FBI renews warning on AI-generated deepfakes impersonating law enforcement in fraud recovery schemes
On July 20, 2026, the FBI’s Internet Crime Complaint Center (IC3) issued an updated Public Service Announcement (Alert No. I-072026-PSA) warning of an evolving fraud scheme in which criminals are impersonating FBI personnel and the IC3 to lure victims into re-targeting scams. The update refreshes an April 2025 advisory (I-04182025-PSA) and reflects a notable increase in sophistication, most significantly the use of AI-generated video, or deepfakes, of senior FBI officials to lend the scheme an air of legitimacy.
While framed as a consumer warning, the advisory carries meaningful implications for companies, particularly in financial services, fraud recovery, and cybersecurity, and for any organization whose employees or executives could plausibly be targeted through a law enforcement or executive impersonation pretext.
What the PSA describes
The scheme generally targets individuals who have already fallen victim to an earlier scam, exploiting their hope of recovering lost funds, a pattern the FBI calls “re-targeting” or “double-dip” fraud. The PSA describes two current variants. In the first, a scam victim who mentions filing an IC3 complaint is contacted by a threat actor posing as an FBI agent on Facebook Messenger or Telegram, who sends a link for the scam victim to “update” their IC3 complaint. That link may carry malicious code or simply be used to collect further financial or personal information. In the second, more advanced variant, threat actors circulated a deepfake AI-generated video of a senior FBI leader directing the viewer to a spoofed version of “ic3.gov.” The counterfeit site mimics the legitimate IC3 portal, but limits interaction to a single-step form requesting only a name, phone number, email, scam type, and estimated loss, then issues a reference number and a false promise of follow-up.
The PSA notes that threat actors are deploying synthetic video and voice in live calls to impersonate executives, law enforcement, and other authority figures, and it flags practical indicators of deepfakes: creating a strong sense of emotion such as fear or urgency, distorted hands or facial features, inaccurate shadows, unrealistic accessories, and lag or unnatural cadence on calls.
Why this matters beyond consumer fraud
The same synthetic media techniques used to impersonate FBI leadership are readily adaptable to impersonating a company’s chief executive, general counsel, or chief financial officer in a business email compromise or wire fraud context. Finance, legal, and security teams should treat this PSA as confirmation that deepfake-enabled social engineering is operational for threat actors, not theoretical. These schemes succeed because targets assume that a call, video, or webpage bearing the trappings of a government agency or known executive must be genuine, an assumption enterprise fraud increasingly exploits. Companies that have already experienced a fraud event, breach, or wire transfer loss should be especially alert of follow-on contact offering “recovery” assistance, which the FBI’s guidance indicates is almost never legitimate.
Practical steps for organizations
Organizations should confirm the identity and legitimacy of any communication requesting financial information or urging immediate action through a known, independently obtained contact channel rather than the channel through which the communication arrived. Fraud awareness and incident response training should reflect that synthetic audio and video are now a standard part of the social engineering toolkit, and employees who handle payments or sensitive data should understand the verification steps to follow regardless of how convincing a request appears or how high up it comes.
The value of early counsel involvement
Schemes of this kind tend to arrive dressed as legitimate law enforcement processes, regulatory inquiries, or executive instructions, which is exactly what makes them effective. Organizations are well served by engaging incident response counsel early, ideally before a suspected incident occurs and certainly as soon as one is suspected, rather than after funds have moved or data has been disclosed. Counsel can help organizations distinguish a genuine law enforcement inquiry from an impersonation attempt, preserve privilege over the investigation, coordinate reporting obligations across jurisdictions, and manage communications with law enforcement, insurers, and affected individuals in a way that limits downstream exposure for an organization. Where a scheme has already succeeded in extracting information or funds, experienced incident response counsel can also help assess notification obligations and coordinate with forensic investigators.
Practical implications
The IC3’s decision to update, rather than reissue, its April 2025 warning suggests this scheme is both persistent and evolving, and organizations should expect continued threats from deepfakes as generative AI tools become more accessible. Companies with public-facing executives, regulated fraud reporting obligations, or prior fraud incidents on record should treat the PSA as a prompt to review their verification protocols, training, and incident response planning.
If you have any questions about your company’s compliance with cyber regulations, concerns about vulnerability to attacks or other breaches, or if you want to learn more about proactive cybersecurity defense, contact a member of McDonald Hopkins’ national data privacy and cybersecurity team.