Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.
On July 20, 2026, the FBI's Internet Crime Complaint Center (IC3, the bureau's online portal for reporting internet fraud) issued a public warning about a scheme that preys on people at their most vulnerable moment, right after they have already been robbed once. Criminals are posing as the FBI staff who process IC3 complaints, and their newest prop is a deepfake, an AI-generated video, of a senior FBI official urging people to come forward and file a report.
The video looks official. The website it points to looks official. Neither is. What makes this campaign worth your attention is not a single large theft but the machinery behind it: synthetic video of a trusted institution, produced cheaply and pushed at scale, used to manufacture the one thing every scam needs and this one had been missing, credibility.
The scheme, detailed in IC3 advisory PSA260720, updates an alert the bureau first published in April 2025. The target is deliberate. Scammers go after people who have already lost money to fraud, because those victims are desperate to recover it and their details often circulate on the same forums where the original scam was sold. First contact comes by email, a phone call, a social media advert, or a post on a fraud-recovery forum.
From there the mechanism is a chain of impersonation. In one version the FBI describes, a victim mentions that they intend to report the incident to the bureau. Soon after, someone claiming to be an agent messages them on Facebook Messenger, then moves the conversation to Telegram and sends a link to "update" their IC3 report. That link either carries malicious code or harvests more financial detail. In the second version, the scammers seed social media with the deepfake video of the FBI official, which drives viewers to a spoofed copy of ic3.gov. The fake site mimics the real one closely but does only one thing: it presents a single form asking for a name, phone number, email, scam type, and estimated loss. Every other link simply loops back to the home page. That estimated-loss field is the tell. It lets the criminals sort respondents by how much they are worth targeting again.
The direct harm is a repeat theft and a fresh haul of personal data from people who could least afford the first loss. For anyone running an organisation, the sharper lesson sits one level up. A deepfake no longer needs to target one executive in one live video call, the pattern behind the roughly $25 million Arup fraud in 2024. It can now be produced once and broadcast like an advertisement, a piece of synthetic social proof that vouches for a fraudulent site to thousands of strangers at a time. If a convincing video of a named federal official can be spun up to sell a fake government page, a convincing video of your CEO endorsing a fake payment portal is the same technique pointed at your brand. Your customers will not think to doubt a video that shows a face they recognise. The systemic shift is that deepfakes have moved from bespoke, one-to-one deception to mass-market marketing, and the thing being counterfeited here is public trust in government itself.
The people this scheme hurts did the responsible thing. They set out to report a crime, and the act of reporting was turned into the trap. That is the uncomfortable core of it: the attackers are not so much breaking a system as wearing its uniform, and AI video now lets them wear it convincingly, at scale, for the price of a prompt. Bring one question to your next security review. If a video of your organisation's most trusted face appeared online tomorrow telling customers to enter their details on a page that was not yours, how quickly would you know, and how would the people watching it tell the difference?


