The FBI is warning that cybercriminals are escalating online fraud campaigns by using AI deepfake IC3 scams to target people who have already lost money to cyber-enabled crime. The latest alert centers on scammers impersonating the FBI’s Internet Crime Complaint Center, commonly known as IC3, and using synthetic media, spoofed websites, and social engineering to re-victimize vulnerable individuals.
The warning, published on July 20, 2026, describes a campaign in which attackers pose as FBI personnel or recovery agents and falsely claim they can help victims recover stolen funds. Instead, the scheme is designed to collect more personal information, financial data, and potentially additional payments from people who are already under emotional and financial pressure.
Key Details
According to public reporting on the FBI alert, the campaign builds on earlier IC3 impersonation activity but introduces newer tactics, including AI-generated videos of FBI officials and fraudulent versions of the official IC3 website. These fake sites are designed to closely resemble legitimate government portals while collecting sensitive information through simplified complaint forms.
The FBI has previously warned that scammers impersonating IC3 employees contact victims through several channels, including email, phone calls, social media, forums, and online communities. In many cases, the attackers claim they have recovered lost funds or can help victims recover money, but the claim is a ruse to obtain more financial information or assets.
In one variant, victims who indicate they plan to file an IC3 complaint are contacted by someone pretending to be an FBI agent through Facebook Messenger. The conversation is then moved to Telegram, where the fake agent sends a link and asks the victim to update an IC3 report. The link may be used to collect further financial data or deliver malicious code.
Another variant uses AI-generated deepfake videos that appear to show a senior FBI official directing users to file complaints through a spoofed IC3 website. The fake page reportedly mimics the appearance of the official IC3 site but offers limited functionality, collecting details such as name, phone number, email address, scam type, and estimated loss before issuing a reference number and promising follow-up contact.
The official IC3 website has also warned that scammers impersonating IC3 may claim to work with recovery firms, law firms, or cryptocurrency services, even though IC3 does not work with non-law enforcement entities to recover lost funds and does not directly contact people for money or information.
Technical Analysis
This campaign is not a malware-first operation. It is a trust-first attack that combines impersonation, phishing infrastructure, deepfake media, and psychological pressure.
The technical chain begins with reconnaissance and targeting. Attackers appear to focus on individuals who have already reported fraud, discussed scams in public forums, joined victim-support groups, or expressed interest in filing an IC3 complaint. This makes the campaign especially dangerous because the victim is already primed to trust someone claiming to be connected to law enforcement.
The second stage is impersonation. Attackers create fake identities that resemble FBI personnel, IC3 representatives, or fund recovery specialists. Earlier FBI guidance described scammers using social media profiles and directing victims to Telegram, where they posed as officials and claimed to have recovered funds.
The third stage is infrastructure abuse. Spoofed IC3 websites are designed to imitate legitimate government services. The FBI has warned that fake IC3 domains may use altered spellings, alternative top-level domains, or other deceptive characteristics to harvest personally identifiable information, including names, addresses, phone numbers, email addresses, and banking information.
The fourth stage is synthetic media amplification. Deepfake videos add a layer of perceived authority by making it appear as if a senior official is endorsing a specific website or process. This tactic is particularly effective because it exploits the public’s trust in government institutions and the growing difficulty of distinguishing authentic video from AI-generated content.
From a MITRE ATT&CK perspective, the activity aligns conceptually with phishing, trusted relationship abuse, impersonation, and user execution through malicious links. There is no publicly disclosed CVE, malware family, ransomware group, or exploit chain associated with this specific alert based on the available information.
Impact and Risks
The most immediate risk is re-victimization. People who have already suffered financial losses may be more likely to respond quickly to someone claiming to represent the FBI or offering a path to recover stolen funds. That emotional pressure gives attackers a powerful social engineering advantage.
The privacy impact is also significant. Fake IC3 portals can collect names, contact details, financial information, banking identifiers, cryptocurrency wallet details, transaction history, and descriptions of prior fraud. The FBI has warned that spoofed IC3 sites may be used for personal information theft and monetary scams.
For individuals, the consequences may include identity theft, additional financial losses, account takeover attempts, targeted phishing, and follow-on fraud. For organizations, the campaign is a reminder that employees targeted in personal scams can become exposed to corporate risk if attackers later use stolen credentials, reused passwords, or compromised personal devices.
Security teams should also treat this as a broader indicator of how AI is reshaping fraud operations. Deepfake content gives low-cost criminal groups the ability to imitate authority figures more convincingly, while phishing kits and spoofed websites make data collection faster and more scalable.
Expert Recommendations
Individuals should navigate to the official IC3 website by typing the address directly into the browser rather than clicking links in messages, search ads, social media posts, or emails. The FBI has specifically advised users to type the IC3 URL, avoid sponsored search results, and verify that the site ends in .gov before entering information.
Anyone contacted by a person claiming to be from IC3 should treat the message as suspicious. The FBI has stated that IC3 does not maintain a social media presence, does not initiate contact by phone, email, or chat app, and does not ask for payment to recover funds.
Victims should never send money, gift cards, cryptocurrency, or other assets to people they have met only online or by phone. The FBI has also warned that IC3 will not ask for payment to recover lost funds or refer victims to a company requesting payment for recovery services.
Security teams should update phishing awareness programs to include AI-generated video and voice impersonation scenarios. Traditional advice focused only on suspicious email links is no longer enough when attackers can use realistic video, voice cloning, and social media identities to create a convincing chain of trust.
Organizations should monitor for employee reports involving fake law enforcement contact, recovery scams, new Telegram-based outreach, and suspicious links that imitate government sites. SOC teams can improve detection by monitoring for lookalike domains, suspicious redirects, newly registered domains resembling official government services, and endpoint activity following visits to fake complaint portals.
Individuals who believe they have interacted with an IC3 impersonator should preserve communications, links, phone numbers, email addresses, wallet addresses, transaction details, and screenshots. The FBI requests that victims report fraudulent or suspicious activity and include identifying information, communication methods, financial transaction data, and details about how the contact was initiated.
Industry Context
The FBI warning reflects a broader shift in cybercrime. Fraud groups are increasingly combining traditional social engineering with AI-generated content, spoofed web infrastructure, cryptocurrency recovery lures, and cross-platform messaging. The result is a more persuasive form of phishing that does not rely solely on email.
This campaign also shows why deepfake fraud is moving beyond celebrity scams and political disinformation. Criminals are using synthetic media to impersonate institutions, not just individuals. When a fake video appears to show a law enforcement official, the victim may be less likely to question the legitimacy of a link or form.
The IC3 impersonation campaign also fits into the wider growth of “recovery scams,” where attackers target people who have already lost money to investment fraud, cryptocurrency scams, tech support scams, or business email compromise. These schemes exploit urgency, shame, and the hope of recovering funds.
For defenders, the key lesson is clear: verification must move beyond visual trust. Logos, polished websites, convincing videos, and official-sounding messages are no longer reliable indicators of legitimacy. Strong authentication, direct navigation to official websites, and independent verification through trusted channels are now essential safeguards.
Conclusion
The FBI’s warning on AI deepfake IC3 scams highlights a dangerous evolution in online fraud: attackers are no longer just pretending to be trusted institutions through emails or fake websites. They are using synthetic media and targeted social engineering to make those impersonations more believable.
For victims, the safest response is to avoid unsolicited recovery offers, never trust links shared through social media or messaging apps, and report suspicious activity only through the legitimate IC3 portal. For security teams, the alert is another sign that AI-enabled social engineering must be treated as a mainstream cyber risk, not an emerging curiosity.