Scammers are now using AI-generated videos of senior FBI officials and fake IC3 websites to target people who already reported being scammed.
What happened
The FBI issued a public service announcement on July 20 warning that scammers have escalated their long-running scheme of impersonating the Bureau's Internet Crime Complaint Center (IC3). Scammers now combine social media impersonation, AI-generated deepfake videos and fake complaint portals to target people who previously filed fraud complaints. In one version, scammers contact a fraud victim on Facebook Messenger, pose as an FBI agent, and send a link claiming to update the victim's report. The link either delivers malicious code or collects further financial information. Scammers also posted AI-generated videos of a senior FBI leader on social media, directing users to a spoofed IC3 site. The fake site copies the real ic3.gov but reduces the complaint process to a single form asking for a name, phone number, email, scam type and estimated financial loss. After a user submits the form, the site issues a fake reference number, and the operators then collect additional data from the victim.
Going deeper
The FBI reports that scammers are also using AI video during live phone calls to impersonate executives or officials. The Bureau urges users to watch for signs of deepfakes, including distorted hands, unrealistic accessories, inaccurate shadows, and voice-call lag. The IC3 confirmed it does not maintain a social media presence, does not communicate through Facebook, Telegram, phone or public forums, and never requests payment to recover lost funds. The Bureau recommends users type ic3.gov directly into their browser's address bar, avoid clicking sponsored search results, and confirm that any IC3 URL ends in a .gov domain.
What was said
Nick Tausek, lead security automation architect at Swimlane, said the scheme has become more polished since the April 2025 warning, noting that what used to be text-only recovery pitches now resembles "an official government process from start to finish."
Pete Luban, field CISO at AttackIQ, said messages that appear to come from the FBI carry disproportionate weight in a phishing context, and that employees who believe they're speaking with law enforcement might "share credentials, financial records, or internal details without following normal verification procedures."
In the know
The IC3, formed in 2000, functions as the FBI's central intake desk for cyber-enabled crime. It is run by the FBI, the lead federal agency for investigating crime, and its mission is to provide the public and private sector with a mechanism to submit information to the FBI concerning suspected cyber-facilitated criminal activity, and to develop effective alliances with law enforcement and industry partners. Reports submitted through the site get analyzed and shared with law enforcement nationwide. People turn to it because they believe it's a safe, official place to report having already been scammed.
Why it matters
Healthcare has seen the same tactic used against physicians. A STAT News piece described a patient who confronted her doctor after seeing a video of him, in a white coat and familiar exam room setting, endorsing a menopause supplement and dismissing standard treatment as a "pharma scam." The physician had never recorded any such message. Someone had built the deepfake from his own interviews, webinars and patient-facing videos, then used the synthetic likeness to sell an unregulated product. As the piece put it, deepfakes undermine the credibility that makes digital care, from telehealth visits to patient portals, possible.
In both cases, scammers aren't inventing a fake authority, they're hijacking a real one that people already trust by default, whether that's a treating physician or a federal agency victims turned to for help. Trust is what makes deepfakes effective, and that trust can easily be weaponized against the person on the receiving end. For IC3, the effects are worse because the targets are people who have already lost money once and are actively looking for a way to recover it, making them more willing to skip normal verification steps for anything that looks official.
The bottom line
Because scammers can now fake the look and sound of a federal official, or a patient's own doctor, verifying a source through an independent channel matters. The FBI's guidance states, go directly to ic3.gov by typing it into the address bar, skip sponsored search results, and confirm the .gov ending, rather than trusting any link, video, or call claiming to be the Bureau.
FAQs
What is a deepfake?
A deepfake is synthetic audio or video created with AI to mimic a real person's face, voice, or mannerisms convincingly enough to pass as authentic.
How can I tell if a video is a deepfake?
Look for small inconsistencies like unnatural blinking, distorted hands, mismatched lighting or shadows, and audio that lags slightly behind lip movement.
What should I do if I think I've been targeted by a scam impersonating a government agency?
Stop all contact, avoid clicking any links, and report the incident directly through the agency's official website, typed manually into your browser.
