Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.
On 20 July 2026 the FBI's Internet Crime Complaint Center, known as the IC3, published an alert about a fraud scheme with an unusually precise target list. The people being approached were not chosen at random. Every one of them had already lost money to a scam, and the criminals contacting them knew it.
The AI-generated video at the centre of the scheme is worth understanding properly, because it is not the fraud itself. It is the letter of introduction that makes the rest of the fraud work. That distinction explains why this campaign lands on people who are, by that stage, extremely alert to being scammed.
Alert I-072026-PSA updates a warning the bureau first issued in April 2025. It documents what the FBI calls re-targeting, known more plainly as a recovery or double-dip scam: the premise that somebody defrauded once is worth defrauding again, this time with the promise of getting the first loss back.
Two variants run alongside each other. In the first, timing does the work. A victim tells the original scammers they intend to report them and file an IC3 complaint. Shortly afterwards, someone claiming to be an FBI agent contacts them on Facebook Messenger, moves the conversation to Telegram, and sends a link to update that complaint. The link either carries malicious code or harvests the financial details the first scam never got. Nobody had to research the victim, because the victim announced their own situation to the people best placed to sell it on. The second variant manufactures the introduction instead. Scammers post AI-generated videos, deepfakes, meaning footage in which a real person's face and voice are reconstructed by a model to say things they never said, showing a senior FBI leader urging viewers to file a complaint. The video points to a spoofed IC3 site that copies the real one's structure and language. Only the complaint form actually works, and every other link bounces the visitor back to the homepage. That form is a single step asking for five things: name, phone number, email address, scam type, and estimated financial loss. On submission it issues a reference number and promises that someone will be in touch. Someone is.
Recovery scams generated more than 10,500 complaints and roughly $1.4 billion in reported losses in the United States during 2025, according to the FBI's annual crime figures, inside a total of $20.9 billion across all internet crime. The weight falls on older victims: Americans aged 60 and over reported $7.7 billion in losses, an average of $38,500 each, with 12,400 people losing more than $100,000 apiece. These are people being robbed twice, and the second theft is the one that takes what was left. Look closely at that five-field form and you can see what it is really for. It is not a complaint intake. Scam type and estimated financial loss are qualification fields, sorting respondents by how much they have left to lose before a human operator spends a minute on them. If you run a fraud desk at a bank, an insurer or a brokerage, the practical consequence is that your recently defrauded customers are now your highest-risk population rather than your safest, and they will be approached while they are still on the phone to you about the first loss. The systemic shift is the one worth carrying out of this. Synthetic media here is not being used to fabricate an event or fool a biometric check. It is being used as a credential, a cheap way to borrow the authority of an institution so that a stranger's link arrives looking like an official referral. Institutional trust used to be expensive to counterfeit, which is precisely why government branding worked as a signal at all.
The uncomfortable part of this alert is not that the technology is impressive. It is where the technology was pointed. The deepfake was not aimed at anyone's eyes, and it did not need to survive close inspection. It was aimed at the assumption that an official-looking video of a government official implies an official website behind it, and that assumption is now the exploitable part. Bring it to your next security meeting as a question about your own communications: when your organisation tells customers or employees how it will contact them, does anyone actually remember? The FBI's alert sets out the tactics and the reporting guidance, and the 2025 Internet Crime Report carries the loss figures.


