Skip to content
Breachfolio
"Your antivirus renewed for $499": do not call the cancellation number
GUIDES · PAYMENT FRAUD

"Your antivirus renewed for $499": do not call the cancellation number

Already called or installed something? Do this first

End the call. If you installed a remote-access tool, disconnect the device from the internet and uninstall it before doing anything else.

The invoice looks real. The phone call is the actual attack.

July 11, 20267 min readDaniel A. & Óscar S.

The email looks exactly like an invoice: an order number, a date, a familiar antivirus brand, and a charge for hundreds of dollars. To cancel it, the message insists you must call within 24 hours, but the phone call is the real target of the scam, not the invoice itself. Both Norton and McAfee document these exact emails, complete with fake invoices and fabricated cancellation numbers, and the FTC has separately warned about fake technology-subscription renewal notices. The high dollar amount creates fear, the tight deadline blocks you from verifying calmly, and the phone number connects you to a fake support agent rather than the real company.

This mirrors a pattern common to invoice-based scams generally: the message doesn't need to be technically sophisticated, it only needs to create enough fear about an unexpected charge and offer a single, artificially urgent channel to "resolve" it. Genuine renewal notices, by contrast, are usually handled entirely inside your account dashboard, with routine billing emails that don't threaten a fast-approaching deadline or demand a phone call just to cancel. If a message insists that calling is the only way to stop a charge, that structural detail alone is worth treating as suspicious before you even evaluate anything else about it.

What happens when you call

The person who answers will typically claim they need to locate the charge or process a refund, and may ask you to install AnyDesk, TeamViewer, or another remote-access tool so they can "help" from their end. Once they have control of your screen, they'll often direct you to open online banking, then stage a fake refund that looks like it overpaid you, and demand you send the "excess" back, which is the actual theft. Other variations skip remote access entirely and just ask for your card number, account credentials, or a one-time SMS code, or push you toward gift cards. What's presented as a routine cancellation process is really designed to end in stolen money and, in the remote-access version, a compromised device.

How to check whether the charge is real

Don't open the attachment and don't use the phone number printed in the message. Instead, type the official antivirus provider's address into your browser yourself and log into your actual account to review subscriptions, billing history, and auto-renewal status. Then separately check your card or bank statement for the charge. If no charge shows up anywhere, there is nothing to cancel: the email can simply be deleted and reported.

Warning signs on the invoice

  • An unusually high renewal amount
  • A phone number presented as the only way to cancel
  • A 24-48 hour deadline pressuring quick action
  • An unexpected PDF or attached document
  • A sender address outside the company's official domain
  • Wrong currency, product name, or customer details
  • A request to install software or open your online banking
  • A "refund" process that requires remote access to your computer

If you already called or installed something

End the call. If you installed a remote-access tool, disconnect the device from the internet and uninstall it before doing anything else. From a different, trusted device, change any passwords that may have been visible during the session. Contact your bank using its official number (never one given during the call) and explain that a third party may have viewed or controlled your online banking. Keep the fake invoice, the phone number used, and any related receipts, and report unauthorized access or financial loss to your bank and, if money was lost, to local authorities.

It's also worth building a habit that prevents this scam from working the next time it lands in your inbox: bookmark the official login page for your antivirus provider directly, rather than relying on search results or links in emails, and check your renewal date and billing history there every so often rather than waiting for an email to prompt you. A password manager that only autofills credentials on the real, saved domain provides a similar layer of protection, since it simply won't offer to fill anything on a lookalike page. None of this requires trusting any single email – it just removes the email as the thing you have to make a judgment call about in the moment.

The browser popup version

A related version of this scam doesn't arrive by email at all – instead, a webpage triggers a barrage of popups claiming your device is infected, styled with a real antivirus logo and a support number. Don't call the number or click anything inside the alert; close the tab or force-quit the browser instead. Afterward, review your browser's notification permissions and installed extensions for anything you don't recognize, since some versions of this scam trick people into granting persistent notification access.

Variants you'll run into

The fake invoice comes in more flavors than the classic $499 email, and recognizing the shared skeleton matters more than any single version. A "your subscription auto-renewed" text message compresses the same script into two lines and a callback number. A voicemail from "the billing department" reads out a charge and asks you to call back to dispute it. A "your protection has expired" email flips the fear from an unwanted charge to an unprotected computer, pushing a fake renewal page that harvests your card instead of a phone call. Some versions impersonate the antivirus brand you actually use – a coincidence made likely by how few major brands exist – while others name a product you've never owned, betting you'll call just to insist you never subscribed.

Watch for the refund-first variation, which inverts the usual order: the message says you're owed money back for an overcharge or a class-action settlement, and the "refund agent" on the phone follows the same remote-access playbook. And note the seasonal pattern: these campaigns spike around tax season, major shopping holidays, and the start of the year, when unexpected charges feel most plausible and most urgent.

How it plays out: a realistic example

Consider Frank, a retired teacher who does his banking online but leans on his son for anything technical. An invoice lands in his inbox: "McAfee Total Protection – annual renewal – $479.99. To cancel, call within 24 hours." Frank doesn't remember buying McAfee, which is exactly why he panics: an unfamiliar charge feels more alarming than a familiar one. He calls. A calm, professional-sounding agent "locates" the charge, apologizes, and offers an immediate refund. To process it, Frank just needs to install a small support tool and log into his bank so the agent can "confirm the deposit."

On the screen, a refund of $4,799.90 appears – ten times the invoice, presented as a typo by the agent, who becomes distressed and says he'll lose his job unless Frank wires back the difference. The refund was never real; the agent edited the page's numbers while controlling the screen. The entire performance exists to make Frank send his own money voluntarily, which is far harder to reverse than a fraudulent charge. Frank hesitates, tells the agent he wants to check with his son first, and hangs up over loud protests. That pause is the whole lesson: no legitimate refund ever requires remote access, secrecy, or urgency, and anyone who resists you taking a moment to verify is telling you what they are.

Prevention habits that close the door

A few structural habits make this scam category fail on arrival. First, know what you actually subscribe to: keep a simple list of your paid software and their renewal months, or scan your card statement once a month for recurring charges. When you know your antivirus renews in March through your account dashboard, a surprise July invoice self-identifies as fake. Second, turn on transaction alerts with your bank or card issuer: a real charge triggers a real notification, so an invoice with no matching alert is noise.

Third, make a personal rule that no phone call ever begins from a number inside an email, popup, or text. If you feel the need to talk to a company, find the number through its official website that you typed into the browser yourself. Finally, have the conversation with the people most likely to be targeted – older relatives who pay for antivirus software and answer their phones. Agree on a family rule: any message about money gets a second opinion before any call, click, or install, and no one is ever "in trouble" for asking. If money was lost, report it to the FTC and file a complaint with the FBI's Internet Crime Complaint Center (IC3), in addition to calling the bank immediately.

Quick checklist

  • Never call a number printed inside an unexpected invoice email
  • Check your subscription by logging into the official site directly
  • Compare the charge against your actual card or bank statement
  • Never install remote-access software because a caller asked you to
  • Never send money back after a "refund" you didn't request
  • Disconnect and uninstall remote-access tools immediately if you're unsure
The one-sentence version. A scary invoice with a phone number as the only way to cancel is the scam – verify any renewal by logging into the official antivirus account yourself, never by calling the number in the email.

Frequently asked questions

Can a real antivirus renewal cost hundreds of dollars?
Prices vary, but the amount on an invoice doesn't authenticate it – always verify your subscription independently through the official account.
Do I need to open the attached PDF to check the charge?
No. Go directly to the official antivirus website and check your subscriptions and billing history instead.
What should I do if the caller saw my online banking?
Contact your bank immediately from a safe, uncompromised device and explain that a third party may have viewed or controlled the session.
Who writes this

Daniel A. and Óscar S. run Breachfolio, a small independent site about security and AI. This article was drafted with AI assistance and reviewed by a person before it went live. We write from documentation, vendor sources and published research rather than from original lab benchmarks, and we link a source in the sentence that relies on it. How we work · About us