FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites

The FBI has issued a public service announcement warning about an advanced scam campaign that uses deepfake videos of senior FBI officials and sophisticated spoofed websites to defraud individuals, particularly those who have previously been victims of fraud. This new warning, released by the FBI's Internet Crime Complaint Center (IC3) on July 20, 2026, indicates a significant escalation from a similar scheme first reported in April 2025.
The current campaign is described as materially more refined, moving beyond simple text-based recovery pitches to mimic official government processes comprehensively. Scammers are combining social media impersonation, generative AI video technology, and highly convincing lookalike complaint portals to create a coordinated attack.
In one observed variant, a fraud victim who had mentioned filing an IC3 complaint was contacted via Facebook Messenger by someone impersonating an FBI agent. This imposter provided a link, ostensibly to update the victim's report. The link either contained malicious code designed to compromise the user's system or was used to harvest additional financial details.
A key element of this escalated campaign involves the use of AI-generated videos of a senior FBI leader hosted on social media platforms. These deepfake videos encourage users to file complaints on a fraudulent IC3 website. The fake portal closely mimics the legitimate ic3.gov site but simplifies the complaint process to a single form requesting basic information such as name, phone number, email, the type of scam, and an estimated financial loss. After submission, the site issues a reference number and promises follow-up, at which point the operators collect further personal data.
Experts note that messages appearing to originate from the FBI carry substantial weight in a phishing context, potentially leading victims to bypass standard verification procedures and share sensitive information like credentials, financial records, or internal details. This tactic mirrors deepfake trading-platform scams documented in May 2025, which also leveraged AI-generated videos of public figures to direct victims to fraudulent sites.
The FBI also confirmed that AI video is being used in live calls to impersonate executives or officials. To help users identify these deepfakes, the Bureau advises looking for visual anomalies such as distorted hands, unrealistic accessories, inaccurate shadows, and noticeable lag in voice calls.
The IC3 explicitly states that it does not maintain a social media presence, does not communicate through platforms like Facebook or Telegram, does not use phone calls or public forums for official communication, and never requests payment for the recovery of lost funds. The FBI strongly urges individuals to directly type "ic3.gov" into their browser's address bar, to avoid clicking on sponsored search results, and to always verify that any IC3 URL ends with a ".gov" domain to ensure authenticity.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.