Scammers targeting veterans: How to stay protected
The Department of Veterans Affairs is warning that scammers are becoming increasingly sophisticated in their attempts to steal personal information, money, and benefits from veterans who rely on VA services. According to VA's Office of Information and Technology, criminals are now using advanced tactics including AI-generated deepfakes, phishing schemes, and fake websites that closely mimic official VA pages to exploit the trust veterans place in the department.
Scammers target veterans because they know many depend on VA for critical healthcare, disability compensation, and other benefits that require sharing sensitive personal information. The goal of these criminals is always the same: to trick veterans into revealing Social Security numbers, banking details, dates of birth, or login credentials that can be used to steal identities or divert benefit payments. In April 2025, VA identified and shut down two fraudulent websites ending in "va.com" and "va.biz" that were designed to look nearly identical to the official VA.gov site and were being used for phishing attacks and spreading malicious software.
These scams affect all veterans who interact with VA services, regardless of disability rating or enrollment status. Any veteran who receives VA healthcare, disability compensation, pension benefits, or uses online VA portals is a potential target. Family members and caregivers can also be victimized, particularly through voice-cloning scams where criminals use AI to mimic a relative's voice and fake emergencies or kidnappings to demand ransom payments.
The three most common tactics scammers use are phishing, deepfake impersonation, and typosquatting. Phishing involves fake emails or messages that appear to come from VA, often creating a false sense of urgency about problems with medical records or benefits. Deepfake impersonation uses AI to create realistic fake voices or videos of VA representatives, bank employees, or family members requesting sensitive information. Typosquatting relies on creating website addresses with slight misspellings of legitimate VA URLs, hoping veterans will accidentally land on fraudulent sites and enter their login credentials.
For disabled veterans, these scams pose particular risks because many rely heavily on consistent benefit payments for basic living expenses and medical care. A successful scam that diverts disability compensation or compromises VA healthcare access can create immediate financial hardship and disrupt critical treatment. The increasing sophistication of these schemes means that even tech-savvy veterans can be fooled by realistic-looking emails, convincing voice calls, or professional-appearing websites that seem legitimate at first glance.
Veterans can protect themselves by following several straightforward practices. Always slow down when any message or call demands immediate action, and verify requests independently by contacting VA directly through the official VA.gov contact page rather than using phone numbers or links provided in suspicious messages. Check website addresses carefully for misspellings before entering any information, and never share passwords, Social Security numbers, or banking details in response to unexpected communications. Enabling multi-factor authentication on VA accounts adds an important extra layer of security. Veterans who believe they've been targeted should report incidents to the VA Inspector General hotline, the FBI's Internet Crime Complaint Center, or the Federal Trade Commission's reporting system at ReportFraud.ftc.gov.
If something feels wrong about a call, email, or website, trust that instinct and take time to verify before responding. Staying informed about emerging scam tactics and checking periodically with trusted sources like the Cybersecurity and Infrastructure Security Agency or VA's official communications can help veterans stay one step ahead of criminals who continue to develop new methods of exploitation.