A true story

The email that cost my dad $30,000 (and why I now keep readers on my phone)

He didn't fall for a Nigerian prince. He tapped a button he couldn't read.

mBy a minrims co-founderUpdated Sept 21, 2026 · This is our story and our product
A gray-haired man in a white shirt reading something on his phone
Not my dad. He wishes.

My dad is not a careless guy. Retired. Sharp. Reads two newspapers a day, front to back, and still balances the checkbook to the penny like it's 1978 and the bank might be lying to him. (Turns out that instinct was fine. Wrong crook, though.) He has never once fallen for a prince. If a stranger calls about his car's extended warranty, the stranger has a bad afternoon.

And this past winter, a bunch of people he'll never meet took him for thirty thousand dollars. It didn't start with a hack. It started with a tap. One tap, on one button, on his iPhone, that he couldn't quite read.

I need you to understand what that tap was, because it's the whole story. It wasn't the robbery. It was the door. Everything that came after it, the credit cards, the laptop, the bank, the thirty grand, my mother's blood pressure, walked in through a door he opened on a phone screen because the type was too small to see what he was opening.

Can't read the sender line on your phone? Neither could he. Buy with Prime: the readers that live on your phone →

Mistake number one: the phone

The email said his US Bank statement was ready. Right logo, right blue, big friendly button. He tapped it. A page popped up: your session has expired, please sign in again. So he signed in. Username, password, done. The page spun for a second, said "timed out, try again later," and he shrugged and went back to his coffee. Annoying. Not alarming. That's the whole design.

Nothing got broken into. Nothing got installed. Not yet. He typed his password into a page that wasn't the bank's, and now somebody in another time zone had it. That's the trick. On a phone, that's the whole trick, and it works like a charm, because the two things that give it away are the two things you can't read without your glasses.

And as best we can tell, it wasn't just the once. These people are patient. They don't kick the door in. They find the door that sticks a little, and they come back through it, quietly, whenever they feel like it. A statement here. A "please confirm your account" there. Each one small. Each one on a screen he couldn't read. Each one handing over one more key. Not fast. Not sloppy. Methodical. Say what you want about them, they're good at their jobs.

9:41●●●●
Inbox
U
Tuesday
To:

Your December statement is ready to view

January 13, 2026 at 7:52 AM

Hi ,

Your statement for the period ending 12/31/2025 is now available. For your security, statements can be viewed online for 30 days.

View my statement

If you did not request this statement, no action is needed.

Please do not reply to this message. This mailbox is not monitored. Member FDIC. Equal Housing Lender.

1
The name. Looks right. Anyone can type a display name.
2
The address. Ten-point gray under the name. Not the bank. You have to tap to see it.
3
The button. Goes to a copy of the login page. Type your password there and it's theirs.
A reconstruction of the email as it looked in the Mail app, sender and recipient blurred. Nothing about it is loud. Everything wrong with it is small.

Somebody actually measured this, by the way. Show people real scam emails on a desktop and they catch 84% of them. Show the same people the same emails on a phone and they catch 74%. They didn't get dumber walking to the couch. The phone just hides the sender's real address one tap deeper, in gray type the size of a grain of rice, and nobody taps. Now take away the reading glasses. My dad's were on the nightstand. Where they always are. Where they are useless.

$20.9B
lost to internet crime in the US in 2025, up 26% in one year (FBI)
#1
phishing, the fake email, was the most-reported internet crime in the country last year
9 in 10
adults over 45 need reading glasses to see type that small
Sit with that for a second

The most-reported internet crime in America is an email with small print. And nine out of ten people my dad's age can't read small print without their glasses. Nobody can tell you how many of those billions started with type somebody couldn't see. I can tell you how thirty grand of it did.

Mistake number two: one password to rule them all

Here's the part I didn't figure out until it was over. The password he typed into that fake page was the same one he used for his email. Or close enough. Most of us do this. Don't lie, you do it too. So once they were through the door, they didn't just have a bank login. They had his inbox.

And an inbox is a map. Every bank. Every credit card. Who he pays, who pays him, what his accountant calls him, what his wife calls him when he's in trouble. They didn't need to break into anything else. They just sat there and read.

Mistake number three: the laptop, because that's where the money lives

This is where it turned. Up to here they had a phone. Phones are for looking. What they wanted was the laptop, because the laptop is where he lives. Email, bills, the brokerage, the bank, the tax guy. Get onto that machine and you're not robbing a man anymore. You're moving in.

So one more email showed up, and this one didn't come from a stranger. It came as a reply, inside a conversation already sitting in his inbox, from a name he knew, under a subject line he'd already seen. "Here's that statement you asked about. See attached." There's a boring technical name for this trick and every fraud crew on earth uses it, because nobody on earth suspects the fourth email in a thread.

And you don't open a reply from somebody you know on your phone in the checkout line. You open it at the desk, on the laptop, with your coffee, like a civilized person. He did. His MacBook asked if he was sure. He was sure. It asked for his password. He typed it. The "statement" was a program wearing a statement costume, and from that moment on, everything he typed on that computer, every password, every card number, was being read by somebody in a room he'll never see. For six months.

Notice what they didn't need this time. They didn't need to fool his eyes. The phone had already handled that. This email came from a name he trusted, in a conversation he was already having, so there was nothing to squint at and nothing to catch. Small print got them in the door. Trust did the rest. And they wanted the laptop for one simple reason: nobody runs their whole financial life from a phone. They do it from a chair.

The pattern

Open the door on the phone, where the type is too small to check. Walk through it slowly. Set up shop on the computer, where he's relaxed, trusts the sender, and keeps the money. That's it. That's the whole scam. It's not clever. It's patient.

"How do they keep getting my new card number?"

This is the question that nearly broke him. He'd spot a charge he didn't make. Call the card company. They'd cancel the card, mail a new one. Two weeks later, a charge on the new card. Cancel, new card, two weeks, charge. Cancel, new card, two weeks, charge. Six months of this, across every card he owned. He started to think the card companies were in on it.

The answer was sitting on his laptop the whole time. Every time he logged in to check the new card, they were reading it too. Every time he typed the new number into a website, they got that too. You cannot out-cancel a thief who's reading over your shoulder. And he never once thought to look at the laptop, because the laptop wasn't where it started. The phone was.

What that looks like in real life is not one dramatic phone call. It's more than a hundred bogus charges, most of them small, spread across every card, and every single one has to be found, flagged, disputed, and explained to a rep who has never heard of you and would like to keep it that way. Hold music. "Can you confirm the last four?" Transferred. Dropped. Call back. Start over. He kept a legal pad. Then the legal pad became a binder. My dad spent the better part of a year working as an unpaid fraud investigator for banks that were supposed to be protecting him. They did not send a thank-you card.

He thought he was losing his mind. He wasn't. He was just outnumbered.

201,266
complaints to the FBI from Americans 60 and over in 2025
$7.75B
what that age group lost, up 59% in one year
$38,500
average loss per victim over 60

Then they took his phone number

It got worse. On a couple of his accounts, somebody changed the phone number the bank sends those little six-digit codes to. So when the bank texted a code to prove it was really him, it went to them. Cute. He changed every password. On the laptop. Which they were reading. He turned on every extra code every bank offered. Which sounds like the fix, except, as the FBI put it in a warning last fall, those codes "will not protect you if you land on a fraudulent login page." Which is where this whole thing started. On a phone. With no glasses.

The $30,000 that walked out of US Bank

In July, somebody walked into three different US Bank branches in Missouri and withdrew $10,000 at each one. Thirty grand. In person. At a teller window. Looked a human being in the eye. Without showing proper ID. US Bank has a name for these. They call them "mobile withdrawals." My dad has a name for them too, and it isn't that.

He is still chasing US Bank to get it back. As of this writing, their answer is "under review." It has been under review for a while.

You think I'm exaggerating. Here's who else it happened to.

I get it. Three branches, no ID, ten grand each. Sounds like a movie. It isn't rare. Here are five from the last few months, all on the record, all linked so you can go read them yourself and get mad on your own time.

Two US Bank branches, 40 minutes apart, Minnesota$12,760

June 11, 2026. A man walks into a US Bank in St. Paul with what looked like photo ID, forges a signature, and pulls $6,280 from a Missouri man's checking account. Forty minutes later he does it again in Woodbury, this time from savings. The victim found out two days later. Same bank as my dad. Same move: fake ID, teller window, gone. Forty minutes.

Hoodline, Sept 2026, citing the criminal complaint
A former bank employee and a ring that ordered replacement cards, New York$1.6M+

Charged July 30, 2026. A bank insider pulled customer info. His partners called the bank pretending to be those customers, ordered replacement debit cards to addresses they controlled, then walked into branches and asked for wires and withdrawals. Dozens of victims whose only mistake was banking there.

US Attorney's Office, Southern District of New York
Fake IDs with real customers' names, Massachusetts$1.1M+

Guilty pleas in May 2026. The ring printed IDs with real customers' names and their own photos, and bank employees on the inside skipped the verification steps. They walked out with cashier's checks drawn on other people's accounts. Ran from late 2022 into 2026.

US Attorney's Office, District of Massachusetts
One email 'from the FTC', Michigan$270,000+

September 2026. A 70-year-old woman in Hazel Park gets an email claiming to be from the Federal Trade Commission. It says there's a warrant out for her. She's told to buy gold to make it go away and not to call the local police. She cashed out her pension and her late husband's. One email. That's all it took.

CBS News / Hazel Park Police, via The Daily Hodl
A hijacked phone number, California$25,000

An 86-year-old woman in Daly City had her phone number ported to a stranger's phone, her contact info on the account changed, and $25,000 wired out before anyone noticed. The bank's verification texts went to the thief. Sound familiar? Same play they ran on my dad.

ABC7 San Francisco

The part nobody warns you about

I hired an IT company to wipe and rebuild every computer and device in his house, the MacBook included, and replace the whole network. Every password. Every account. That fixed the computers. It did not fix him.

He downloaded the app for every bank and every card and turned on every alert there is. Now his phone buzzes for a $4 coffee and he flinches like it's incoming. He has developed what I can only describe as a twitch. Every buzz is round two until proven otherwise. He checks the accounts at breakfast, at lunch, and once more before bed, like a man checking the stove. The stove is fine, Dad. The stove has always been fine.

And then there's my mom. Because he now reviews every charge on her cards, too. Every one. "What's this $38 at Target?" She has been married to this man for a very long time, and at no point in that time did she sign up for a line-item audit of her Target runs. I asked her how she was holding up. Her answer is not printable on a family website. Of everyone in this story, she might be the angriest. Not at the thieves. At the audit.

What the statistics leave out

The money is the small part. The hours, the hold music, the binder, the twitch, the marriage. That's the real bill, and nobody sends you a statement for it.

The part where I'm honest with you

Reading glasses don't stop scammers. I'm not going to stand here and pretend they do.

What they do is let you read the small print, and the small print is exactly where the scam lives. The sender's real address. The web address at the top of the page. The three letters at the end of a file name. Nine out of ten adults over 45 need readers to see type that size, and on a phone every tell is that size. If you can read it, you can catch it. If you can't, you're guessing. And these people are betting you're guessing.

My dad has readers. They were on his nightstand. His phone was in his hand.

That gap is why we built minrims. Two friends, both squinting at menus by 45, both sick of readers that were never where we needed them. So we made a pair that folds flat into a case the size of a MagSafe wallet and sticks to the back of your iPhone. Your phone is the one thing you never leave behind. Now your readers aren't either. That's the whole pitch. I told you I'd be honest.

Six things to do this week (with or without readers)

  1. On your phone, tap the sender's name on any email that asks you to do something. Look at the actual address. If it isn't the company's real one, delete it. Four seconds. Would have saved my dad thirty grand.
  2. Never sign in from a link in an email. Type the bank's address yourself, or use a bookmark. A real bank will never mind. A fake one will be crushed.
  3. If a reply in a conversation you're already having shows up with an attachment you didn't ask for, call the person. Their account may be the one that's hacked. Yes, it's awkward. Do it anyway.
  4. Stop using one password for everything. Yes, you. A password manager is free, and it's the only reason this story is about my dad and not about me.
  5. Ask your bank for a verbal password on in-branch withdrawals. Five minutes. It would have stopped the teller cold.
  6. Keep your readers with you. Sounds dumb. It's the one that would have saved my dad.

Bottom line

The fraud didn't start at the bank, and it didn't start on the laptop. It started on a phone, in six-point type, with no glasses, and everything else walked in through that door. Fix the small thing.

The readers in this story

minrims Clear Slim V2

Foldable readers in a MagSafe-compatible case that lives on the back of your iPhone. Five strengths, blue-light filtering lenses, TR90 frames. Ships from Amazon, free 30-day returns.

minrims Clear Slim readers unfolded above an iPhone, with the MagSafe case
$39.95Clear Slim · V2
Prime eligible
1. Pick your strengthNot sure which? Strength guide
✓ Amazon account checkout✓ Free 30-day returns✓ Ships from Amazon
About this page. minrims is our company and this is our product. The story above is my family's. Names, places, and some details are left out or changed for my parents' privacy; the events, the amounts, and the bank are not. The email shown is a reconstruction. The laptop infection is told the way these attacks are documented to work (CISA advisory AA20-280A; Palo Alto Networks Unit 42 on email thread hijacking and on Atomic macOS Stealer; Kroll). Statistics are from the FBI Internet Crime Complaint Center 2025 Annual Report ($20.9 billion in reported losses, up 26%; phishing the most-reported crime type; $7.75 billion reported by victims 60 and over) and peer-reviewed research (Dixon et al., ACM MHCI 2022; American Optometric Association). The cases listed are from public court filings and news reports, linked above. Reading glasses correct near vision. They do not detect or prevent fraud, malware, or identity theft. If you believe you have been the victim of fraud, contact your bank and file a report at ic3.gov. Full disclosure.