The US Federal Bureau of Investigation has warned that fraudsters are impersonating its agents on social media in a bid to prey on individuals who have already fallen victim to crime. The FBI's Internet Crime Complaint Center (IC3) said any account claiming to represent the bureau on platforms such as Facebook, X or Instagram is fake.
According to the IC3, the scammers contact victims of previous frauds, often claiming they can help recover lost funds or secure compensation. In reality, the criminals seek to extract further payments or sensitive personal information under the guise of official assistance. The IC3 stressed that legitimate FBI agents never initiate contact via social media to demand money or request personal data.
While the alert specifically addresses US victims, cybersecurity experts in the UK say the same tactics could easily be adapted to target British citizens. Jake Moore, a former police cybercrime advisor now at ESET, commented: 'Impersonating law enforcement is a particularly cruel twist on social engineering. Victims are already vulnerable, and the authority of an FBI badge — even a fake one — can override their natural scepticism.'
The UK's National Cyber Security Centre (NCSC) has previously warned about 'CEO fraud' and impersonation scams, but the FBI case highlights a growing trend of criminals using social media to pose as official bodies. The UK Information Commissioner's Office (ICO) advises the public to verify any unsolicited contact claiming to be from a law enforcement agency by calling the organisation directly using a known phone number.
For UK businesses, the implications extend beyond individual victims. Companies that handle sensitive customer data could see reputational damage if fraudsters leverage stolen information to make their impersonation more convincing. Under the UK's Data Protection Act 2018, firms have a duty to report breaches that pose a risk to individuals, and the ICO can issue fines of up to £17.5 million or 4 per cent of global turnover for serious failings.
The EU's AI Act, which came into full force in August 2024, also has indirect relevance here. Social media platforms use AI-driven algorithms to recommend content and detect fraudulent accounts. The Act requires high-risk AI systems — including those used in content moderation — to be transparent and subject to human oversight. If platforms fail to catch impersonation accounts, they could face regulatory scrutiny under both the EU framework and the UK's Online Safety Act, which imposes a duty of care on tech firms to protect users from fraudulent content.