The Phishing Hall of Shame: Fake Invoice and Subscription Renewal Scams
This is the fake invoice and subscription renewal phishing scam, one of the most successful and durable tricks in the online con artist’s playbook. It works because it exploits a very human reaction: the urge to fix a problem immediately. The scammer doesn’t need you to click a malicious link. They just need you to pick up the phone.
The setup is deceptively simple. You receive an email that looks like it came from a company you actually use—Norton, McAfee, PayPal, Amazon, Geek Squad, or even a local utility provider. The email bears a realistic logo, proper formatting, and often a fake invoice number. It says you’ve been charged a large sum, usually between $300 and $500, for a renewal or a purchase you never made. Below that is a bolded phone number with wording like “Call immediately to cancel and receive a full refund.” The email may also warn that the charge is pending and will post in 24 hours if you don’t act.
You call. A polite, professional‑sounding person answers. They confirm your name and email address—information the scammer already stole or bought—and express sympathy. They tell you they can reverse the charge, but first they need to “verify your identity.” That means asking for your bank account number, your credit card details, or, more often, remote access to your computer. They’ll guide you to download software like TeamViewer or AnyDesk. Once they have control, they can see your online banking logins, transfer money, or install malware that steals passwords for months to come. If you resist giving remote access, they pivot to a refund via “excess payment” trick: they claim they accidentally refunded you $2,000 by mistake and need you to send back the difference via wire transfer or gift cards.
Why does this scam target middle‑aged Americans so effectively? Because you have subscriptions. You’re likely managing antivirus software, streaming services, cloud storage, and online shopping accounts. You’re busy, you’re responsible, and you don’t want to be overcharged. Scammers know that people in their late forties to mid‑sixties often handle household finances and feel a strong sense of duty to correct billing errors. They also know you’re less likely to second‑guess an official‑looking email that mentions a brand you trust. The urgency—the threat of a large pending charge—short‑circuits your usual skepticism.
Real cases are everywhere. In a common variant, victims receive a fake email claiming their Apple ID was used to purchase a $250 gift card. The email includes a number to call if they didn’t authorize the purchase. When they call, the “Apple support” agent asks for the six‑digit code sent to their phone—actually a two‑factor authentication code that lets the scammer reset the Apple ID password and lock them out. Another version targets Geek Squad customers: an email says a three‑year tech support plan for $399 has been auto‑renewed, and the phone number connects to a scripted scammer who eventually demands payment in Best Buy gift cards.
Red flags are plentiful if you know where to look. The email address of the sender is almost never the real domain—it might be `support@norton‑billing.com` instead of `norton.com`. The greeting may be generic like “Dear Customer” instead of your actual name. The dollar amount is always an odd, high number designed to shock. Legitimate companies don’t send invoices for large renewals without prior notification, and they certainly don’t ask you to call an 800 number listed only in the email. Real customer service will never demand remote access to your computer to process a refund. And no legitimate business asks for payment via gift cards, cryptocurrency, or wire transfer.
If you receive such an email, do not call the number. Do not reply. Do not click anything. Instead, open a fresh browser tab and go directly to the company’s official website. Log into your account and check your billing history. If there’s no charge, ignore and delete the email. Forward it to the Federal Trade Commission at reportfraud.ftc.gov and to the company’s abuse email address (like `abuse@norton.com`). Then block the sender.
The golden rule for this scam is simple: never act on a financial alert that arrives unsolicited. Pause. Breathe. Verify through a channel you trust, not the one the email hands you. The scammer’s entire script relies on your panic. Starve them of it, and they have nothing.


