TL;DR: Elder financial exploitation detection is the practice of identifying the illegal or improper use of an older adult's funds, which FinCEN separates into elder scams committed by strangers and elder theft committed by trusted persons. FinCEN received 155,415 EFE-related BSA reports between June 2022 and June 2023, tied to roughly $27 billion in reported suspicious activity. Detection is structurally difficult because most of these transactions are authorized by the customer and run through channels a generic fraud rule reads as normal.
Two Crimes, One Checkbox

Elder financial exploitation is the illegal or improper use of an older adult's funds, property, or assets, with older adults typically defined as those aged 60 or over. FinCEN divides it into two categories that behave nothing alike. Elder scams involve transferring money to a stranger or imposter for a promised benefit the older adult never receives. Elder theft involves someone the older adult knows and trusts — an adult child, a professional caregiver, the holder of a power of attorney — taking their assets, funds, or income.
Both land in the same SAR checkbox. They do not produce the same evidence.
FinCEN's Financial Trend Analysis, published in April 2024, attributed roughly 80 percent of EFE-related filings to scams and 20 percent to theft. FinCEN was explicit that the split reflects filing behavior rather than incidence — theft is underreported precisely because the perpetrator is trusted and the activity resembles routine account use. Adult children were the perpetrator in nearly 40 percent of the theft filings FinCEN reviewed manually.
The Signals That Live Outside the Monitoring System
FinCEN's 2022 Advisory on Elder Financial Exploitation sets out two red flag categories, and only one is visible to a transaction monitoring system. The financial red flags are conventional data problems: dormant accounts with large balances beginning constant withdrawals, bulk gift card purchases, and wire memos reading "tech support services" or "winnings."
The behavioral red flags are observational. A customer appears distressed or cannot answer basic questions about their own account activity. A customer takes direction during a transaction from someone on a cell phone and will not hang up. A caregiver answers for the customer or will not leave their side. Power of attorney shifts suddenly to a new individual.
These are the highest-signal indicators available for elder theft, and in most institutions they are captured nowhere. FinCEN asks specifically that behavioral red flags and the names of the staff who witnessed them appear in the SAR narrative, which requires a path for a frontline observation to reach an investigator. Building that path is often the largest available detection improvement, and it requires no model changes. A customer who mentions that an online partner has asked them to receive and forward payments is describing mule account activity alongside their own victimization.
Why Generic Fraud Rules Miss Elder Exploitation
Standard fraud controls are built to detect unauthorized activity, and most elder financial exploitation is authorized. The customer initiates the wire. Credentials are correct, the device is recognized, and step-up authentication passes because the customer completes it. Every control designed to confirm the account holder's identity returns yes. The question that matters — whether the customer understands who benefits — is not one an authentication stack can ask.
The second gap is legitimate access. In elder theft the perpetrator frequently holds credentials, a card, a checkbook, joint signing authority, or a power of attorney. FinCEN found that theft perpetrators made little effort to obfuscate payments, writing themselves checks or paying their own bills through online bill pay. What changes is who the money serves, which is invisible to rules that score transactions rather than relationships.
The third gap is baseline design. Older customers often present long, stable, low-variance histories, so a meaningful deviation can still be small against the thresholds most rules use. A dormant account producing steady withdrawals is a strong signal that a threshold-based rule treats as unremarkable until the aggregate crosses a dollar amount. Behavioral baselining rather than static thresholds is the fix.
Perpetrators also favor channels that avoid staff contact: peer-to-peer transfers, ATMs, and convertible virtual currency kiosks. Institutions that concentrate their controls at the teller line are watching the channel perpetrators deliberately avoid. Because the same activity implicates fraud, BSA, and consumer protection functions at once, the case for converging fraud and AML operations is unusually direct here.
Reporting: SAR Mechanics and the Senior Safe Act

An EFE SAR is filed like any other SAR, with two additions FinCEN requests specifically: filers mark the Elder Financial Exploitation checkbox in Field 38(d), and include the key term "EFE FIN-2022-A002" in Field 2, the Filing Institution Note to FinCEN, and again in the narrative. FinCEN uses those markers to isolate the EFE population for trend analysis, so an unmarked filing is invisible for policy purposes however strong its narrative.
The narrative carries the weight, and the discipline behind a SAR narrative an investigator can act on matters more here than in most typologies, because the behavioral context is the evidence. Institutions may also file voluntarily below the $5,000 mandatory threshold, or $2,000 for money services businesses. Reporting to law enforcement or Adult Protective Services runs in parallel and does not relieve the filing obligation.
The Senior Safe Act, enacted in May 2018, gives covered institutions and eligible employees immunity from liability in any civil or administrative proceeding for disclosing suspected exploitation of a senior citizen to a covered agency. The immunity is conditional: the employee must have completed training on identifying and reporting exploitation before making the report, and the report must be made in good faith and with reasonable care. As the Senior Safe Act fact sheet from the SEC, FINRA, and NASAA notes, the statute mandates neither reporting nor training — it makes the safe harbor contingent on the training. An institution that cannot evidence completion cannot rely on the protection.
Holds, Trusted Contacts, and the Limits of Intervention
Detection without an intervention playbook produces reports and no prevented losses. The Interagency Statement on Elder Financial Exploitation, issued in December 2024 by the Federal Reserve, CFPB, FDIC, FinCEN, NCUA, OCC, and state regulators and revised in June 2026, sets out practices across nine areas. It establishes no compliance standard and imposes no new supervisory expectations, making it a benchmark rather than a rule to satisfy.
Transaction holds are the primary intervention. Some state laws permit institutions to temporarily hold a transaction or delay a disbursement when exploitation is suspected, generally with specified timelines and sometimes immunity. The authority is state-specific, so a multi-state institution needs a hold matrix rather than a single procedure. Holds carry their own risk: the interagency statement points to enforcement actions over restrictions on account access, and notes that policies must not produce age discrimination impermissible under the Equal Credit Opportunity Act. A hold applied on documented grounds, within a statutory window, with a path for the customer to establish legitimacy, is defensible. A hold applied because a customer is old is not.
Trusted contact designation is the lower-friction complement. An account holder nominates someone — a family member, attorney, or accountant — whom the institution may contact if it cannot reach the account holder or suspects exploitation. Absent separate authorization, that contact cannot view accounts or transact, and SAR confidentiality still applies. Credit unions filed 8 percent of EFE-related reports in FinCEN's review period, which makes resourcing at smaller institutions the practical constraint on program design.
How to Evaluate an Elder Exploitation Detection Program
Seven capabilities separate programs that detect elder financial exploitation from programs that only document it.
One measure sits above the rest: how often the institution stops a payment rather than reports one. That depends less on model sophistication than on how fast a behavioral observation travels from the person who made it to someone authorized to place a hold. Scale is moving against manual review — according to the FBI's Internet Crime Complaint Center, victims over 60 filed more than 201,000 complaints in 2025 with reported losses above $7.7 billion, up 59 percent against 2024.
Where Sphinx Fits
Sphinx operates at the investigation and triage layer, automating the analyst work that follows an elder exploitation alert. Agents assemble the account history, prior behavioral notes, related parties, and payment chain into a single case file, apply the EFE checkbox and key term controls, and route judgment calls — a hold decision, an APS referral — to a human analyst. Every recommendation is logged and explainable, and analysts retain override authority. In elder financial exploitation, the interval between first signal and decision determines whether funds are recoverable.
Frequently Asked Questions
What is the difference between elder scams and elder theft?
Elder scams involve transferring money to a stranger or imposter for a promised benefit that never arrives — tech support, romance, and investment scams among them. Elder theft involves a trusted person, most often an adult child or caregiver, taking the older adult's funds. FinCEN attributed roughly 80 percent of EFE-related filings to scams and 20 percent to theft.
Is a bank required to file a SAR for suspected elder financial exploitation?
Yes, where the activity meets the standard mandatory SAR criteria, including the $5,000 threshold for most institutions and $2,000 for money services businesses. Institutions may also file voluntarily below those thresholds. FinCEN requests that filers mark the Elder Financial Exploitation checkbox in Field 38(d) and include the key term "EFE FIN-2022-A002" in Field 2 and the narrative.
What does the Senior Safe Act protect?
The Senior Safe Act gives covered financial institutions and eligible employees immunity from liability in any civil or administrative proceeding for disclosing suspected exploitation of a senior citizen to a covered agency. It requires training on identifying and reporting exploitation beforehand, and a report made in good faith and with reasonable care. The safe harbor is unavailable without the training.
Can a bank place a hold to stop suspected elder exploitation?
Some state statutes permit institutions to place a temporary hold on a transaction or delay a disbursement when exploitation is suspected, generally within specified timelines and sometimes with immunity. The authority is state-specific rather than federal. Regulators have taken enforcement actions over restrictions on account access, and hold policies must not produce age discrimination impermissible under the Equal Credit Opportunity Act.
Why don't standard fraud rules catch elder financial exploitation?
Because most of it is authorized activity. The customer initiates the payment and authentication passes, so controls built to detect account takeover return nothing. In elder theft the perpetrator often holds a card, checkbook, or power of attorney, so there is no unauthorized access to detect. Detection depends on customer-specific baselines, monitoring of changes in account authority, and structured capture of frontline observations.

.png)