Skip to main content

The Money Overview

The FBI warns a three-phase “Phantom Hacker” scam is draining seniors’ entire retirement savings

The FBI is warning that a scam it calls the “Phantom Hacker” is wiping out older Americans’ entire retirement and savings accounts by layering three impersonators into a single, patient con. The scheme has cost victims hundreds of millions of dollars, and roughly half of the people who report it are over 60 — a group that shoulders the majority of the losses. What makes it dangerous is not a technical break-in but a sequence of phone calls engineered to move a lifetime of savings into a criminal’s account while the victim believes they are protecting it.

How the three-phase Phantom Hacker sequence unfolds

The con opens with a tech-support impostor. A pop-up, text, email, or call warns that the victim’s computer has a problem, and a phone number connects them to someone posing as support from a familiar company. That person talks the victim into installing remote-access software, then claims to find evidence of hackers and asks the victim to log into their financial accounts to check for unauthorized charges — a step that quietly lets the scammer see which account holds the most money.

From there the roles multiply, according to the FBI’s Internet Crime Complaint Center. A second caller poses as the victim’s bank or brokerage, warns that foreign hackers have breached the accounts, and insists the only way to protect the money is to move it — by wire, cash, or cryptocurrency — to a “safe” account supposedly tied to a government agency. A third impostor may then pose as an official from the Federal Reserve or another agency, sometimes sending letters on fake government letterhead to keep the victim compliant.

The transfers are rarely a single event. Scammers often direct victims to send money in installments over days, weeks, or months, and they insist on secrecy — telling the victim not to explain the real reason to family members or bank tellers. That instruction is what allows the losses to swell into six figures before anyone with distance from the manipulation has a chance to intervene.


Free retirement updates: Scam calls targeting retirees change every week. The free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.

Why the impostors target retirement and brokerage accounts

The design is built to find the richest target. By having victims open their accounts during the first phase under the guise of a security check, the scammers learn whether a checking balance, a brokerage account, or a retirement fund holds the most, then steer the theft toward it. The FBI reported that Americans 60 and older lost a record $4.885 billion to fraud in 2024, with tech-support schemes among the costliest categories.

Retirement accounts carry an added sting. Draining an IRA or 401(k) can trigger taxes and early-withdrawal consequences on top of the stolen principal, and unlike a fraudulent credit-card charge, an authorized wire the victim was tricked into sending is far harder to reverse. Because the account holder initiated the transfer, the sending bank often cannot recover the funds once they land in an overseas account controlled by the fraud network.

The scheme is an evolution of older tech-support scams, and that lineage is part of why it works. Earlier versions simply charged victims for fake computer repairs; this one adds impersonated bank and government roles specifically to locate and empty the single most valuable account. By the time the second or third caller arrives, the victim has already been primed by a supposed security emergency to accept that drastic action, including moving their savings, is somehow necessary.

Cybersecurity specialists say artificial intelligence is making the impersonations more convincing, with cloned voices and polished scripts that blunt a victim’s skepticism. Reported losses from the scheme have topped $1 billion since 2024, and those same experts warn that the scam’s reliance on trust rather than technical intrusion is precisely what lets it slip past the security software people assume will protect them.

The one rule that breaks the scam

The scheme collapses on a single fact: no legitimate bank, brokerage, or government agency will ever ask a customer to move money to a “safe” account in order to protect it. The Federal Reserve does not hold personal protective accounts for citizens, and no real fraud department resolves a breach by having the account holder wire their balance somewhere else. Any call that ends with that instruction is, by its nature, the fraud.

The supporting rules follow from the same logic. Federal guidance urges people not to call a number in a pop-up or text, not to install software at a stranger’s request, and never to grant remote access to a computer. The government will not demand payment or transfers by wire to foreign accounts, cryptocurrency, or gift cards — the exact channels the Phantom Hacker depends on to move money it can never be forced to return.

For retirees, the practical defense is time. The scheme runs on isolation and urgency, so pausing to call the bank back at a number printed on a statement, or telling one trusted person before moving any money, dismantles it. The FBI asks victims to report the fraud through its complaint center, but recovery remains uncertain — which is why interrupting the sequence, rather than trying to undo it afterward, is where the savings are actually kept.

This article was produced with AI assistance and reviewed against primary sources by The Money Overview editorial team.

More Financial Reading


Plain-English help keeping more of your money in retirement. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.