FRAUD CHECK — Squire It™
sharelivefraud.com/squire-it
LIVE FRAUD ALERT
LIVEFRAUD Check #1
FBI WARNS

People who have already lost money to a scam are being contacted again by criminals posing as FBI staff or the Internet Crime Complaint Center (IC3), who claim to have recovered the victim's funds or offer to help recover them — using fake social media profiles, AI-generated videos of officials, and spoofed IC3-lookalike websites to collect personal and financial data.

MODERATE CONFIDENCEPublished 2026-08-14
S
Q
U
I
R
E
D
E
S
K
·
C
H
E
C
K
E
D
·
B
A
T
T
L
E
D
·
R
E
C
E
I
P
T
E
D
·
S

What we found

The FBI has issued an updated public service announcement about an ongoing scheme in which criminals impersonate FBI personnel handling Internet Crime Complaint Center (IC3) complaints in order to deceive and revictimize people. According to the advisory, contact arrives by email, phone call, social media approach, or advertisements on social media and forums, and almost all complainants said the scammers claimed to have recovered the victim's lost funds or offered to assist in recovering them — a ruse aimed at people who have already lost money. In one described variant, after a victim tells a scammer they will report them to the FBI and file an IC3 report, someone posing as an FBI agent contacts them on Facebook Messenger, moves the conversation to Telegram, and sends a link to "update" the report — a link that may carry malicious code or be used to collect further financial data. In a second variant, AI-generated "deepfake" videos depicting a senior FBI leader circulated on a social media platform, urging users to submit complaints on a spoofed IC3 website that copies the structure and content of the real site but only permits the complaint form to function, with all other links returning the user to the home page. The FBI notes that the fake intake form is a single step asking only for name, phone number, email address, scam type, and estimated financial loss, then issues a reference number and says someone will be in touch. The advisory states that IC3 does not maintain any social media presence, does not investigate crimes or recover funds through Facebook, Telegram, or similar platforms, and will never directly contact individuals by phone, email, social media, apps, online chat, or public forums — any profile or page claiming to be IC3 or offering fund recovery is fraudulent. The FBI also states IC3 will never ask for payment to recover lost funds and will not refer anyone to a company that charges for recovery. Recommended defensive steps in the advisory include typing www.ic3.gov directly into the browser address bar rather than using a search engine, skipping "sponsored" search results, confirming the URL ends in .gov, and never entering sensitive information on a site whose legitimacy is unclear. The advisory lists visual and audio tells for synthetic media, including distorted hands or feet, irregular facial features, unrealistic glasses or jewelry, inaccurate shadows, watermarks, voice call lag, and unnatural movement, while cautioning that AI-generated content is often difficult to identify. Victims are directed to file complaints only at www.ic3.gov with contact details, communication methods, and transaction records, and complainants aged 60 or over can get filing assistance from the DOJ Elder Justice Hotline at 833-372-8311. If you have previously reported a scam and someone reaches out claiming to be FBI or IC3 staff with good news about your money, treat it as a second attempt on your wallet and re-establish contact yourself through the official site.
THE RULE
HIGH — targets people already known to have lost money, uses impersonated government authority plus synthetic video, and harvests identity and financial data through a convincing lookalike complaint form.

What we don’t know

The bench — who voted

The card names a count. Here are the seats behind it, with what each one said.

GROQopenai/gpt-oss-120b
Finding states "almost all complainants said the scammers claimed to have recovered the victim's lost funds" – the evidence row only notes the advisory characterizes complainant reports, without specifying that proportion.

Reviewed by 1 independent model; it judged the finding to go beyond the evidence.

▼ Protocol & challenge record
Objection (high): Material omission that changes the safety advice: the PSA explicitly says that while IC3 itself never contacts individuals, 'If further information is needed, individuals will be contacted by FBI employees from local field offices or other law enforcement officers.' The finding drops this clause entirely, and then closes with an unsourced instruction to treat anyone 'claiming to be FBI or IC3 staff with good news about your money' as a scammer. Real FBI field-office personnel do contact victims. The distinction the source draws (IC3 = never; FBI field office = possibly) is collapsed, which both over-generalizes the source and could cause a reader to disregard a genuine law-enforcement contact. The advice sentence carries row_ids: [] and is doing the most work in the piece.
Not resolved — preserved on the record.
Objection (medium): Overclaim on data harvested. The claim sentence says the spoofed site and profiles 'collect personal and financial data.' The source says the fake intake form asks only for name, phone number, email address, scam type, and estimated financial loss — that is PII plus a self-reported loss figure, not financial account data. The only 'financial data' element is hedged in the source ('The link may contain malicious code or may be used to collect more financial data'). The claim converts a hedged 'may' into an asserted capability, and the risk_line repeats it ('harvests identity and financial data through a convincing lookalike complaint form').
Not resolved — preserved on the record.
Objection (medium): Confidence 'high' is unscoped. It is defensible for 'an official FBI PSA dated 2026-07-20 says X'; it is not defensible for the real-world proposition in the claim ('People ... are being contacted again'). Everything about prevalence, currency of the campaign, and whether the infrastructure is live rests on the agency's own uncorroborated characterization of complainant reports — the confidence_reasons even concede 'No corroborating press or community reporting was harvested.' Listing a disqualifying gap as a reason for high confidence is internally inconsistent; it belongs in limitations.
Not resolved — preserved on the record.
Objection (medium): Interpretive gloss on the deepfake distribution. Source: 'A social media platform shared AI-generated videos depicting a senior FBI leader encouraging users to submit victim complaints on a spoofed IC3 website.' The most natural reading is that a platform shared the videos with the FBI (i.e., reported them) — the FBI's knowledge is second-hand from a platform referral. The finding renders this as videos that 'circulated on a social media platform,' which asserts public distribution and reach that the sentence does not establish. Either reading is possible; the draft picks one without flagging the ambiguity.
Not resolved — preserved on the record.
Objection (medium): Scope broadening on the 'all fraudulent' line. Source: 'Any social media profiles or pages claiming to represent IC3 or offering to recover lost money are fraudulent.' Finding: 'any profile or page claiming to be IC3 or offering fund recovery is fraudulent.' Dropping 'social media' turns a platform-specific statement into a categorical one that would sweep in lawful asset-recovery and legal services. Small edit, real semantic drift.
Not resolved — preserved on the record.
Objection (medium): Risk_line 'HIGH' is asserted without any scale evidence. No victim counts, no loss totals, no domains, no IOCs, no takedown status, no named platforms — the evidence limitation says so explicitly. The document is an update to an April 2025 alert (I-04182025-PSA); an alternative explanation for its existence is routine periodic refresh of a standing advisory rather than a measurable surge. The draft does not consider or exclude that reading before assigning HIGH.
Not resolved — preserved on the record.
Objection (low): Single-source, single-URL dependency with no archive or mirror. The entire finding hangs on one row. Domain (ic3.gov) and PSA numbering (PSA260720 matching a 2026-07-20 date, following I-04182025-PSA) are internally consistent, but nothing here independently confirms the page resolves or has not been superseded by a later PSA.
Resolved: Partially self-resolved on internal consistency: the PSA identifier PSA260720 matches the stated publication date 2026-07-20, and the referenced predecessor I-04182025-PSA matches an April 18, 2025 alert with the same title. Entity/domain match is clean (ic3.gov is the issuing agency's own domain), so this is not an impersonation-of-source problem — only an unverified-liveness problem. Downgraded to low and moved to open.
Objection (low): Minor paraphrase drift in the deepfake tells: source lists 'unrealistic facial features, indistinct or irregular faces'; the finding compresses this to 'irregular facial features.' Trivial in isolation, but it is the same compression habit that produced O1 and O5.
Resolved: Checked against source text; meaning is not reversed and no reader would be misled. Noted for the record, not blocking.
Objection (low): Omitted defensive guidance that is arguably more actionable than what was kept: 'Do not send money, gift cards, cryptocurrency, or other assets to people you do not know or have met only online,' and 'Report any accounts impersonating IC3 to that social media's safety or support contacts.' The draft kept the browser-hygiene tips and dropped the payment-refusal and platform-reporting tips.
Resolved: Confirmed these are omissions of completeness, not errors. Nothing in the finding contradicts them. Recommend adding the payment-refusal line since it is the single most protective tip in the PSA; not blocking on its own.
Preserved dissent
ON THE RECORDI do not accept the 'high' confidence as written. The draft's own fourth confidence_reason states that no corroborating reporting was harvested and that scale and current status cannot be cross-checked. That is a reason to lower confidence, not a footnote under a high rating. An official primary source establishes what the agency said; it does not establish that the described campaign is active today, at any particular scale, or that the described infrastructure is still reachable. Confidence should be scoped: high on the existence and content of the advisory, unknown on everything downstream of it.
ON THE RECORDThe most serious problem in this draft is not a citation gap, it is a safety-advice defect. By deleting the PSA's own carve-out that 'individuals will be contacted by FBI employees from local field offices or other law enforcement officers,' and then adding an unsourced closing line telling readers to treat any contact 'claiming to be FBI or IC3 staff' as a second attempt on their wallet, the draft gives advice the source does not give and that the source in fact qualifies. A reader who follows it could stonewall a legitimate field-office callback. An unsourced sentence (row_ids: []) that contradicts a clause the draft chose to omit from the same paragraph it otherwise quotes closely is the worst combination available. I would hold publication until this is fixed.
ON THE RECORDI also think the HIGH risk line is doing rhetorical work the evidence does not support. There are no victim counts, no loss figures, no domains, no platform names, and no takedown status — the draft's own limitation field says as much. Rating a threat HIGH while conceding you cannot measure it is a category error; state the harm profile and say the incidence is unquantified.

The sources

Official sourceFBI Warns of Scammers Impersonating the IC32026-07-20
An official FBI/IC3 public service announcement dated 2026-07-20 describes an ongoing scheme in which criminals impersonate FBI personnel and IC3 to revictimize prior scam victims via fake social media profiles, AI-generated videos of a senior FBI leader, and a spoofed IC3 complaint website that harvests name, phone, email, scam type, and loss amount.
Authority: official. Retrieved 2026-08-14.
Limitation: The advisory does not give victim counts, aggregate losses, the spoofed domain names, the social media platforms involved, or whether the fake sites and profiles have been taken down; the volume claim rests on the agency's own characterization of complainant reports rather than published figures.
Open the original source →

Other checks

Every check we have published →

Share this receipt
sharelivefraud.com/check/ie_k5G4

Approved by ihubglobalhq on 2026-08-15, after the six-point evidence checklist.

Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.

Phishy? Send it → sharelivefraud.com/squire-it

Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.

Naming a source is not an endorsement, and being named here is not an accusation against any company.

Powered by SquireIt™

Verify this receipt at squireit.com

Join Squire’s First Watch

Alerts before the feed. Credit when your summons becomes a receipt. A vote on what we check next. Founding names are permanent.

Get the next one

We publish a receipt for every alert, including the ones we decide not to run.

We will ask you to confirm before anything is sent. Your address is used for this and nothing else, and is never shared.