Skip to main content

Morning Overview

The FBI says ‘phantom hacker’ scams are quietly draining retirement accounts

Federal investigators have spent the past two years tracking a patient, layered fraud they call the “phantom hacker” scam, a con that empties bank, brokerage and retirement accounts one wire at a time. Unlike a stolen-card charge, the scheme unfolds over days or weeks and leans on a single manipulation: convincing the account holder that the only way to protect their savings is to move it themselves. The Federal Bureau of Investigation has flagged older adults as the primary targets, because they tend to hold the largest lifetime balances and are most likely to answer an unexpected phone call.

The three imposters who take turns on the phone

The scheme runs like a relay. In the first stage a caller or pop-up warning poses as tech support from a well-known company, claiming the victim’s computer has been hacked or infected. Once granted remote access, the “technician” pretends to run a security scan and reports that bank or investment accounts are under attack. The Internet Crime Complaint Center describes how the case is then handed off to a second actor impersonating the fraud department of the victim’s own bank or brokerage, who confirms the fake breach and offers to help. A third caller, posing as a federal official, arrives to add authority and urgency. Each layer reinforces the last, so a skeptical target who might hang up on one stranger is worn down by what looks like coordinated help from a company, a bank and the government.

Why retirement and brokerage balances are the prize

Investigators note that the phantom hacker scheme is engineered to reach the accounts most people never touch on impulse. Everyday checking balances are small; the real money sits in individual retirement accounts, 401(k) rollovers and taxable brokerage holdings built over decades. Because those accounts often require a phone call or a wire to move large sums, the scammers do not need to steal a password at all. They simply guide the owner through the withdrawal, framing each step as a defensive move. The general fraud guidance the bureau publishes through its scams and safety resources stresses that a legitimate institution will never ask a customer to move money to keep it safe, yet that instruction is exactly what makes this con effective against people who assume a caller from “the fraud department” is on their side.

The ‘safe account’ lie at the center of the con

The pivot that turns a suspicious phone call into a drained account is the promise of a protected destination. The government imposter tells the victim their money is compromised and must be transferred to a new “alias” or “safe” account, often described as being held by the Federal Reserve or another agency for safekeeping. In reality the destination is controlled by the criminals, frequently overseas, and the funds move by wire transfer, cryptocurrency or even cash handed to a courier. Victims are usually coached to keep the matter secret, warned that bank tellers or family members cannot be trusted because the “investigation” is confidential. That secrecy instruction is a hallmark of the scheme and a reason losses can climb into the hundreds of thousands of dollars before anyone else notices.

Losses that land hardest on older savers

Elder-fraud figures compiled by the bureau consistently show that people over 60 report the steepest total losses to online crime, driven in large part by tech-support and government-imposter schemes like this one. The damage is amplified because retirement money, once withdrawn and wired abroad, is rarely recoverable, and because a single victim can lose an entire nest egg rather than a capped card balance. The Federal Trade Commission’s consumer guidance makes the same point from the prevention side: imposters succeed by combining a fake emergency with pressure to act immediately and alone, and the antidote is to slow the interaction down and verify through a separately obtained phone number.

The warning signs and the response

Fraud investigators describe a consistent set of red flags. An unsolicited message claiming a device is hacked, a request for remote access, a caller who transfers the conversation to a “bank” or “government” official, and any instruction to move money to protect it are each grounds to disconnect. Officials advise that no federal agency will call to demand a wire transfer, request payment in gift cards or cryptocurrency, or ask anyone to convert savings into cash or gold for a courier to collect. Anyone who has already granted remote access is urged to disconnect the device from the internet, run a security scan, contact the real bank using the number printed on a statement, and report the incident to the Internet Crime Complaint Center. Family members are encouraged to talk openly with older relatives about the pattern, since the scheme relies on isolation and secrecy to work. Reporting matters even after money is gone, because rapid notification occasionally lets banks recall a domestic wire, and every complaint feeds the data investigators use to trace the networks behind the calls.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview