What happens after you've been scammed once? Almost nobody warns you about the second wave: a different set of criminals who go looking for people who have already been hit, because they are the easiest people in the world to sell hope to. In July 2026 the FBI put out an alert about exactly that, and this time the bait includes video of FBI officials that was never filmed. Let's take it apart.
What is the FBI actually warning about?
On 20 July 2026 the FBI's Internet Crime Complaint Center published Alert I-072026-PSA, "FBI Warns of Scammers Impersonating the IC3". It's an update to an earlier alert from April 2025 with the same title, which tells you something on its own: this didn't go away, it got better produced.
IC3 is the place you report an internet crime to the FBI. It sits at one address: www.ic3.gov. That makes it a perfect thing to impersonate, because the people looking for it are, by definition, people who just lost money and want it back.
The FBI's own footnote gives the category a name. Re-targeting scams, it says, are "often called 'recovery' or 'double-dip' scams": schemes aimed at people who have already been defrauded.
What do the two schemes look like?
The FBI describes two, and they run on different rails.
Scheme one: the agent in your DMs. A victim mentions to the original scammers that they're going to file an IC3 report. Shortly after, someone claiming to be an FBI agent contacts them on Facebook Messenger, then moves the conversation to Telegram. Eventually a link arrives, to "update the submitted IC3 report." The FBI says that link "may contain malicious code or may be used to collect more financial data to revictimize the person."
The April 2025 alert described a related, more theatrical version: fake female personas joining online support groups for fraud victims, presenting themselves as fellow victims, then recommending you contact a man named "Jaime Quin," supposedly the "Chief Director" of IC3, on Telegram. There is no such role and no such person.
Scheme two: the video that was never filmed. This is the new part. The FBI says a social media platform carried "AI-generated videos depicting a senior FBI leader encouraging users to submit victim complaints on a spoofed IC3 website." The fake site copies the structure and content of the real one, but only one thing on it actually works: the complaint form. Every other link bounces you back to the home page.
That form is a single step and asks for exactly five things: name, phone number, email address, scam type, and estimated financial loss. Then it hands you a reference number, which is not a reference to anything. You've just told a stranger you have money missing, how much, and how to reach you. Infosecurity Magazine's write-up quotes an outside analyst calling this round "materially more polished" than the 2025 version.
How common is it?
Nobody has published a big number, and I'm not going to invent one. The July 2026 alert contains no statistics at all. The only hard figure in this whole story comes from the April 2025 alert, and it's this, word for word: "Between December 2023 and February 2025, the FBI received more than 100 reports of IC3 impersonation scams."
That's reports to one agency, about one impersonated brand, over roughly fifteen months. Treat it as a floor, not a measurement.
Three rules the FBI states flatly
These are the useful part of the alert, because they're absolute. Anything that contradicts one of them is fake, no judgment call required.
- IC3 has no social media presence. The alert says any profile or page claiming to represent IC3, or offering to recover lost money, "are fraudulent and are actively attempting to steal your personal or financial information." No Facebook page. No Telegram channel.
- IC3 never contacts you first. Not by phone, email, social media, app, chat, or forum. If the FBI needs more information, the alert says you'll be contacted by FBI employees from a local field office or other law enforcement officers.
- IC3 never asks for payment to recover funds; it also never refers you to a company that charges for it.
Malwarebytes and Help Net Security both landed on the same summary the day after the alert: no upfront fee, no unsolicited "recovery agent," no credentials handed to anyone who slid into your messages.
Why does the address bar beat the video?
Here's the thing about a deepfake: you can't out-stare it. Video and audio of public officials are now cheap to fabricate, and "does this look real?" is a losing question. So swap the question. Don't ask whether the person is real. Ask whether the address is real.
A video can show you anything. It cannot change what's written in your browser's address bar. And the real IC3 lives at exactly one place.
www.ic3.govthe FBI's Internet Crime Complaint Centeranything elsea different owner, whatever it looks likeThe alert's own instructions are unusually specific about this, and worth following literally:
- Type
www.ic3.govinto the address bar yourself. The FBI says to do this "rather than using a search engine." - If you do search, skip the sponsored results. The alert calls them "usually paid imitators looking to deter traffic from the legitimate IC3 website."
- Check that the address ends in
.govand reads exactlywww.ic3.gov. Notic3-gov.com, notic3.gov.report-claim.net, not a hyphenated cousin. - Don't click a link whose address differs from the real site, however official the message around it looks.
- Never pay to get money back. A fee to recover funds is the scam, full stop.
One more, aimed at how these sites are built: the fake described in the alert had a working complaint form and nothing else. If you land on a "government" site and every link except the form is dead, that's not a slow server. That's the whole site.
Where does IP Tracker fit?
IP Tracker is a free Chrome extension. Paste a domain, or a full email address, into the popup; the free tier gives you 25 checks a day, no account, no tracking. Only the value you paste is looked up.
For a case like this it does three useful things. It compares the domain against the official domains of more than 120 widely impersonated organizations after normalizing look-alike characters, so a swapped character or a near-miss spelling gets named rather than glanced past. It shows whether Google Safe Browsing (Google's list of reported dangerous sites) has flagged the address, and how many security vendors flag it on VirusTotal. And it shows the domain's creation date, because a "federal agency" registered eleven days ago is worth a pause. 🤓
It also reads subdomain tricks the right way round, which matters here: in ic3.gov.claim-portal.net the part that actually owns the address is claim-portal.net, and ic3.gov is just decoration someone typed on the left.
What can't it do?
Four limits, stated plainly, because this is a topic where false confidence costs money:
- It can't tell you a site is safe. It surfaces signals: flagged, not flagged, newly registered, reported. The judgment stays yours.
- It can't see a deepfake. No domain check evaluates a video, an audio clip, or the person in your DMs. It only ever looks at an address you paste.
- Blocklists lag. A phishing site put up this morning may be flagged by nobody yet. That's exactly the window these campaigns are built for.
- A perfect-looking domain can still be wrong. The check compares what you paste. If a fake address is simply unknown rather than obviously imitative, it may come back with nothing to report, which is information, not clearance.
What if it's already happened?
Report at www.ic3.gov, typed in yourself. If the victim is 60 or older, both FBI alerts list the Department of Justice Elder Justice Hotline: 1-833-FRAUD-11 (833-372-8311). And if someone contacts you afterwards offering to get the money back, especially warmly, especially on a messaging app, that is the second wave, not the rescue.
To summarize:
- ✓ IC3 has no social media accounts and never messages you first.
- ✓ Nobody official ever charges a fee to recover stolen funds.
- ✓ Type
www.ic3.govyourself; skip sponsored search results. - ✓ Judge the address bar, not the face in the video.
- ✓ Or paste the domain into IP Tracker and see what's known about it.
Stay sharp, and be kinder to yourself than the second wave is counting on. 🛡️