In mid-September 2025, people who had just been robbed online went looking for the place where you report being robbed online. Some never arrived. Instead of ic3.gov, the Internet Crime Complaint Center operated by the FBI, they landed on ic3-gov.com, or ic3gov.org — domains carrying the Bureau's seal, the IC3 banner and the same institutional blue as the real thing. Analysts identified the first wave on 18 September; the Bureau published a warning the following day, telling the public to type the address manually, check the domain ends in .gov, and ignore sponsored search results.
Ten months later, on 20 July 2026, the same centre issued a further alert, numbered I-072026-PSA, describing something more elaborate. Criminals were no longer merely cloning the website. They were building fake social media profiles for FBI personnel, opening conversations with fraud victims on Facebook Messenger, then moving those conversations to Telegram, where they sent links to spoofed complaint portals harvesting names, telephone numbers, email addresses, the type of scam suffered and the amount lost, before issuing a fabricated reference number and asking for more. And they were circulating AI-generated video of senior FBI officials, urging viewers to file complaints at an address that was not the FBI's, and generating synthetic video for real-time video chats in which the person on the call appeared to be a law enforcement official.
The Bureau's central corrective was blunt and slightly melancholy: the IC3 does not maintain a social media presence, does not contact individuals directly through messaging platforms, and will never ask for payment to recover lost funds. An agency whose entire function is to be the trustworthy destination for people who have just been deceived now spends its public communications explaining the circumstances under which it does not exist.
This is not a new category of crime. Refund and recovery fraud — a stranger promising, for a fee, to retrieve money you have already lost — is old enough to have generated decades of consumer warnings. What has changed is production quality and the precision of the targeting. The question is not whether people should be more careful. It is who, among the platforms carrying the contact, the agency whose face is borrowed and the legislators who have not written the relevant law, is responsible for the second wound.
What the Bureau Has Warned About, Twice Before
The July 2026 alert is the third in a sequence, and the escalation is clearer in retrospect.
The first came on 18 April 2025, reporting that between December 2023 and February 2025 the FBI had received more than one hundred complaints about people impersonating IC3 employees. Contact arrived by email, telephone, social media or online forums. Almost every complainant said the impersonator had claimed either to have recovered their lost funds or to be able to assist in recovering them. The Bureau described one recurring pattern in which scammers created female persona profiles, joined online groups for fraud victims, presented themselves as fellow victims, then referred members to a supposed senior official reachable on Telegram. The tactics were essentially conversational: someone lied to you in writing.
The second, in September 2025, concerned infrastructure rather than personas: look-alike domains intercepting traffic intended for the real portal, and deceptive emails purporting to confirm complaints victims had never submitted.
The third fuses the two and adds synthetic video. Security analysts characterised the scheme as considerably more polished than the earlier warning had described, evolving from text-only approaches into something resembling an official government process from beginning to end: a video of an official, a website that looks like a government website, a form, a reference number, a follow-up. Each element is individually unremarkable. Assembled in sequence, they reconstruct the ritual of reporting a crime to the state.
One detail deserves precision. Reporting describes deepfake videos of senior FBI officials, but neither the alert nor the press coverage appears to identify which officials were depicted; any description of the scheme as targeting a specific, named executive should be treated as unverified.
The FBI's detection advice, repeated from a December 2024 alert on criminal use of generative AI, tells you a great deal about the state of the defence. Look for distorted hands, unrealistic eyes, implausible jewellery, inaccurate shadows, lag between lip movement and voice. These were reasonable heuristics in 2023. As guidance for someone confronted with a short, compressed clip on a phone screen in 2026, they are closer to ritual than method. The July alert concedes as much, noting that AI-generated content has become so sophisticated that it is increasingly difficult to detect. The checklist degrades further still when the synthetic face is on a live call rather than in a recorded clip: nothing can be paused, rewound or examined a second time, and the ordinary pressure to answer while someone waits on the other end removes the interval in which scrutiny would happen. A heuristic that assumes the viewer can look twice is of limited use to a person who cannot look twice.
Why the Freshly Defrauded Are the Most Valuable Targets
The strategic insight behind recovery fraud is that a person who has just lost money is not a worse target than a person who has not. They are a better one.
This is counterintuitive only if you assume that being scammed produces caution. The consumer protection literature has long documented so-called sucker lists — records of prior victims containing name, telephone number, scam type and sum lost, traded among criminal operators on the theory that someone who paid once may pay again. The Federal Trade Commission has warned about these lists and the approach they enable, in which the caller already knows what happened to you — itself the most persuasive credential available.
The academic evidence is stronger than generally appreciated, because one dataset is unusually good. Marguerite DeLiema of the University of Minnesota and Lynn Langton of RTI International analysed two decades of records seized from fraud organisations by the United States Postal Inspection Service, covering more than two million victims. Because this was transactional data rather than survey responses, it recorded what people did rather than what they would admit. Revictimisation rates rose with age in certain scam categories. The ten thousand most frequently responsive individuals had responded to fraudulent solicitations between 82 and 562 times each. Their average age was 78.
That is not a portrait of gullibility. It is a targeting system working as designed, applied repeatedly to people identified as responsive and who are, by the fiftieth approach, in a psychological state the fraud itself produced.
A 2025 qualitative study in the journal Victims and Offenders, based on interviews with twelve cyberscam victim-survivors and eight of their friends and family members, found pervasive impacts: distress, shame, decay of trust, conflict within families, support needs largely unmet. Shame does specific structural work. It discourages disclosure to family, removing the most reliable circuit-breaker in fraud — a second opinion from someone not emotionally invested in the outcome. It also makes the victim receptive to any approach that treats them as a legitimate claimant rather than a fool. Layered on top is escalation of commitment: the more a person has lost, the more expensive it becomes to accept the loss is final. A recovery scam is an offer to undo the first fraud, aimed at someone for whom that has become the organising priority of their week.
What the July 2026 alert adds is timing. The scheme targets people who have recently reported financial fraud or expressed an intention to do so — a window in which two conditions coincide and neither lasts long: financial desperation peaks, and trust in law enforcement is momentarily very high, because the victim has just voluntarily reached out to it. Filing an IC3 complaint is an act of hope. The scheme is built to intercept it.
The underlying market is not small. The Global Anti-Scam Alliance, in a report with the analytics firm Feedzai published in October 2025, surveyed 46,000 adults across 42 markets: 57 per cent had encountered a scam in the previous twelve months, 23 per cent had lost money, and only around 30 per cent of those who reported to their payment provider recovered anything. That gap is the space recovery fraud occupies.
A Record Year and the Cohort Absorbing It
The FBI's 2025 Internet Crime Report, published in April 2026, supplies the backdrop. The IC3 received 1,008,597 complaints, the first time in its twenty-five-year history that annual volume exceeded one million. Reported losses reached $20.877 billion, a 26 per cent increase on the $16.6 billion recorded in 2024.
Investment fraud remained the largest driver at more than $8.6 billion, followed by business email compromise at more than $3 billion and technical support fraud at $2.1 billion. Cryptocurrency featured in more than $11 billion of losses across 181,565 complaints. For the first time the report used AI-related as a formal descriptor, recording 22,364 complaints and roughly $893 million in losses — a floor rather than a measurement, since it captures only cases where the victim knew, and thought to say, that artificial intelligence was involved.
The elder fraud figures make the recovery scam legible as a strategy. Americans aged 60 and over filed 201,266 complaints in 2025 and reported losses of $7.75 billion, an annual increase of 59 per cent. The average loss in that group was around $38,500, and roughly 12,400 individuals lost more than $100,000 each. Investment fraud accounted for $3.52 billion of that total and technical support fraud for $1.04 billion. Complainants over 60 made up roughly a fifth of all complaints but close to 37 per cent of all reported losses.
The Federal Trade Commission's data tells a compatible story by a different method. Consumers filed more than a million imposter scam reports in 2025 and reported $3.5 billion in losses, making impersonation the most-reported fraud category for the fifth consecutive year. Around $920 million was attributed to government impersonators, up from $789 million in 2024, with such reports rising about 40 per cent year on year.
What the Evidence Actually Supports About Age and Synthetic Media
It is tempting to close the loop between those datasets by asserting that older adults are least able to recognise AI-generated video and audio and are therefore uniquely exposed. The claim is plausible. It is also more slippery than it looks, and the published research supports a narrower version than the one usually stated.
Start with what is reasonably well evidenced: awareness. A study by the biometric authentication firm iProov, based on 2,000 consumers in the United Kingdom and United States exposed to genuine and synthetic images and video, found that 30 per cent of respondents aged 55 to 64 and 39 per cent of those aged 65 and over had never heard of deepfakes at all, against 22 per cent overall. You cannot look for something you do not know exists.
The same study cuts against any simple generational framing. Only 0.1 per cent of participants correctly identified every genuine and synthetic item shown, participants were around 36 per cent less likely to identify a synthetic video than a synthetic image, and adults aged 18 to 34 displayed the largest gap between measured performance and self-assessed confidence. If detection is the defence, the defence is failing across the age range, and the group most likely to over-trust its own judgement is not the oldest.
Direct experimental evidence on age and accuracy is thinner than the discourse suggests. A study of audiovisual deepfake perception by Ammarah Hashmi and colleagues, which asked 110 participants to judge forty videos, reported that its oldest age band performed less accurately than younger bands — but that band was 41 to 50. It says nothing directly about people over 60, because it did not measure them separately. It also found every AI model tested outperformed every human, and that people systematically overestimated their own ability.
Qualitative work has looked specifically at seniors. Research by Zhiwei Tang, Dion Goh, Chei Sian Lee and Yang Yang, based on interviews with twenty participants aged 55 to 70, found they gravitate towards judgements about the authenticity of the video's subject rather than peripheral technical details, preferring intuition over consulting other people or verification resources. A comparative study in the International Journal of Human–Computer Interaction found both groups drawing on similar cue categories, with seniors leaning more on accumulated life experience.
That is more useful than an accuracy ranking, and it explains the scheme's design. If older adults assess a video by asking whether the person in it seems authentic, rather than inspecting shadows and hand geometry, a synthetic clip of a plausible official speaking plausible institutional language defeats the strategy at the point it is applied. The vulnerability is not primarily perceptual. It is that the heuristic in use is the one generative video is now good at satisfying.
One further consideration is lost in the focus on detection. The FBI's Operation Level Up, which proactively identifies people being defrauded and telephones them, notified 3,780 victims during 2025 and estimates it prevented $225.9 million in losses. Seventy-eight per cent of those contacted did not know they were being scammed. Detection was not failing at the margin. It was absent.
First Contact Happens on Someone Else's Platform
Every version of this scheme begins somewhere. In the July 2026 alert it begins on Facebook Messenger and migrates to Telegram, with deepfake videos circulating on social platforms to drive traffic. That is a specific, addressable fact about infrastructure, not an act of God.
Meta has not been idle. In March 2026 it announced a package of anti-scam measures, reporting that it had removed 159 million scam advertisements during 2025, with 92 per cent taken down before any user reported them, and disabled 10.9 million accounts across Facebook and Instagram linked to organised scam centres. In February 2026 it filed lawsuits against deceptive advertisers in Brazil, China and Vietnam, and set a target of raising the share of advertising revenue from verified advertisers from 70 to 90 per cent by the end of 2026.
Those are not trivial numbers, but they concern advertising and mass-scale account networks. The IC3 scheme requires neither. It requires one fake profile, one direct message to a person who has just posted in a fraud victims' support group, and a link. Direct messaging between two consenting parties is the hardest surface on any platform to police, and it is where this scheme lives.
Telegram is the second half of the pattern, and the conversation is moved there deliberately. The platform's posture shifted after the arrest of its founder Pavel Durov in France in August 2024, part of an investigation into insufficient moderation of illegal activity, after which Telegram began cooperating with law enforcement and expanded takedowns. Security researchers report enforcement at extraordinary scale — tens of millions of channels and groups blocked during 2025. The same research finds criminal ecosystems on the platform are not shrinking: groups use join-request gating to defeat automated moderation and maintain pre-built backup channels allowing near-instant reconstitution after removal.
This is the recurring shape of platform enforcement statistics: volume of removals measures activity, not outcome. A scheme that needs one working channel at a time, and can rebuild it in minutes, is largely indifferent to a takedown rate expressed in hundreds of thousands per day.
There is also a structural blind spot no enforcement budget resolves. Once a conversation moves into an encrypted direct message the platform has no view of its contents, and the design decision producing that blindness is the same one producing the privacy guarantee users are entitled to expect. Any proposal to fix scam contact by giving platforms visibility into private messages is a proposal to remove encryption. Direct-message fraud must therefore be addressed through weaker signals — account age, behavioural patterns, the profile claiming to represent a federal agency.
Two Continents and Two Answers on Platform Duty
Whether any of this becomes a legal obligation depends enormously on jurisdiction.
In the United States, Section 230 of the Communications Decency Act has historically meant a platform is not the publisher of a fake FBI profile created by a user, and that losses flowing from it are not the platform's to answer for. The precedent most on point is unhelpful to victims: in Herrick v. Grindr, involving an impersonating profile used to direct strangers to the plaintiff, the court dismissed the claim even where the harm was framed as a product defect, because the injury still originated in content supplied by another user.
That settlement is being tested. On 10 April 2026 the Massachusetts Supreme Judicial Court ruled unanimously in Commonwealth v. Meta Platforms that Section 230 did not immunise Meta from state consumer-protection and tort claims where the alleged harms stemmed from the company's own conduct — the design of platform features and misleading statements about safety — rather than from third-party content. The case concerns Instagram's effects on children rather than fraud, but the reasoning is portable: if a claim can be framed around how a service was built and what its operator said about it, the immunity does less work. Litigation directly about scam advertising is under way, including a class action filed against Meta in April 2026 alleging that the company profits from scam advertisements while misleading users.
Europe imposes systemic duties instead of litigating individual harms. Under the Digital Services Act, large platforms must maintain effective mechanisms against fraudulent advertising and mitigate the resulting risks. On 21 May 2026 the European consumer organisation BEUC, with 29 member groups, filed complaints against Meta, Google and TikTok with the European Commission and national Digital Services Coordinators. Between December 2025 and March 2026 the groups flagged almost 900 advertisements suspected of breaching EU law. The platforms removed 27 per cent; 52 per cent of reports were rejected or ignored. BEUC estimates the fraudulent advertising still running reaches more than 200 million European consumers a month.
The United Kingdom's approach under the Online Safety Act reached a concrete stage almost exactly as the FBI published its alert. On 10 July 2026 Ofcom opened a consultation, running until 2 October, on a draft Fraudulent Advertising Code of Practice containing close to forty measures for the largest categorised services: banning fraudulent advertisers and preventing re-registration, verifying advertiser identity, and testing AI-driven ad creation tools for misuse. Non-compliance carries penalties up to £18 million or 10 per cent of global revenue.
The limitation is written into the scope. The draft code covers paid advertising. It does not cover user-generated content, and it does not cover organic search results. A deepfake video posted to a feed rather than bought as an advertisement, followed by a direct message from a fake profile, falls outside it. The most advanced fraud-specific platform regulation in the democratic world addresses the part of the IC3 scheme that is optional, and not the part that is essential.
The Domain Nobody Can Quite Protect
The FBI's advice — type ic3.gov manually, check the .gov — reflects a real structural advantage and a real structural limit.
The advantage is that .gov is a genuinely controlled space. Under the DOTGOV Act of 2021, the Cybersecurity and Infrastructure Security Agency administers the top-level domain, restricting registration to verified United States federal, state, local, tribal and territorial entities, mandating multi-factor authentication and enforcing HTTPS. Nobody registers a fraudulent .gov domain, because nobody can.
The limit is that this forces the fraud one character sideways. The September 2025 spoofs used ic3-gov.com and ic3gov.org: ordinary commercial domains, registrable in minutes by anyone with a payment method, and no mechanism exists by which CISA or the FBI can prevent their creation. Suppression happens afterwards, through abuse reports to registrars and hosting providers, and the timing is unfavourable. Academic analysis of phishing domain lifecycles finds that although some malicious sites vanish within hours, the average interval between detection and deregistration runs to roughly 11.5 days, and squatted domains impersonating a specific brand persist on the order of three weeks. A scheme that needs the site live only long enough for a victim who received a Telegram link this morning to complete a form this afternoon is entirely compatible with an eleven-day takedown.
Provenance signalling is the technology most often proposed for the video half of the problem. The Coalition for Content Provenance and Authenticity has assembled a substantial standard and a very large membership, and the idea is sound: cryptographically sign content at creation so that origin and edit history travel with it. But C2PA manifests are removable by design and fragile in practice. Embedded manifests are lost whenever a file is re-saved by a tool that is not provenance-aware, and mainstream platforms routinely re-encode media on upload, stripping credentials as a by-product of transcoding rather than by deliberate act. Durable variants combining watermarking and fingerprinting improve matters, but the asymmetry remains: provenance proves that something is what it claims to be, and cannot prove that unsigned content is fake. Where most authentic video also carries no credential, absence of provenance signals nothing.
Detection is the other proposed answer, and the honest reading is discouraging. Deepfake detectors routinely report accuracy above 99 per cent on established academic benchmarks. Evaluated against Deepfake-Eval-2024, built from synthetic media actually circulating on social platforms, state-of-the-art open-source models fell precipitously, with reported reductions in area-under-curve of around 50 per cent for video, 48 per cent for audio and 45 per cent for images. Detectors are good at recognising the generators they were trained on. The generator used to make next month's video does not exist yet.
An Impersonation Statute Written for Badges, Not Pixels
The legal position in the United States is not that impersonating an FBI official is lawful. It is that the statutes were written for a different medium and scaled for a different volume.
Section 912 of Title 18 of the United States Code makes it an offence to falsely pretend to be an officer or employee of the United States and either act as such or, under that pretence, obtain anything of value. The maximum sentence is three years. It is adequate for the person who flashes a false badge, and adequate for whoever runs the IC3 scheme — assuming they are within reach of American jurisdiction, which offshore fraud infrastructure makes unlikely. What it does not reach is the production of the synthetic video, or any duty for the intermediaries distributing it.
The Federal Trade Commission's Government and Business Impersonation Rule, in force since 1 April 2024, is more modern. It prohibits fraudulent impersonation of government agencies and their officers, and lets the Commission seek monetary redress directly in federal court. When it finalised that rule the Commission simultaneously proposed extending the prohibition to impersonation of individuals, citing AI-generated deepfakes as a technology threatening to turbocharge impersonation fraud, and floated a provision imposing liability on parties supplying goods or services — including AI tools — with reason to know they would be used for unlawful impersonation. After an informal hearing in January 2025 the Commission indicated it would not proceed with that means-and-instrumentalities provision, and as of mid-2026 regulatory trackers record the extension to individuals as unfinalised. The proposal that would have reached the toolmakers is the one that was dropped.
Federal deepfake legislation exists but is narrow. The TAKE IT DOWN Act, signed on 19 May 2025, criminalises knowing publication of non-consensual intimate imagery including AI-generated digital forgeries, and requires covered platforms to remove reported material within 48 hours; platforms had until 19 May 2026 to build the process, and the FTC began enforcement that month. It is a real law with real teeth and nothing to say about a synthetic FBI official, because its subject is intimate imagery. The NO FAKES Act, which would create a federal property right in an individual's voice and visual likeness against unauthorised digital replicas, was advanced by the Senate Judiciary Committee on 18 June 2026 and is closer to enactment than in any previous session, but is still not law — and would primarily empower the depicted individual, here a serving federal official suing over a video that has already emptied someone's savings account. State law is dense but uneven: most states have enacted legislation addressing AI-generated media, roughly thirty have election-specific provisions, and every state has non-consensual intimate imagery protections, though many predate generative AI. The coverage is real; the coherence is not, and none of it binds a criminal operating from outside the country.
The European Union is about to attempt transparency at scale. Article 50 of the AI Act imposes obligations applying from 2 August 2026: deployers producing deepfakes — content resembling existing persons or events and falsely appearing authentic — must disclose it, and outputs of generative systems must be identifiable as artificially generated in machine-readable form. Under the Digital Omnibus agreement the general transparency duties bite on that date, while the machine-readable marking obligation is deferred to 2 December 2026 for systems already placed on the market before it. Infringements can attract penalties up to €15 million or 3 per cent of worldwide turnover. The gap is obvious. Criminals will not label their output, and the penalties are calibrated for corporate non-compliance rather than criminal enterprise. What Article 50 may achieve is a norm in which unmarked synthetic content becomes anomalous. That is worth something. It is not protection.
The Case for Restraint
There are decent arguments against every intervention above, and they deserve stating properly rather than as formality.
Criminalising synthetic impersonation of officials in broad terms would collide with the First Amendment. Depictions of government figures are core political speech, and satire, parody and criticism routinely involve putting words into the mouths of public officials. A statute drawn tightly enough to catch a fraudulent recovery-scam video, and loose enough to survive drafting by a legislature under pressure, is likely to catch protected expression too. Fraud-specific framing — requiring intent to deceive for financial gain — narrows the problem, but largely duplicates fraud statutes that already exist.
Platform liability rules carry a documented failure mode. Where a service faces penalties for content it fails to remove and none for content it removes wrongly, the rational response is aggressive removal, and the material caught in that net is disproportionately produced by people without resources to appeal. A 48-hour takedown obligation is defensible for a narrow category. Generalised to impersonation — which includes every parody account and every critical commentary adopting an institutional voice — it becomes something else.
Provenance and detection both invite over-reliance. If the public is trained to treat a content credential as proof of authenticity, the first successful credential-laundering technique produces harm greater than the tool prevented, because it exploits a trust the tool created. And a detection system right 95 per cent of the time tells five per cent of victims their genuine evidence is fake.
There is also a case that resources are better spent elsewhere. A randomised controlled trial by DeLiema, M. Daniel Brannock, Edward Preble and Langton, published in Innovation in Aging in 2024, tested mailed interventions with prior fraud victims. A single warning letter from the Postal Inspection Service reduced revictimisation by 8.6 per cent over four months; the same letter followed by five further mailings achieved a 22.4 per cent reduction. That is an unglamorous intervention delivered by post, and it protected a population no deepfake detector has ever helped. The cheapest thing demonstrably working is a letter.
Where the Cost of Vigilance Actually Lands
The advice at the end of the FBI's alert is sound, and worth reading for what it assumes. Type the address manually. Avoid sponsored search results. Verify the .gov. Do not trust social media profiles or messaging apps claiming to represent the IC3. Look for distorted hands and inaccurate shadows.
Every one of those instructions transfers a cost onto the person least able to bear it. The recipient has just lost money. They may be in their seventies. They may not know what a sponsored search result is, or why a domain suffix matters, or that ic3-gov.com and ic3.gov are not variants of the same thing. Asking them to perform forensic analysis on a video asks them to succeed where 99.9 per cent of iProov's participants failed.
There is a deeper incoherence in the advice, and it is nobody's fault. The IC3 says it will never contact you. But Operation Level Up exists precisely because the FBI does contact victims — proactively, by telephone, unsolicited — and 78 per cent of those it reached in 2025 had no idea they were being defrauded until the Bureau told them. The public is asked to hold two rules at once: an unsolicited approach from the FBI is a red flag, and an unsolicited approach from the FBI may be the intervention that saves your retirement. Distinguishing them requires exactly the institutional literacy this cohort has least of, and that the scheme is engineered to exploit.
That incoherence is the argument for shifting the burden. Not because individuals bear no responsibility, but because the current allocation is arithmetically absurd. On one side is a person defrauded once, in the worst week of their financial life, asked to authenticate synthetic video. On the other are entities that can act structurally: the platform that can require verification before an account claims to represent a federal agency; the registrar that can decline to sell ic3-gov.com; the agency that can establish a single cryptographically verifiable channel through which victims confirm a complaint's status; and the legislature that can extend a mid-century impersonation statute to the medium in which impersonation now happens, and finalise a rulemaking it began in 2024.
None of these is difficult in the way detecting deepfakes is difficult. They are difficult in the way assigning liability is always difficult, which is to say politically rather than technically. The IC3 scheme is not a story about the frontier of artificial intelligence; the tools involved are commodity products. It is a story about an institution whose credibility is its only real asset discovering that credibility is cheap to counterfeit and expensive to defend, and about a legal architecture that has not decided whose problem that is.
The scheme's designers have already answered the question. They decided it was the victim's problem, and built accordingly.

