Conceptual image illustrating FBI warning on deepfake videos impersonating IC3 leadership in cybersecurity realm.

The FBI's Internet Crime Complaint Center (IC3) issued a public service announcement on July 20 warning that scammers are now using AI-generated deepfake videos of senior FBI leadership to defraud people who have already been scammed once. If your firm handles fraud complaints, customer recovery, or any process where staff might interact with people claiming to be federal agents, this changes how convincing those approaches now look. (Source: Infosecurity-Magazine)

The core scheme is not new. The IC3 flagged a text-based version of it back in April 2025, where fraudsters posed as the Bureau and offered to help victims recover lost funds. What's changed is the production quality. According to Nick Tausek, lead security automation architect at Swimlane, the campaign has become far more polished, moving from text-only recovery pitches to something that resembles "an official government process from start to finish."

Here is how the current version works. The FBI confirmed that scammers combine three pieces: social media impersonation, generative AI video, and lookalike complaint portals. A social media platform hosted deepfake videos of a senior FBI leader urging viewers to file complaints on a spoofed version of ic3.gov.

The fake portal copied the look of the real site but stripped the complaint process down to a single form asking for name, phone number, email, scam type, and estimated financial loss. After submission, the site returned a reference number and promised follow-up. That reference number is the bait — it makes the interaction feel legitimate while the operators harvest the victim's details for a second round of fraud.

This mirrors the deepfake trading-platform scams that Group-IB documented in May 2025, which used AI-generated videos of public figures to funnel victims into fraudulent sites. The same playbook now targets people looking for help after an earlier loss.

The IC3 does not maintain a social media presence, does not communicate through Facebook, Telegram, phone, or public forums, and never requests payment to recover lost funds.

Why Deepfakes of Law Enforcement Pose Unique Business and Organizational Risk

The core problem is that a message appearing to come from the FBI carries weight that a message from an unknown sender never will. As Pete Luban, field CISO at AttackIQ, put it, employees who believe they are speaking with law enforcement may hand over information they would otherwise guard.

Staff who think they are cooperating with a federal investigation might "share credentials, financial records, or internal details without following normal verification procedures."

That single sentence describes the operational failure. Your existing phishing training tells staff to distrust unexpected requests, but it also tells them to cooperate with legitimate authorities. When a convincing deepfake video of a senior FBI official sits in the middle of that contradiction, your normal verification steps get skipped — not because the training failed, but because the impersonation exploits the exception you built into it.

Consider what the spoofed IC3 form actually collects: name, phone number, email, scam type and estimated financial loss. On its own that looks harmless. But if an employee at your firm submits it while trying to "update a complaint" on behalf of a defrauded client, you have now leaked client identity and financial-loss data to an attacker, through an employee who believed they were doing their job.

The follow-up matters too: the fake portal issues a reference number and promises contact later, which gives the operators a pretext to come back and harvest more. Your staff member has no reason to treat the second contact as suspicious because the first one seemed official.

Key Insight: For regulated firms, that hands attackers exactly the kind of personal and financial data that triggers breach-notification duties.

The credential-harvesting risk is more direct in the Facebook Messenger variant, where the supplied link either carried malicious code or requested further financial details. If that link runs on a corporate device, you are dealing with a potential endpoint compromise, not just a scammed individual. The distinction determines whether this is a customer-support incident or a network incident.

There is a reputational angle that catches organizations off guard. If attackers spoof your brand alongside the FBI's — for example, by claiming your firm is coordinating a recovery process with the Bureau — you become the vector, and your clients experience the fraud as something you enabled. You then spend resources correcting a false association you never created.

Government and critical-infrastructure operators face a compounding effect. The IC3 has stated plainly that it does not maintain a social media presence, does not communicate through Facebook, Telegram, phone or public forums, and never requests payment to recover funds. Once deepfakes of officials circulate widely, the public — and your own staff — start second-guessing genuine outreach. Real advisories, real complaint requests and real coordination calls all lose credibility at once.

That is the ripple effect on incident response. If your team has been trained to distrust video and voice from officials because of deepfakes, they may hesitate during an actual coordinated response with law enforcement:

  • Slower verification of genuine agency contacts during an active investigation
  • Reluctance to act on real IC3 or partner-agency instructions
  • Time lost re-confirming identity through side channels mid-incident

The FBI also noted attackers are using AI video in live calls to impersonate executives and officials, with tells such as distorted hands, unrealistic accessories, inaccurate shadows and voice-call lag. For your business, that means a live video call from a "regulator" or "executive" is no longer proof of who you are talking to. Any process that authorizes payments or releases data on the strength of a recognized face or voice now needs a second, independent check before action is taken.

Technical Mechanics of Deepfake-Enabled Social Engineering

The attack chain begins with an AI-generated video of a senior FBI official. These videos are hosted on a social media platform, where the fabricated figure urges viewers to file or update fraud complaints. The video's authority is the hook: the face and voice belong to a recognizable public official, which is exactly the visual verification most people rely on to decide whether a message is legitimate.

Deepfakes bypass that check because they reproduce the specific cues humans use to confirm identity. A viewer sees the correct face, hears an approximation of the correct voice, and stops questioning. The FBI notes that generated video still carries artifacts, and lists the ones worth watching for:

  • Distorted or malformed hands in the video frame
  • Unrealistic accessories that render inconsistently
  • Inaccurate shadows that don't match the lighting
  • Voice-call lag during live impersonation attempts

For business context: these artifacts are the only reliable tell your staff have, and they are the first thing improving generation models eliminate. Training people to spot bad hands works today and will work less well over time.

From the video, victims are directed to a spoofed portal that imitates the real ic3.gov. The fake site is deliberately simplified. Where the genuine complaint workflow is multi-step, the lookalike strips the process down to a single form requesting name, phone number, email, scam type, and estimated financial loss. After submission, the site returns a reference number and promises follow-up.

That reference number is part of the deception. It gives the interaction the feel of an official case being opened, which keeps the victim engaged for the second stage, where operators harvest additional data during the promised follow-up contact.

A separate variant of the campaign uses direct messaging rather than video. A fraud victim who mentioned filing an IC3 complaint was contacted on Facebook Messenger by someone posing as an FBI agent. That contact supplied a link framed as a way to update the existing report. In this variant the link either carried malicious code or collected further financial details, giving responders two distinct payload outcomes to watch for from the same lure.

The distinction matters for triage. A credential-and-data-harvesting link produces web traffic to a spoofed domain and form submissions, while a malicious-code link may produce an endpoint execution event. Both start from the same social-engineering premise, so the same victim population sees different technical indicators depending on which branch they hit.

The FBI also confirmed AI video is being used in live calls, not only pre-recorded posts. Operators impersonate executives or officials in real time, which is where the voice-call lag indicator applies. Live deepfake calls compress the decision window because the victim is responding in conversation rather than reviewing a static message.

For SOC analysts, the recognizable pattern across variants is the pairing of an impersonated authority figure with a lookalike .gov-adjacent domain that does not actually end in a genuine .gov address. Distribution runs through social platforms and sponsored search placement rather than email, so the initial contact frequently never touches corporate mail gateways. The pattern matches the deepfake trading-platform scams that Group-IB documented in May 2025, which similarly used AI-generated video of public figures to funnel victims toward fraudulent sites.

Detection and Immediate Response for Deepfake Impersonation Attempts

The single most important action is to verify any unusual IC3 video, message, or directive through a channel you establish yourself — not one supplied in the communication. The IC3 has confirmed it maintains no social media presence and never contacts people through Facebook, Telegram, phone, or public forums. So any inbound video, message, or call claiming to be IC3 or an FBI agent is a signal to stop and confirm, not to act.

Following the NIST Cybersecurity Framework, here is how to structure detection and response to these deepfake impersonation attempts.

Start with what your staff can actually confirm. Build a verification protocol that treats any purported FBI or IC3 contact as unverified until checked against a number your team already holds. That means:

  • Maintaining the phone number and address of your local FBI field office in your incident contacts, so staff can call the Bureau directly rather than trusting a callback number from the message.
  • Treating the real portal address as the only valid destination — users should type ic3.gov into the address bar, skip sponsored search results, and confirm any IC3 URL ends in a .gov domain.
  • Recording that IC3 never requests payment to recover lost funds, which makes any recovery fee request an immediate disqualifier.

On the protective side, apply multi-factor authentication to the systems and mailboxes that handle law enforcement requests, victim data, or financial records. A deepfake call convinces an employee to act; MFA limits what that employee can hand over from a single credential prompt. This matters because staff who believe they are cooperating with a federal investigation may skip their usual checks, and a second authentication factor forces a pause before sensitive systems open.

For detection, deploy email and messaging filter rules that flag unsolicited links to video content claiming to come from federal law enforcement, and route those to your security team for review. Because these campaigns move through social platforms and messaging apps rather than corporate email alone, brief your security staff directly on the specific tells the Bureau published:

  • Distorted or malformed hands in the video.
  • Unrealistic accessories or inaccurate shadows.
  • Lag between audio and video during live calls impersonating executives or officials.

Identity abuse is the core mechanic here — an attacker borrows a trusted identity to pull credentials and financial records out of your staff. In environments Capstone manages, Adlumin monitors authentication patterns and flags login anomalies that follow a social-engineering contact, catching the moment stolen credentials get used rather than relying on the employee to notice the deception.

For response, when a deepfake contact is reported, preserve the message, link, and any submitted reference number, then report it to the real IC3 and your field office. If an employee already entered data into a spoofed form — name, phone, email, scam type, and loss estimate were the fields the fake portal collected — reset any exposed credentials and monitor the affected accounts for follow-on contact, since operators harvest that data for a second approach.

Recovery here is mostly about closing the gap that let the contact succeed. Run tabletop exercises with your incident response team that specifically practice validating a federal communication end to end: who receives the contact, who they call to confirm, and what they are authorized to release before confirmation. A documented verification step, rehearsed, is what stops a convincing video from turning into disclosed records.

Validating Federal Communications and Building Resilience Against Impersonation

The single most reliable way to confirm a communication is genuine is to call the FBI field office directly, using a number you look up yourself. Do not use any phone number, link, or contact detail supplied in the message, video, or call. If someone claims to represent the Bureau and references your fraud report, hang up and dial the published field office line independently.

The IC3 has been explicit about how it operates, and those statements are your baseline for verification. The Bureau never requests payment to recover lost funds, and any request for a wire transfer, gift cards, or cryptocurrency to "release" recovered money is fraudulent.

Before you act on any inbound contact, confirm the following against what legitimate IC3 activity looks like:

  • Check the domain. A real IC3 URL ends in .gov. Type ic3.gov into the address bar yourself rather than clicking a link or trusting a sponsored search result.
  • Watch for stripped-down forms. A legitimate complaint process is detailed; a single form asking only for name, phone, email, scam type, and estimated loss is a harvesting page, not the real portal.
  • Reject pressure and urgency. Genuine investigations do not demand credentials, financial records, or immediate payment over Facebook Messenger, Telegram, or a phone call.

For live video calls where someone claims to be an executive or official, the Bureau flagged specific visual tells: distorted hands, unrealistic accessories, inaccurate shadows, and lag between the audio and the speaker's mouth. If you spot these during a call requesting sensitive data or funds, end the call and verify through a known channel.

On the protective side, remove the ambiguity that makes these approaches work. Establish a written internal rule that no staff member acts on a law-enforcement request, video, or recovery offer without an independent callback to a verified number. That policy should apply to everyone who handles fraud complaints, customer recovery, or financial transfers, so no single employee can be pressured into bypassing it.

For detection across accounts and login activity, watch for the credential misuse that follows a successful lure. When a victim submits data to a spoofed portal or shares internal details on a fake call, the stolen credentials get reused against your systems. SentinelOne flags anomalous session behavior and endpoint activity tied to credential replay across managed environments, catching the follow-on access before it spreads.

Security teams should document suspected deepfakes in a way that supports both internal investigation and a formal report. Capture what you can preserve:

  • The URL of any spoofed portal and the platform hosting the deepfake video, with screenshots and timestamps.
  • The full message or call metadata — sender profile, phone number, and any reference number the fake site issued.
  • A record of what information was requested or submitted, so you can scope potential exposure.

Report confirmed impersonation attempts to the FBI through the genuine ic3.gov portal that you navigate to directly. Preserve the original evidence rather than forwarding it, since forwarded copies can strip metadata investigators rely on.

Recovery here is mostly about closing the gap the scheme exploited. After an incident, reset any credentials that may have been shared, review recent financial transfers for redirection, and brief staff on the specific tells and the callback rule. Update your fraud-handling procedures so the next impersonation attempt meets a verification step instead of a cooperative employee.

Key Actions: Verification First, Then Incident Response

The single most reliable takeaway from this campaign is straightforward: a video or message showing a recognizable FBI official is no longer evidence that the communication is genuine. Generative AI now reproduces a familiar face and voice well enough to pass the checks most people make instinctively, so what you see and hear cannot stand as confirmation on its own.

That means your default response to any inbound communication claiming to come from IC3 leadership is to withhold action until you confirm it through a channel you control. Do not click links, submit forms, or supply financial or identity details based on a video, a Messenger contact, or a call — regardless of how official the process appears end to end.

To confirm anything, go to the official reporting mechanism yourself. The one authoritative destination is ic3.gov, reached by typing the address directly and checking that the domain ends in .gov. Any communication that pushes you toward a different portal, a sponsored search result, or a payment step to recover lost funds is a fraud signal, not a step in a real investigation.

This campaign will keep changing shape. The FBI has already documented AI video used in live calls to impersonate executives and officials, and the underlying techniques improve with each iteration. Treat a federal impersonation attempt with the same rigor you would apply to a suspected data breach: assume nothing is legitimate until independently verified, and route the incident through your established response process rather than acting on the message in front of you.

In This Article

Top hits