Morning Overview

The FBI warns ‘phantom hacker’ scams are quietly draining older Americans’ life savings

A layered fraud that federal investigators call the “phantom hacker” scam has proven unusually effective at emptying the retirement and savings accounts of older Americans. Unlike a single deceptive phone call, it unfolds in stages, with a rotating cast of impostors who pose as tech-support agents, then bank officials, then government employees, each building on the fear planted by the last. The result is a scheme engineered to march a victim, step by careful step, toward wiring their own money to criminals.

The FBI has flagged the tactic as a growing threat because of who it targets and how much it takes. Older adults often hold larger balances in savings and retirement accounts, and the scam is designed to reach those accounts directly rather than to skim small amounts. Victims frequently lose sums that represent years or decades of accumulated savings, and the deliberate, multi-actor structure is what makes it so damaging.

How the three-phase scheme unfolds

The scam typically begins with a message that appears to come from a technology company, warning that a computer has been compromised. This first impostor, playing a tech-support representative, persuades the target to grant remote access to the machine or to install software, ostensibly to fix the problem. What that access actually provides is a foothold and a pretext, along with a look at the victim’s financial accounts.

In the second phase, a different caller poses as a representative of the victim’s bank or a financial institution, claiming that the account is under threat from foreign hackers and that the money must be moved to keep it safe. The third phase introduces someone impersonating a government official, often invoking a federal agency, who reinforces the story and directs the victim to transfer funds to a supposedly protected account. The FBI’s Internet Crime Complaint Center, reachable through its public reporting portal, has been the channel through which many of these losses are documented.

Why the layered approach works

The power of the scheme lies in its choreography. Each new impersonator lends the previous claim more credibility, so that by the time a government-sounding official calls, the victim has already been primed by two earlier warnings. The consistency across the three voices makes the fabricated crisis feel verified from multiple independent directions, when in reality it is a single coordinated operation.

The scam also inverts the victim’s instinct to seek help. A person alarmed by a hacking warning naturally wants to protect their money, and the fraudsters position themselves as the protectors. Instead of resisting a threat, the victim believes they are cooperating with the very people trying to keep their savings secure. That reframing is what allows the criminals to persuade someone to authorize large transfers with their own hands.

The signatures that give it away

Several features recur across cases and serve as warning signs. Legitimate financial institutions and government agencies do not call to say that an account must be emptied and the money wired elsewhere to keep it safe; that instruction, however urgent it sounds, is a hallmark of fraud. Requests to move funds to a “safe” or “protected” account, to buy assets on the caller’s instruction, or to keep the matter secret from family and bank staff all point in the same direction.

The insistence on secrecy is particularly telling. Scammers press victims not to discuss the situation with relatives or even with bank employees who might question a large withdrawal, because outside scrutiny is the fastest way to unravel the story. A demand for confidentiality around a financial emergency is not a sign of security; it is a sign that someone does not want the claim examined.

Why older adults are the focus

The scheme concentrates on older Americans for practical reasons. This group is more likely to hold substantial balances in savings and retirement accounts, which raises the payoff of a successful attack. Isolation can play a role as well, since a victim without someone nearby to consult is easier to steer through the multi-stage sequence without interruption.

The emotional toll extends beyond the financial loss. Because victims actively participate in the transfers, believing they are doing the responsible thing, the aftermath often carries a heavy sense of self-blame. That dynamic can discourage reporting, which in turn makes the true scale of the problem harder to measure and the criminals harder to disrupt.

Breaking the chain before the transfer

The most reliable defense is to treat any unsolicited contact about a compromised computer or endangered account with deep suspicion and to refuse to grant remote access to a device. Verifying independently, by hanging up and calling the institution back using a number from an official statement or the back of a bank card rather than one provided by the caller, exposes almost every version of the scam. No genuine agency or bank will object to that step.

Talking to a trusted family member or a bank employee in person before moving any money reintroduces exactly the outside perspective the fraudsters work to eliminate. Reporting suspected fraud to the FBI’s Internet Crime Complaint Center, and to local law enforcement, both documents the crime and feeds the data that investigators use to track and pursue these networks.

The phantom hacker scam succeeds by making victims feel they are protecting themselves while doing the opposite. Recognizing that the instruction to move money for safety is itself the fraud, and pausing to verify through a known, independent channel, is the single most effective way to stop the sequence before the savings are gone.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview