How Do Seniors Stay Safe Online?

How Do Seniors Stay Safe Online?
Money & SecurityBy 8 min readUpdated 2026-07-19

Staying safe online is about habits, not technical skill: a long, unique password for each important account, two-factor authentication on email and banking, and never clicking links in unexpected emails or texts — go to the company's site yourself. No real bank or agency asks for your password or a verification code. Slowing down when a message rushes you stops most scams.

Quick answer

Staying safe online comes down to a few habits, not technical skill. Use a long, unique password for each important account and turn on two-factor authentication for email and banking. Never click links in unexpected emails or texts — go to the company's site yourself — and remember no real bank or agency asks for your password, full card number, or a verification code. Slowing down when a message rushes you stops most scams.

If you remember one thing

Scammers win by making you act fast. Almost every online con relies on urgency — “your account will be closed,” “act now,” “there's a problem with your payment.” The single most protective habit is to slow down and check directly: don't click the link, don't call the number in the message. Open your bank's app or type the address yourself. A real problem will still be there after you take a breath.

How do I create passwords I can actually remember — and keep safe?

Passwords are the locks on your online life, and reusing one everywhere is like using the same key for your house, car, and safe. Here's the modern, manageable approach:

  • Make them long, not cryptic. A passphrase of a few random words — like copper-lantern-quiet-river — is both harder to crack and easier to remember than P@ss1!
  • Use a different password for each important account. If one site is breached, the rest stay safe.
  • Let a password manager do the remembering. A trusted password manager stores them all behind one master password, so you only memorize one. Your phone or browser has one built in.
  • Turn on two-factor authentication for email and banking. That's the code texted or shown on your phone — even if someone learns your password, they can't get in without your phone.
  • Protect your email above all. It's the master key: anyone in your email can reset the passwords to everything else.

How can I tell if an email or text is a scam?

Most trouble arrives as a message designed to make you click before you think — a fake delivery notice, a “problem” with an account, a prize, or an alarming warning. These are the tells:

  • It pushes urgency or fear. “Immediate action required,” “your account is suspended,” “you owe money.” Pressure is the point.
  • It asks for information no real company asks for. Your password, full card number, Social Security number, or a one-time verification code — legitimate businesses never request these by text, email, or call.
  • The sender or address is slightly off. A tiny misspelling of a real company, or a display name that doesn't match the actual email address.
  • It wants payment in gift cards, wire, or a money app. No honest business or agency is paid this way — it's the surest sign of a scam.
  • When in doubt, don't click. Contact the company through a number or website you already trust, not the one in the message.

“Your computer has a virus!” pop-ups are the scam

A pop-up that fills your screen warning of a virus and giving a number to call is itself the trick. Don't call it, and never let a stranger take remote control of your computer — that's how they empty accounts. Close the window; if it won't close, shut the browser or restart the computer. Real security software doesn't cold-call you.

In 2025, 201,266 people aged 60 and older reported losing $7.748 billion to internet crime — an average of $38,500 each, with 12,444 of them losing more than $100,000. Those are the FBI’s own numbers, from the elder fraud section of the 2025 IC3 Annual Report. Here is every crime type the FBI ranked in its top ten by dollars lost, plus the one people over 60 report most often, and what each actually looks like when it reaches you.

The FBI’s ten highest-loss internet crime types for victims aged 60 and older, plus phishing and spoofing (the most-reported type), from the 2025 IC3 Annual Report. Across all crime types, 201,266 complainants aged 60+ reported $7.748 billion in losses in 2025 — an average of $38,500 each. These are only the losses people actually reported. The FTC notes that the vast majority of frauds are never reported, so figures like these capture a fraction of the older adults actually harmed; the true totals are higher.
Scam typeWhat it looks likeReported losses, victims 60+ (2025)The tell
InvestmentAn offer of large returns with minimal risk — a retirement, 401(k), Ponzi or pyramid pitch, very often involving cryptocurrency. 16,926 complaints.$3,519,296,354You can’t withdraw your own money. Real platforms don’t invent new fees or taxes when you try to cash out, and no legitimate business demands payment in cryptocurrency.
Tech and customer supportSomeone posing as tech or customer support: a pop-up warning, a call about a virus, or a notice that your antivirus subscription auto-renewed for hundreds of dollars. 21,333 complaints.$1,040,730,043No real tech company calls, emails or texts you first to say something is wrong with your computer. And a real security pop-up never gives you a phone number to call.
Confidence and romanceSomeone becomes a partner, friend or family member online — including the grandparent scheme, where the caller claims a grandchild is in jail or in danger. 10,188 complaints.$584,032,745They can never meet in person, and eventually they ask for money. The FTC’s rule is flat: never send money or gifts to a sweetheart you haven’t met in person.
Business email compromiseA compromised or spoofed email account redirects a wire transfer — often a real estate closing, an invoice, or a payment to a contractor. 4,566 complaints.$568,048,472Wiring instructions that change at the last minute are the scam. Confirm any payment change by calling a number you already had, never one in the email.
Government impersonationSomeone claiming to be from the Social Security Administration, the IRS, Medicare or the FBI threatens arrest or prosecution unless you pay or move your money. 8,628 complaints.$413,206,251Any request to move money to “protect” it is the scam. A government agency will never demand payment in gift cards, cryptocurrency, cash or gold — and there is no such thing as a federal safety locker.
Personal data breachYour sensitive personal information is copied, viewed or stolen from somewhere it was supposed to be secure, then used against you. 11,705 complaints.$324,470,413The breach itself isn’t the theft — the follow-up call is. Anyone who contacts you about a breach and asks you to verify details or move funds is the second scam.
Lottery, sweepstakes and inheritanceYou’ve won a lottery you never entered, or you’re owed an inheritance from a relative you’ve never heard of — but there are fees and taxes to pay first. 2,785 complaints.$136,328,519You never pay to collect a prize. If money has to go out before money comes in, it’s a scam — and you can’t win a contest you didn’t enter.
Non-payment and non-deliveryYou pay and the goods or services never arrive, or arrive far below what was promised. 9,743 complaints.$127,041,813The seller steers you off the platform and away from a credit card, toward a payment app, wire, gift card or crypto — the methods with no way to get your money back.
Real estateLoss of funds from a real estate investment, or fraud involving a rental or timeshare property. 2,473 complaints.$123,671,936Pressure to wire a deposit for a place you haven’t seen, from an agent you found through the listing itself rather than anyone you can independently verify.
EmploymentA work-from-home job that turns out to cost you money — starter kits, fake training, reshipping packages, or a fake check you’re asked to partly refund. 2,853 complaints.$78,712,899A real employer never asks you to pay to start, and never sends you a check and asks you to send part of it back. Reshipping packages is never a real job.
Phishing and spoofing (most-reported type for 60+)Unsolicited emails, texts or calls that appear to be from a company you use, asking for personal, financial or login details. The single most common complaint from this age group — 48,064 complaints.$77,020,936Legitimate companies don’t email or text you a link to update your payment information. A generic greeting, plus an urgent account problem, plus a link, equals a fake.

How do I browse and shop safely?

  • Keep your devices updated. Those update reminders on your phone and computer usually include security fixes — install them.
  • Look for the padlock and https before entering payment or personal details. A missing padlock is a red flag (though its presence alone doesn't guarantee honesty).
  • Pay with a credit card. It offers the strongest fraud protection — you can dispute charges you didn't authorize.
  • Be careful on public Wi-Fi. Cafe or library Wi-Fi is fine for reading; save banking and shopping for your home network or your phone's own data.
  • Buy from sites you sought out, not flashy social-media ads promising unbelievable deals.

For a deeper look at shopping specifically, see our guide on how to shop online safely. If it's Medicare-related calls you're worried about, read how to spot Medicare scams.

How do I protect my privacy online?

  • Share less on social media. Birth date, hometown, pet and family names are the very answers to security questions — and gifts to scammers who target you personally.
  • Set your profiles to private so only people you know can see your posts.
  • Think before you accept friend or follow requests. Imposters copy real profiles to reach a person's friends.
  • Decline what you don't need. Apps and sites ask for your location, contacts, and camera — say no unless there's a clear reason to allow it.

What should I do if something goes wrong?

  1. Change your passwords, starting with email and any account involved, and turn on two-factor authentication.
  2. Call your bank or card company if money or card details were exposed — ask them to block the card and issue a new one.
  3. Run a scan or ask for help if you clicked something or installed anything, from someone you trust or the device maker's official support.
  4. Report it to the FTC at ReportFraud.ftc.gov, and consider a credit freeze if personal information was stolen.
  5. Don't be embarrassed. These scams fool millions of careful people every year — acting quickly is what limits the harm.

You may be interested in…

The Caregiver Bundle
2 Paperbacks

The Caregiver Bundle

$44.99$51.98Save $6.99Learn more →

Get organized, stay safe

Knowing what you have is half the defense

A lot of online safety is bookkeeping: which accounts exist, which card each one bills, who to phone when something looks wrong. The End of Life Planner gives all of it fill-in sections, and records no passwords or account numbers by design — the book is useless to anyone who finds it and complete for the person you meant it for.

See the End of Life Planner →

Good to know

Common questions

I clicked a link in a text about a package. What do I do right now?

If you only clicked and typed nothing, you’re probably fine — close it, delete the message, and don’t go back. If you entered a password, change that password now, and change it anywhere else you reused it. If you entered card or bank details, call the card issuer or bank immediately and ask them to block the card. Then run your device’s security update, and report the message at ReportFraud.ftc.gov.

Someone said they were from Microsoft and I let them onto my computer.

Disconnect the computer from the internet, then update its security software and run a full scan, deleting anything it flags. Change the passwords for your email and bank from a different device, since those are what the caller was after. Real tech companies don’t call people out of the blue about virus warnings. Report it at ReportFraud.ftc.gov, and at IC3.gov if you lost money.

I gave someone my Social Security number. How bad is this, and what do I do?

Go to IdentityTheft.gov — it’s the FTC’s official site, and it builds you a personalized recovery plan and the letters you’ll need. That’s the specific step the FTC directs people to when a scammer has their Social Security number. From there you can place a free fraud alert or credit freeze with the credit bureaus and start monitoring your reports. It’s serious, but it’s a known problem with a defined process.

Someone claiming to be from my bank asked me to read back the code they’d just texted me.

Hang up — that’s the scam, every time. That code is the second factor protecting your account, and the caller needs it because they’re already trying to log in as you. No bank, agency or company will ever ask for a password or a verification code. If you already read it out, call your bank on the number printed on your card and change the account password now.

What is two-factor authentication, and do I really need it?

It’s a second step after your password — usually a code texted to you, or a fingerprint — and yes, it’s the single highest-value thing you can turn on. CISA names multifactor authentication one of its four basic steps to stay safe online, because it means a stolen password alone isn’t enough to get into your account. Turn it on for your email first (whoever controls your email can reset every other password), then your bank.

I can’t keep track of a different password for everything.

Nobody can, which is why the answer is a password manager rather than a better memory. It stores a long, unique password for every account behind one master password you actually remember; CISA recommends strong passwords plus a password manager as a basic protection. If you’d rather not use one yet, at minimum give your email and your bank passwords that you use nowhere else — those two are the accounts everything else hangs on.

Is it safe to use the Wi-Fi at the library or a coffee shop?

For reading news or checking a menu, yes. For banking, shopping, or anything where you type a password or card number, wait until you’re on your home network or use your phone’s own cellular data. Also keep your devices updated — CISA lists installing software updates promptly as one of its four core habits, because those updates close the flaws criminals rely on.

It already happened and I feel like an idiot. Who do I even tell?

Tell your bank or card company first, because that’s the only call with a real chance of stopping the money. Then report it to the FTC at ReportFraud.ftc.gov, and to the FBI at IC3.gov if it happened online; if your Social Security number or identity was involved, go to IdentityTheft.gov for a recovery plan. These scripts are built by professionals and rehearsed on thousands of people — you were targeted, not careless. Report it anyway, because your report is how the next person gets warned.

Free Starter Kit

Start getting retirement in order — one simple checklist at a time

Free quick-start checklists to help you organize the practical parts of retirement: what to gather, what to decide, and what to write down first.

  • What to gather
  • What to update
  • What to share with family
Get the free kit
What to gather, what to update, and who to tell.
No spam. Unsubscribe anytime. Organizational tools only — not legal or financial advice.

Almost there — check your inbox.

We just sent a confirmation email. Click the link inside and your free download lands right after. (If you don't see it, check spam or promotions.)