A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus PNC "mistaken deposit" story that had him wire his savings to a gold dealer and collect the coins in person, while bank and dealer staff watched him stay on the phone the whole time.
Reviewed by the Social Engineering Examples team.
Between June 5-6, 2024, Jeffrey Maas, a 76-year-old West Orange, NJ retiree and PNC Bank customer, was defrauded of $390,000 in a "phantom hacker/courier" vishing scheme. It began with a fake Norton/Symantec antivirus billing email prompting a support call; the caller (posing as PayPal) gained remote access to Maas's computer and manipulated an on-screen "refund form" to falsely show a $300,000 mistaken deposit, backed by a forged PNC statement. A second scammer, reached via a phone number displayed on the manipulated screen and posing as PNC bank staff, gave Maas a short list of coin dealers and convinced him the only fix was to wire the funds to one of them and buy gold coins. While remaining on an open phone line with the scammer, Maas had a PNC branch employee wire $300,000 to American Coin & Stamp Co. in Clifton, NJ on June 5 and another $90,000 on June 6, then drove to the dealer both times to collect the physical coins before handing them to couriers at his home. PNC branch staff in West Orange and American Coin employees allegedly processed the unusual, life-savings-draining, in-person transactions without questioning why an elderly customer was audibly on a phone call throughout. West Orange Police later arrested Jaynesh Patel (Bensalem, PA), identified via a vehicle license plate, in October 2024; he faces separate criminal charges. Maas filed a civil negligence suit against PNC Bank and American Coin & Stamp Co. in Essex County Superior Court (Maas v. Patel et al., No. ESX-L-001994-26) on March 10, 2026; the court denied PNC's motion to dismiss on June 18, 2026, and the case remains pending.
The scam began as a classic tech-support / refund vishing lure and pivoted mid-call into a fabricated bank-error narrative: (1) Maas received a fake "Norton/Symantec Associates" billing email demanding he call a helpline about a small unpaid charge; (2) he called the number and reached a scammer (alleged alias "Jason Green") who claimed to be a PayPal representative and walked him through a "refund form," gaining remote access/screen control of his computer; (3) as Maas typed a small refund amount (~$300), the scammer manipulated the screen to show $300,000 had been deposited into his account by mistake, using a doctored/forged PNC statement; (4) a "help line" phone number for his own bank appeared on the manipulated screen; Maas called it and reached a second scammer (alleged alias "Edward Cullen") posing as PNC staff, who gave Maas a short list of coin dealers and said the only fix was to wire the money to one of them and convert it into gold coins to return to the "bank"; (5) Maas stayed on an open, active phone line with the scammer while physically at his PNC branch in West Orange, NJ, where a bank employee wired the funds directly to American Coin & Stamp Co.'s account, and then again while collecting the gold coins in person at American Coin's Clifton, NJ store, on June 5, 2024 ($300,000) and again on June 6, 2024 ($90,000, after the scammers invented a second "mistaken deposit"/reward-miscalculation story); (6) the purchased gold coins were handed to couriers who came to Maas's home (vehicles later described as a black Nissan Rogue and a Honda with Pennsylvania plates). The hybrid's effectiveness rested on chaining three separate impersonations (antivirus vendor to payment processor to bank) so that each institution's "channel" (email, then phone, then in-person banking, then in-person retail) seemed to independently corroborate the last, and on keeping the victim continuously "on the line" so bank and dealer staff who were physically present never had a private moment to question him.
Lure: a routine-looking antivirus renewal/billing email (fake Norton/Symantec invoice) that escalates via phone to "we accidentally deposited too much into your account, please help us correct it," an urgency-plus-helpfulness frame that flips the victim from concerned customer to a person trying to do the bank a favor. Tell-tale signs that were missed or overridden: a "refund form" where a vendor remotely edits your entered dollar amount upward by 1000x; a bank "help line" number that appears only inside a remote-access/manipulated screen rather than on the back of a card or bank statement; being told by "the bank" that the fix for its own accounting mistake is for the customer to wire nearly his entire savings to a coin dealer and buy gold coins; and, most visibly to real-world witnesses, an elderly customer standing at a teller window or gold-dealer counter for two consecutive days moving nearly his entire net worth while audibly on an active phone call with an unidentified third party coaching him.
Victim reported the fraud to West Orange police; an "intensive... cyber-chase which crossed state lines" investigation led to the arrest of Jaynesh Patel of Bensalem, Pennsylvania (identified via a getaway/pickup vehicle's license plate), announced by West Orange PD on October 1, 2024; Patel was separately charged/indicted on theft-by-deception and conspiracy-related counts and, per Business Insider, pleaded not guilty. The primary phone-based impersonators (aliases "Jason Green" and "Edward Cullen") were not identified/arrested in the sources reviewed. On March 10-11, 2026, Maas (represented by Pollock Cohen LLP) filed a civil negligence suit in Essex County Superior Court (Maas v. Patel et al., No. ESX-L-001994-26) against PNC Bank and American Coin & Stamp Co., alleging both failed to intervene despite obvious elder-financial-exploitation red flags. On June 18, 2026, Judge Aldo Russo denied PNC's motion to dismiss, rejecting PNC's argument that it owed no duty of care and that UCC preemption barred the claim; the court accepted the plaintiff's argument that a PNC employee's statement that "gold was a good investment" created a fiduciary duty. As of the most recent reporting reviewed (June 23, 2026), the civil case remains active/pending with no final judgment or settlement reported.
This case illustrates a multi-stage vishing hybrid that chains impersonations across an email lure, a fake tech-support/payment-processor call, and a fake bank call, while using the "victim stays on the phone during the real-world transaction" technique to neutralize the one safeguard institutions normally rely on: face-to-face staff judgment. It is also a rare instance where the resulting harm produced active civil litigation testing whether banks and precious-metals dealers have an affirmative duty (beyond simply not being complicit) to intervene when they observe classic elder-financial-exploitation red flags (FinCEN-documented indicators: an older customer on an active phone call, liquidating nearly all savings, buying unusual assets), making it a precedent-setting question for the industry's fraud-prevention obligations, decided in the plaintiff's favor at the motion-to-dismiss stage.
Defenses that should have stopped this: (1) bank teller/branch staff trained to flag classic elder-financial-exploitation red flags per FinCEN guidance: a customer visibly on an active phone call while executing large, unusual wire transfers, liquidating nearly all savings, being coached step-by-step; (2) mandatory "cooling off" holds, in-person callback verification, or Adult Protective Services referral for large senior wire transfers tied to phone instructions; (3) never trust a phone number or "help line" that appears on-screen during/after a remote-access session, since it is scammer-controlled, not the real bank/vendor line; (4) precious-metals dealers implementing "know your customer" style friction (age, purchase size/frequency, visible phone coaching) before large same-week wire-to-gold conversions; (5) consumer awareness that legitimate refund forms never involve a vendor remotely editing a dollar figure on your screen, and that "mistaken deposit, please return the difference via gold/wire" is a scripted fraud narrative, not a real bank/PayPal process; (6) end remote-access sessions and independently look up institutions' phone numbers rather than using numbers shown mid-session. The case is significant precedent-wise because it tests whether banks/dealers have an affirmative duty to intervene, not just process transactions.
A Singaporean finance professional in her 50s lost S$1.2 million (~US$900,000) over two months after scammers impersonating an Anti-Scam Centre…
Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and…
A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America, with a…