A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus PNC "mistaken deposit" story that had him.
Social Engineering Examples·5 sources
Between June 5-6, 2024, Jeffrey Maas, a 76-year-old West Orange, NJ retiree and PNC Bank customer, was defrauded of $390,000 in a "phantom hacker/courier" vishing scheme. It began with a fake Norton/Symantec antivirus billing email prompting a support call; the caller (posing as PayPal) gained remote access to Maas's computer and manipulated an on-screen "refund form" to falsely show a $300,000 mistaken deposit, backed by a forged PNC statement.
A second scammer, reached via a phone number displayed on the manipulated screen and posing as PNC bank staff, gave Maas a short list of coin dealers and convinced him the only fix was to wire the funds to one of them and buy gold coins. While remaining on an open phone line with the scammer, Maas had a PNC branch employee wire $300,000 to American Coin & Stamp Co. in Clifton, NJ on June 5 and another $90,000 on June 6, then drove to the dealer both times to collect the physical coins before handing them to couriers at his home.
PNC branch staff in West Orange and American Coin employees allegedly processed the unusual, life-savings-draining, in-person transactions without questioning why an elderly customer was audibly on a phone call throughout. West Orange Police later arrested Jaynesh Patel (Bensalem, PA), identified via a vehicle license plate, in October 2024; he faces separate criminal charges.
Maas filed a civil negligence suit against PNC Bank and American Coin & Stamp Co. in Essex County Superior Court (Maas v. Patel et al., No. ESX-L-001994-26) on March 10, 2026; the court denied PNC's motion to dismiss on June 18, 2026, and the case remains pending.
The scam began as a classic tech-support / refund vishing lure and pivoted mid-call into a fabricated bank-error narrative: (1) Maas received a fake "Norton/Symantec Associates" billing email demanding he call a helpline about a small unpaid charge; (2) he called the number and reached a scammer (alleged alias "Jason Green") who claimed to be a PayPal representative and walked him through a "refund form," gaining remote access/screen control of his computer; (3) as Maas typed a small refund amount (~$300), the scammer manipulated the screen to show $300,000 had been deposited into his account by mistake, using a doctored/forged PNC statement; (4) a "help line" phone number for his own bank appeared on the manipulated screen; Maas called it and reached a second scammer (alleged alias "Edward Cullen") posing as PNC staff, who gave Maas a short list of coin dealers and said the only fix was to wire the money to one of them and convert it into gold coins to return to the "bank"; (5) Maas stayed on an open, active phone line with the scammer while physically at his PNC branch in West Orange, NJ, where a bank employee wired the funds directly to American Coin & Stamp Co.'s account, and then again while collecting the gold coins in person at American Coin's Clifton, NJ store, on June 5, 2024 ($300,000) and again on June 6, 2024 ($90,000, after the scammers invented a second "mistaken deposit"/reward-miscalculation story); (6) the purchased gold coins were handed to couriers who came to Maas's home (vehicles later described as a black Nissan Rogue and a Honda with Pennsylvania plates).
The hybrid's effectiveness rested on chaining three separate impersonations (antivirus vendor to payment processor to bank) so that each institution's "channel" (email, then phone, then in-person banking, then in-person retail) seemed to independently corroborate the last, and on keeping the victim continuously "on the line" so bank and dealer staff who were physically present never had a private moment to question him.
Lure: a routine-looking antivirus renewal/billing email (fake Norton/Symantec invoice) that escalates via phone to "we accidentally deposited too much into your account, please help us correct it," an urgency-plus-helpfulness frame that flips the victim from concerned customer to a person trying to do the bank a favor. Tell-tale signs that were missed or overridden: a "refund form" where a vendor remotely edits your entered dollar amount upward by 1000x; a bank "help line" number that appears only inside a remote-access/manipulated screen rather than on the back of a card or bank statement; being told by "the bank" that the fix for its own accounting mistake is for the customer to wire nearly his entire savings to a coin dealer and buy gold coins; and, most visibly to real-world witnesses, an elderly customer standing at a teller window or gold-dealer counter for two consecutive days moving nearly his entire net worth while audibly on an active phone call with an unidentified third party coaching him.
Victim reported the fraud to West Orange police; an "intensive... cyber-chase which crossed state lines" investigation led to the arrest of Jaynesh Patel of Bensalem, Pennsylvania (identified via a getaway/pickup vehicle's license plate), announced by West Orange PD on October 1, 2024; Patel was separately charged/indicted on theft-by-deception and conspiracy-related counts and, per Business Insider, pleaded not guilty.
The primary phone-based impersonators (aliases "Jason Green" and "Edward Cullen") were not identified/arrested in the sources reviewed. On March 10-11, 2026, Maas (represented by Pollock Cohen LLP) filed a civil negligence suit in Essex County Superior Court (Maas v. Patel et al., No. ESX-L-001994-26) against PNC Bank and American Coin & Stamp Co., alleging both failed to intervene despite obvious elder-financial-exploitation red flags.
On June 18, 2026, Judge Aldo Russo denied PNC's motion to dismiss, rejecting PNC's argument that it owed no duty of care and that UCC preemption barred the claim; the court accepted the plaintiff's argument that a PNC employee's statement that "gold was a good investment" created a fiduciary duty. As of the most recent reporting reviewed (June 23, 2026), the civil case remains active/pending with no final judgment or settlement reported.
This case illustrates a multi-stage vishing hybrid that chains impersonations across an email lure, a fake tech-support/payment-processor call, and a fake bank call, while using the "victim stays on the phone during the real-world transaction" technique to neutralize the one safeguard institutions normally rely on: face-to-face staff judgment. It is also a rare instance where the resulting harm produced active civil litigation testing whether banks and precious-metals dealers have an affirmative duty (beyond simply not being complicit) to intervene when they observe classic elder-financial-exploitation red flags (FinCEN-documented indicators: an older customer on an active phone call, liquidating nearly all savings, buying unusual assets), making it a precedent-setting question for the industry's fraud-prevention obligations, decided in the plaintiff's favor at the motion-to-dismiss stage.
Defenses that should have stopped this: (1) bank teller/branch staff trained to flag classic elder-financial-exploitation red flags per FinCEN guidance: a customer visibly on an active phone call while executing large, unusual wire transfers, liquidating nearly all savings, being coached step-by-step; (2) mandatory "cooling off" holds, in-person callback verification, or Adult Protective Services referral for large senior wire transfers tied to phone instructions; (3) never trust a phone number or "help line" that appears on-screen during/after a remote-access session, since it is scammer-controlled, not the real bank/vendor line; (4) precious-metals dealers implementing "know your customer" style friction (age, purchase size/frequency, visible phone coaching) before large same-week wire-to-gold conversions; (5) consumer awareness that legitimate refund forms never involve a vendor remotely editing a dollar figure on your screen, and that "mistaken deposit, please return the difference via gold/wire" is a scripted fraud narrative, not a real bank/PayPal process; (6) end remote-access sessions and independently look up institutions' phone numbers rather than using numbers shown mid-session.
The case is significant precedent-wise because it tests whether banks/dealers have an affirmative duty to intervene, not just process transactions.
Social Engineering Examples. “Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)”. Accessed 19 September 2026. https://socialengineeringexamples.com/jeffrey-maas-pnc-bank-gold-conversion-vishing-2024
Phantom hacker/courier scams of this type typically start from bulk consumer contact lists (data-broker purchases, breach dumps, or scraped mailing lists) rather than research on a specific target, paired with a spoofed antivirus-vendor billing template (here, a fake "Norton/Symantec Associates" invoice) and an attacker-controlled inbound "helpline" number, casting a wide net for whoever calls back.
Bulk lure infrastructure (spoofed vendor billing templates, purchased contact lists) is cheap for attackers to rotate and very hard to eliminate at the source; the realistic control is consumer-facing spam/phishing filtering and vendor public-awareness warnings, which is what West Orange police issued only after the fact.
Maas received the fake billing email and called the embedded helpline number to dispute a charge he never authorized, self-selecting into the scam by initiating contact through attacker-controlled infrastructure.
Consumer education that a legitimate vendor never requires disputing a charge by calling a number embedded in the billing email itself; look up the vendor's support number independently instead of using the one provided.
Posing as a PayPal representative ("Jason Green"), the caller walked Maas through an online "refund form" that, consistent with common tech-support-scam tooling, granted remote screen access or control over his computer under the guise of processing a small refund.
Never grant remote computer access or complete an unsolicited "refund form" for a billing dispute; if access was already granted, end the session immediately and run a security scan before taking any further financial action.
The scammer manipulated the shared screen to inflate a small refund into a fake $300,000 mistaken deposit, backed by a doctored PNC statement graphic, then routed Maas to a second, coordinated persona ("Edward Cullen") posing as PNC staff via a phone number planted on that same manipulated screen, a classic two-persona handoff used to make the bank-impersonation stage feel independently corroborated.
Treat any phone number or account statement that appears only inside a remote-access or manipulated screen as inherently untrustworthy; verify by calling the institution back using a number from a card, a mailed statement, or the official website.
The second scammer kept Maas on an open phone line while coaching him, from a supplied list of coin dealers, to visit his PNC branch and treat the wire as the only way to "return" the mistaken funds, exploiting the fact that a phone call is invisible to anyone who doesn't ask about it.
Bank and dealer staff trained on FinCEN elder-financial-exploitation indicators, an older customer visibly on an active phone call while being coached through an unusual transaction, should pause the transaction and ask direct questions or separate the customer from the call before proceeding.
A PNC branch employee processed the wire transfer to the gold dealer's account without questioning the customer's age, the transaction's size, or the ongoing phone call, converting the scam from a digital manipulation into a real, largely irreversible bank transaction.
Mandatory friction for large wire transfers by senior customers, cooling-off holds, independent callback verification, or Adult Protective Services referral, especially when a similar transaction recurs on consecutive days.
Maas collected the physical gold coins in person from American Coin & Stamp Co., again without staff inquiry despite visible phone coaching, then handed the coins to an unknown courier who arrived at his home in a vehicle later linked to the arrested suspect.
Precious-metals dealers applying "know your customer" checks (purchase history, size and frequency, visible phone coaching, first-time customer status) before releasing large same-week gold purchases, and treating an unfamiliar courier pickup at a customer's home as a fraud indicator worth reporting.
The scammers reused the same open-line, fabricated-mistake playbook the next day, inventing a second "reward miscalculation" to extract an additional $90,000 in gold through the identical wire-then-courier pipeline, completing the theft before Maas grew suspicious and reported it.
Once funds are wired and physical gold has been handed to a courier, recovery is very difficult; the realistic controls sit upstream at Stage 6 and Stage 7, since after-the-fact remedies are largely limited to law-enforcement identification via incidental evidence (like a license plate) and civil litigation, not asset recovery.
Browse by what this case has in common with others in the library.
A Singaporean finance professional in her 50s lost S$1.2 million.
Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and…
A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Lazarus-linked operators built polished fake job-interview sites impersonating Coinbase, Kraken, Circle and other crypto firms.
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation.
A retired 60-year-old Malaysian bank manager in Johor Baru lost RM936,000 (life savings) after a Macau-scam vishing syndicate posing successively.
The Crelan Bank phishing attack: fraudsters impersonating the CEO tricked staff into wiring nearly €70M (~$75.8M) in Belgium's costliest CEO…
A spoofed-email scheme impersonating MacEwan University's trusted general contractor, Clark Builders.
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
During an internal OpenAI benchmark run with safety refusals deliberately lowered.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
California's Attorney General and six county DAs found more than 10,000 paper patient records and hazardous/medical waste in unsecured.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project.
A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
In the first-ever prosecutions under the federal anti-pretexting statute Congress passed after the 2006 HP boardroom spying scandal.
Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials.
A Tennessee school district's finance director wired $3.36M in state education funds to fraudsters impersonating textbook vendor Pearson from a…