LIVE · cybersecurity feed
Live wire
security

Scammers impersonate FBI on social media, prey on crime victims

IC3 says any account claiming to represent it is fake

zeroday.news · 12d ago

The FBI's Internet Crime Complaint Center (IC3) has issued a renewed warning about scammers impersonating the agency and its personnel on social media platforms, exploiting individuals who have already fallen victim to cybercrime. The fraudsters are employing various tactics, including AI-generated content, to appear legitimate and deceive victims into providing personal or financial information.

According to the IC3, these schemes involve two primary approaches. In the first, scammers create fake social media profiles and pages that mimic FBI personnel or the IC3. They then infiltrate online groups dedicated to fraud victims or directly contact individuals, claiming to represent the FBI or the complaint center. In some instances, victims who have expressed an intent to report a scam to the FBI or file an IC3 complaint are subsequently contacted by an impersonator who directs them to a spoofed IC3 update page or continues communication through messaging applications.

The second approach involves the creation of AI-generated videos featuring senior FBI officials, which are then posted on social media. These videos direct users to a fraudulent IC3 website where they are prompted to report cybercrimes. The information collected through these fake reports is then used by the scammers to contact victims for further fraudulent activities. The IC3 noted that these AI-generated depictions of public figures are designed to enhance the perceived legitimacy of the scams.

Victims have reported being contacted through various channels, including email, phone calls, social media advertisements, and online forums. A common thread among almost all complainants is that the scammers claimed to have recovered lost funds or offered assistance in doing so.

The IC3 emphasizes that it does not maintain any social media presence and does not investigate crimes or offer to recover lost funds through social media platforms. Any social media profiles or pages claiming to represent the IC3 or offering fund recovery services are fraudulent and are actively attempting to steal personal or financial information. The IC3 also confirmed that it will never directly communicate with individuals via phone, email, social media, phone apps, online chat, or public forums.

Legitimate contact with a cybercrime victim who has reported an incident via the official IC3 website will only be made by an FBI employee from a local field office or another authorized law enforcement official. The IC3 advises individuals who have fallen victim to cybercrime or online scams to refrain from posting about their experiences on social media, as this can attract malicious actors seeking to exploit them further.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.