DOJ/FTC alleged that Citizens Disability and subsidiary CD Media made 109 million-plus illegal telemarketing calls.
Social Engineering Examples·4 sources
Citizens Disability, LLC, a Massachusetts-based company that helps consumers apply for Social Security Disability Insurance (SSDI) benefits, and its subsidiary CD Media, LLC contracted with third-party lead generators and call centers to sell their paid benefits-application-assistance services. Per the DOJ complaint (filed upon FTC referral) in the District of Massachusetts (Case No. 1:25-cv-12826), between January 2019 and July 2022 the defendants allegedly caused more than 109 million outbound telemarketing calls to be placed, including more than 25.7 million calls to telephone numbers listed on the National Do Not Call (DNC) Registry.
The leads for these calls were allegedly harvested through deceptive "consent farm" websites that offered consumers sweepstakes entries, coupons, or other services in exchange for contact information, without adequately disclosing that the information would be used for telemarketing solicitation. Many recipients were lower-income or disabled consumers.
A subset of the calls allegedly used prerecorded robocalls in which a voice identifying itself as "Amber" or "Audrey" falsely told the consumer "it show[s] here that you recently inquired about your eligibility for Social Security Disability benefits," creating the false impression the call was a personalized follow-up to the consumer's own prior outreach, when in fact the consumer's data had simply been scraped from an unrelated coupon/sweepstakes site.
Defendants neither admitted nor denied these allegations in resolving the matter via stipulated order.
The scheme combined a data-harvesting front end with a pretexting-based robocall back end. First, consent-farm websites advertising prizes, coupons, or other unrelated services collected consumers' names and phone numbers, with telemarketing use of that data buried or omitted from disclosures. Those lead lists were sold/passed to Citizens Disability's contracted call centers, which then dialed the numbers, including numbers on the DNC Registry, in violation of the Telemarketing Sales Rule (TSR), using prerecorded messages that lacked the required prior express written consent.
The core social-engineering hook was the false-continuity pretext: rather than cold-calling as a stranger, the robocall (voiced as "Amber" or "Audrey") asserted the consumer had already reached out about SSDI eligibility, manufacturing a sense of familiarity and legitimacy (and an implicit echo of official Social Security Administration contact) that lowered the recipient's skepticism and increased pickup/engagement, funneling interested consumers to live agents to sell benefits-application assistance.
The tell was the specific script line quoted in the FTC complaint: a prerecorded voice identifying itself only as "Amber" or "Audrey" stating "it show[s] here that you recently inquired about your eligibility for Social Security Disability benefits," a claim the recipient had never actually made. Consumers who had never visited any SSDI-related site (and in many cases were on the DNC Registry) had no way to have "inquired," which is the giveaway that the call originated from purchased consent-farm data rather than a genuine prior contact; legitimate SSA-related outreach would not come from a third-party disability-services telemarketer referencing an inquiry the consumer never made.
The United States, acting via DOJ upon a 3-0 FTC referral vote, filed a complaint and simultaneous proposed stipulated order in the U.S. District Court for the District of Massachusetts on September 30, 2025 (Case No. 1:25-cv-12826; FTC matter no. 2223158). The stipulated order, entered the same day, imposed a $2 million civil penalty judgment jointly and severally against Citizens Disability, LLC and CD Media, LLC, with $1 million suspended contingent on compliance and timely payment of the remaining $1 million (in two $500,000 installments).
It permanently enjoins the defendants from prerecorded robocall telemarketing (absent a narrow statutory exception), from calling DNC-listed numbers absent a valid exception, and from misrepresenting that a call is in response to a consumer's own SSDI-eligibility inquiry; it also requires due diligence and monitoring of lead generators and proper recordkeeping.
Defendants neither admitted nor denied the allegations in the complaint as part of the settlement. No individuals were named or charged in the federal action. The FTC case page lists the matter as "Under Order" as of the filing date; no reporting reviewed confirmed collection beyond the ordered payment schedule.
The case is a clean, well-documented illustration of the "false-continuity" pretexting variant at industrial scale: the complaint's allegations of over 109 million calls and 25.7 million-plus DNC-registry contacts show that this pretext (falsely claiming to be responding to the consumer's own inquiry) can be deployed as a mass-market lead-conversion tool, not just a bespoke targeted attack.
It also demonstrates how legitimate-seeming "coupon" and "sweepstakes" data-collection sites function as an upstream feeder for pretexting campaigns, and how the pretext is engineered to specifically exploit consumers already anxious about disability benefits, a population selected in part for vulnerability (lower-income, disabled). For an educational site, it's a strong real-world case for teaching "verify independently, never trust an inbound claim that you already contacted them" and for showing regulators' TSR/FTC Act theory of liability against both the telemarketer and its lead-generation supply chain.
FTC/DOJ enforcement resulted in a permanent injunction barring: (1) prerecorded/robocall telemarketing except under a narrow statutory safe harbor; (2) calls to numbers on the National Do Not Call Registry absent a valid exception; (3) misrepresentations that a call is in response to a consumer's own SSDI-eligibility inquiry or implies SSA affiliation; and required due diligence/monitoring of third-party lead generators, recordkeeping, and restrictions on use/retention of consumer data harvested via consent-farm sites.
For consumers, the case illustrates standard robocall defenses: numbers on the DNC Registry are not fully protected against sweepstakes/coupon-site data harvesting; a caller claiming "you recently inquired" should be independently verified by contacting SSA (ssa.gov or 1-800-772-1213) directly rather than trusting the inbound caller; legitimate SSA communications do not originate from third-party disability-benefits marketing firms.
Social Engineering Examples. “Citizens Disability SSDI Impersonation/Robocall Scheme”. Accessed 19 September 2026. https://socialengineeringexamples.com/citizens-disability-ssdi-robocall-scheme-2025
per the complaint, third-party lead generators operated websites offering sweepstakes entries, coupons, or other unrelated services to induce consumers to hand over their name and phone number, with the fact that this data would be used for telemarketing buried or omitted from disclosures. This is the data-harvesting front end that supplies raw targets, functioning like a low-cost OSINT layer built from consumers' own voluntarily submitted information rather than public-record research.
Consent-farm data harvesting is difficult to stop at the point of collection because consumers voluntarily submit their own information in exchange for a perceived reward; the practical control is regulatory, requiring lead-generation sites to clearly and conspicuously disclose that submitted data will be used for telemarketing (as the stipulated order now mandates), plus consumer-side skepticism toward sweepstakes and coupon forms that ask for a phone number.
Citizens Disability and CD Media contracted with third-party call centers and built prerecorded robocall scripts voiced by personas identified only as "Amber" or "Audrey." The scripts were engineered around a specific false-continuity claim, that the consumer had "recently inquired" about SSDI eligibility, designed to manufacture legitimacy and an implicit echo of official Social Security Administration contact before a human ever spoke to the target.
Requiring due diligence and ongoing monitoring of third-party lead generators and call centers, including script review and immediate suspension of vendors found using deceptive material, of the kind the stipulated order imposes on the defendants going forward, disrupts the supply chain that manufactures deceptive scripts before they ever reach a consumer.
the complaint alleges the defendants caused more than 109 million outbound telemarketing calls between January 2019 and July 2022, including over 25.7 million to numbers on the National Do Not Call Registry, indicating dialing infrastructure operated at industrial scale with little or no DNC scrubbing or consent verification before calls went out.
Carrier-side call-authentication and robocall-mitigation technology (such as STIR/SHAKEN call verification) combined with real-time National Do Not Call Registry scrubbing prior to dialing would have blocked a large share of the alleged 25.7 million-plus DNC-listed calls before they were placed.
the robocall opened with the false personalized-inquiry claim, lowering the recipient's skepticism by implying prior engagement and official-sounding legitimacy, which increased pickup and continued engagement compared to a cold, unexplained sales call.
Consumer education is the realistic control here, verify any inbound claim of a prior inquiry independently by contacting the Social Security Administration directly (ssa.gov or 1-800-772-1213) rather than trusting the caller, since legitimate SSA-related outreach would not originate from a third-party disability-benefits marketing firm referencing an inquiry the consumer never made.
consumers who stayed on the line or called back were routed from the prerecorded message to live telemarketers who continued the sales pitch for Citizens Disability's paid SSDI benefits-application-assistance services.
Call-center-level compliance monitoring and recorded-call auditing, of the type the injunction now requires as an ongoing obligation, can catch agents continuing a false-continuity pitch after the robocall handoff, though this control is largely available to regulators and the companies themselves rather than to consumers.
live agents closed sales of the paid advocacy service, completing the scheme's objective of converting harvested leads into paying customers, with many recipients allegedly being lower-income or disabled consumers particularly likely to be anxious about disability benefits.
After-the-fact regulatory deterrence, permanent injunctions against robocalling, DNC violations, and inquiry-response misrepresentations, plus civil penalties, is the control that materialized in this case; it does not undo completed sales but raises the cost of running the scheme going forward and requires destruction of unlawfully obtained consumer data.
Browse by what this case has in common with others in the library.
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America.
Costa Rica-based ringleader Roger Roger used spoofed government caller ID to convince hundreds of elderly victims they had won sweepstakes…
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
A mass SMS phishing campaign impersonating U.S. toll agencies spoofed 'unpaid toll' notices, drawing 2,000+ FBI complaints within weeks.
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread.
Advance Machine Company's West Coast sales manager repeatedly rifled Tennant Company's sealed, covered dumpster in California to steal sales leads.
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
A fraudster impersonating CEO Rob Mee tricked a Pivotal employee into emailing back the W-2 tax data of the company's…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
DOJ alleges Ghanaian twins Jamal and Kamal Abubakari and U.S.-based Amanda Opoku-Boachie ran an AI-video-enabled romance fraud ring that used…
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
A Dominican Republic call-center network ran a multi-role "grandparent"/"family-in-need-of-bail" scam: openers posed as a distressed grandchild.
A caller posing as two different Clorox employees talked Cognizant's outsourced IT help desk into resetting their passwords and MFA…