FBI Warns Scammers Use AI Deepfakes and Fake IC3 Sites to Re-Victimize Fraud Victims

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Spread the love

The FBI has issued a new Public Service Announcement warning that cybercriminals are increasingly using AI-generated deepfakes and spoofed Internet Crime Complaint Center (IC3) websites to target victims who have already lost money to scams.

This advisory, released on July 20, 2026, highlights how threat actors are evolving traditional fraud schemes by combining social engineering, impersonation, and artificial intelligence to create highly convincing attacks.

According to the FBI, the campaign specifically targets individuals who have previously reported financial fraud or expressed intent to file complaints with the IC3.

Attackers exploit this moment of vulnerability by posing as law enforcement officials or recovery agents, falsely claiming they can help recover stolen funds. In reality, their operation aims to extract additional sensitive information or financial assets from these victims.

FBI Warns AI Deepfakes Using Fake IC3 Sites

The agency identified multiple variants of the scheme. In one case, scammers impersonate FBI personnel on social media platforms like Facebook and messaging apps such as Telegram.

After initial contact, victims are directed to malicious links disguised as IC3 complaint update portals. These links either harvest personally identifiable information or deliver malicious code.

The attackers often create a sense of urgency and authority, convincing victims that immediate action is necessary to recover their losses.

A more advanced variation of this scam involves the use of AI-generated deepfake videos. In these cases, threat actors produce highly realistic videos of senior FBI officials appearing to endorse specific complaint submission processes. These videos are shared across social media platforms to build credibility and drive traffic to fraudulent websites.

The spoofed IC3 websites closely resemble the official design but offer limited functionality, typically providing only a simplified complaint form that collects key personal and financial details.

Once a victim submits their information, the fake platform generates a reference number. It promises follow-up communication, further reinforcing the illusion of legitimacy.

However, this data is then used for further fraud or identity theft. The FBI emphasized that these tactics rely heavily on psychological manipulation, combining trust in government institutions with advanced synthetic media to deceive users.

The PSA also warns in Alert Number I-072026-PSA that AI-generated content has become so sophisticated that it is increasingly difficult to detect.

Deepfake videos may feature subtle visual inconsistencies, such as distorted facial features, unnatural movements, or mismatched audio, but these indicators are not always obvious.

In some cases, scammers also employ voice cloning to impersonate officials or known contacts, making verification even more challenging.

Importantly, the FBI clarified that the IC3 does not maintain a social media presence and does not contact individuals directly via messaging platforms, phone calls, or email to recover funds.

Any such communication should be treated as fraudulent. The official IC3 complaint process is only accessible through the legitimate website, and users are advised to enter the URL manually rather than relying on search engine results, which may include sponsored malicious links.

The agency urges victims and organizations to remain vigilant, particularly when encountering unsolicited messages offering financial recovery services.

Individuals who suspect they have been targeted or re-victimized are encouraged to report incidents directly through the official IC3 portal, providing detailed information, including communication methods, transaction data, and attacker identifiers.

This latest warning underscores a broader trend in cybercrime where AI is lowering the barrier to entry for sophisticated social engineering attacks.

By combining deepfake technology with impersonation and phishing infrastructure, threat actors are significantly increasing the effectiveness of fraud campaigns while making detection and prevention more complex for individuals and security teams.

The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment