
Fake FBI “IC3” Agents Re-Scam Past Victims
Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The…
The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI agent and sent a link to “update” their IC3 complaint, which either delivers malicious code or harvests additional details.
The scheme relies on impersonating a trusted authority, the FBI and its Internet Crime Complaint Center (IC3), to re-victimize people who had already filed or discussed a fraud complaint. In one variant, a fraud victim who mentioned filing an IC3 complaint was contacted on Facebook Messenger by someone posing as an FBI agent, who supplied a link to update the report. The link either carried malicious code or collected further financial details.
A second variant used AI-generated videos of a senior FBI leader urging users to file complaints on a spoofed IC3 site. The fake portal mimicked the real ic3.gov but stripped the complaint workflow down to a single form requesting name, phone number, email, scam type and estimated financial loss. After submission, the site issued a reference number and promised follow-up, at which point the operators harvested further data. A third variant involved live video calls using AI to impersonate executives or officials, aiming to extract credentials or financial records directly.
Messages appearing to come from the FBI carried disproportionate weight in a phishing context, making targets less likely to question the request. Prior fraud victims were especially vulnerable because they were already expecting follow-up communication about their case, and the promise of recovering lost funds added emotional pressure. The use of deepfake video added a layer of visual credibility that text-based phishing lacks, making authority claims feel more legitimate at a glance.
Organizations should treat law enforcement outreach as a high-risk impersonation scenario and train employees to verify independently through known official channels rather than links supplied in messages. IC3 said it does not maintain a social media presence and never requests payment to recover lost funds, so staff should be reminded that recovery offers are a common follow-on fraud tactic. The Bureau urged users to type ic3.gov directly into the address bar, avoid sponsored search results and verify that any IC3 URL ends in a .gov domain. Finally, awareness training should include deepfake indicators so employees pause and verify before acting on video-based authority cues, particularly in finance, HR, and executive roles where credential or financial requests are more consequential.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Scammers create AI-generated videos of a senior FBI leader urging people to file complaints on a spoofed IC3 site, and also use AI video in live calls to impersonate executives or officials.
The fake portal mimics the real ic3.gov but reduces the process to a single form collecting name, phone number, email, scam type and estimated financial loss, then issues a reference number and promises follow-up while harvesting more data.
No, IC3 said it does not maintain a social media presence and never requests payment to recover lost funds, so any outreach via Facebook, Telegram or phone claiming otherwise should be treated as fraudulent.
The FBI urged users to type ic3.gov directly into the address bar, avoid sponsored search results, and verify that any IC3 URL ends in a .gov domain.
Imagine this: a video of a senior FBI leader telling you to update your IC3 complaint to get your money back. Scammers are using deepfake videos and fake IC3 sites to re-target people who already filed fraud reports, even messaging them on Facebook with links to "update the report" that steal more details. Here’s the catch: the real FBI and IC3 don’t contact you on Facebook, Telegram, or random calls, and they never charge fees to recover funds. Those one-page "IC3" forms and instant reference numbers are just data-harvesting traps. Your move: if anything claims to be FBI or IC3, ignore the link and type ic3.gov yourself, if it’s not .gov, it’s not them.

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

The FBI warns scammers are impersonating FBI/IC3 staff and re-targeting people who already lost money to fraud. The scammers use emails, phone calls, social…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…