Law enforcement recently conducted the largest ever coordinated sweep of identity fraud cases targeting the elderly. According to the U.S. Department of Justice, more than 250 defendants have been charged in the sweep, 200 of whom have been charged criminally.

Elders Fall Victim to Social Engineering Schemes

Some of these identity fraud campaigns included grandparent scams in which seniors were contacted and told that their grandchildren had been arrested and needed bail money. Other scams suggested that seniors had won the lottery but needed to pay a large fee to get the winnings, or that they owed back taxes to the Internal Revenue Service (IRS).

In total, the Justice Department reported that more than 1 million people collectively lost “hundreds of millions of dollars” through these scams.

While some identity fraud is conducted through traditional technologies such as the telephone, there are other methods. For example, romance scams involve an attacker befriending a senior online and then asking for money to visit the U.S., among other pretenses.

An expert from the American Association of Retired Persons (AARP) Foundation noted that technology makes life much easier for scammers, as reported by USA Today. While phone-based scams might ensnare one senior at a time, email and other online channels allow fraudsters to reach millions of potential victims at once.

Identity Fraud by the Numbers

According to the Federal Trade Commission (FTC)’s “Consumer Sentinel Network Data Book 2017,” identity fraud made up 14 percent of consumer complaints last year, second only to debt collection.

The FTC also showed that, while scams against the elderly are a concern, younger citizens are equally at risk: 40 percent of millennials in their 20s said they lost money to fraud, compared to 18 percent of those over 70. However, seniors tended to suffer higher median losses than other age groups, the report found.

Although credit card scams involving new or existing accounts were among the major identity fraud issues highlighted in the FTC’s data, it also referred to other modes of attack such as online shopping and payment account schemes, data theft via email and social media, and more.

More from

Emotional Blowback: Dealing With Post-Incident Stress

Cyberattacks are on the rise as adversaries find new ways of creating chaos and increasing profits. Attacks evolve constantly and often involve real-world consequences. The growing criminal Software-as-a-Service enterprise puts ready-made tools in the hands of threat actors who can use them against the software supply chain and other critical systems. And then there's the threat of nation-state attacks, with major incidents reported every month and no sign of them slowing. Amidst these growing concerns, cybersecurity professionals continue to report…

RansomExx Upgrades to Rust

IBM Security X-Force Threat Researchers have discovered a new variant of the RansomExx ransomware that has been rewritten in the Rust programming language, joining a growing trend of ransomware developers switching to the language. Malware written in Rust often benefits from lower AV detection rates (compared to those written in more common languages) and this may have been the primary reason to use the language. For example, the sample analyzed in this report was not detected as malicious in the…

Why Operational Technology Security Cannot Be Avoided

Operational technology (OT) includes any hardware and software that directly monitors and controls industrial equipment and all its assets, processes and events to detect or initiate a change. Yet despite occupying a critical role in a large number of essential industries, OT security is also uniquely vulnerable to attack. From power grids to nuclear plants, attacks on OT systems have caused devastating work interruptions and physical damage in industries across the globe. In fact, cyberattacks with OT targets have substantially…

Resilient Companies Have a Disaster Recovery Plan

Historically, disaster recovery (DR) planning focused on protection against unlikely events such as fires, floods and natural disasters. Some companies mistakenly view DR as an insurance policy for which the likelihood of a claim is low. With the current financial and economic pressures, cutting or underfunding DR planning is a tempting prospect for many organizations. That impulse could be costly. Unfortunately, many companies have adopted newer technology delivery models without DR in mind, such as Cloud Infrastructure-as-a-Service (IaaS), Software-as-a-Service (SaaS)…