The Federal Bureau of Investigation (FBI) has issued a critical warning about cybercriminals creating counterfeit versions of the Internet Crime Complaint Center (IC3) website to conduct phishing attacks and steal sensitive personal information. These fraudulent sites closely mimic the legitimate www.ic3.gov portal, replicating its content, layout, and visuals to deceive users into submitting personal data such as names, addresses, phone numbers, emails, and banking details.
Recent investigations have uncovered impostor domains like “ichelpindex.com,” which have been flagged as non-official and identified in security scans, including VirusTotal searches for “ic3.” These deceptive sites exploit the trust users place in the IC3, the FBI’s primary platform for reporting cybercrimes like fraud and scams. Victims often encounter these fake sites through search engines, sponsored links, or manipulated online forums where scammers pose as fellow victims, directing traffic to phony IC3 recovery services.
In some instances, fraudsters impersonate IC3 staff via messaging platforms like Telegram, promising fund recovery but instead extracting more data for account takeovers. The FBI has noted over 100 such impersonation reports between late 2023 and early 2025, with a significant surge in spoofed sites in 2025, prompting public service announcements in April and September of that year.
Identifying Fake IC3 Websites
Security researchers have observed that these phishing pages replicate the real site’s welcome message and complaint form but use altered domains with misspellings or non-.gov top-level domains. For example, legitimate IC3 websites end in .gov, while fake sites may use alternate spellings or TLDs like .com. Additionally, victims often access these fraudulent sites through search engines or sponsored ads, whereas the real IC3 site is typically accessed by typing the URL directly into the browser.
These fake sites may request personal or financial information under the guise of assisting with fund recovery, whereas the legitimate IC3 does not request payments for such services. Furthermore, the real IC3 does not maintain social media profiles, so any such profiles directing users to these sites are likely fraudulent. The graphics on these fake sites may also exhibit low-quality artifacts, in contrast to the professional U.S. government style of the authentic IC3 website.
The FBI urges the public to type www.ic3.gov directly into their browsers, avoid sponsored search results, and verify that the website ends in .gov. Users should never share sensitive data on unverified sites and report any suspicions only through the official portal. The IC3 maintains no social media presence and never requests payments for fund recovery. Recent FBI social media posts have reinforced these alerts amid rising complaints.
Public vigilance remains crucial as scammers continue to evolve their tactics, targeting prior scam victims seeking recourse. By adhering to direct navigation and maintaining a healthy skepticism, users can thwart these sophisticated phishing operations.
This development underscores the growing sophistication of cybercriminals who are now leveraging AI-generated deepfakes to create highly convincing fraudulent websites. As these technologies become more accessible, it is imperative for individuals and organizations to enhance their cybersecurity awareness and adopt proactive measures to protect against such deceptive practices.