Explainer

Fraud victims over 60 keep asking the same question: "How did they get my new card number?"

The FBI says seniors lost $7.7 billion to online crime last year. Most of it started with something they couldn't read.

mBy a minrims co-founderUpdated Sept 18, 2026 · ✓ Fact checked · About this page

Last year Americans over 60 filed 201,266 complaints with the FBI's Internet Crime Complaint Center and reported $7.7 billion in losses. That's up 59% in a single year. The average victim lost $38,500. And a huge share of it started the same way: an email or text on a phone, a name that looked right, and an address nobody checked.

Readers that stay on your phone, so you can actually read the sender line →

201,266
complaints to the FBI from Americans over 60 in 2025
$7.7B
reported losses for that age group, up 59% year over year
$38,500
average loss per victim over 60

The phone is the weak point

Phone mail apps show the sender's display name and hide the address behind it. You can set the name to anything. The address is where the lie is, and on a phone it's one tap and one squint away, in gray, at nine points.

In 2022 a team of researchers watched people sort the same phishing emails on a desktop and then on a phone. Accuracy fell from 84% on the desktop to 74% on the phone. The reason wasn't that people got dumber on a small screen. It was that the address was hidden by default, most participants never expanded it, and you can't hover over a link on a phone to see where it goes. The cues that give a fake away are the ones the phone hides.

9:41●●●●
Inbox
U
Tuesday
To:

Your December statement is ready to view

January 13, 2026 at 7:52 AM

Hi ,

Your statement for the period ending 12/31/2025 is now available. For your security, statements can be viewed online for 30 days.

View my statement

If you did not request this statement, no action is needed.

Please do not reply to this message. This mailbox is not monitored. Member FDIC. Equal Housing Lender.

1
The name. Looks right. Anyone can type a display name.
2
The address. Ten-point gray under the name. Not the bank. You have to tap to see it.
3
The button. Goes to a copy of the login page. Type your password there and it's theirs.
A reconstruction, sender and recipient blurred. The display name says one thing, the address says another, and the attachment isn't a PDF. All three are small print.

Why older eyes make it worse

Presbyopia, the normal loss of near focus, affects an estimated 128 million Americans and nearly 90% of adults over 45. Without readers, nine-point gray text on a phone isn't hard to read. It's unreadable. A 2022 review in Frontiers in Psychology found small font sizes cause visual fatigue fastest in older adults and recommended 10.5 to 17 point text on phones for people in their late fifties through seventies. Nobody's mail app does that for the sender address.

Then there's the study nobody over 60 wants to hear about. In 2024, researchers at the University of Florida and the University of Arizona put 182 people between 18 and 90 through 60 simulated phishing emails in their real inboxes over 30 days. The ability to spot a phish declined steadily with age. Their line: "The older you are, the higher the risk." Not because older people are careless. Because the tells are small, and small is the problem.

How they keep getting the new card

This is the part victims describe as the crazy-making part. A charge shows up. They call the bank. The bank cancels the card and mails a new one. Two weeks later there's a charge on the new card. And the next one.

There are two common answers. The first is on the victim's own device: a keylogger or infostealer that came in through an attachment or a fake "update" and now copies every login, including the one used to check the new card. Cancelling the card doesn't help when the thief is reading over your shoulder.

The second answer is the bank itself. In July, federal prosecutors in New York charged a ring that included a former bank employee. They posed as customers by phone and in person, requested replacement debit cards, and intercepted them in the mail. More than $1.6 million. The customers did everything right. The new cards never reached them.

When it moves from your screen to a bank branch

The screen is where it starts. It rarely stays there. Once someone has your login, your card, and enough of your details, the endgame is a teller window.

This month a Minnesota man was charged with walking into two US Bank branches with a forged photo ID and withdrawing $12,760 from a Missouri man's accounts. He admitted, according to the charging documents, to being part of an organized, multi-state bank fraud scheme. In Massachusetts, a bank insider fed customer data to a ring that printed fake IDs with real customer names and walked out with cashier's checks for two years. More than $1.1 million. In Daly City, California, an 86-year-old woman named Joann had her phone number ported without her authorization, her contact information changed, and $25,000 wired out before anyone caught it.

The FBI put out a public warning last November about account takeovers that begin with someone impersonating the bank's support line: more than 5,100 complaints and $262 million in losses since January 2025. The line worth remembering from that warning: "MFA will not protect you if you land on a fraudulent login page."

One family's version

My dad is retired, sharp, reads two newspapers a day. This past winter he opened an email on his phone that looked like it came from his bank. Your statement is ready. He tapped the button and typed his password into a page that wasn't the bank's. A few days later a second email, opened on his laptop this time, carried the attachment. The statement opened. So did a keylogger.

For six months every replacement card got hit within weeks. Then someone changed the phone number on two of his accounts and reset the PINs, so the bank's verification texts went to them. Then someone walked into three US Bank branches in Missouri and withdrew $10,000 at each one, in person, without proper ID. Thirty thousand dollars. Getting it back is, in US Bank's words, still under review.

The fix was an IT company wiping and rebuilding every device in his house and a new network. All of it, from one tap on one email he couldn't read clearly on a phone.

What actually helps

  1. Tap the sender's name on any email that asks you to do something. Read the address. Wrong domain, delete.
  2. Never open an attachment you weren't expecting. Call the company using the number on its website.
  3. Use an authenticator app for two-factor instead of text messages wherever the bank allows it.
  4. Ask your bank for a verbal password on in-branch transactions. Five minutes.
  5. Keep your readers with you. The small print is where the fraud lives.

Bottom line

The fraud economy runs on small text. Read it.

The readers in this story

minrims Clear Slim V2

Foldable readers in a MagSafe-compatible case that lives on the back of your iPhone. Five strengths, blue-light filtering lenses, TR90 frames. Ships from Amazon, free 30-day returns.

minrims Clear Slim readers unfolded above an iPhone, with the MagSafe case
$39.95Clear Slim · V2
Prime eligible
1. Pick your strengthNot sure which? Strength guide
Amazon account checkoutFree 30-day returnsShips from Amazon
About this page. minrims is our company and this is our product. The family story is the author's, told with permission, with some details changed for privacy. Statistics and cases: FBI Internet Crime Complaint Center 2025 Annual Report; FBI public service announcement, November 2025; Dixon et al., ACM MHCI 2022; Frontiers in Psychology, 2022; PNAS Nexus, August 2024; American Optometric Association; US Department of Justice press releases (SDNY, July 2026; District of Massachusetts, May 2026); local news reports on the Minnesota and Daly City cases. Reading glasses correct near vision. They do not detect or prevent fraud, malware, or identity theft. If you believe you have been the victim of fraud, contact your bank and file a report at ic3.gov. Full disclosure.