401(k) account takeover fraud drained $751,430 in a single phone call

NEWYou can now listen to Fox News articles!
An imposter called Alight Solutions, the recordkeeper for Colgate-Palmolive’s 401(k) plan, and posed as a Colgate employee. Wanted to update contact information on an account. Months later, the entire $751,430 balance was sent in one go to an address and bank account in Las Vegas. The real owner of the account, Paula Disberry, lived in South Africa.
To get the money back, Disberry sued Alight, Colgate’s charity committee, and BNY Mellon, the company responsible for the scheme. The case was later settled on undisclosed terms. The court never ruled on whether Alight was required to repay the funds.
In February 2026, the Government Accountability Office told the U.S. Department of Labor to issue new guidance on retirement plan participant data. GAO cited eleven separate lawsuits filed between 2009 and 2024 under the Employee Retirement Income Security Act, the federal law that regulates private retirement plans.
Once the account takeover reaches the 401(k), consumer protections governing credit card fraud do not apply.
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent safety alerts and special deals straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit: CyberGuy.com – Trusted by millions of people who watch CyberGuy on TV every day.
- Additionally, you will have instant access to my information. The Ultimate Scam Survival Guide It’s free when you join.
REMOVE YOUR DATA TO PROTECT YOUR RETIREMENT FROM SCAMMERS
A stolen 401(k) shows how one phone call, exposed personal information and poor account switching measures can deplete retirement savings. (Kurt “CyberGuy” Knutsson)
How to empty a 401(k) account?
The Disberry case began when a fraudster called Alight’s Benefits Information Center. He gave the last four digits of Disberry’s name. Social Security numberdate of birth and Alight’s registered postal address. This was enough to clear the call centre’s security check.
He then asked Alight to update the contact information on Disberry’s account. Alight did not send any alerts to Disberry’s registered email address or phone number. Instead, the company issued a temporary password via mail.
Disberry’s plan had a 14-day waiting period between address change and distribution. Alight allegedly skipped this in his lawsuit. Within a few weeks, the fraudster logged in, demanded full payment, and sent a check to the BNY Mellon Las Vegas address.
Why isn’t a 401(k) account takeover an isolated incident?
Heide Bartnett, a former Abbott Laboratories employee, sued Alight over a $245,000 401(k) distribution. It claimed a hacker used the plan portal’s “forgot my password” feature to reset credentials and trigger payment. Other retirement plan record keepers have faced similar cybertheft lawsuits.
The problem extends beyond 401(k) accounts. The FBI’s April 2026 Internet Crime Report found that Americans age 60 and older lost $7.7 billion due to internet crimes in 2025, a 59% increase from the previous year. $3.5 billion of those losses come from investment fraud, making retirement-age savers a prime target for online criminals.
INTO A SCAMMER’S DAY AND HOW THEY TARGET YOU

Compromise of retirement accounts can start with leaked names, dates of birth, partial Social Security numbers and passwords reused from past data breaches. (Kurt “CyberGuy” Knutsson)
How did thieves get into retirement accounts?
Account takeover starts with information someone already has. Names, dates of birth, partial SSNs, and email addresses dark web breach dumpsIt is often combined with leaked passwords from unrelated services. When an account owner reuses a password across accounts, hackers can test that breach data directly on the registrar’s login portal.
Disberry’s acquisition bypassed the login portal entirely. The fraudster never directly logged into Disberry’s account. He called Alight’s call center, used what he knew about Disberry to clear his authentication, and changed his contact information. After that, the temporary password Alight sent went somewhere only the fraudster could get hold of.
Some thieves bypass the registrar and go straight to the account holder. The New York Times documented the case of 76-year-old retired attorney Barry Heitin, who lost $740,000 in 2024 after receiving a call from someone claiming to be a federal fraud investigator. The caller convinced Heitin that his retirement accounts were under attack and directed him to transfer the money himself. He believed he was assisting a federal investigation.
How do you protect your 401(k) and retirement savings?
Federal protections against retirement account theft are limited, but some account-level controls cost nothing and can make takeovers more difficult.
- Hungry multi-factor authentication in the recordkeeper portal. A stolen password is much less useful when a single-use code is required.
- Enable alerts for every account change. Email and text alerts for password resets, contact information updates, address changes, and bank account changes are the first signals that someone else has accessed your account.
- Ask your plan administrator about distribution holds. Some plans impose a waiting period between address change and distribution. Get the policy in writing and confirm what triggered the block.
- Review statements quarterly. A new bank account or a change in contact information is revealed more quickly in quarterly reviews than in annual reviews.
- Get an IRS Identity Protection PIN. You can find the six-digit PIN at: irs.gov/ippinPrevents fraudulent tax returns filed using your SSN.
- Freeze your credit at all three bureaus. A. freeze new accounts to prevent it from being opened on your behalf. Equifax, Experian and TransUnion have offered free freezes since September 2018.
HOW TO STOP FAKE BANK SCAMS BEFORE THEY EMPTY YOUR WALLET

Multi-factor authentication, account change alerts, credit freezes and regular statement reviews can help protect your 401(k) before thieves strike. (Kurt “CyberGuy” Knutsson)
Where identity theft monitoring can help
Account change alerts in the registrar portal only work if the registrar sends them. The Disberry case showed what can happen when these warnings are not sent.
A strong identity theft monitoring service can add another layer of protection by monitoring suspicious activity beyond the retirement plan portal. Some services allow you to link bank, credit card, and investment accounts so you can receive alerts when unusual transactions occur. In a retirement account takeover, this can help flag suspicious money movement even if the custodian misses the outgoing transfer.
Many identity theft monitoring services also monitor changes to your credit reports, scanning the dark web for exposed personal information and searching data broker or person search sites for your details. Some plans also include fraud resolution support and identity theft insurance for affordable recovery costs.
How can you check if your personal information has been exposed?
If you’re not sure whether criminals have already disclosed your information, take action immediately. Start with a free identity breach scan to see if your data appears in known leaks. Early detection gives you greater control and helps you intervene before fraud spreads. You can also check if your personal information is currently being used for identity theft, fraud or appearing on the dark web.
See my tips and top picks for Best Identity Theft Protection at CyberGuy.com
Kurt’s important takeaways
It can feel separate from the everyday fraud risks we hear about regarding retirement accounts, credit cards, email accounts, and bank logins. But this case shows how quickly a 401(k) can become a target if someone has enough personal information to trick the call center or reset account access. The scary part is that a stolen retirement account may not provide the same consumer protections people expect from credit card fraud. This makes prevention and early warning signs even more important. Turn on multi-factor authentication, enable any account alerts your plan offers, and ask your employer or plan administrator what happens after an address, phone number, or bank account change. No one should have to find out months later that their life savings have disappeared. The sooner you detect suspicious activity, the better your chances of stopping the damage before it turns into a financial nightmare.
CLICK TO DOWNLOAD FOX NEWS APPLICATION
Should retirement plans be required to send stronger alerts before any major account changes or distributions, especially when it comes to someone’s life savings? Let us know by writing to CyberGuy.comcyberguy.com
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent safety alerts and special deals straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit: CyberGuy.com – Trusted by millions of people who watch CyberGuy on TV every day.
- Additionally, you will have instant access to my information. The Ultimate Scam Survival Guide It’s free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.




