IC3 warns scammers impersonate the FBI and promise stolen-fund recoveries on social media
The bureau’s message is blunt: any IC3 or FBI contact offering recovery is fake, often with AI videos and spoof sites.

The FBI’s Internet Crime Complaint Center (IC3) updated a warning Monday about scammers impersonating the bureau on social media and through follow-on outreach. For decision-makers, the consequence is operational: these schemes target victims who report incidents, gather information, and revictimize people using believable AI content and fake reporting flows.
The FBI’s Internet Crime Complaint Center, or IC3, says scammers are impersonating the FBI online and pitching stolen-fund recoveries. IC3 updated its warning on Monday because fraudsters continue to use the scheme “to deceive and revictimize individuals,” including by contacting victims directly and trying to steer them to fake reporting pages.
IC3’s central point is simple, and it arrives in capital letters even when the scammer is trying to sound official: any account claiming to represent IC3 is fake. The bureau also says it does not investigate crimes or offer to recover lost funds through social media, and that it “will never directly communicate with individuals via phone, email, social media, phone apps, online chat, or public forums.” If you are a leader dealing with cyber incidents, this matters because the victim experience does not end when the first report is filed. The scammer playbook is built for what comes after.
According to IC3, there are two major schemes being used to target cybercrime victims, both directly and by soliciting them to report incidents. In the first scheme, scammers create fraudulent social media profiles and pages impersonating FBI personnel or IC3. They may also infiltrate online groups for fraud victims or contact victims directly while claiming to represent the FBI or the complaint center.
IC3 says a second branch appears when victims have already realized they were being scammed and intend to report the incident to the FBI or file an IC3 complaint. In that scenario, the impersonator directs victims to a fake IC3 update page or keeps communicating via messaging apps. The pattern is designed to exploit trust at a moment of heightened vulnerability: the victim has been hurt, they are actively seeking resolution, and now they are told where to click next.
Then there is the newer layer: social-media content designed to look legitimate at speed. In the other instance IC3 described, scammers are creating AI-generated videos on social media that depict senior FBI officials and direct users to a spoofed IC3 website to report cybercrimes they may have fallen victim to. The scammers then collect the information and use it to contact victims for further fraud. IC3 also notes that AI-generated depictions of public figures are similarly being used to make these scams appear legitimate.
For organizations, this is not just a consumer safety issue. It is a governance and incident-response issue. When a cybercrime victim engages with reporting channels, their data, preferences, and personal context can become part of the next scam stage if the flow is redirected to look-alike pages or fake “updates.” Even if your company never touches the reporting itself, your incident communications, customer portals, and help lines can become the path by which attackers “meet” victims. The second-order implication is clear: AI video and spoofed sites reduce the cost of impersonation, so the attack surface expands beyond the original fraud vector.
IC3 also says that “Some individuals received an email or a phone call, while others were approached, or observed an advertisement via social media or forums.” It adds that “Almost all complainants indicated the scammers claimed to have recovered the victim's lost funds or offered to assist in recovering funds.” That detail is important for leaders because it tells you the scam’s hook is always the same: a promise of recovery. In real workflows, recovery language can mirror legitimate remediation efforts, so the threat is not just impersonation. It is impersonation using the same emotional language victims use to justify hope.
Finally, IC3 provides the boundary conditions for what should be treated as real. If a cybercrime victim reports an incident via IC3’s actual website, IC3 says any contact made will be by an FBI employee from a local field office or other law enforcement official. Everything else is a trap, including social media and messaging app outreach that claims to be IC3. The strategic stakes for peers are straightforward: if your team relies on victims, customers, or partners to self-report incidents, plan for post-report impersonation. Treat the reporting moment as the beginning of a fraud campaign, not the end.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

By 2035, data centers could use 4x more electricity than today
A new build pipeline through 2033 may consume power on par with India, forcing operators to plan for scarcity now.
Frozen-fiber tech couples light and sound 1,000x more strongly than standard glass
A glass capillary frozen into a fiber lets photonic systems trade energy waste for tighter light-sound linkage.
Nvidia publishes Vera AI server CPU specs, posting SPEC CPU 2026 integer lead over AMD
The company released a white paper with SPEC CPU 2026 results, placing Vera ahead of AMD's Epyc 9755 for integer performance.

