LIVE · cybersecurity feed
Live wire
security

FBI Warns of Deepfake Videos Impersonating IC3 Leadership

FBI warned of deepfake videos of IC3 leadership directing users to spoofed complaint sites

zeroday.news · 11d ago

The FBI has issued a public service announcement warning about an advanced scam campaign that uses deepfake videos of senior FBI officials and sophisticated spoofed websites to defraud individuals, particularly those who have previously been victims of fraud. This new warning, released by the FBI's Internet Crime Complaint Center (IC3) on July 20, 2026, indicates a significant escalation from a similar scheme first reported in April 2025.

The current campaign is described as materially more refined, moving beyond simple text-based recovery pitches to mimic official government processes comprehensively. Scammers are combining social media impersonation, generative AI video technology, and highly convincing lookalike complaint portals to create a coordinated attack.

In one observed variant, a fraud victim who had mentioned filing an IC3 complaint was contacted via Facebook Messenger by someone impersonating an FBI agent. This imposter provided a link, ostensibly to update the victim's report. The link either contained malicious code designed to compromise the user's system or was used to harvest additional financial details.

A key element of this escalated campaign involves the use of AI-generated videos of a senior FBI leader hosted on social media platforms. These deepfake videos encourage users to file complaints on a fraudulent IC3 website. The fake portal closely mimics the legitimate ic3.gov site but simplifies the complaint process to a single form requesting basic information such as name, phone number, email, the type of scam, and an estimated financial loss. After submission, the site issues a reference number and promises follow-up, at which point the operators collect further personal data.

Experts note that messages appearing to originate from the FBI carry substantial weight in a phishing context, potentially leading victims to bypass standard verification procedures and share sensitive information like credentials, financial records, or internal details. This tactic mirrors deepfake trading-platform scams documented in May 2025, which also leveraged AI-generated videos of public figures to direct victims to fraudulent sites.

The FBI also confirmed that AI video is being used in live calls to impersonate executives or officials. To help users identify these deepfakes, the Bureau advises looking for visual anomalies such as distorted hands, unrealistic accessories, inaccurate shadows, and noticeable lag in voice calls.

The IC3 explicitly states that it does not maintain a social media presence, does not communicate through platforms like Facebook or Telegram, does not use phone calls or public forums for official communication, and never requests payment for the recovery of lost funds. The FBI strongly urges individuals to directly type "ic3.gov" into their browser's address bar, to avoid clicking on sponsored search results, and to always verify that any IC3 URL ends with a ".gov" domain to ensure authenticity.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.