Retirement savings are increasingly becoming a target for fraudsters, prompting a new warning from the UK’s pensions watchdog. The Pensions Regulator (TPR) has raised concerns after reports revealed that around £500,000 has already been stolen from pension funds, with an additional £2.5 million potentially at risk between 2021 and 2025.
Authorities say criminals are using stolen personal data to bypass security checks, allowing them to access pension accounts and redirect funds. The warning highlights a growing problem within the pension system and calls for stronger security measures from both pension providers and savers.
Warning
The Pensions Regulator issued an alert to more than 35,000 pension professionals across the UK. The aim is to encourage administrators, trustees, and financial institutions to strengthen identity verification and monitor suspicious activity more closely.
According to the regulator, fraudsters are increasingly exploiting weaknesses in verification systems. By using stolen personal information, they are able to impersonate pension holders and gain control over accounts.
Once access is obtained, criminals may change payment instructions, transfer funds, or open new accounts in the victim’s name.
Losses
Investigations have shown that significant sums have already been stolen from retirement savings.
| Period | Estimated Loss |
|---|---|
| Confirmed losses | £500,000 |
| Potential risk (2021–2025) | £2.5 million |
These figures come from reports submitted to authorities by pension administrators and trustees. Officials believe the actual losses could be higher because some cases may go unreported.
The regulator noted that retirement funds are particularly attractive targets because they often contain large amounts accumulated over decades.
Methods
Fraudsters use several techniques to obtain the personal information needed to access pension accounts.
Common methods include:
- Compromised email accounts
- Intercepted postal communications
- Phishing messages requesting personal details
- Data breaches exposing personal records
Once criminals collect enough information, they can pass identity verification checks used by pension providers.
In some cases, scammers create duplicate pension accounts in a victim’s name and transfer funds into them before withdrawing the money.
Access
After gaining control of a pension account, criminals can make changes that are difficult to detect immediately.
Typical fraudulent actions include:
| Fraud Tactic | Description |
|---|---|
| Bank detail changes | Redirect pension payments to new accounts |
| Account transfers | Move pension funds to new schemes |
| Fake accounts | Open duplicate accounts in victim’s name |
| False death claims | Claim funds by reporting a fake death |
Because these actions may appear legitimate within the system, victims sometimes discover the fraud only after funds have already been withdrawn.
Industry
Gaucho Rasmussen, executive director for enforcement and legal at the Pensions Regulator, warned that criminals are persistent in targeting retirement savings.
He emphasized that pension professionals play an important role in preventing fraud.
According to the regulator, around 90 percent of the intelligence used to issue the alert came directly from pension trustees and administrators who reported suspicious activity.
This collaboration between industry professionals and authorities is considered essential for detecting and preventing scams.
Cooperation
The warning was issued in partnership with the City of London Police, which operates the UK’s national fraud reporting platform known as Report Fraud.
Chris Bell, service delivery director at the City of London Police, said cooperation between financial institutions, regulators, and the public is essential to reduce the risk of pension fraud.
The Report Fraud platform allows individuals and organisations to report suspicious activity, helping authorities identify patterns and warn the public.
Officials say each report contributes valuable information that helps strengthen fraud prevention across the pension system.
Trends
Authorities also reported an increase in impersonation fraud cases during 2025 involving UK pension holders living in Africa. However, regulators stress that the risk is not limited to any single region.
Pension savers around the world could be targeted if criminals gain access to their personal data.
The main fraud techniques observed include identity theft, weak passwords, fake duplicate accounts, and fraudulent claims related to death benefits.
These trends highlight the importance of stronger security practices for both pension providers and individual savers.
Protection
The Pensions Regulator is urging pension schemes to review their security procedures and strengthen identity verification processes.
Recommended measures include:
- Improving identity verification checks
- Strengthening data protection systems
- Encouraging two-step verification
- Promoting stronger account passwords
Savers are also advised to remain cautious when receiving unsolicited communications requesting personal information. Even messages that appear legitimate should be carefully verified before sharing sensitive details.
Anyone who suspects their pension account may have been targeted is encouraged to report the incident immediately through the Report Fraud service online or by phone.
The warning highlights the growing importance of protecting retirement savings in an increasingly digital financial environment. As pension funds continue to accumulate over time, authorities say stronger safeguards and vigilance will be necessary to reduce the risk of fraud.
FAQs
How much pension money has been lost to fraud?
About £500,000 has been reported lost so far.
What is the potential pension fraud risk amount?
Authorities say up to £2.5 million may be at risk.
What is the Report Fraud service?
A UK platform run by City of London Police to report scams.
How do pension fraudsters access accounts?
Often through stolen personal data or identity theft.
How can savers protect their pension accounts?
Use strong passwords and enable two-step verification.















