Deepfake FBI Videos Push Victims to Fake IC3 Sites

Infosecurity Magazine · High sophistication
Last updated July 30, 2026

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI agent and sent a link to “update” their IC3 complaint, which either delivers malicious code or harvests additional details.

How the attack worked

The scheme relies on impersonating a trusted authority, the FBI and its Internet Crime Complaint Center (IC3), to re-victimize people who had already filed or discussed a fraud complaint. In one variant, a fraud victim who mentioned filing an IC3 complaint was contacted on Facebook Messenger by someone posing as an FBI agent, who supplied a link to update the report. The link either carried malicious code or collected further financial details.

A second variant used AI-generated videos of a senior FBI leader urging users to file complaints on a spoofed IC3 site. The fake portal mimicked the real ic3.gov but stripped the complaint workflow down to a single form requesting name, phone number, email, scam type and estimated financial loss. After submission, the site issued a reference number and promised follow-up, at which point the operators harvested further data. A third variant involved live video calls using AI to impersonate executives or officials, aiming to extract credentials or financial records directly.

Why it succeeded

Messages appearing to come from the FBI carried disproportionate weight in a phishing context, making targets less likely to question the request. Prior fraud victims were especially vulnerable because they were already expecting follow-up communication about their case, and the promise of recovering lost funds added emotional pressure. The use of deepfake video added a layer of visual credibility that text-based phishing lacks, making authority claims feel more legitimate at a glance.

What to watch for

  • Outreach claiming to be from the FBI or IC3 that arrives via social media messaging rather than official channels
  • Links asking you to "update" a complaint instead of directing you to navigate to a known official site yourself
  • Deepfake video indicators such as distorted hands, unrealistic accessories, inaccurate shadows and voice-call lag
  • Forms requesting sensitive personal or financial details beyond what a normal complaint process would need
  • Any request for payment to "recover" previously lost funds

How to build resistance

Organizations should treat law enforcement outreach as a high-risk impersonation scenario and train employees to verify independently through known official channels rather than links supplied in messages. IC3 said it does not maintain a social media presence and never requests payment to recover lost funds, so staff should be reminded that recovery offers are a common follow-on fraud tactic. The Bureau urged users to type ic3.gov directly into the address bar, avoid sponsored search results and verify that any IC3 URL ends in a .gov domain. Finally, awareness training should include deepfake indicators so employees pause and verify before acting on video-based authority cues, particularly in finance, HR, and executive roles where credential or financial requests are more consequential.

Key findings

  • Scammers are impersonating IC3/FBI officials with deepfake videos and directing people to spoofed IC3 websites.
  • Victims are targeted for “recovery” follow-on fraud (re-victimization), especially those who previously filed or discussed filing an IC3 complaint.
  • One observed variant uses Facebook Messenger impersonation of an FBI agent and a link to “update the report,” which either delivers malicious code or collects financial details.
  • Spoofed IC3 portals mimic ic3.gov branding but simplify the process into a single data-harvesting form and then issue a reference number to build credibility.
  • FBI/IC3 reiterated it does not have a social media presence and does not communicate via Facebook/Telegram/phone/public forums, and never requests payment to recover funds.
  • Users were advised to type ic3.gov directly, avoid sponsored search results, and ensure the URL ends in .gov.

Who’s being targeted

  • Commonly targeted roles: All Employees, Executives, Finance, HR, Customer Support / Fraud teams.
  • Affected industries: Government / law enforcement services (impersonated), General public / consumers, Any business whose employees could be socially engineered using “law enforcement” authority.
  • Attack channels: email, website, vishing.
  • Impersonated: FBI agent / IC3, Senior FBI leader / IC3 leadership, Executive or government official.

Red flags to watch for

  • Message claims to be from FBI/IC3 but directs you to a link instead of typing ic3.gov directly
  • Pressure/urgency and authority-based pretext (law enforcement)
  • Request for extra personal/financial details beyond normal processes
  • Portal is a lookalike of ic3.gov and may not be a real .gov domain
  • Form asks for sensitive personal details and promises follow-up after issuing a reference number
  • Video/visual cues of deepfake content (distorted hands, unrealistic accessories, inaccurate shadows)
  • Voice-call lag or unnatural audio/visual sync
  • Visual anomalies (hands, shadows, accessories)
  • Request to bypass normal verification procedures
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How are scammers using deepfake videos in this IC3 impersonation scheme?

Scammers create AI-generated videos of a senior FBI leader urging people to file complaints on a spoofed IC3 site, and also use AI video in live calls to impersonate executives or officials.

What happens on the fake IC3 portals?

The fake portal mimics the real ic3.gov but reduces the process to a single form collecting name, phone number, email, scam type and estimated financial loss, then issues a reference number and promises follow-up while harvesting more data.

Does the FBI or IC3 ever contact victims through social media?

No, IC3 said it does not maintain a social media presence and never requests payment to recover lost funds, so any outreach via Facebook, Telegram or phone claiming otherwise should be treated as fraudulent.

What should someone do instead of clicking a link claiming to be from IC3?

The FBI urged users to type ic3.gov directly into the address bar, avoid sponsored search results, and verify that any IC3 URL ends in a .gov domain.

Read the video transcript

Imagine this: a video of a senior FBI leader telling you to update your IC3 complaint to get your money back. Scammers are using deepfake videos and fake IC3 sites to re-target people who already filed fraud reports, even messaging them on Facebook with links to "update the report" that steal more details. Here’s the catch: the real FBI and IC3 don’t contact you on Facebook, Telegram, or random calls, and they never charge fees to recover funds. Those one-page "IC3" forms and instant reference numbers are just data-harvesting traps. Your move: if anything claims to be FBI or IC3, ignore the link and type ic3.gov yourself, if it’s not .gov, it’s not them.

Categories

Similar attacks

FBI Warns of Social Media Reset-Code Scams

FBI Warns of Social Media Reset-Code Scams

The FBI says criminals are using social engineering to take over social media accounts, steal explicit content, and sell or post it online along with victims’ personal information. Reported tactics include pretending to be a social media company representative, spamming victims with password-reset…

August 12, 2026
Fake FBI “IC3” Agents Re-Scam Past Victims

Fake FBI “IC3” Agents Re-Scam Past Victims

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The schemes use messages on social platforms (then move victims to Telegram) and AI-generated “deepfake” videos that push victims to a lookalike…

July 21, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
FBI: OAuth Consent Phishing Targets Prominent People

FBI: OAuth Consent Phishing Targets Prominent People

The FBI warns attackers are impersonating public figures on messaging apps and email to trick targets into approving a malicious OAuth app. Victims are sent links that lead to real Microsoft or Google login/consent screens, where approving access grants attackers ongoing access to emails and files.…

September 2, 2026