If you’re worried about a parent or grandparent clicking the wrong link, the most useful thing to understand up front is that the biggest losses don’t come from malware at all. They come from someone being talked into sending money or granting access.
$7.75B
lost by Americans 60+ to cybercrime in 2025
Up 59% in a single year
$38,500
average loss per victim
12,400 people lost more than $100,000 each
201,266
complaints filed by people over 60
FBI Internet Crime Complaint Center
Where that money went matters, because it tells you what to actually defend against.
| Category | 2025 losses, ages 60+ |
|---|---|
| Investment fraud | $3.52B |
| Tech / customer support scams | $1.04B |
| Confidence and romance scams | $584M |
| AI-referencing complaints | $352M |
Only one of those is meaningfully a computer problem. That shapes everything below.
Start with DNS filtering — free, and the highest-leverage step
The single best technical control for an older relative isn’t antivirus. It’s blocking known-malicious domains before the browser ever loads them, at the network level, so it works on every device in the house without installing anything on them.
Change the DNS settings on their router to a filtering resolver:
- Quad9 (
9.9.9.9) — free, blocks known malicious domains, no account needed. A sensible default if you want to change two numbers and never think about it again. - OpenDNS Family Shield (
208.67.222.123) — free, adds adult-content filtering on top. - NextDNS — free tier, adds per-category blocking and a log you can review remotely. Worth the extra setup if you want to see what’s actually being blocked.
This catches a large share of phishing and malware-hosting domains automatically, including the link in a text message they’d otherwise tap. It requires no ongoing effort from them, and they will not notice it is there.
The phone is the gap
Router DNS only covers devices on the home Wi-Fi. A phone on cellular data bypasses it entirely — and a large share of scam approaches now arrive by text message, opened on exactly that device.
NextDNS is the practical fix: it installs a configuration profile on iOS and Android that follows the phone onto mobile data. One caveat worth knowing — on the free tier, once the monthly query allowance runs out, NextDNS quietly stops filtering rather than breaking the internet. If you’re relying on it, the paid tier is a few dollars a month.
The browser extension is the other half
The most common tech-support scam is a full-screen browser popup claiming the computer is infected, usually reached through a malicious search ad. Malwarebytes Browser Guard is a free extension for Chrome, Edge, Firefox and Safari that blocks those pages and the ads that lead to them. It’s one of the higher-value things you can put on a relative’s machine in two minutes.
Malwarebytes also sells a consumer suite — Malwarebytes Premium, including mobile apps with scam-text filtering. That overlaps with what we sell, and we’ll say plainly that for a single family computer it’s a reasonable choice and cheaper than us.
Where endpoint protection fits
Everything above reduces the chance of reaching a bad page. Endpoint protection is what catches whatever executes on the machine anyway — a malicious download, a script from a compromised site, ransomware.
What EDR adds over ordinary antivirus, in this specific situation:
- You can see it from your own house. A central console shows whether the agent is healthy, whether something was detected, and what happened — without asking them to describe an error message over the phone.
- It notices if protection gets turned off. A common step in a tech-support scam is talking the victim into disabling their security. Consumer antivirus switched off is silent. A console shows an unhealthy or missing agent.
That second point is the honest reason to consider a managed product for a relative rather than a consumer suite: not better detection, but you being able to check on it without having to ask them anything.
Rollback, and what “properly configured” means
If ransomware does run, SentinelOne can return the machine to its pre-attack state — the encrypted files come back. For someone whose photos have never been backed up, this is the single most valuable thing on the list. It’s also the capability most often described without its conditions, so here they are:
| Condition | Why it matters |
|---|---|
| Windows only | Rollback is built on Volume Shadow Copy Service. macOS and Linux agents remove what a threat did, but can’t restore files this way. On a Mac, plan on backups instead. |
| Snapshots enabled | With enough disk set aside for shadow storage. If VSS is off or the allocation is too small, there is nothing to roll back to. A machine short on free disk is how this quietly stops working. |
| Anti-tamper left on | Ransomware routinely deletes shadow copies first, precisely because it defeats this. Anti-tamper is what’s meant to stop that. |
| Not a backup | Rollback covers the protected endpoint. Not a network drive, a cloud folder, or the old laptop in the closet with no agent on it. |
The part no software fixes
Look back at the chart. Investment fraud and tech-support scams accounted for over $4.5 billion of the $7.75 billion. In both, the victim is persuaded to act. The computer is working perfectly. No antivirus, DNS filter or EDR product intervenes when someone voluntarily wires money or reads out a code.
The FBI also logged more than 3,100 complaints from seniors referencing AI in 2025, with losses over $352 million — voice cloning and convincing fake personas make these approaches harder to spot than the clumsy versions people were warned about years ago.
What actually helps is social, not technical:
- Agree a rule in advance: no financial decision on the same day it’s proposed. Almost every scam depends on urgency. Removing urgency removes most of the leverage.
- Agree that nobody legitimate ever asks for remote access after an unsolicited call or pop-up. Microsoft, Apple, banks and the government do not do this, ever.
- Set up a family code word for “it’s really me” calls, given voice cloning.
- Make it safe to say “I think I got caught.” Shame is why these losses compound — people hide the first one and then chase it. Someone who can call you without embarrassment loses far less.
- Ask to be a secondary contact on their bank account if they’re willing. Banks stop more of this than software does.
If it has already happened
Speed matters more than anything else here, and reporting is free:
- The bank, immediately, before anything else if money has actually moved.
- IC3.gov — the FBI’s complaint centre. For a fraudulent wire transfer, reporting quickly gives the FBI’s Recovery Asset Team its best chance of freezing the funds before they’re gone. Hours matter.
- reportfraud.ftc.gov — the FTC’s reporting site, and where the identity-theft recovery steps live.
- AARP’s scam and fraud resources include a free helpline staffed by people who talk to victims all day and won’t make anyone feel stupid. The FTC’s Pass It On material is written to be shared with older adults without being condescending, which is rarer than it sounds.
A reasonable setup, in order
-
DNS filtering on the router Free · 15 min
Covers every device on the Wi-Fi. Add a NextDNS profile on the phone so it's covered on cellular too.
-
Malwarebytes Browser Guard Free
In whichever browser they use. It targets the exact popup that drives tech-support scams.
-
Automatic updates, an ad blocker, a non-admin account
Unglamorous and effective. Much malware simply fails without admin rights.
-
Endpoint protection with a console you can check
So you find out about a problem without relying on them to report it, and so a ransomware attack on a Windows machine can be rolled back rather than just cleaned up.
-
The conversation Matters most
Urgency, remote access, and the code word. This is the one that covers the $4.5 billion of losses the other four don't touch.
If you want the fourth item for a relative, we license SentinelOne at $7–$10 per endpoint per month with no minimum — one machine is a valid order. See pricing, or the comparison against consumer antivirus if you’re weighing it against Norton or Defender.
Figures from the FBI IC3 annual and elder fraud reports, published 2026. The external products linked here are ones we’d suggest to a friend; we have no commercial relationship with any of them.