An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
Social Engineering Examples·4 sources
Between at least January 2020 and January 2021, Victoria Crosby of Atlantic City, New Jersey ran a bereavement-targeted advance-fee fraud scheme. Using a prepaid cellphone and fictitious names, she called elderly people whose spouse or family member had recently died, claiming to be an employee of a retirement benefit office or a life insurance company.
She told victims that a life insurance policy or pension left by their deceased relative, naming them as beneficiary, was "in arrears," and that they had to pay the arrearage (typically via reloadable prepaid retail gift cards, with the 10-digit codes read to her by phone) before the benefit could be paid out. She cashed out the cards into accounts she controlled and withdrew funds from ATMs around Atlantic County, NJ.
At least 17 victims paid her more than $100,000 combined; DOJ's plea filing states $110,380 flowed into her bank account in 2020 alone. Concurrently, Crosby was receiving SSI, Medicaid, and HUD public-housing assistance in Atlantic City and did not disclose this fraud income to those agencies, for which she would otherwise have been ineligible. A joint SSA OIG/HUD OIG/DOJ investigation opened in February 2021 (complaint filed June 16, 2021, charging wire fraud, SSA-benefit concealment, health care fraud, and false statements to HUD).
Crosby pleaded guilty to wire fraud on November 16, 2023, before U.S. District Judge Robert B. Kugler in Camden. Per the SSA OIG Fall 2025 Semiannual Report to Congress, she was sentenced in July 2025 to 24 months in prison, 3 years of supervised release, $106,639 restitution to the fraud victims, and additional restitution of $9,057 to HUD, $86,689 to the New Jersey Division of Revenue, and $13,020 to SSA.
Using a prepaid ("burner") cellphone and fictitious names, Crosby called victims, identified because a spouse or family member had recently died, and claimed to be an employee of a "retirement benefit office" and/or a life insurance company. She told each victim that their late family member's pension or life insurance policy, of which the victim was the named beneficiary, was "in arrears," and that the victim had to pay the arrearage before the policy's benefit could be released to them.
She then walked victims through purchasing reloadable prepaid cards at retail stores and reading her the 10-digit codes printed on the back over the phone; once she had a code she logged into the card's online account, drained the balance into accounts she controlled, and withdrew the cash from ATMs in Atlantic City, Brigantine, and Absecon, New Jersey.
In at least one case documented in the charging information, Crosby called back the next day posing as a "supervisor" correcting the arrears figure upward, extracting a second, larger prepaid-card payment from the same widow. Separately and concurrently, Crosby did not report this fraud income to SSA, Medicaid, or HUD while she was collecting SSI, Medicaid, and public-housing rental assistance in Atlantic City, making her ineligible for those benefits had the agencies known of her actual income.
Lure: "I'm calling from [a retirement benefit office / your late husband's life insurance company], his policy names you as beneficiary, but it's in arrears, and you need to pay the arrearage before we can release your benefit." The follow-up "supervisor correction" call (raising the amount owed) added a second false-authority layer. Tell in hindsight: no genuine insurer or pension office demands payment via reloadable gift/prepaid card codes read over the phone to "unlock" a benefit that is rightfully the beneficiary's; legitimate arrears or fees are never collected this way, and a second caller "correcting" the amount upward is a classic double-tap extraction pattern.
Victoria Crosby was charged by criminal complaint on June 16, 2021 with wire fraud, concealing information affecting continued SSA payments, health care fraud, and making false statements to HUD. She pleaded guilty on November 16, 2023, before U.S. District Judge Robert B. Kugler in Camden, NJ, to a one-count information charging wire fraud (18 U.S.C. §§ 1343, 2), admitting to the life-insurance-arrears scheme and to concealing over $110,000 in income from SSA, Medicaid, and HUD.
In July 2025 she was sentenced to 24 months in prison plus 3 years of supervised release, and ordered to pay $106,639 in restitution to her fraud victims along with separate restitution of $9,057 to HUD, $86,689 to the New Jersey Division of Revenue, and $13,020 to SSA for the benefits-concealment conduct.
This case is a clean, fully-adjudicated example of the "beneficiary-in-arrears" advance-fee pretext, a variant that specifically weaponizes the immediate aftermath of a family death, a moment when victims are grieving, distracted, and primed to trust anyone who claims to be delivering money owed to them rather than asking them to send money. It also shows how a single low-tech offender (one burner phone, no digital infrastructure, no malware) sustained a scheme against at least 17 victims across state lines using only voice social engineering and prepaid-card cash-out, and how the same offender's parallel failure to disclose fraud income created a second, independently prosecuted benefits-fraud exposure.
It is useful for consumer/elder-fraud awareness content and for benefits-agency fraud teams alike.
Never make a payment, especially via reloadable prepaid gift cards or by reading card codes over the phone, to "unlock," "release," or "correct arrears on" an insurance or pension benefit; no legitimate insurer, retirement agency, or government office collects payment that way. Treat unsolicited calls referencing a recently deceased spouse/relative's benefits as a red flag, particularly in the days/weeks after a death (obituaries and public death notices are a common sourcing vector for these lists).
Independently verify any claimed "arrears" or "beneficiary" status by calling the insurer or agency back using a number from an official statement or the insurer's public website, not a number given by the caller. Family members and financial institutions should flag repeat large purchases of reloadable prepaid/gift cards by elderly customers, a well-documented advance-fee fraud indicator that store clerks and banks are increasingly trained to intercept.
Adult Protective Services and SSA/HUD benefit caseworkers should cross-check sudden unreported income against recipients' benefit eligibility, since the same offender in this case was separately concealing over $100,000 in fraud proceeds while collecting SSI, Medicaid, and HUD housing assistance.
Social Engineering Examples. “New Jersey Life-Insurance-Beneficiary Pretexting of Elderly Widows/Widowers”. Accessed 19 September 2026. https://socialengineeringexamples.com/nj-life-insurance-beneficiary-pretexting-widows-2025
Crosby is documented as having called victims identified because a spouse or family member had recently died, consistent with sourcing candidate names, addresses, and phone numbers from publicly available bereavement signals such as obituaries and public death notices, a well-documented lead source for this pretext family.
Public obituaries and death notices are legitimately public information and cannot realistically be suppressed; the practical control is downstream, training families, executors, and funeral-adjacent services to expect a wave of unsolicited benefit-related contact after a published death and to treat it with default suspicion during that window.
Crosby acquired a prepaid "burner" cellphone and adopted fictitious names and a fabricated employer identity (a purported retirement benefit office or life insurance company), giving her a disposable, hard-to-trace calling identity before any contact was made.
Prepaid burner phones and fabricated caller identities are cheap and largely undetectable before a call is placed; carrier-level caller-ID authentication (e.g. STIR/SHAKEN-style call verification) only partially mitigates this, so the realistic defense sits at later verification stages rather than blocking phone acquisition itself.
Crosby cold-called each victim, introduced herself under a fictitious name, and falsely claimed to be an employee of a retirement benefit office or life insurance company contacting them about a policy or pension left by their deceased family member.
Recipients of an unsolicited call claiming to be from an insurer or benefits office should hang up and independently call back using a number from an official statement or the insurer's/agency's public website, never a number or claim supplied by the caller.
She told the victim that the policy or pension, of which they were the named beneficiary, was "in arrears" and that they had to pay the arrearage before the benefit could be released, framing the payment as unlocking money that was already rightfully theirs.
Any request to pay money in order to "unlock," "release," or "correct arrears on" a benefit that is supposedly already owed to the recipient should be treated as a hard red flag, since legitimate insurers, pension offices, and government agencies never require an advance payment to release a beneficiary's own funds.
Victims were instructed to purchase reloadable prepaid cards at retail stores and read the 10-digit codes off the back of the cards to Crosby over the phone, a payment method that is functionally irreversible and hard to trace once the codes are handed over.
Reloadable prepaid/gift cards are a well-documented advance-fee fraud payment indicator; retail store clerks and bank staff trained to question customers buying multiple high-value reloadable cards, and to warn of scams at the point of sale, can interrupt the scheme before codes are ever handed over.
In at least one documented case, Crosby called back the next day posing as a "supervisor" who claimed the previous arrears figure was wrong, using the appearance of a second, more authoritative source to extract an additional, larger prepaid-card payment from the same victim.
A follow-up "supervisor" call correcting a previously quoted amount upward should be recognized as a classic double-tap escalation pattern and trigger the same independent callback verification as Stage 3, rather than being treated as more credible because it claims higher authority.
Crosby logged into the prepaid cards' online accounts with the codes she had collected, transferred the balances into accounts she controlled, and withdrew the funds in cash from ATMs in Atlantic City, Brigantine, and Absecon, New Jersey, spreading withdrawals across multiple locations.
Prepaid-card issuers and banks can flag rapid loading of newly purchased card balances into unfamiliar third-party accounts followed by cash withdrawals across multiple nearby ATM locations as an anomalous cash-out pattern warranting a hold or manual review.
Crosby retained the stolen funds (over $100,000 from at least 17 victims, $110,380 into her bank account in 2020 alone) while concealing that income from SSA, Medicaid, and HUD so she could keep collecting SSI, Medicaid, and public-housing assistance she would otherwise have been ineligible for.
Benefits agencies such as SSA, Medicaid, and HUD can run periodic income and asset cross-checks (data matching, eligibility redeterminations) against recipients to catch undisclosed income, including proceeds of an unrelated criminal scheme, that would otherwise let concealment persist indefinitely.
Browse by what this case has in common with others in the library.
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
Two Scottish small businesses lost £31,000 and over £5,000 after callers impersonating bank fraud-team staff talked owners into wiring money.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Posing as NatWest bank security, vishing criminals convinced Surrey solicitor Karen Mackie to wire £734,000 of client money to fraudulent…
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously…
A forged "change your remittance bank account" email tricked a Puerto Rico government corporation into wiring $2.6M to a fraudster-controlled…
In late December 2012, attackers rigged the Council on Foreign Relations website to silently exploit an Internet Explorer zero-day and…
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
A trusted, decades-respected Kansas community bank CEO was groomed over WhatsApp into a crypto "pig butchering" scam.
A compromised Constant Contact account let Russia-linked Nobelium send USAID-spoofed phishing emails to 150-350 government and NGO organizations.
A complex criminal phishing scheme induced Argan, Inc. to send two outbound wires in March 2023, producing a roughly $3…
Scammers impersonating a school construction contractor sent a forged bank-account-change request, and Cabarrus County.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project.
A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials.
A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…
A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project.