VERDICT: VERIFIED (V5)
Some pension fraud no longer depends on persuading the saver to make a transfer. The attacker may instead try to convince the pension scheme that they are the saver.
CLAIM
Fraudsters are using hacking and impersonation techniques to gain unauthorised access to pension accounts and attempt to bypass scheme security.
EVIDENCE
The Pensions Regulator (TPR) published an industry alert after an analyst seconded to the National Fraud Intelligence Bureau examined Action Fraud reports received between October 2024 and March 2025. TPR said almost a third of the reports analysed referenced attempts to bypass pension-scheme defences and exploit security vulnerabilities to gain unauthorised access to members’ accounts.
Methods identified by TPR included hacking a member’s email to obtain correspondence with the pension scheme, then impersonating the member and attempting to change beneficiary bank details. TPR also identified attempts involving fake pension accounts, poorly secured credentials and diversion of deceased members’ pension funds. Members aged 50–69 represented 55% of reported victims in the analysis.
TEST
The finding comes from the pensions regulator and is based on analysed fraud reports. The “almost a third” figure applies to the reports in that specific October 2024–March 2025 analysis; it must not be presented as one third of all UK pension fraud.
VERDICT
V5 — Verified. The impersonation/account-takeover technique is directly documented by TPR.
How to prevent it
- Turn on two-step verification for your email and pension accounts where available.
- Use a unique password for the email account connected to your pension.
- Check that your pension provider holds your correct contact details.
- Treat unexpected notifications of changed bank or contact details as urgent and contact the scheme through a known route.
Warning signs
- An unexpected pension notification says your bank, beneficiary or contact details have changed.
- You receive password-reset or login alerts you did not initiate.
- Pension correspondence disappears from or appears unexpectedly in a compromised email account.
What to do if you responded
Contact the pension scheme using independently verified details, ask whether any account, beneficiary or payment instructions have changed, secure the linked email account and change reused passwords. Preserve security alerts and correspondence.
Where to report it
Tell the pension provider immediately. If fraud or attempted fraud is identified, use the appropriate official fraud-reporting route. See Fraud First Aid if money or account access may already be affected.
Source: The Pensions Regulator, “Industry alert: impersonation fraud”, published September 2025 and updated January 2026.
Evidence boundary: the regulator establishes the technique and the characteristics of the analysed reports. TVD is not attributing failures to any particular pension provider.
Leave a Reply