The FBI's Internet Crime Complaint Center issued a September 17 warning about scammers impersonating law-enforcement and government officials to pressure people into sending money or personal information. The alert is aimed at the public, but the business lesson is hard to miss: when a request sounds official, urgent, and scary, the verification process matters more than the caller's confidence.
IC3 said it received nearly 61,000 complaints about law-enforcement or government impersonation scams from January 2025 through July 2026, with reported losses above $1.6 billion. The FBI described scammers using spoofed phone numbers, email addresses, employee names, and credentials tied to known agencies. Some use aggressive scripts, keep victims on the phone, demand secrecy, and push payments by bank wire, cryptocurrency, prepaid cards, couriers, or cash inserted into cryptocurrency kiosks.
Why This Belongs on the Owner's Desk
For a New Jersey business, this is not only a consumer scam story. It is an approval-control story. A call about a license, subpoena, court matter, tax issue, employee record, patient file, customer account, or investigation can land with a receptionist, office manager, billing employee, practice administrator, or owner. If the process depends on one person deciding whether the caller sounds legitimate, the business is leaving too much to adrenaline.
The FBI specifically noted that scammers may tailor the approach to certain victims, including medical practitioners. A practice owner or administrator who hears that a professional license is at risk may feel immediate pressure to comply. That is the point. The scam works by making normal verification feel risky, rude, or too slow.
The Control Is Verification, Not Suspicion
The practical decision is not to distrust every official contact. It is to define how the business verifies one before money, personally identifiable information, credentials, documents, or customer records leave the building. The rule can be simple: official-sounding demands get paused, documented, and independently verified through known public channels.
That means employees should not use the phone number, email address, payment link, video-call identity, or website supplied by the person making the demand. The FBI warns that scammers may use URLs that closely resemble official domains, including incorrect domain endings. The safer process is to look up the agency through a known official source, call a published number, and route the issue through the manager or owner assigned to handle legal, compliance, banking, or licensing matters.
One detail deserves extra attention: IC3 said scammers are using newer technologies, including artificial intelligence, to make impersonation schemes look more legitimate on video calls. That does not mean every video call is fake. It does mean a face on a screen is no longer enough evidence by itself. Video can support a conversation, but it should not replace an independent callback, a written record, and a second-person approval for sensitive action.
Questions To Ask Your IT Provider Or Internal Team
- Where do official requests go first? Decide who receives, records, and escalates legal, government, licensing, law-enforcement, court, banking, and tax-related requests.
- What requires a second approval? Payments, credential resets, customer data exports, employee records, patient information, and vendor banking changes should not depend on one person's judgment.
- Can staff see the real sender and domain? Email systems should make full addresses visible, especially on mobile devices where impersonation is easier to miss.
- How are suspicious contacts documented? Keep the caller ID, email headers, messages, payment instructions, cryptocurrency wallet details, URLs, and any names used.
- Who contacts the bank or insurer if money moves? IC3's BEC guidance emphasizes fast contact with the originating financial institution when fraud is recognized.
A Practical Next Step
Pick one workflow this week: government, court, licensing, tax, or law-enforcement requests. Write the internal rule in plain language. For example: no payment, data release, credential change, or private document sharing happens until the request is independently verified through an official public channel and approved by a second responsible person.
Then make sure the rule is not buried in a policy folder nobody opens. Put it where front-desk staff, billing, finance, HR, and managers will actually see it. A five-minute escalation path is much cheaper than a five-figure wire recall, a privacy incident, or a frantic license scare. Scammers are counting on pressure to do the work. Your process should make pressure less persuasive.
Sources and further reading