Deepfake FBI Videos Push Victims to Fake IC3 Sites

Infosecurity Magazine · High sophistication
Last updated July 30, 2026

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI agent and sent a link to “update” their IC3 complaint, which either delivers malicious code or harvests additional details.

How the attack worked

The scheme relies on impersonating a trusted authority, the FBI and its Internet Crime Complaint Center (IC3), to re-victimize people who had already filed or discussed a fraud complaint. In one variant, a fraud victim who mentioned filing an IC3 complaint was contacted on Facebook Messenger by someone posing as an FBI agent, who supplied a link to update the report. The link either carried malicious code or collected further financial details.

A second variant used AI-generated videos of a senior FBI leader urging users to file complaints on a spoofed IC3 site. The fake portal mimicked the real ic3.gov but stripped the complaint workflow down to a single form requesting name, phone number, email, scam type and estimated financial loss. After submission, the site issued a reference number and promised follow-up, at which point the operators harvested further data. A third variant involved live video calls using AI to impersonate executives or officials, aiming to extract credentials or financial records directly.

Why it succeeded

Messages appearing to come from the FBI carried disproportionate weight in a phishing context, making targets less likely to question the request. Prior fraud victims were especially vulnerable because they were already expecting follow-up communication about their case, and the promise of recovering lost funds added emotional pressure. The use of deepfake video added a layer of visual credibility that text-based phishing lacks, making authority claims feel more legitimate at a glance.

What to watch for

  • Outreach claiming to be from the FBI or IC3 that arrives via social media messaging rather than official channels
  • Links asking you to "update" a complaint instead of directing you to navigate to a known official site yourself
  • Deepfake video indicators such as distorted hands, unrealistic accessories, inaccurate shadows and voice-call lag
  • Forms requesting sensitive personal or financial details beyond what a normal complaint process would need
  • Any request for payment to "recover" previously lost funds

How to build resistance

Organizations should treat law enforcement outreach as a high-risk impersonation scenario and train employees to verify independently through known official channels rather than links supplied in messages. IC3 said it does not maintain a social media presence and never requests payment to recover lost funds, so staff should be reminded that recovery offers are a common follow-on fraud tactic. The Bureau urged users to type ic3.gov directly into the address bar, avoid sponsored search results and verify that any IC3 URL ends in a .gov domain. Finally, awareness training should include deepfake indicators so employees pause and verify before acting on video-based authority cues, particularly in finance, HR, and executive roles where credential or financial requests are more consequential.

Key findings

  • Scammers are impersonating IC3/FBI officials with deepfake videos and directing people to spoofed IC3 websites.
  • Victims are targeted for “recovery” follow-on fraud (re-victimization), especially those who previously filed or discussed filing an IC3 complaint.
  • One observed variant uses Facebook Messenger impersonation of an FBI agent and a link to “update the report,” which either delivers malicious code or collects financial details.
  • Spoofed IC3 portals mimic ic3.gov branding but simplify the process into a single data-harvesting form and then issue a reference number to build credibility.
  • FBI/IC3 reiterated it does not have a social media presence and does not communicate via Facebook/Telegram/phone/public forums, and never requests payment to recover funds.
  • Users were advised to type ic3.gov directly, avoid sponsored search results, and ensure the URL ends in .gov.

Who’s being targeted

  • Commonly targeted roles: All Employees, Executives, Finance, HR, Customer Support / Fraud teams.
  • Affected industries: Government / law enforcement services (impersonated), General public / consumers, Any business whose employees could be socially engineered using “law enforcement” authority.
  • Attack channels: email, website, vishing.
  • Impersonated: FBI agent / IC3, Senior FBI leader / IC3 leadership, Executive or government official.

Red flags to watch for

  • Message claims to be from FBI/IC3 but directs you to a link instead of typing ic3.gov directly
  • Pressure/urgency and authority-based pretext (law enforcement)
  • Request for extra personal/financial details beyond normal processes
  • Portal is a lookalike of ic3.gov and may not be a real .gov domain
  • Form asks for sensitive personal details and promises follow-up after issuing a reference number
  • Video/visual cues of deepfake content (distorted hands, unrealistic accessories, inaccurate shadows)
  • Voice-call lag or unnatural audio/visual sync
  • Visual anomalies (hands, shadows, accessories)
  • Request to bypass normal verification procedures
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How are scammers using deepfake videos in this IC3 impersonation scheme?

Scammers create AI-generated videos of a senior FBI leader urging people to file complaints on a spoofed IC3 site, and also use AI video in live calls to impersonate executives or officials.

What happens on the fake IC3 portals?

The fake portal mimics the real ic3.gov but reduces the process to a single form collecting name, phone number, email, scam type and estimated financial loss, then issues a reference number and promises follow-up while harvesting more data.

Does the FBI or IC3 ever contact victims through social media?

No, IC3 said it does not maintain a social media presence and never requests payment to recover lost funds, so any outreach via Facebook, Telegram or phone claiming otherwise should be treated as fraudulent.

What should someone do instead of clicking a link claiming to be from IC3?

The FBI urged users to type ic3.gov directly into the address bar, avoid sponsored search results, and verify that any IC3 URL ends in a .gov domain.

Read the video transcript

Imagine this: a video of a senior FBI leader telling you to update your IC3 complaint to get your money back. Scammers are using deepfake videos and fake IC3 sites to re-target people who already filed fraud reports, even messaging them on Facebook with links to "update the report" that steal more details. Here’s the catch: the real FBI and IC3 don’t contact you on Facebook, Telegram, or random calls, and they never charge fees to recover funds. Those one-page "IC3" forms and instant reference numbers are just data-harvesting traps. Your move: if anything claims to be FBI or IC3, ignore the link and type ic3.gov yourself, if it’s not .gov, it’s not them.

Similar attacks