Scam Protection
The $5 File Scammers Buy Before They Call You — And How to Disappear From It
Last updated: 2026-06-27
The Call That Felt Completely Real
A woman in her late 60s received a call from someone who said he was from her bank's fraud department. He knew her full name. Her street address. The last four digits of her account. The name of her adult daughter. And the approximate balance in her checking account.
It sounded exactly like a real fraud alert — because the caller had the same information her bank would have. She confirmed the "suspicious transaction," provided a verification code, and lost $11,000 before the call ended.
Here's what no one told her: the caller wasn't a hacker. He didn't break into her bank's servers. He went to a data broker website, paid about $5, and downloaded a report that contained most of what he needed. He filled in the rest from a second site for another $3.
This is the threat seniors almost never hear about. And it changes everything about how you should think about online safety.
What Is a Data Broker — And Why Should You Care?
A data broker is a company that collects, packages, and sells personal information about private citizens. They pull from public records (property deeds, court filings, voter registration, DMV data), purchase transaction histories from retailers and loyalty programs, and scrape social media profiles, news mentions, and business directories.
There are over 3,000 data broker companies operating legally in the United States. Most people have profiles on dozens of them. Some of the largest — Spokeo, Whitepages, BeenVerified, Intelius, Radaris, MyLife — will sell a detailed report on almost any American adult for a few dollars or less.
A typical data broker report on a person over 60 might include:
- Full legal name and any aliases or maiden names
- Current and past home addresses going back decades
- Phone numbers (cell and landline)
- Email addresses
- Names and ages of family members, including adult children
- Neighbors' names and addresses
- Property ownership details and estimated home value
- Vehicle registration records
- Estimated net worth and income range
- Political party affiliation
- Businesses you've owned or been associated with
- Court records, including civil filings
- Social media accounts
None of this requires hacking. It's all legally compiled from records that exist about you — records generated by 60 or more years of living a normal American life.
Your Data Trail Is the Target, Not Your Password
Here is the assumption most senior security advice is built on: scammers succeed because seniors don't know enough about technology.
That assumption is largely wrong.
The FBI's 2024 Elder Fraud Report documented $3.4 billion in losses to people over 60. The overwhelming majority of those losses came through phone calls and emails where the scammer sounded credible — not because the victim clicked a phishing link or used a weak password, but because the scammer arrived armed with accurate personal information.
Knowing that information existed and how to use it required zero technical skill. It required a credit card and a few minutes on a data broker site.
The real reframe: your vulnerability isn't your tech knowledge — it's your 60+ year data footprint. And unlike your password, you can actually shrink it.
How Scammers Use a Data Broker File
Understanding the playbook makes you dramatically harder to deceive.
Step 1: Build the target profile. A scammer pays $5-15 for a report on you. They learn your name, family members, address, rough finances, phone number, and possibly your email.
Step 2: Choose the impersonation. With your financial profile in hand, they pick the institution that makes the most sense to impersonate. If the report shows property ownership, maybe it's the county tax office. Estimated net worth in six figures? Your bank or brokerage. Medicare ID patterns suggest your age bracket — so Medicare fraud becomes viable.
Step 3: Create urgency using YOUR details. This is what makes the call feel real. Instead of "there's a problem with your account," they say "we're seeing suspicious activity on your Sunshine Bank Visa ending in 4421 from a location on Maple Street — is that you?" They know enough to trigger genuine alarm and enough to seem legitimate.
Step 4: Extract what they still need. The data broker file rarely contains your full account number, PIN, or Social Security number. That's what the call is for. Once you're scared and convinced they're legitimate, you hand over the missing pieces.
Step 5: Act fast. Wire transfers, gift cards, and cryptocurrency are used because they're nearly impossible to reverse. The entire fraud often completes in under 30 minutes.
The critical insight: by the time the phone rings, the dangerous part is already done. The data broker sold them the foundation. Your trust does the rest.
Why People Over 60 Are Disproportionately Targeted
It's not because you're less tech-savvy. There are three structural reasons.
First, accumulated wealth. Decades of work, home equity, and retirement savings mean the average person over 60 has significantly more liquid assets than someone 30 years younger. Fraudsters are running a business — they target where the money is.
Second, a richer data footprint. Sixty-plus years of public records, property transactions, business dealings, and community activity means your data broker profile is thick. A 24-year-old's profile is thin. Yours is comprehensive — and comprehensive profiles enable more convincing impersonation.
Third, different verification instincts. Many people under 40 grew up never answering unknown phone numbers and treating unsolicited contact with default suspicion. That instinct was trained by years of spam, robocalls, and scam texts. People who built their habits in an era when phone calls from institutions were genuinely trustworthy don't have the same reflex — and that's not a character flaw. It's a generational artifact of living in a time when institutions were more trustworthy.
What You Can Actually Do: Shrink Your Data Footprint
Instead of trying to become more suspicious — which is exhausting, socially isolating, and makes you miss real alerts — the smarter move is to make your profile less useful before the call ever happens.
Request removal from the major data brokers. The largest data broker sites are legally required to honor removal requests. The process is tedious — each site has its own opt-out form — but the results last. You have to re-submit periodically, but you can meaningfully shrink your footprint.
Start with these: Spokeo, Whitepages, BeenVerified, Intelius, Radaris, MyLife, PeopleFinder, TruthFinder. A Google search for "[site name] opt out" will take you to the right form for each.
Consider an automated data removal service. This is exactly what Aura does. In addition to credit monitoring and identity theft insurance, Aura's data broker removal feature continuously scans over 30 major broker sites for your information and submits removal requests on your behalf — including when your profile reappears after an initial removal (which happens regularly, as brokers re-acquire data).
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
The Freeze That Actually Works
One of the most powerful and underused tools available to you has nothing to do with software.
A credit freeze — also called a security freeze — locks your credit file at all three major bureaus (Equifax, Experian, TransUnion) so that no new credit account can be opened in your name without you personally lifting the freeze first. It's free. It doesn't affect your credit score. And it stops one of the most common downstream consequences of identity theft cold.
To freeze your credit: go directly to Equifax.com, Experian.com, and TransUnion.com and navigate to their security freeze sections. You'll need to create accounts and verify your identity. The process takes about 15-20 minutes per bureau.
If you do need to apply for new credit, you can temporarily lift the freeze for a specific lender, then re-freeze it. It's a small hassle that blocks a large category of fraud.
Protecting Assets That Can't Be Wired Away
Here's a structural angle that rarely comes up in cybersecurity conversations.
The end goal of most financial scams is to move your money somewhere the scammer can access and you can't reverse. Wire transfers are the primary vehicle — they're fast, they're final, and once the money moves, recovery is rare.
What can't be wired? Physical assets.
Some people over 60 hold a portion of their wealth outside of digital financial systems — in physical gold and silver, for example. Augusta Precious Metals is one of the more reputable firms in the precious metals space for retirement-age investors, with a strong emphasis on education and no high-pressure sales tactics.
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
I'm not suggesting you liquidate your accounts and buy gold bars. But the principle matters: a scammer on the phone cannot instruct you to wire physical metal anywhere. Diversifying a portion of retirement savings into assets that exist outside the digital financial system is, among its other properties, a form of fraud resistance. A thief who steals your wire transfer reference number gets nothing if there's nothing to wire.
Building Your Personal Verification Protocol
Since the threat arrives as a phone call from someone who sounds credible, the most practical defense is a personal rule you follow before taking any account action over the phone.
The rule: Never take action on any financial or security matter during an inbound call. If someone calls you claiming to be your bank, Medicare, the IRS, or your insurance company, tell them you'll call back. Hang up. Look up the organization's phone number yourself — not from the caller ID, not from a number they gave you — and call from scratch.
This single habit collapses the entire data broker playbook. It doesn't matter how much information the caller has if your response is always "I'll call you back at the number on your website."
It will feel awkward the first few times. The caller may express urgency. That urgency is a signal, not a reason to stay on the line.
The Upside of This Reframe
Here's the hopeful part of this reframe: understanding the data broker mechanism is genuinely empowering.
The standard security narrative for seniors is defensive and shame-adjacent — be more careful, don't be tricked, pay more attention. It implicitly suggests the problem is a personal failing.
This reframe says something different: you've been targeted based on structural factors — your wealth, your data footprint, your generational trust instincts — not because of any mistake you made. And two of those three structural factors are things you can actually change.
Shrink your data footprint. Know the playbook. Build one simple verification habit. And keep some of your wealth in forms that can't be moved by a phone call.
That's not anxiety management. That's strategy.
Ready to see what data brokers have on you? Start with a free search of your name on Spokeo or Whitepages — you'll likely find how detailed your public profile already is. Then consider whether automated removal with Aura makes sense for your situation. The goal isn't paranoia. It's making yourself a harder target before the phone ever rings.
Have a question about data brokers or your online privacy? Send it to our team — we answer every message.
Get the ClearShield Weekly Brief — one plain-English email each week with the latest scam alerts, privacy tips, and security updates written specifically for adults 55+. No tech jargon. No spam. Just the things you actually need to know.