A true story

The email that cost my dad $30,000 (and why I now keep readers on my phone)

He didn't fall for a Nigerian prince. He tapped a button he couldn't read.

mBy a minrims co-founderUpdated Sept 18, 2026 · This is our story and our product
A gray-haired man in a white shirt reading something on his phone
Not my dad. He wishes.

My dad is not a careless guy. Retired. Sharp. Reads two newspapers a day, front to back, and balances the checkbook to the penny like it's 1978. He has never once fallen for a prince. If a stranger calls about his car's extended warranty, the stranger has a bad afternoon.

And this past winter, people he'll never meet took him for thirty thousand dollars, and it all started with one tap on his iPhone. Not a hack. A tap. On a button he couldn't quite read.

I want to be clear about what that tap was, because it's the whole story. It wasn't the robbery. It was the door. Everything that came after, the credit cards, the laptop, the bank, the thirty grand, came through a door he opened on a phone screen because the type was too small to see what he was opening.

Can't read the sender line on your phone? Neither could he. See the readers that live on your phone →

Mistake number one: the phone

The email said his US Bank statement was ready. Right logo, right blue, big friendly button. He tapped it. A page came up that said his session had expired, please sign in again. So he did. Username, password, done. The page thought about it for a second, said "timed out, try again later," and he went back to his coffee. Annoying. Not alarming. That's the point.

Nothing was hacked. Nothing was installed. He just typed his password into a page that wasn't the bank's. That's the whole trick, and it's the only trick, and on a phone it works like a charm, because the two things that give it away are the two things you can't read without your glasses.

And as far as we can tell, it wasn't just once. These people are patient. They don't kick the door in. They find a door that opens easily and they come back through it, quietly, again and again. A statement here. A "confirm your account" there. Each one small, each one on a screen he couldn't read, each one handing over one more piece. That's how they work. Not fast. Methodical.

9:41●●●●
Inbox
U
Tuesday
To:

Your December statement is ready to view

January 13, 2026 at 7:52 AM

Hi ,

Your statement for the period ending 12/31/2025 is now available. For your security, statements can be viewed online for 30 days.

View my statement

If you did not request this statement, no action is needed.

Please do not reply to this message. This mailbox is not monitored. Member FDIC. Equal Housing Lender.

1
The name. Looks right. Anyone can type a display name.
2
The address. Ten-point gray under the name. Not the bank. You have to tap to see it.
3
The button. Goes to a copy of the login page. Type your password there and it's theirs.
A reconstruction of the email as it looked in the Mail app, sender and recipient blurred. Nothing about it is loud. Everything wrong with it is small.

Researchers have actually measured this. Show people real scam emails on a desktop computer and they catch 84% of them. Show the same people the same emails on a phone and they catch 74%. Not because they got dumber on the way to the couch. Because the phone hides the sender's real address one tap deeper, in gray type the size of a grain of rice, and nobody taps. Now take away the reading glasses. My dad's were on his nightstand.

$20.9B
lost to internet crime in the US in 2025, up 26% in one year (FBI)
#1
phishing, the fake email, was the most-reported crime in the country last year
9 in 10
adults over 45 need reading glasses to see type that small
Think about that for a second

The most common crime in America is an email with small print. And nine out of ten people my dad's age can't read small print without their glasses. Nobody can tell you how many of those billions started with type somebody couldn't see. I can tell you how thirty thousand of it did.

Mistake number two: one password to rule them all

Here's the part I didn't understand until it was over. The password he typed into that fake page was the same one he used for his email. Or close enough. Most of us do this. Don't lie. So once they were through the door, they didn't just have a bank login. They had his inbox.

And an inbox is a map. Every bank. Every credit card. Who he pays, who pays him, what his accountant calls him, what his brother calls him. They didn't need to break into anything else. They just read.

Mistake number three: the laptop, because that's where the money lives

This is the moment the whole thing turned. Up to here they had a phone. What they wanted was the laptop, because the laptop is where he lives. Email, bills, the brokerage, the bank, the tax guy. Get onto that machine and you're not robbing a man. You're moving in.

So one more email arrived, and this one didn't come from a stranger. It came as a reply to a conversation already sitting in his inbox, from a name he knew, with a subject line he'd already seen. "Here's that statement you asked about. See attached." That's a real technique with a boring name, and every fraud crew on earth uses it, because nobody suspects the fourth email in a thread.

And you don't open a reply from somebody you know on your phone in the grocery line. You open it at the desk, on the laptop, with your coffee, where you do your real email. He did. His MacBook asked if he was sure. He was sure. It asked for his password. He typed it. The "statement" was a program dressed as a statement, and from that moment on, everything he typed on that computer, every password, every card number, was being read by somebody in a room he'll never see. For six months.

People feel safer on the desktop. Turns out that's the problem. Researchers at Carnegie Mellon looked at half a million real clicks and found people on a computer were more than four times as likely to click something risky as the same people on a phone. The small screen keeps you on edge. The big screen, the real keyboard, and the chair put you at ease. As they put it: "The danger lurks when we are at ease." The desk is also where the money is. Nobody moves $30,000 from a phone. They do it from a chair.

The pattern

Open the door on the phone, where the type is too small to check. Walk through it slowly. Land on the computer, where he's relaxed, trusts the sender, and keeps the money. That's it. That's the whole scam.

"How do they keep getting my new card number?"

This was the question that drove him nuts. He'd spot a charge he didn't make. Call the card company. They'd cancel the card and mail a new one. Two weeks later, a charge on the new card. Cancel, new card, two weeks, charge. Over and over. Six months of it, across every card he owned.

The answer was sitting on his laptop. Every time he logged in to check the new card, they were reading it too. Every time he typed the new number into a website, they got that too. You cannot out-cancel a thief who is reading over your shoulder. And he never thought to look at the laptop, because the laptop wasn't where it started. The phone was.

What that looks like in real life is not one dramatic phone call. It's more than a hundred fraudulent charges, most of them small, spread across every card, and every single one has to be found, flagged, disputed, and explained to a rep who has never heard of you. Hold music. "Can you confirm the last four?" Transferred. Dropped. Call back. He kept a legal pad. Then a binder. My dad spent the better part of a year working as an unpaid fraud investigator for banks that were supposed to be protecting him.

He thought he was losing it. He wasn't. He was just outnumbered.

201,266
complaints to the FBI from Americans 60 and over in 2025
$7.75B
what that age group lost, up 59% in one year
$38,500
average loss per victim over 60

Then they took his phone number

It got worse. On a couple of his accounts, someone changed the phone number the bank sends its little six-digit codes to. So when the bank texted a code to prove it was really him, it went to them. He changed every password. He turned on every extra code the banks offered. Which sounds like the fix, except, as the FBI put it in a warning last fall, those codes "will not protect you if you land on a fraudulent login page." Which is where this whole thing started.

The $30,000 that walked out of US Bank

In July, someone walked into three different US Bank branches in Missouri and withdrew $10,000 at each one. Thirty grand. In person. At a teller window. Without showing proper ID. US Bank calls these "mobile withdrawals." My dad calls them something else.

He is still chasing US Bank to get it back. As of this writing, their answer is "under review."

You think I'm exaggerating. Here's who else it happened to.

I get it. Three branches, no ID, ten grand each. It sounds like a movie. It isn't rare. These are all from the last few months, all on the record, all linked so you can read them yourself.

Two US Bank branches, 40 minutes apart, Minnesota$12,760

June 11, 2026. A man walks into a US Bank in St. Paul with what looked like photo ID, forges a signature, and pulls $6,280 from a Missouri man's checking account. Forty minutes later he does it again in Woodbury, this time from savings. The victim found out two days later. Same bank as my dad. Same move: fake ID, teller window, gone.

Hoodline, Sept 2026, citing the criminal complaint
A former bank employee and a ring that ordered replacement cards, New York$1.6M+

Charged July 30, 2026. A bank insider pulled customer info. His partners called the bank pretending to be those customers, ordered replacement debit cards to addresses they controlled, then walked into branches and asked for wires and withdrawals. Dozens of victims who did nothing wrong except bank there.

US Attorney's Office, Southern District of New York
Fake IDs with real customers' names, Massachusetts$1.1M+

Guilty pleas in May 2026. The ring printed IDs with real customers' names and their own photos, and bank employees on the inside skipped the verification steps. They walked out with cashier's checks drawn on other people's accounts. Ran from late 2022 into 2026.

US Attorney's Office, District of Massachusetts
One email 'from the FTC', Michigan$270,000+

September 2026. A 70-year-old woman in Hazel Park gets an email claiming to be from the Federal Trade Commission. It says there's a warrant out for her. She's told to buy gold to make it go away and not to call the local police. She cashed out her pension and her late husband's. It started with one email she believed.

CBS News / Hazel Park Police, via The Daily Hodl
A hijacked phone number, California$25,000

An 86-year-old woman in Daly City had her phone number ported to a stranger's phone, her contact info on the account changed, and $25,000 wired out before anyone noticed. The bank's verification texts went to the thief. Sound familiar? It's the exact move they pulled on my dad.

ABC7 San Francisco

The part nobody warns you about

I hired an IT company to wipe and rebuild every computer and device in his house, the MacBook included, and replace the network. Every password. Every account. That fixed the computers. It did not fix him.

He downloaded the app for every bank and every card and turned on every alert there is. Now his phone buzzes for a $4 coffee and he flinches. He has developed what I can only describe as a twitch. Every buzz is round two until proven otherwise. He checks the accounts at breakfast, at lunch, and once more before bed, like a man checking the stove.

And then there's my mom. Because he now reviews every charge on her cards, too. Every one. "What's this $38 at Target?" She has been married to this man for a very long time, and at no point in that time did she want anyone looking that closely at her Target runs. I asked her how she was holding up. Her answer is not printable. Of everyone in this story, she might be the angriest. Not at the thieves. At the audit.

What the statistics leave out

The money is the small part. The hours, the hold music, the binder, the twitch, the marriage. That's the real bill, and nobody sends you a statement for it.

The part where I'm honest with you

Reading glasses don't stop scammers. I'm not going to pretend they do.

What they do is let you read the small print, and the small print is exactly where the scam lives. The sender's real address. The web address at the top of the page. The three letters at the end of a file name. Nine out of ten adults over 45 need readers to see type that size, and on a phone the tells are all that size. If you can read it, you can catch it. If you can't, you're guessing.

My dad has readers. They were on his nightstand. His phone was in his hand.

That gap is why we built minrims. Two friends, both squinting at menus by 45, both tired of readers that were never where we needed them. So we made a pair that folds into a case the size of a MagSafe wallet and sticks to the back of your iPhone. Your phone is the one thing you never leave behind. Now your readers aren't either.

Six things to do this week (with or without readers)

  1. On your phone, tap the sender's name on any email that asks you to do something. Look at the actual address. If it isn't the company's real one, delete it. This takes four seconds and would have saved my dad thirty grand.
  2. Never sign in from a link in an email. Type the bank's address yourself, or use a bookmark. A real bank will never mind.
  3. If a reply in a conversation you're already having shows up with an attachment you didn't ask for, call the person. Their account may be the one that's hacked.
  4. Stop using one password for everything. Yes, you. A password manager is free, and it's the reason this story didn't happen to me.
  5. Ask your bank for a verbal password on in-branch withdrawals. It takes five minutes and it would have stopped the teller.
  6. Keep your readers with you. Sounds dumb. It's the one that would have saved my dad.

Bottom line

The fraud didn't start at the bank, and it didn't start on the laptop. It started on a phone, in six-point type, with no glasses, and everything else walked in through that door. Fix the small thing.

The readers in this story

minrims Clear Slim V2

Foldable readers in a MagSafe-compatible case that lives on the back of your iPhone. Five strengths, blue-light filtering lenses, TR90 frames. Ships from Amazon, free 30-day returns.

minrims Clear Slim readers unfolded above an iPhone, with the MagSafe case
$39.95Clear Slim · V2
Prime eligible
1. Pick your strengthNot sure which? Strength guide
Amazon account checkoutFree 30-day returnsShips from Amazon
About this page. minrims is our company and this is our product. The story above is my family's. Names, places, and some details are left out or changed for my parents' privacy; the events, the amounts, and the bank are not. The email shown is a reconstruction. The way the laptop was infected is described as these attacks are documented to work (CISA advisory AA20-280A; Palo Alto Networks Unit 42 on email thread hijacking and on Atomic macOS Stealer; Kroll). The desktop-versus-phone finding is from Carnegie Mellon and Ben-Gurion University (2025). Statistics are from the FBI Internet Crime Complaint Center 2025 Annual Report ($20.9 billion in reported losses, up 26%; phishing the most-reported crime type; $7.75 billion reported by victims 60 and over) and peer-reviewed research (Dixon et al., ACM MHCI 2022; American Optometric Association). The cases listed are from public court filings and news reports, linked above. Reading glasses correct near vision. They do not detect or prevent fraud, malware, or identity theft. If you believe you have been the victim of fraud, contact your bank and file a report at ic3.gov. Full disclosure.