ACFE Insights Blog

Direct Deposit Fraud: A Case Study on Social Engineering Call Center Staffs

This article examines a case study, through the lens of one of the scam’s victims, on how fraudsters were able to trick an organization’s call center staff to divert pension checks. To change the members’ direct deposit account information, the scheme included using social engineering when targeting the call staff to mimic retiree victims as elderly, vulnerable and confused. A total of $154,507 was stolen across 10 accounts before this takeover fraud was discovered, and new anti-fraud measures were installed to prevent future attacks.

By Amy  Block Joy , Ph.D. July 2026 Duration: 8-minute read
Please sign in to save this to your favorites.

As a retired member of a pension plan, I initially discovered on January 1, 2026, what I later learned was a direct deposit fraud scheme taking place. After logging into my online bank, I found that my monthly pension had not been deposited. After attempting and failing to gain access to my pension account, I called the Pension Office for assistance. Speaking to a call center representative, I provided the required identifying information (last four digits of a social security number, legal name and birthdate) for the representative to access my account details. During that initial phone call, I learned the following:  

  • My monthly pension had been successfully deposited into a credit union account instead of my bank.
  • Two significant account changes had recently been made: my contact information (email address) and direct deposit bank information (name and account number).
  • Notifications of these changes were emailed to the new and fraudulent contact information. No notifications were emailed to my personal email address originally listed for the account.

After an investigation, it was determined that several weeks earlier, without notifying the original account holders, a fraudster masquerading as a pensioner contacted the organization’s (e.g., Pension Office) call center and successfully changed several members’ email addresses. After those emails were changed, the fraudster used the “forgot username” option on the organization’s portal. By inputting minimal information (last four digits of social security number, last name and birthdate), the fraudster was able to access the correct usernames for various accounts. The fraudster then requested and received a password reset link, changing the members’ account passwords. Once the fraudster accessed the accounts, direct deposit information was changed from the members’ banks to the fraudster’s account with a credit union, and they received the members’ pension payments within a few weeks.  

The Pension Office's multi-factor authentication (MFA) was ineffective, as the attacks targeted steps in the process before MFA would be used. When the contact information was changed, the fraudster was able to successfully take over all account activities, including notifications to the primary account holders. 

Security Failures 

The most significant security failure was the lack of notifications by the Pension Office after account information was changed. No notification was sent to the original account holder when the fraudster initiated a request to change the primary email address. From that moment on, only the new contact email address received notifications.  

After reporting the fraud, I was interviewed by the organization’s team manager who disclosed that the call center representatives, who are third-party contract hires, do not send notifications after making account changes.  

The second security failure was allowing the “forgot username” option to display the correct username via email notification without notifying the primary account holder. In this case, the username notification was sent to the fraudster via the fraudulent contact email address that was updated in the account.  

The third security failure was the lack of fraud training for call center staff. With these third-party representatives serving seniors, specialized fraud awareness training could have equipped them to recognize attempts to impersonate seniors. Adults over the age of 60 are prime targets of fraud due to the perception that they are trusting, vulnerable and easy to manipulate. Unfortunately, the perception that seniors are confused and vulnerable can backfire when staff are trained to help them with compassion but not to anticipate fraud. 

Name Mix-Up

One of the tactics used by the fraudster was tricking the call center representative using the assumption that seniors may be vulnerable or forgetful. In my case, the Pension Office manager reported that the fraudster had trouble with my name, mixing up the middle and last name by mistake; perhaps the fraudster only knew part of the name, but during the phone call, the representative corrected them. The fraudster sounded like a senior, acted confused and cried so hard that the representative could hardly understand their answers to the security questions. This is just one example of how bad actors use social engineering to con employees on the phone. 

The manager also reported that there were multiple changes made to my direct deposit information, with many different banks attempted to be used in the span of about a week.  

In total, investigations found that this scheme resulted in 345 cases of suspected fraud. A total of $885,939 in fraud was intercepted and stopped across 47 accounts, with $154,507 in funds lost in 10 of them. (The Pension Office later reimbursed all members who endured losses to their accounts.) 

Enhanced Anti-Fraud Measures 

These examples illustrate how important it is to make an account secure, especially those that are rarely used by the account holder. Following this case, the organization made multiple security enhancements very quickly. These included strengthening identity verification, stronger login protections, applying timely notifications following account changes and monitoring high-risk transactions. In addition, staff received anti-fraud training to improve recognition and awareness of common red flags, and the third-party contract workers are no longer allowed to make account changes. 

After these anti-fraud measures were made, a Pension Office staff member presented findings of the preliminary investigation at a meeting in April 2026: 

“We did engage a cyber forensics firm. They looked at all of our data, and they looked at all of our patterns, so they were able to determine that the threat action was not in our system... [The targeted accounts] were socially engineered and not part of a computerized infiltration.” 

He also spoke about the threat actor(s):  

“We don’t know if it was one person or a bunch, but [they were] going in and trying to social engineer their way into figuring out a bit here, a little bit there, and then took a step back and combined it together. That allowed them to get into the account” 

“They were masquerading. They were pretending to be somebody they were not ... pretending to be confused or pretend to have close to the right information but not quite. Potentially the [customer service representative] might repeat back to them what they thought they heard.  That’s kind of how they did that thing. They do it multiple times for the same account.” 

During my account’s takeover, the fraudster used multiple attempts to gain pieces of knowledge each time they spoke to different call center representatives. Having multiple employees answer the phone at a call center provides a unique opportunity for fraud, as a fraudster can gain valuable information with each phone contact and increase their knowledge base. 

Monitoring Patterns of Risk  

The bottom line: Organizations need to monitor repeat calls to change information on the same account. Additionally, call center representatives who work with seniors benefit from training on red flags so that they aren’t psychologically manipulated by what they interpret as a confused customer. An organization may use third-party contract hires to answer the phones, but ultimately, these representatives are the organization’s first line of defense against fraud.  

Organizations who serve senior customers must recognize that retired pension plan members will not be monitoring their accounts as regularly as others with more knowledge of digital security and best practices for safeguarding personally identifiable information. A survey published in the Journal of Accountancy reported that one-quarter of seniors and adults with a high school education or less never check their bank account balance, and four in 10 adults never check their retirement account balances at all. 

Monitoring frequent changes of direct deposit information is another way to enhance security. Fraudsters are more likely to change direct-deposit information before payday, so monitoring patterns of activity just before payday can disrupt these social engineering schemes targeting organization employees. 

After a significant fraud event, restoring customer confidence is key to restoring trust. This requires several steps. First, organizations must implement stronger security controls. Second, they must also be transparent about what happened and the enhanced anti-fraud measures that were made. Doing so will help customers trust that their organization is taking the fraud seriously. And third, getting stakeholders to be part of the solution can rebuild the institution’s reputation. Both the organization and its customers all want the same result: financial security.  

I learned a valuable lesson from my experience as a victim of this scheme. Yes, the fraudster robbed me of my money, but they stole something much more valuable: my peace of mind. Staying vigilant and checking my accounts regularly is one way to stay safe in today’s cyber-security world. 

Amy Block Joy, Ph.D., is a Professor Emerita at UC Berkeley. She has published books and papers on her discovery of $2.3 million in fraud. Her book, “Whistleblower” (2018) is a first-person non-fiction account of the consequences of reporting wrongdoing in the workplace. 

Topic:
Tags: