Case Library / Pretexting & Impersonation / Phantom Hacker Scam: Milan Jackson / Bank of America Impersonation (Chicago, 2024-2025)

Phantom Hacker Scam: Milan Jackson / Bank of America Impersonation (Chicago, 2024-2025)

A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America, with a spoofed caller ID matching the real number on the back of her bank card, convinced her a hacker was draining her account and that transferring the funds would "protect" them, a case the FBI cites as a textbook "Phantom Hacker" scam.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Milan Jackson, a hairstylist on Chicago's North Side, received a phone call from someone claiming to work for Bank of America who warned her that a hacker was in the process of stealing $20,000 from her account. She checked the caller's number against the customer-service number printed on the back of her genuine Bank of America card, and the numbers matched (the caller had spoofed the bank's real number), which convinced her the call was legitimate. Following the caller's instructions, she logged into her online banking account and wired the full $20,000 to a different account that she was told would keep her money "protected" from the supposed hacker. Afterward she went to a physical Bank of America branch, where staff informed her she had been scammed. ABC7 Chicago published the story on January 16, 2025, with commentary from FBI Special Agent Rachel LaRocque explicitly linking the case to the FBI's "Phantom Hacker" scam alert category (FBI/IC3 PSA 230929, issued Sept. 29, 2023), which describes a multi-stage con typically combining fake tech-support, fake bank employee, and fake government-official impersonation to pressure victims into moving money to accounts the scammers control. Note: Jackson is described in reporting as a hairstylist raising two children and saving to open her own business; no source describes her as elderly or a senior citizen, so the "elder fraud" victim profile typical of the broader Phantom Hacker category does not apply to this specific individual.

How the Attack Worked

The scammer called claiming to be from Bank of America and warned Jackson that a "hacker" was attempting to steal $20,000 from her account. To build trust, the call's caller ID displayed (or the returned/callback number matched) the genuine customer-service number printed on the back of Jackson's real Bank of America card, a spoofing technique that defeats the common-sense advice to "verify the number." Believing the call was legitimate because the number checked out, Jackson followed the caller's instructions: she logged into her online banking account and wired $20,000 to a separate account that the caller said would "protect" her money from the hacker. In reality, that destination account was controlled by the scammer. This matches the FBI/IC3-documented "Phantom Hacker" scam pattern, which typically layers three escalating impersonation stages (fake tech-support, then fake financial-institution employee, then fake U.S. government official) to walk victims through moving money to what they believe is a secure government- or bank-protected account; the publicly reported facts on Jackson's specific case center on the bank-impersonation/spoofed-caller-ID phase and the resulting wire transfer.

The Lure & the Tell

Lure: an urgent, alarming call from someone claiming to be a bank representative, warning that a hacker was actively trying to steal a specific dollar amount ($20,000) from her account right now, creating fear and time pressure; credibility was reinforced because the caller ID/callback number matched the real customer-service number on the back of her actual Bank of America card. Tell (in hindsight): a real bank will never ask a customer to move their own money to another account, via wire or Zelle, to "protect" it from a hacker; instructing the customer to personally initiate a transfer to a "safe" account is itself the scam, not a security measure, and a matching caller ID/phone number is not proof of authenticity since it can be spoofed.

Outcome

Jackson wired the full $20,000 as instructed, then went to a Bank of America branch afterward and was told the call had been a scam. Bank of America told ABC7 that it might attempt to recover the funds but could not guarantee recovery once a client has personally authorized a wire transfer. Public reporting reviewed shows no confirmed recovery of the funds and no publicly disclosed arrest, indictment, or criminal charges tied specifically to this incident. The case became a public-awareness vehicle: it was covered by ABC7 Chicago (Jan. 16, 2025) with commentary from FBI Special Agent Rachel LaRocque, tying it to the FBI's broader "Phantom Hacker" scam alert.

Why It Matters

This case is a clean, widely-cited illustration of two dangerous misconceptions the FBI is actively trying to correct: (1) that a matching caller ID or callback number proves a call is genuine (it can be spoofed even against a number printed on a real bank card), and (2) that "moving your money to a safe account" is ever a legitimate bank security instruction (real banks never ask customers to self-initiate transfers to "protect" funds). It demonstrates how the well-documented, FBI-tracked "Phantom Hacker" scam family exploits institutional trust and urgency to bypass a victim's own verification instincts. Notably, it can succeed against victims outside the scam family's more commonly reported elderly-victim profile, and it underscores that once a victim personally authorizes a wire transfer, recovery is not guaranteed even when the bank is notified promptly, making prevention-focused education the primary defense.

Defenses

FBI/IC3 and Bank of America guidance from the coverage: legitimate financial institutions never call and ask a customer to move money to a "safe" account or via wire/Zelle; caller ID can be spoofed to match a real bank's printed number, so matching the number on the back of a card is NOT proof of legitimacy; never act on unsolicited "hacker on your account" calls; hang up and call the bank back using the number on your card or statement (not a callback number the caller provides or that appears via the same spoofed line); banks cannot guarantee recovery of self-authorized wire transfers, so prevention (not recovery) is the primary control; be skeptical of any instruction to move funds to "protect" them from a hacker, a hallmark of the Phantom Hacker scam family per FBI IC3 PSA 230929.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target and phone-number sourcing: Consistent with the FBI/IC3 Phantom Hacker pattern (PSA 230929), scammers running this scheme typically work from large lists of phone numbers and personal or account data obtained through data-broker records, prior breach dumps, or mass robocalling operations, rather than researching a specific named individual in advance.
Countering Stage 1: Bulk phone-number and personal-data leakage from breaches and data brokers sits largely outside any individual bank customer's or single institution's control, so the realistic control is not stopping the sourcing but hardening the call itself, which is where Stages 3 through 6 below act.
2
Caller-ID spoofing setup: The caller used a spoofing capability, likely a commercial VoIP or spoofing service of the kind FBI guidance on phishing and spoofing warns about, to make the outbound call display Bank of America's genuine, publicly printed customer-service number.
Countering Stage 2: Caller-ID spoofing is difficult for an individual consumer to detect in real time even with carrier-level protections like STIR/SHAKEN in place, so the effective control is not trusting caller ID at all for financial instructions, which is addressed directly at Stage 4.
3
Initial contact and pretext: A scammer cold-called Jackson posing as a Bank of America representative and opened with an alarming claim: a hacker was actively trying to steal a specific dollar amount, $20,000, from her account right now.
Countering Stage 3: FBI/IC3 and bank public-awareness campaigns train consumers that any unsolicited call claiming a hacker is actively draining an account is a known scam pattern, giving people a reason to be suspicious of the call from the first sentence rather than only in hindsight.
4
False verification via spoofed caller ID: Jackson checked the incoming number against the customer-service number printed on the back of her real Bank of America card, saw a match, and concluded on that basis that the call was legitimate, exactly the false-confidence effect FBI Special Agent Rachel LaRocque later warned the public about.
Countering Stage 4: FBI/IC3 guidance explicitly states a caller ID or callback number matching a bank's real published number is not proof of legitimacy because it can be spoofed, and instructs consumers to instead hang up and independently dial the number on their card or statement themselves.
5
Urgency and fear escalation: The caller kept reinforcing time pressure ("we only have this amount of time"), which is documented in Jackson's own account and is a hallmark of the Phantom Hacker script, to keep her moving fast enough that she would not pause to hang up and independently verify.
Countering Stage 5: Consumer-education materials from banks and the FBI flag extreme urgency about moving money immediately as a fraud hallmark, and encourage a hard rule of pausing, hanging up, and consulting a family member or calling the bank back before acting on any such call.
6
Directed self-transfer instruction: The caller instructed Jackson to personally log into her online banking account and wire the full $20,000 to a different account, framed as a step that would "protect" her money from the hacker rather than as a transfer to the scammer.
Countering Stage 6: Bank of America has stated publicly it will never call and ask a customer to move money to a "safe" account via wire or Zelle, so treating any such instruction as an automatic red flag, regardless of how urgent or official the caller sounds, closes off this stage before a transfer is initiated.
7
Fund exfiltration and objective completion: Jackson executed the wire to an account controlled by the scammer; the funds moved out of her control immediately, and public reporting shows no confirmed recovery, consistent with how quickly Phantom Hacker proceeds typically move stolen funds onward once received.
Countering Stage 7: Once a customer personally authorizes a wire transfer, Bank of America has confirmed recovery is not guaranteed even when reported promptly, so the realistic controls at this stage are bank-side anomaly detection and transaction holds on unusual large wires plus rapid IC3/law-enforcement reporting to attempt a recall before funds move further, rather than any control the victim can exercise after the fact.
Quick Facts
Victim
Milan Jackson, Chicago hairstylist
Location
Chicago, Illinois, USA
Date
2024 (exact date not publicly specified; reported by ABC7 Chicago on 2025-01-16)
Impact
$20,000 wired by the victim to an account controlled by scammers; publicly reported as not recovered (Bank of America told ABC7 it might attempt recovery but could not guarantee it once the client had authorized the transfer).
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Financial Services & Insurance
Related

Related Cases

Southern California Edison Utility Disconnection Threat Scam (2025)

Scammers impersonating Southern California Edison used real-time-negotiated "pay now or we shut off your power in 30 minutes" phone and…

Incident 2024Read →

Jeffrey Maas PNC Bank Gold-Conversion Vishing Fraud (West Orange, NJ, 2024)

A retired New Jersey man lost $390,000 in two days after a fake Norton/PayPal refund call escalated into a bogus…

Incident 2024Read →

Forest Blizzard (APT28/Fancy Bear) Uses GPT-4 for Satellite Comms and Radar Tech Reconnaissance

Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar imaging technology…

Incident 2024Read →