A North Carolina man drew 121 months in prison for selling the details of more than 7 million elderly Americans to scammers who stole over $9 million.

three people sitting on a bench talking to each other

Troy Murray, a 57-year-old from Hickory, North Carolina, was sentenced to 121 months in federal prison for selling the personal information of more than 7 million elderly Americans to scammers based in Jamaica. The scheme ran from 2016 through 2023, and the stolen data fed fraud operations that caused more than $9 million in losses. Murray was also ordered to forfeit $5,214,688.48 and serve three years of supervised release.

Why Murray’s 121-month sentence signals a shift in data-fraud enforcement

The sentence is one of the longest handed down in a case built around the sale of consumer data rather than the direct execution of scams. Murray did not call victims or collect their money. He compiled and sold lead lists, charging about $500 per batch of 100 to 300 names, and shifted payment methods over time to avoid detection. The buyers then used those lists to target older Americans with sweepstakes and imposter schemes. By prosecuting and sentencing the data supplier as aggressively as the scammers themselves, federal authorities treated the pipeline of personal information as a core component of the fraud, not a peripheral service.

That approach raises a direct question: would tighter restrictions on the sale of modeled consumer lists by data firms reduce elder-fraud complaints in FTC and FBI datasets? A meaningful test would compare complaint volumes in zip-code clusters before and after new enforcement actions over an 18-month window. No such analysis has been published, but the theory has a real-world precedent. Epsilon Data Management LLC, a marketing company, paid a $150 million penalty under a deferred prosecution agreement for selling consumer lists that ended up in the hands of fraud operators targeting seniors. The Epsilon case and Murray’s sentencing together suggest federal prosecutors view the data supply chain as a high-value enforcement target and are increasingly willing to treat list brokers as full participants in criminal conspiracies.

For legitimate data brokers and marketers, the Murray case is a warning shot. Prosecutors did not need to prove that Murray personally lied to victims or handled their funds; it was enough that he knowingly supplied age-targeted data to overseas callers who were clearly engaged in fraud. That theory of liability narrows the safe harbor for companies that sell finely segmented lists without conducting due diligence on who is buying them and how the information will be used.

How Murray built and sold lead lists for seven years

According to Justice Department filings, Murray operated under the alias “Steve Dixson” while selling data to Jamaican-based fraud rings. He assembled lists containing names, phone numbers, and other personal details of Americans aged 55 and older, then sold those lists in small batches. The $500-per-batch price point kept individual transactions low enough to avoid immediate financial scrutiny, while the volume of sales over seven years generated millions in revenue. The court’s forfeiture order of $5,214,688.48 reflects the scale of that income and the central role his lists played in the fraud.

The buyers used the data to contact victims directly, pressuring them into sending money through sweepstakes and lottery schemes that the Justice Department’s Elder Justice Initiative classifies as classic “advance-fee” scams. Callers typically told older adults they had won large prizes but needed to pay taxes, customs fees, or processing charges before receiving their winnings. Because the lead lists were filtered for age and responsiveness, the callers could focus their efforts on people statistically more likely to answer the phone and stay on the line, raising the hit rate for each batch of data.

Murray’s use of an alias and his gradual shift in payment methods-from more traceable channels to harder-to-monitor options-illustrate how data suppliers can adapt to enforcement pressure without fundamentally changing their business model. What ultimately made the scheme vulnerable was not a single large transaction but the accumulation of complaints from victims and the paper trail of repeated list sales to the same overseas customers.

Implications for seniors and their families

The Murray case underscores how little information scammers actually need to cause serious harm. A name, age range, and working phone number were enough to launch high-pressure calls that, in aggregate, cost victims more than $9 million. Families often discover the fraud only after repeated wire transfers or unusual credit card charges have already drained savings.

Consumer advocates say that while aggressive prosecutions can disrupt major data pipelines, prevention still depends heavily on awareness. Older adults and caregivers are encouraged to treat unsolicited calls about prizes, government benefits, or urgent payments with skepticism, to avoid sharing personal details over the phone, and to hang up if they feel pressured or confused. They can also report suspected scams to federal agencies, which rely on complaint data to spot emerging patterns and build cases like the one against Murray.

For practical support, families can turn to resources such as the federal Eldercare Locator, which connects older adults and caregivers with local services, legal aid, and fraud-prevention programs. As prosecutors continue to target the upstream sellers of personal data, those community-level tools remain a critical line of defense for the people most at risk.

Free for readers: The free Retirement Shield newsletter sends plain-English help keeping more of your money in retirement — the scams to dodge, the benefits you’re owed, and what’s changing with Social Security and Medicare, a couple times a week. Get the free newsletter.

Leave a Reply

Your email address will not be published. Required fields are marked *