Cybersecurity · September 4, 2026 · intSignal Research

Older Californians and the $1.4 Billion: Elder Cyber-Fraud in the 2025 Data

Share this article

A disproportionate share, concentrated in one age group

Among all the ways California's cybercrime losses break down, one of the starkest is by age. In 2025, Californians aged 60 and over filed 22,157 internet-crime complaints and reported $1.40 billion in losses — first in the nation. That is 38 percent of the state's total reported losses from just 19 percent of its complaints, according to intSignal Research's analysis of the FBI's Internet Crime Complaint Center data.

The pattern is national, and accelerating: losses reported by the 60-and-over population across the country rose 59 percent in 2025, to $7.7 billion. California, with its large population of older residents holding accumulated assets, sits squarely in the path of those fraud flows.

Why a business should care about elder fraud

It is tempting to file this under consumer protection and move on. That would be a mistake, because the same techniques that drain a retiree's accounts are aimed at businesses that serve older clients — and at their staff.

  • Firms serving older Californians are targets by proxy. Family offices, trusts, wealth managers, medical practices, and professional-services firms hold exactly the accounts and authority that high-dollar fraud seeks to redirect. A fraudster impersonating a client to move funds is exploiting your workflow, not just your client's trust.
  • The employee-facing variants use identical playbooks. Executive impersonation, payroll diversion, and real-estate wire fraud are the same social-engineering techniques, pointed at your finance team instead of a consumer. A staff member who can be talked into changing payment instructions is the business version of the same vulnerability.
  • Reputation and duty of care. When a client is defrauded through an interaction that touched your systems or your people, the fallout is yours to manage regardless of where the failure originated.

Controls that protect clients and the business at once

The good news is that the highest-leverage defenses do double duty — they protect older clients and the business through the same mechanism:

  • Out-of-band verification of any payment change. Confirming new or changed payment or wire instructions through a separate, known channel is the single most effective, near-zero-cost fraud control a business can adopt. It stops client-directed fraud and business email compromise with one habit.
  • Multi-factor authentication on the accounts that move money. Email, banking, and portal access are where account takeover begins.
  • Staff awareness aimed at the real scenarios. Generic training does little; security-awareness training built around impersonation, urgency, and payment-change requests addresses the techniques actually in use.

A necessary caution about all of these figures: IC3 data reflects only what victims report, and the FBI has estimated that in at least one case only about 20 percent of a criminal group's victims came forward. Elder-fraud losses in particular are widely believed to be under-reported. The $1.40 billion is a floor, not a ceiling.


The figures in this article are drawn from the California Cybersecurity Risk Report 2027 by intSignal Research, where each is traced to its source, method, and limitations.

Share this article