The $1.4 Billion Scam That Impersonates the FBI

    Subscribe to our newsletter

    By submitting this form, you agree to the Allure Security privacy policy.

    Share Article

    When cryptocurrency fraud victims seek help, the next call they receive may be from someone pretending to be the people who are supposed to protect them.

    In January 2024, the FBI launched Operation Level Up, a program designed to identify Americans falling victim to cryptocurrency investment fraud and contact them before they lost more money. Agents would call or email, explain the scheme, and walk the victim through filing a report. By 2025, the operation had notified more than 8,000 victims and helped prevent an estimated $500 million in additional losses.

    The operation’s success created a problem the FBI apparently anticipated but could not prevent. The Operation Level Up page on FBI.gov now carries a warning that reads like a dispatch from the other side of the impersonation problem: “It is common for fraudsters to impersonate FBI employees or other government officials and pretend to represent legitimate operations such as Operation Level Up.”

    The FBI built a program to protect victims. Attackers began impersonating the program itself.

    How recovery scams work

    According to the FBI, “almost all victims, after they lost their money, are contacted by scammers conducting recovery fraud schemes.” The targeting is not random. It relies on breach data, complaint records, and in some cases direct knowledge of the original scam, meaning the recovery fraudsters know exactly who lost money, approximately how much, and which scheme was involved.

    The contact arrives through social media, email, or a professional-looking website, and the person on the other end claims to represent a law firm, a government agency, or a recovery service with authorization to investigate the case. A January 2026 FBI public service announcement described the current variant in detail: fictitious law firms producing documents with legitimate firm insignia and letterheads, claiming affiliation with the FBI, the Consumer Financial Protection Bureau, and other government entities, and referencing real financial institutions to build credibility.

    What separates recovery scams from most brand impersonation campaigns is the precision of the targeting. A typical phishing campaign casts a wide net, hoping a percentage of recipients will trust the spoofed identity enough to act. Recovery scams target a pre-qualified list of individuals who have already demonstrated vulnerability to trust-based manipulation, and they impersonate the specific institutions those individuals would turn to for help. The FBI’s own January 2026 advisory described the approach as one that combines “targeting vulnerable populations, particularly the elderly; exploiting victims’ emotional state and financial need to recover funds from a previous scam; and giving victims the sense of safety and security by impersonating or falsely affiliating themselves with multiple government entities.”

    The victim, already looking for any path to recovering what they lost, is asked to pay fees, taxes, or processing costs to unlock the recovery. The money goes to the same criminal ecosystem that took it the first time. The IC3 gathered more than 10,500 complaints about recovery scams in 2025, with estimated losses totaling $1.4 billion.

    Who bears the cost

    The demographic pattern is stark. Americans aged 60 and older filed 2,529 recovery scam complaints in 2025 and reported more than $540 million in losses, leading all age groups by a wide margin. The FBI’s own case notes describe one elderly victim surviving on disability payments who had already sent scammers $1,200 and was prepared to cut into money he needed for food to continue paying.

    This is also the demographic most likely to hold significant assets at traditional financial institutions, and the downstream consequences extend well beyond the crypto ecosystem where the fraud originates. A retiree who loses savings to a crypto investment scam and then loses more to a recovery scam impersonating the FBI is a credit union member whose financial life has been destabilized by a chain of fraud that their institution never saw, because the attacks occurred in ecosystems the institution does not monitor.

    The personal information harvested through these schemes does not stay in those ecosystems either. The dark web credential economy does not separate crypto credentials from banking credentials, and the data collected through recovery scams, including names, addresses, financial account details, and behavioral patterns, can fuel account takeover attempts and social engineering campaigns against whatever other accounts the victim holds. The fraud that started with a fake investment platform and continued with a fake FBI agent can eventually arrive at the institution where the victim’s checking account lives.

    The FBI’s response to recovery scams has escalated in parallel with the threat. Three public service announcements since August 2023, each more detailed than the last, reflect an agency adapting its guidance in real time. The January 2026 advisory went so far as to recommend a “zero trust” posture for anyone claiming to offer recovery services. But advisories, however detailed, face the same structural limitation as any awareness-based defense: they depend on the victim recognizing the impersonation before trusting it. The fraud works precisely because the victim has every reason to believe the person on the other end is who they claim to be.

    The Bottom Line

    Recovery scams generated $1.4 billion in losses in 2025 by borrowing the credibility of the institutions that fraud victims trust most. The FBI’s own victim outreach program became a brand that attackers impersonated, which says something about both the scale of the problem and the limits of any response that does not include protecting the brand itself. Any institution whose name carries authority in a crisis, whether a law enforcement agency, a financial regulator, or a bank, is a candidate for the same exploitation.

    Key Takeaways

    What is a recovery scam?

    A recovery scam occurs when fraudsters impersonate law firms, government agencies, or law enforcement to contact individuals who have already lost money to fraud, claiming to be able to recover their lost funds in exchange for fees. The FBI reported more than 10,500 recovery scam complaints and $1.4 billion in losses in 2025.

    How do recovery scams use brand impersonation?

    Scammers produce documents with legitimate law firm letterheads, claim affiliation with the FBI or Consumer Financial Protection Bureau, and reference real financial institutions to build credibility. The FBI has warned that attackers are impersonating its own Operation Level Up program, which was created specifically to help fraud victims.

    Who is most affected by recovery scams?

    Americans aged 60 and older filed 2,529 recovery scam complaints in 2025 with more than $540 million in losses, leading all age groups. This demographic also holds the largest share of assets at traditional financial institutions, creating downstream risk for banks and credit unions.

    Why should financial institutions care about recovery scams?

    The personal and financial information harvested through recovery scams can fuel account takeover attempts and social engineering campaigns against whatever other accounts the victim holds. A member destabilized by sequential fraud in ecosystems the institution does not monitor still appears at the institution’s door when the damage reaches their primary accounts.

    How are recovery scams related to broader brand impersonation threats?

    Recovery scams apply the same mechanism as phishing sites, fake storefronts, and impersonated customer support accounts: borrowing the credibility of a trusted institution to manipulate the target. The difference is the precision of the targeting, using pre-qualified lists of vulnerable individuals and impersonating the specific organizations those individuals would turn to for help.

    See the threats targeting your brand right now

    Get a customized assessment showing active impersonation, phishing infrastructure, and exposed credentials specific to your organization. No commitment required.