The digital landscape has become an increasingly hostile environment for older adults, with elder fraud emerging as one of the most pressing cybersecurity and social issues in the United States. As technology continues to weave itself into the fabric of daily life, those who are less familiar with its nuances—specifically the senior demographic—are being disproportionately targeted by sophisticated criminal networks. Recent analysis of data provided by the Federal Bureau of Investigation (FBI) paints a grim picture of this trend: in 2024 alone, personal data exposed online served as the catalyst for 72% of all elder fraud cases, resulting in a staggering $4.2 billion in financial losses for victims.
This surge in criminal activity is not merely the result of random phishing attempts; it is a calculated industry fueled by the commodification of personal information. Scammers are moving away from broad, generic messaging and toward hyper-personalized attacks that exploit the trust and social structures of families. The scale of these losses highlights a critical vulnerability in how we manage our digital footprints, particularly when that footprint inadvertently exposes our most vulnerable loved ones to exploitation.
The Mechanics of Modern Deception
To understand why these scams are so effective, one must look at how digital information is harvested and weaponized. Family chat groups, which are now standard for coordinating everything from medical appointments to travel itineraries, have become a goldmine for bad actors. When family members share seemingly mundane details—such as the date of an upcoming surgery or the location of a vacation—they are inadvertently building a profile that a scammer can exploit. By monitoring these channels, criminals gain the context necessary to impersonate family members with alarming accuracy.
A common misconception is that end-to-end encryption—a feature found in popular platforms like iMessage and WhatsApp—provides a total shield against such threats. While encryption protects the contents of a message from interception while in transit, it does not prevent a bad actor from gaining access to the accounts themselves. This is where the practice of "SIM swapping" becomes a devastatingly effective tool in the fraudster’s arsenal.

SIM swapping is a form of account takeover that relies on social engineering rather than technical hacking. Once a scammer has gathered enough personal details from public records or social media to verify a target’s identity, they contact the victim’s mobile carrier. Posing as the account holder, they claim that their phone has been lost or damaged and request that the service be transferred to a new SIM card under their control. If the carrier’s support representative is successfully deceived, the victim’s phone service is cut off, and the scammer begins receiving all incoming texts and calls.
The consequences of a successful SIM swap are profound. Because many security systems rely on SMS-based two-factor authentication (2FA) to verify identity, the scammer can use these intercepted codes to reset passwords and gain unauthorized access to bank accounts, email portals, and, critically, those private family messaging groups. Once inside, the scammer possesses the perfect disguise. Armed with both the historical context from the chat and the ability to intercept incoming messages, they can orchestrate elaborate ruses, convincing family members that they are in urgent need of financial assistance.
The sophistication of these attacks has reached a new level with the integration of artificial intelligence. By utilizing voice notes shared within family chats, scammers can now employ deepfake audio technology to mimic the voice of a relative. A victim, receiving a call that sounds exactly like their child or grandchild and is supported by "insider" knowledge about their life, is far more likely to bypass their natural skepticism and provide the requested funds or sensitive information.
Protecting Vulnerable Populations in a Connected World
Addressing the epidemic of elder fraud requires a multifaceted approach to digital hygiene. The first line of defense is the systematic reduction of the personal information available to bad actors. Data broker sites, which aggregate and sell information ranging from home addresses and phone numbers to hobbies and travel history, are the primary resource for scammers looking to build their target profiles. Because there are hundreds of these brokers operating simultaneously, manually scrubbing one’s information from the internet is a nearly impossible task for the average individual. Services like Incogni have emerged as a necessary solution, automating the removal of personal data from these databases to limit the raw material available to criminals.

The second pillar of protection is the widespread adoption of robust security practices, specifically regarding two-factor authentication. While SMS-based 2FA is better than having no protection at all, it is highly susceptible to the SIM-swap attacks described above. Experts strongly advise transitioning to dedicated authenticator apps or hardware security keys whenever possible. These methods ensure that the authentication process is tied to a specific physical device rather than a phone number that can be hijacked via a mobile carrier. If a service offers the choice between a text message code and an authenticator app, the app should always be the preferred option.
Beyond technical safeguards, the most effective defense remains human verification. In an era where digital communication can be easily spoofed, the "out-of-band" verification method is vital. If a family member receives a suspicious text message claiming to be a relative in trouble, they should immediately attempt to contact that person through a different, established channel. If the message came via text, reply with an email; if it came via email, place a direct phone call. By forcing the interaction onto a different communication medium, the scammer’s ability to maintain the illusion is significantly diminished.
Finally, families are increasingly turning to the use of a "secret family password." This is a pre-agreed phrase that is known only to trusted family members and is never shared via text, email, or social media. In the event of a high-pressure, emergency-style phone call, the recipient can ask the caller to provide the password. Even if the scammer has access to the victim’s phone, has simulated their voice using AI, and has read their previous messages, they will not know the secret password. This simple, low-tech protocol serves as an essential fail-safe, providing a final layer of security that effectively stops most impersonation attempts in their tracks.
As these threats evolve, the importance of maintaining a vigilant and informed approach to online safety cannot be overstated. By minimizing digital exposure, upgrading authentication methods, and establishing clear protocols for identity verification, families can significantly lower the risk of falling victim to the multi-billion dollar elder fraud industry.

For readers looking to take proactive steps in securing their digital presence, Incogni is currently offering a 55% discount on subscriptions for 9to5Mac readers who use the checkout code 9TO5MAC. While digital tools can help clean up one’s footprint, the combination of technological awareness and family communication remains the most potent weapon against the rising threat of digital fraud.

