behind the deception becomes only one part of the problem. The larger issue is the ecosystem around it: advertising platforms, data brokers, lead generators, financial intermediaries, customer onboarding systems and the governance structures responsible for monitoring them.

For Africa, the challenge is therefore not simply to detect deepfakes.

It is to build digital systems where synthetic content, questionable data practices and misleading financial claims cannot easily move from the screen to someone’s bank account.

The Banxso case offers a powerful reminder: when digital trust becomes a financial asset, governing how that trust is created, verified and exploited becomes a data governance responsibility.

Leave a Reply

Your email address will not be published. Required fields are marked *