LIVE · cybersecurity feed
Live wire
security

Don’t trust that “FBI agent” in your DMs

The FBI is warning that fraudsters are using fake IC3 accounts and direct messages to target people who've already been scammed.

zeroday.news · 11d ago

The Federal Bureau of Investigation's Internet Crime Complaint Center (IC3) has issued a warning regarding an increase in "recovery scams" where criminals impersonate FBI agents and IC3 employees on social media and messaging applications. These scammers specifically target individuals who have previously fallen victim to cybercrime, aiming to defraud them again.

The FBI states that these schemes are becoming more sophisticated, often featuring official-looking FBI logos and branding to enhance their credibility. Scammers create fake social media accounts, sometimes with fabricated positive reviews, to lure victims. An example provided described an account named "Reliable Scam Recovery Inc" or "Ic3 Scam Recovery Inc" that promised assistance with recovering funds lost to various online frauds, including investment, crypto, and romance scams.

These fraudulent posts contain vague but reassuring claims, such as having an "experienced recovery team" and offering "professional case assessment" and "secure and confidential support." They also make high-level promises like "investigate scam activities" and "trace transactions," implying specialized legal or technical capabilities that legitimate agencies possess.

Scammers actively monitor social media for posts from individuals who have reported a scam to the FBI or intend to do so. They then contact these victims directly, posing as FBI follow-up contacts. To further convince skeptical victims, some scammers create deepfake audio and video content depicting senior FBI officials or other recognizable public figures urging victims to submit their case through a specific link to "speed up recovery." The FBI confirms that criminals are increasingly utilizing AI-generated deepfake technology to make these messages appear authentic.

The IC3 emphasizes that it does not maintain an official social media presence and does not investigate crimes or contact victims directly via social media to recover funds. The IC3's official website explicitly states that it does not collaborate with non-law enforcement entities, such as law firms or cryptocurrency services, for fund recuperation or case investigations, and will never directly solicit information or money from victims.

To avoid falling victim to these recovery scams, the FBI advises several precautions. Individuals should never pay upfront fees to recover stolen money, as legitimate government agencies do not request advance payments for such services. Unsolicited claims from anyone offering to reverse a previous scam should be viewed with extreme suspicion. Victims should never provide remote access to their devices, share passwords, recovery phrases, identification documents, or financial information with unknown third parties, as this information can be used for identity theft or further fraud.

If a message or contact from an alleged "agent" appears in direct messages shortly after a public post about being a crime victim or reporting to the FBI, it should be assumed to be a scammer unless independently verified through official channels. Suspected scams should be reported to the IC3 at ic3.gov.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.