FRAUD CHECK — Squire It™
sharelivefraud.com/squire-it
LIVE FRAUD ALERT
LIVEFRAUD Check #18
CFPB WARNS

Unsolicited direct messages from someone claiming to be an FBI agent are being flagged by consumers, against a steady monthly volume of fraud-or-scam complaints logged at the CFPB.

LOW CONFIDENCEPublished 2026-08-18
S
Q
U
I
R
E
D
E
S
K
·
C
H
E
C
K
E
D
·
B
A
T
T
L
E
D
·
R
E
C
E
I
P
T
E
D
·
S

What we found

A community lookup this month asked about a security vendor's blog page whose web address reads "don't trust that FBI agent in your DMs". That row is a single lookup and the page's own text was not harvested, so we cannot describe how the impersonation is carried out, what the sender asks for, or how any money moves. Separately, the CFPB's public complaint database recorded, under the issue "Fraud or scam", 587 complaints matching "scam" in the 30 days to 2026-08-14, 599 in the 30 days to 2026-08-15, 548 in the 30 days to 2026-08-16 and 515 in the 30 days to 2026-08-17. Those four windows overlap by 29 days each and the rows carry counts only — no narratives and no company names — and the counts are complaints received rather than substantiated findings, so they cannot be read as a trend or tied to the direct-message impersonation above. If an account slides into your direct messages claiming to be a federal agent, do not reply in that thread: close it, look up the agency's public number yourself, and ask them whether anyone is trying to reach you. LIVEFRAUD ALERTS is an independent consumer awareness desk and is not affiliated with, endorsed by or speaking for any agency, company or brand named here. This alert was written only from the harvested rows listed as evidence; nothing outside them was used.
THE RULE
A stranger claiming a badge in your inbox costs nothing to send, and the harvested material does not show what happens after you reply — so the safe assumption is that answering is the risk.

What we don’t know

The bench — who voted

3 INDEPENDENT AI MODELS REVIEWED THIS. ALL 3: MODERATE RISK.

The card names a count. Here are the seats behind it, with what each one said.

ANTHROPICclaude-opus-5 · MODERATE
The headline claim that unsolicited FBI-impersonation DMs 'are being flagged by consumers' is not carried by row [1]. That row records one person looking up the web address of a security vendor's blog post. It establishes that a vendor published a page with that title and that one lookup occurred; it does not establish that any consumer received such a message, still less multiple consumers flagging it. Plural 'consumers' and 'flagged' both stretch a single lookup of a marketing URL.
DISSENT, PRESERVEDThe body of the finding is unusually honest: it names the single-lookup limit, the 29-day overlap, the received-not-substantiated caveat, and states plainly that the two evidence strands cannot be joined. My 'overstated' verdict falls on the claim line, not on the analysis beneath it. Rewriting the claim to 'One community lookup this month concerned a vendor article about FBI impersonation in direct messages' would make the package hold.
DISSENT, PRESERVEDOn the grade: the underlying pattern class - someone posing as federal law enforcement in a private message - is capable of very large individual losses and coercive harm. I grade moderate only because these rows show no contact mechanics, no ask, no payment rail and no victim. If mechanics were ever harvested showing a payment or credential demand, I would move to high without hesitation.
DISSENT, PRESERVEDThe practical advice given - do not reply in-thread, look up the agency's own published number, verify independently - is sound and is the correct action regardless of how thin the evidence is. That advice should survive any redraft.
GROQopenai/gpt-oss-120b · MODERATE
Including overlapping CFPB complaint counts may lead readers to infer a trend or connection to the DM impersonation despite the disclaimer that they cannot be tied.
OPENROUTERopenrouter/free · MODERATE
The evidence for consumers flagging unsolicited DMs is based on a single community lookup of a blog URL, which does not constitute evidence of consumers actively flagging such messages. This weakens the first part of the claim.
DISSENT, PRESERVEDWhile the alert includes appropriate caveats, the initial claim overstates the connection between the isolated blog lookup and the broad CFPB complaint data. The risk to readers is real but not well-established by the evidence provided, so the grade of moderate reflects the potential harm without confirmation of prevalence.

Reviewed by 3 independent models: 1 found it carried by the evidence, 2 did not.

▼ Protocol & challenge record
Objection (high): The claim line says impersonation DMs "are being flagged by consumers" (plural, ongoing). The only supporting row is "1 person has asked about malwarebytes.com" — n=1, and what that person looked up was a security vendor's domain, not a DM they received. The row establishes one act of curiosity about a vendor page; it does not establish that any consumer received, or reported receiving, an FBI-impersonation DM. Plural "consumers" and the progressive "are being flagged" both overclaim beyond a single lookup.
Resolved: Rewrite claim to the size of the row: 'One community lookup asked about a security vendor page whose address refers to people impersonating FBI agents in direct messages.' Drop 'consumers' plural and 'are being flagged'.
Objection (high): The claim line asserts a "steady monthly volume" of CFPB fraud-or-scam complaints, while finding sentence 4 says the windows "cannot be read as a trend." "Steady" is a trend/stability characterisation and is contradicted by the draft's own limitation — and by the numbers, which run 515 to 599 (a ~16% spread) across windows sharing 29 of 30 days. Four heavily overlapping windows cannot support "steady" any more than they could support "rising." The headline claim contradicts the body.
Resolved: Delete 'against a steady monthly volume of fraud-or-scam complaints logged at the CFPB' from the claim. No characterisation of level or stability is available from four windows overlapping by 29 days.
Objection (high): Row metadata and query URL disagree. Each row's prose says 'Issue "Fraud or scam" recorded N complaints matching "scam"', but the harvested API URL contains only search_term=scam&field=all&date_received_min/max — there is no issue= or filter parameter restricting results to the "Fraud or scam" issue. On the URL as harvested, these counts are all complaints anywhere in the database whose full-text matches "scam", across every issue and product. The finding repeats the unsupported issue attribution verbatim: 'recorded, under the issue "Fraud or scam"'. Either the row prose is wrong or the URL is incomplete; either way the published sentence asserts a filter the evidence does not show.
Resolved: Either re-harvest with an explicit issue filter and cite the filtered URL, or change the finding to 'complaints whose text matched "scam" across all issues', and add a limitation that the harvested query URL shows no issue restriction.
Objection (medium): Source-to-claim stretch: the entire substantive topic is read out of a URL slug ("dont-trust-that-fbi-agent-in-your-dms"). Slugs are marketing artefacts and frequently diverge from article scope. The article could be about crypto-recovery scams, sextortion follow-ups, a specific arrest, or scammers posing as FBI to "unfreeze" accounts. The draft flags that the page text was not harvested, which is good, but the claim line still presents the slug's assertion as a live consumer-facing threat pattern. A headline built on an unread page is a headline built on nothing.
Not resolved — preserved on the record.
Objection (medium): Date currency and mislabelling. The harvested URL path is /blog/news/2026/07/ — the underlying article is from July 2026. The lookup row is timestamped 2026-08-17. The finding says "A community lookup this month", which is only true relative to an unstated 'today' and silently leaves the reader to infer the source material is current. The month of the source page (July) is available in the evidence and is omitted.
Resolved: State the source page's own month: 'a blog page published in July 2026, looked up on 2026-08-17'. Replace the relative 'this month' with the dated lookup timestamp.
Objection (medium): Wrong-register / jurisdiction mismatch on the CFPB series. The CFPB complaint database covers consumer financial products and services against named financial companies. A stranger impersonating a federal agent in a social-media DM is not, absent a financial-product nexus, a CFPB matter; it would surface at IC3 or the FTC Sentinel. So the CFPB counts are not merely 'unlinked' to the DM topic — they are drawn from a corpus where this conduct would not normally be logged at all. Placing them in the same claim sentence manufactures scale.
Not resolved — preserved on the record.
Objection (medium): Reporting four near-identical overlapping windows adds zero information over reporting one, but reads to any ordinary reader as a four-point time series with a decline at the end (587, 599, 548, 515). The disclaiming sentence that follows does not undo the visual/rhetorical effect of four dated numbers in sequence. If the point is 'roughly 500-600 keyword matches in a 30-day window', say that once.
Resolved: Report a single window (the most recent, 515 in the 30 days to 2026-08-17) and note in one clause that three earlier overlapping windows were harvested and are not a series.
Objection (medium): Internal contradiction in the surviving directive option. "Tell everyone in your contacts who uses social media direct messages" names a platform class (social media DMs), while the draft's own unknowns list includes "Which platforms the direct messages arrive on." Nothing harvested identifies a platform. By the draft's own §11 logic — which rejected eight tokens as "NOT IN EVIDENCE" — this directive names a group and a channel that no harvested row supports and should also have been dropped.
Resolved: Drop the directive option entirely, or reduce it to 'Tell anyone who might get a message like this' with no platform named, and add 'social media direct messages' to targeting_dropped for the same reason the other tokens were dropped.
Objection (low): The targeting_dropped list shows the callout/directive filter tokenising a phrase into fragments ("agent'", "fbi", "claiming", "stranger", "dms") and emitting a boilerplate rejection per token. These are not candidate audience groups; this is a pipeline artefact. It does not corrupt the finding, but publishing it as reasoning is misleading about what was actually considered and rejected.
Resolved: Suppress token-level rejection entries from the published record; list at most the one coherent candidate group that was considered, or nothing.
Objection (low): The risk_line reasons from absence: "the harvested material does not show what happens after you reply — so the safe assumption is that answering is the risk." That is an editorial precaution dressed as an inference, and "costs nothing to send" is an assertion about scammer economics found in no row. Precautionary advice is defensible; presenting it as something the evidence supports is not.
Resolved: Re-label the risk line explicitly as desk precaution, e.g. 'Nothing harvested shows what follows a reply; we advise treating a reply as the risk' — so the reader sees it as editorial policy, not evidence.
Objection (medium): Alternative explanation for the one community row that the draft never considers: someone checking malwarebytes.com may be verifying whether a link they were sent is safe, whether the vendor itself is legitimate, or may have been sent the article by a friend. A domain-reputation lookup of a well-known security vendor is weak evidence of anything about the vendor's subject matter, and it is at least as consistent with the article circulating as with the scam circulating.
Resolved: Add the alternative reading to the limitation on the community row: a domain lookup may reflect someone verifying the vendor or a forwarded link, not an approach received.
Objection (medium): Net evidentiary position: one URL whose contents were not read, plus four redundant keyword counts from a database where the alleged conduct would not be logged. After every limitation the draft itself states is applied, nothing informative remains. This is not a low-confidence alert; it is an alert with no established subject. The honest output is either no alert, or a bare 'we have seen one lookup of an unread article; here is generic impersonation hygiene' note with the claim line and CFPB block removed.
Not resolved — preserved on the record.
Preserved dissent
ON THE RECORDI do not think this should publish in anything close to its current form. The claim line makes two assertions the body then retracts — that consumers (plural) are flagging these DMs, and that CFPB volume is 'steady'. A headline that the finding has to walk back is not a low-confidence headline; it is an inaccurate one.
ON THE RECORDThe CFPB block should be cut, not caveated. Four windows overlapping by 29 days, from a database that does not ordinarily receive reports of strangers posing as federal agents on social media, contribute nothing to this topic. Their only function in the alert is to make one unread URL look like it sits on top of a body of data. Adding 'so they cannot be read as a trend or tied to the direct-message impersonation above' is an admission that the material does not belong in the alert at all.
ON THE RECORDReading a threat description out of a URL slug is the core defect here, and the draft's honesty about it does not cure it. We do not know what that page says. Writing 'don't trust that FBI agent in your DMs' into a consumer alert because it appears in a web address is publishing a vendor's headline as our own finding.
ON THE RECORDThe row states 'no issue filter' in the URL while the row prose and the finding both assert the 'Fraud or scam' issue. Whatever the explanation, we are currently attributing a filter to a query that does not contain one. That should block publication of those four sentences independent of everything else.
ON THE RECORDIf the desk overrides me and publishes, the record should show that the challenger's position was: one domain lookup of an unread page is not a story, and the correct output was generic impersonation hygiene with no claim of an observed campaign and no CFPB numbers.

The sources

Official sourceCFPB complaints — Fraud or scam: 587 since 2026-07-15
The CFPB recorded 587 complaints matching "scam" under the issue "Fraud or scam" in the 30 days to 2026-08-14.
Authority: aggregate. Retrieved 2026-08-18.
Limitation: Aggregate count only, no narratives or company names; complaints received, not substantiated findings.
Open the original source →
Official sourceCFPB complaints — Fraud or scam: 548 since 2026-07-17
The CFPB recorded 548 such complaints in the 30 days to 2026-08-16.
Authority: aggregate. Retrieved 2026-08-18.
Limitation: Window overlaps the other counts by 29 days; aggregate only, complaints received, not substantiated findings.
Open the original source →
Official sourceCFPB complaints — Fraud or scam: 599 since 2026-07-16
The CFPB recorded 599 such complaints in the 30 days to 2026-08-15.
Authority: aggregate. Retrieved 2026-08-18.
Limitation: Window overlaps the other counts by 29 days; aggregate only, complaints received, not substantiated findings.
Open the original source →
Official sourceCFPB complaints — Fraud or scam: 515 since 2026-07-18
The CFPB recorded 515 such complaints in the 30 days to 2026-08-17.
Authority: aggregate. Retrieved 2026-08-18.
Limitation: Window overlaps the other counts by 29 days; aggregate only, complaints received, not substantiated findings.
Open the original source →
Reported1 person has asked about malwarebytes.com2026-08-17
A community lookup this month asked about a security vendor's blog page whose web address reads "don't trust that FBI agent in your DMs".
Authority: community. Retrieved 2026-08-18.
Limitation: One lookup by one person; only the URL was harvested, not the article text, so no detail of the approach, ask or payment method is available.
Open the original source →

Other checks

Every check we have published →

Share this receipt
sharelivefraud.com/check/9LkX3AU

Approved by ihubglobalhq on 2026-08-18, after the six-point evidence checklist.

Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.

Phishy? Send it → sharelivefraud.com/squire-it

Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.

Naming a source is not an endorsement, and being named here is not an accusation against any company.

Powered by SquireIt™

Verify this receipt at squireit.com

Join Squire’s First Watch

Alerts before the feed. Credit when your summons becomes a receipt. A vote on what we check next. Founding names are permanent.

Get the next one

We publish a receipt for every alert, including the ones we decide not to run.

We will ask you to confirm before anything is sent. Your address is used for this and nothing else, and is never shared.