Skip to main content
Emerging Threats

FBI Warns of Deepfake Videos Targeting IC3 Leadership

Government agency public area with podium and blurred video on screen.

"What used to be text-only recovery pitches...now resembled an official government process from start to finish," warned Nick Tausek, summarizing how impersonation scams have evolved into a coordinated, high-fidelity con.

The latest IC3 public notice and timeline

On July 20 the Internet Crime Complaint Center (IC3) issued a public service announcement warning that a long-running impersonation scheme has escalated. The new bulletin follows an April 2025 warning about the same core scheme and describes operators combining social media impersonation, generative AI video and lookalike complaint portals into a single campaign designed to re-target prior fraud victims.

Deepfake videos of senior FBI leadership

The Bureau confirmed social platforms have hosted AI-generated videos portraying a senior FBI leader urging users to file complaints on a spoofed IC3 site. The announcement also noted scammers are using AI video in live calls to impersonate executives or officials. The Bureau advised viewers to look for visual and audio artifacts—distorted hands, unrealistic accessories, inaccurate shadows and voice-call lag—as possible indicators of synthetic-media abuse.

Spoofed IC3 portals and the second‑victim play

Reportedly the fake complaint portals closely mimicked the real ic3.gov while simplifying the complaint workflow to a single form. That form requested name, phone number, email, scam type and estimated financial loss. After submission the counterfeit pages issued a reference number and promised follow-up; at that point, operators harvested additional data. IC3 emphasized it does not maintain a social media presence, does not communicate through Facebook, Telegram, phone or public forums, and never requests payment to recover lost funds.

Messaging vectors: Facebook Messenger variant and malicious links

One described variant targeted people who had already mentioned filing an IC3 complaint. A fraud victim was contacted through Facebook Messenger by someone posing as an FBI agent who supplied a link to "update" the report. The link either carried malicious code or collected further financial details. The Bureau urged users to type ic3.gov directly into the address bar, to avoid sponsored search results and to verify that any IC3 URL ends in a .gov domain.

Expert observations: Swimlane, AttackIQ, and parallels to other deepfake scams

Security practitioners flagged the shift from low-effort text pitches to polished, authoritative-looking interactions. Nick Tausek of Swimlane said the scheme had become materially more polished since the April 2025 warning. Pete Luban, field CISO at AttackIQ, highlighted the psychological leverage of apparent law-enforcement contact: when messages appear to come from the FBI they carry "disproportionate weight in a phishing context," and employees who believe they are speaking with law enforcement might "share credentials, financial records, or internal details without following normal verification procedures."

The pattern echoes a May 2025 Group-IB analysis of deepfake trading-platform scams that used AI-generated videos of public figures to funnel victims into fraudulent sites, underscoring how synthetic media and lookalike sites form a repeatable fraud playbook.

What this means for technologists, affected enterprises, and the general public

  • Technologists and security teams: Expect multi-modal campaigns that marry social impersonation, synthetic video and lookalike web portals. Verification controls should assume the attacker may present convincing audio‑visual cues and a superficially legitimate URL.
  • Affected enterprises and employees: Treat any unsolicited message that claims to be law enforcement as high risk. As Pete Luban noted, contact that appears to come from the FBI can prompt bypassing normal verification steps; maintain out‑of‑band confirmation procedures before sharing credentials or financial details.
  • The general public: Follow the Bureau's advice—type ic3.gov directly into the address bar, avoid sponsored search results, and verify any IC3-related URL ends in .gov. Remember that IC3 does not use Facebook, Telegram, phone or public forums to communicate and will not request payment to recover funds.

The fraud campaign described by the IC3 is not simply a technical tweak; it is an operational upgrade combining synthetic media, direct messaging and counterfeit portals to re-exploit people who have already been victimized. The Bureau's July 20 advisory narrows the defensive focus to a few concrete behaviors—verify domains, avoid platform links, watch for synthetic-media artifacts—but leaves open how quickly platforms and fraud targets will adapt to this more polished play. For now, the immediate, actionable step the IC3 and practitioners uniformly recommend is simple and specific: navigate to ic3.gov yourself and do not follow unsolicited links that claim to be from the Bureau.

https://www.infosecurity-magazine.com/news/fbi-deepfake-videos-ic3/