Fake FBI “IC3” Agents Re-Scam Past Victims

Help Net Security · High sophistication
Last updated July 31, 2026

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The schemes use messages on social platforms (then move victims to Telegram) and AI-generated “deepfake” videos that push victims to a lookalike IC3 website to harvest personal and financial details.

How the scam plays out

This attack specifically targets people who have already been scammed once, an audience that is emotionally invested in recovering their losses and therefore primed to respond to anything that looks like a follow-up on their case. Two distinct approaches were described. In the first, a victim receives an email or phone call, then someone claiming to be an FBI agent reaches out on Facebook Messenger and moves the conversation to Telegram. The fake agent sends a link and asks the victim to update their IC3 report, a request that can lead to malicious code delivery or the collection of additional financial data.

In the second approach, scammers circulate AI-generated deepfake video of a senior FBI official urging people to file complaints through what looks like the official IC3 site. The fake page mimics the design of ic3.gov closely and accepts a single-step complaint form asking for a name, phone number, email, scam type, and estimated loss. After submission, victims get a reference number and a promise that someone will follow up, reinforcing the illusion of legitimacy.

Why it succeeds

The pretext works because it exploits people who already believe they are engaged with law enforcement over a real complaint. Moving the conversation from a mainstream platform to Telegram removes the interaction from a monitored, reportable channel. The deepfake video adds a layer of authority that is difficult for many people to question in the moment, especially when it appears to come from a recognizable government source.

What to watch for

  • Unsolicited outreach claiming to be from the FBI or IC3, especially via phone, email, or social media
  • A push to click a link to "update" an existing complaint
  • Conversations that shift from an official-seeming channel to a private chat app like Telegram
  • Video or audio that looks or sounds unnatural, especially when it is used to create urgency
  • A website that resembles ic3.gov but has a non-.gov domain, minimal functionality, or links that loop back to the home page

Building resistance

IC3 has no social media presence, never initiates contact by phone, email, or chat app, and never asks for payment to recover funds. Anyone checking the site should type the official address directly into the browser, such as www.ic3.gov, rather than clicking a sponsored search result or a link sent by an unknown contact. Encourage staff and consumers to pause and verify any video or urgent message claiming to be from a government official before responding, and to treat any request to "update" a prior report as a red flag rather than a routine follow-up.

Key findings

  • Scammers impersonate FBI/IC3 personnel to "revictimize people who already lost money once."
  • Victims are contacted via email, phone calls, or social media/online forums; one described flow starts on Facebook Messenger and shifts to Telegram.
  • Attackers send a link claiming the victim must "update their IC3 report"; the link may deliver malicious code or collect additional financial data.
  • A second scheme uses AI-generated video of a senior FBI official to push victims to a spoofed IC3 site that collects contact details and loss amounts, then issues a reference number and promises follow-up.
  • The FBI emphasizes IC3 has no social media presence and does not initiate contact via phone/email/chat apps, and it never asks for payment to recover funds.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance teams, Customer support / fraud operations, Executives (impersonation & deepfake awareness).
  • Affected industries: Consumers / General public, Government (law enforcement impersonation).
  • Attack channels: linkedin, email, vishing, website.
  • Impersonated: FBI / IC3 complaint handler, Senior FBI official / IC3 website.

Red flags to watch for

  • Unsolicited outreach claiming to be FBI/IC3
  • Push to click a link to ‘update’ a complaint
  • Conversation moved from an official channel to a chat app (Telegram)
  • Video looks or sounds unnatural (deepfake indicators)
  • Website looks like IC3 but behavior is odd (links loop back; limited functionality)
  • Non-.gov or mistyped domain; reliance on sponsored results
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

Does the FBI or IC3 ever call or email victims about their complaints?

No. IC3 has no social media presence and never initiates contact by phone, email, or chat app, according to the FBI's guidance cited in this report.

How do scammers use deepfake video in this scam?

Scammers circulate AI-generated video clips of a senior FBI official urging people to file complaints, directing them to a lookalike site that mimics the design of ic3.gov.

What should I do if someone contacts me claiming to be an FBI agent about an IC3 report?

Treat the outreach as suspicious, do not click any link they send, and instead type the official IC3 address directly into your browser rather than following a sponsored search result.

What are signs a site claiming to be IC3 is fake?

Watch for a domain that does not end in .gov, an overly simple single-step complaint form, and links on the page that just loop back to the home screen instead of leading anywhere else.

Read the video transcript

You file an FBI IC3 complaint after a scam… and weeks later, a “FBI agent” messages you saying they can help get your money back. They start on Facebook or LinkedIn, then push you to Telegram or a phone call, send a link, and say, “You must update your IC3 report here.” Another version even plays an AI video of a senior FBI official pointing you to a lookalike IC3 site. Here’s the catch: IC3 has no social media accounts, doesn’t call, email, or chat you first, and will never send you a link or ask for payment to recover funds. A fake site often has just one or two pages, with every other link looping back to the same form. If anyone says they’re FBI or IC3 and contacts you first, don’t click their link. Close it, go to ic3.gov by typing it yourself, and only trust what you see there.

Categories

Similar attacks

Fake FBI ‘IC3 Help’ Scams Hit Victims Twice

Fake FBI ‘IC3 Help’ Scams Hit Victims Twice

The FBI warns scammers are impersonating FBI/IC3 staff and re-targeting people who already lost money to fraud. The scammers use emails, phone calls, social media messages, and even AI-generated videos to push victims to spoofed IC3 websites or to hand over more personal and financial information,…

July 21, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake “FBI Agents” Target Scam Victims in DMs

Fake “FBI Agents” Target Scam Victims in DMs

The FBI’s IC3 warns that scammers are impersonating FBI/IC3 staff on social media and messaging apps, especially targeting people who have already been scammed. The criminals use convincing branding (logos, fake reviews) and may even use AI-generated deepfake videos to pressure victims into…

July 21, 2026
Fake FIFA Ticket Sites Steal Cards and OTPs

Fake FIFA Ticket Sites Steal Cards and OTPs

Researchers and the FBI warn that criminals are luring World Cup fans to convincing fake FIFA ticket websites, often via social media ads and shared links. The scam steals payment details in real time during checkout, including card data and one-time passcodes (OTPs), while victims believe they are…

July 16, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026