Introduction
A phone call from someone claiming to be your bank can feel convincing, especially when the caller knows your last name and the last four digits of your account number, and insists your account needs immediate action.
To “verify” you, they ask for your KYC details and the one-time password (OTP) sent to your phone.
It feels routine because we’re used to receiving calls from our banks. It isn’t. No legitimate bank representative asks for a one-time password over the phone, and no customer should ever share one with an unsolicited caller.
This is a fraud call, and by the time it ends, the account may already be compromised.
Today, scammers rely on tools that make impersonation harder to detect: fake caller IDs, AI‑generated voice clones, or fake login pages.
The FBI Internet Crime Complaint Center (IC3) reported 201,266 complaints from individuals aged 60 and older in 2025, totaling approximately $7.7 billion in losses.
This made elders the age group with the highest number of complaints and the highest financial losses in the United States.
The Scale of the Problem
The rise of elder fraud reflects a broader shift in cyber-enabled crime. Criminals increasingly combine social engineering, impersonation, cryptocurrency scams, and tech-support fraud to exploit seniors who may have significant savings, retirement funds, and home equity.
Source: FBI IC3 2025 Elder Fraud Report
Why Elders are Targeted
Cybercriminals often view elders as attractive targets because they may:
- Maintain larger financial reserves
- Own their homes outright
- Be less familiar with evolving digital fraud tactics
- Be more likely to trust authority figures, such as government officials or bank representatives
- Respond urgently to requests involving family, healthcare, or financial security
The report also highlights the growing use of AI-generated voices, messages, and fake identities in confidence and distress scams, making fraudulent communications harder to detect. Scammers increasingly rely on tools that make impersonation harder to detect: fake caller IDs, AI-generated voice clones, and convincing fake login pages.
How the Scam Reaches the Contact Center
Three patterns show up most often, and all three eventually reach a live phone call:
Investment fraud
Victims are approached through text messages, social media, or dating apps and directed to professional-looking trading platforms displaying fabricated profits. When they attempt to withdraw funds, they’re asked to pay additional taxes or fees first, and cryptocurrency is now the preferred payment method for this scheme: IC3 recorded $11.37 billion in crypto-related losses across all age groups in 2025, with investment fraud accounting for more than $7.2 billion of it.
Government Impersonation
Criminals claim to represent agencies such as the Social Security Administration, law enforcement, or healthcare providers, pressuring victims to transfer money to avoid arrest, penalties, or account suspension.
Tech support fraud
Fake pop-up warnings or phone calls convince victims that their computers are infected. Scammers then gain remote access, steal financial information, or instruct victims to move money into scammer-controlled accounts.
| Download Case Study: How A Leading US Bank Cuts Fraud Losses & AHT by 20% With Pindrop and NovelVox Agent Accelerator |
The Attack Doesn’t End When the Phone Rings
Every one of these schemes eventually funnels into the same moment: a live phone call, in which a criminal or a coached victim is talking to a real person at a real institution.
Social engineering succeeds in that moment for a simple reason: the agent on the other end has seconds to verify who’s calling, retrieve the right context, follow policy, and decide what to do next, often while switching between systems that weren’t built to talk to each other. That’s the point where fraud prevention either holds or doesn’t.
FBI’s Recovery Efforts
In 2025, the FBI’s recovery team handled 642 elder-related Financial Fraud Kill Chain (FFKC) incidents.
The top elder fraud categories were Tech Support/Account Takeover (360 incidents), followed by Business Email Compromise (104 incidents) and Investment/Crypto scams (64 incidents).
Verification Alone Isn’t Enough
Confirming who’s calling isn’t the same as deciding what that caller should be allowed to do. Those are two different questions, answered by two different controls:
- Authenticate: Is this person who they claim to be?
- Validate: Does the information they’ve provided check out against what the institution has on file?
- Authorize: Is this specific caller permitted to take this specific action, right now?
- Execute: Only once all three are satisfied does the workflow allow the action to proceed.
A caller who correctly answers a security question isn’t automatically authorized to move funds, reset a login, or close an account. The institution still has to control what happens after someone is verified.
| Also Read: Multi-Agent Banking Won’t Survive 2026 Without an Execution Layer |
For SI and CCaaS Partners
- For SI and CCaaS partners building on financial-services deployments, caller verification isn’t a feature request that shows up once. It’s a recurring requirement across nearly every banking and credit union engagement.
- Agent Accelerator’s verification workflows are configurable to each institution’s own policy, not a fixed script, which means the same underlying capability can support different verification standards across different customers without custom-building the logic each time.
- NovelVox has supported this kind of deployment work for 17+ years, with CMMi Level 3 certification and 1,000+ installations across 250+ customers.
How Financial Institutions Can Strengthen Caller Verification
Financial institutions need a way to ensure the authenticate-validate-authorize-execute sequence occurs consistently on every call, regardless of which agent picks up. That’s a workflow problem before it’s a security problem: it’s where Agent Accelerator fits in.
With Agent Accelerator, agents can:
What Elders Can Do About It
A few habits make the difference between falling for this call and hanging up on it:
- Verify independently: Hang up and call the institution directly using a number you already trust, not one provided by the caller.
- Never send cryptocurrency to strangers: Legitimate agencies and institutions do not request payment in cryptocurrency.
- Talk to family or a trusted advisor before investing: A second opinion can help prevent rushed or emotional decisions.
- Enable account alerts: Most banks can notify you of unusual account activity in real time.
- Report quickly: Contact your bank immediately and file a complaint with the IC3.
Conclusion
The call at the start of this article didn’t fail because a bank lacked security. It worked because, for a few seconds, a real agent had to decide, unaided, whether to trust a stranger on the phone.
That’s the moment fraud prevention actually happens, not in a warning email sent after the fact, and not in a policy document nobody has time to consult mid-call.
Agent Accelerator doesn’t ask agents to remember every verification step, search across systems, or make that judgment call alone. It gives them a consistent, guided path from authentication through execution, on every call, every time.
For financial institutions facing a multibillion-dollar problem with no sign of slowing down, that consistency is the control that matters.