An antivirus renewal invoice? Do not call the number provided to cancel it
A message claims you are about to pay a large fee for software you do not remember buying. Check the real account before asking a scammer for a refund.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 15 September 2026
- READING TIME
- 7 min read
- TOPIC
- Human Security
An invoice arrives for the automatic renewal of antivirus software or a technical-support plan. The amount is high, the company name is familiar and the message gives you 24 hours to cancel. The largest instruction does not lead to an account page. It tells you to call immediately.
Wanting to stop the charge is entirely reasonable. The scammer relies on you treating the number in the message as a billing department. The supposed transaction may not exist at all.
First check whether any money was actually taken
Do not reply, open the attachment or use the supplied number. Open your banking or card app independently and review recent transactions. Visit the relevant service directly to see whether there is an active subscription.
If there is no transaction and no subscription, there is nothing to cancel through the message. Report it as phishing and remove it after reporting. Do not call “just to make sure”, because the conversation is the next stage of the trap.
If a charge really appears, contact the bank or company using details from its official app, an earlier agreement or a website address you entered yourself. Do not rely on information contained in the document you are trying to verify.
The “refund” can become a request to control your computer
After you call, the fake agent may ask you to install remote-support software. They claim they need to find the transaction, complete a refund form or remove the renewed licence. Next, they encourage you to open online banking, provide card details or enter a refund amount on a page they control.
The screen may then show an apparent mistake: instead of a £100 refund, for example, you see £1,000. The caller says they will lose their job unless you immediately return the difference by transfer, gift card or cryptocurrency. The balance may only be a manipulated display, with no excessive refund ever made.
A genuine billing dispute does not require an agent to watch you sign in to your bank. Do not install a tool from their link or share an authorisation code.
If you already made the call
Calling alone does not mean the account has been compromised. End the conversation, ignore return calls and record the message, number, time and identity used by the caller.
If you supplied card details, authorised a payment or opened banking during a remote session, contact your bank immediately through a genuine channel. Use another trusted device. Ask the bank to secure the card and account and review suspicious activity.
If somebody controlled the computer, disconnect it from the network and tell workplace IT or a trusted service you found independently. Change exposed passwords on a checked device, beginning with email. Removing the remote-access program alone cannot establish that nothing else changed.
A fake invoice can reach anyone at work
The message may arrive in finance, reception or with an employee who genuinely buys software. The process should not depend on one person remembering every supplier. A shared subscription register, a named service owner and independently sourced billing contacts provide a simple check.
Employees should also know that making the call is not a reason to conceal the incident. A prompt report allows the organisation to determine whether remote access or a payment occurred.
What the source confirms and what Breachroad recommends
The US Federal Trade Commission describes fake invoices and technical-support subscription renewals. The messages use familiar company names, claim a large renewal charge and demand a quick call to dispute it. According to the FTC, the call may lead to remote access, a fake refund and a demand to repay a supposed overpayment. The source describes a pattern reported in the United States, not a specific campaign in every country.
Breachroad recommends beginning with the real account statement, not the invoice email. If there is no charge, there is nothing to cancel through a suspicious number. If the scammer saw or controlled your screen, follow our guide to responding after a fake remote-support session. Organisations can rehearse these decisions through cybersecurity awareness training.


