Cybersecurity in the Age of AI: How Retirees and Long‑Term Investors Can Protect Themselves from Modern Scams  

Emily Lambert, IACCP®, Vice President, Senior Operations Manager & Chief Compliance Officer

As technology evolves, so do the tactics used by cybercriminals. Retirees and long-term investors are increasingly being targeted with sophisticated scams designed to capitalize on trust and the fast pace of everyday life. What makes today’s environment especially concerning is how convincing these scams have become.

How Artificial Intelligence Is Changing Cybercrime 

Artificial intelligence now allows criminals to create highly realistic emails, websites, text messages, and even voice recordings that can sound remarkably authentic. Fraudulent communications no longer contain the obvious spelling errors or awkward language we used to associate with scams. In many cases, they appear completely legitimate. 

The Rise of Spoofing and Impersonation Attacks 

We are also seeing an increase in what are known as “spoofing” attacks — where phone numbers, email addresses, and even caller IDs are manipulated to appear as though a communication is coming from a trusted source, such as your bank, a family member, or even your financial advisor. 

Why RelationshipBased Scams Are Becoming More Common 

Many of these scams are now relationship-based. Cybercriminals gather information from social media, public records, or prior data breaches to make communications feel personal and credible. The more information they gather, the more believable these scams can appear. 

Why Cybercriminals Target DecisionMaking, Not Just Technology 

While the technology behind these attacks is evolving rapidly, many of the underlying tactics still rely on urgency and emotional decision-making. In many cases, the real target is not your computer — it is your decision-making process. 

That is why one of the most important cybersecurity habits is simply slowing down. 

A Reminder That Anyone Can Be Targeted 

And honestly, this can happen to anyone. 

My dad is one of the smartest people I know, but he is also incredibly trusting and always moving a mile a minute. I’ve honestly lost count of how many times my parents have had to cancel a credit card because he clicked something too quickly or responded before fully double-checking a request. Thankfully, those situations were caught early, but it’s a good reminder that these scams are designed to catch people off guard. Cybercriminals are often counting on us being distracted, busy, or simply trying to move too quickly. 

That extra moment to pause and confirm something can make a significant difference. 

Red Flags That Should Always Trigger a Pause 

If you receive an unexpected request involving money movement, passwords, account information, gift cards, wire transfers, or urgent secrecy, pause before taking action. Legitimate organizations generally will not pressure you to act immediately without allowing time for independent confirmation. 

Why Stolen Credentials Are the New Point of Entry 

One important shift we are seeing in cybersecurity today is that many cybercriminals are no longer “breaking into” systems in the traditional sense — instead, they are logging in using stolen passwords, compromised credentials, and information gathered through phishing scams or prior data breaches. That is why password security, account monitoring, and authentication procedures are more important than ever. 

Safer Ways to Verify Financial Communications 

Rather than clicking links in emails or text messages, navigate directly to the organization’s official website or call a trusted phone number you already have on file. Even if a message appears authentic, confirmation is critical. Never trust, always verify in these instances. 

Being Cautious with Search Engines and Sponsored Links 

Clients should also be cautious when using internet search engines. Cybercriminals increasingly use malicious advertisements and fake “sponsored” websites designed to look like legitimate financial institutions, technology companies, or customer support pages. Rather than clicking on sponsored links, it is often safer to navigate directly to a company’s known website or use a bookmarked page you already trust. 

Strengthening Account Security with Passwords and MFA 

It is also important to use strong, unique passwords across your financial accounts. Reusing the same password across multiple websites significantly increases your risk if one account is ever compromised. We also generally recommend using a reputable password manager to securely store and generate passwords rather than relying solely on passwords saved within a web browser. 

In addition, clients should strongly consider enabling multi-factor authentication — often referred to as MFA — on financial and email accounts whenever available. MFA adds an additional layer of protection by requiring a second form of verification beyond just your password, such as a code texted to your phone, an authentication app, or biometric verification like Face ID or a fingerprint. Even if a password is stolen, MFA can often help prevent unauthorized access to an account. 

A Critical Reminder About Verification Codes 

It is also important to remember that those verification codes are intended only for you. Legitimate financial institutions, custodians, and technology providers should never ask you to disclose MFA verification codes through unsolicited calls, texts, or emails. Requests of that nature should be treated as a significant red flag and potential scam attempt. 

Why Software Updates and Device Security Matter 

Another often overlooked area of cybersecurity is keeping devices and software updated. Software updates frequently contain important security patches designed to address newly discovered vulnerabilities. Delaying updates can leave computers, tablets, and phones unnecessarily exposed to risk. 

Protecting Your Primary Email Account 

We also encourage clients to pay particular attention to securing their primary email account. Your email often serves as the recovery method for banking, investment, and other financial accounts. If an email account becomes compromised, it can create a pathway for criminals to reset passwords and gain access to additional accounts. 

Staying Safe in Public and Shared Networks 

Another important consideration is protecting your information in public settings. Avoid accessing sensitive financial accounts while connected to public Wi-Fi networks in places like airports, hotels, or coffee shops unless you are using a trusted and secure connection. 

And perhaps most importantly — never hesitate to ask questions. 

Cybercriminals are becoming extraordinarily sophisticated, and even highly knowledgeable individuals can fall victim to scams. Taking extra time to confirm a request is not inconvenient or excessive — it is one of the most effective habits for reducing fraud risk. 

A Simple Guiding Principle for Today’s Environment 

One of the best guiding principles in today’s environment is simple: slow down, never trust unexpected requests at face value, and always verify independently before taking action. 

Howe & Rusling’s Commitment to Client Protection 

At Howe & Rusling, cybersecurity and the protection of client information remain a top priority. We know many of these scams can feel unsettling and increasingly difficult to recognize, which is why we encourage clients to contact our office anytime they receive a suspicious communication, a request to move money, or anything that simply does not feel right. 

In many cases, a brief phone call can help prevent a very costly mistake — and we are always happy to take that extra call. 

Thank you for taking the time to stay informed and proactive about cybersecurity. Remaining cautious and vigilant is one of the best ways to protect both your personal information and the assets you’ve worked so hard to build. 

Disclosures: This material is provided for informational and educational purposes only and should not be construed as investment, legal, tax, cybersecurity, or other professional advice. The information presented reflects the opinions of the author as of the date of publication and is subject to change without notice. Cybersecurity threats continue to evolve, and no security measure can eliminate all risk or guarantee protection against fraud, identity theft, phishing attacks, data breaches, or other cyber incidents. Readers should exercise independent judgment and consult appropriate professionals regarding their individual circumstances. Any references to third-party products, services, websites, password managers, authentication applications, operating systems, internet browsers, or technology providers are provided solely for illustrative and educational purposes. Such references do not constitute an endorsement or recommendation by Howe & Rusling, Inc., and Howe & Rusling is not responsible for the content, security, or privacy practices of third-party providers. Clients should independently verify any requests involving account information, passwords, money movement, or other sensitive information through trusted contact methods before taking action. Investment advisory services are offered through Howe & Rusling, Inc., an SEC-registered investment adviser. Registration with the U.S. Securities and Exchange Commission does not imply a certain level of skill or training. 

Get the latest content from Beyond the Bell