Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

A message says your power will be disconnected tomorrow? Check the bill outside the message

A tiny balance and same-day shutoff threat are designed to trigger a fast click. Learn how to verify the account and pay a real bill safely.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
19 September 2026
READING TIME
14 min read
TOPIC
Human Security
A message says your power will be disconnected tomorrow? Check the bill outside the message

“Your account is short by 6.42. Power will be disconnected tomorrow. Pay now.” The message carries the utility logo, an agreement number and a short link. The amount is so small that paying seems more sensible than risking a defrosting refrigerator, failed heating or business interruption.

That is why the scenario works. The scammer does not want you to examine a bill. They turn a tiny amount into an urgent problem and lead you to a page that steals card or banking details, or approval for a much larger transaction. Sometimes a “collections department” calls after the text and walks you through payment by code, app or cryptocurrency.

You can have a genuine overdue balance and receive a fraudulent message at the same time. The safe response is not “ignore every bill.” It is “verify the balance and pay through a channel you opened independently.”

Separate two questions: is there a debt, and is the message genuine?

Remembering a late bill does not authenticate the sender. Criminals send messages at scale and rely on some recipients using the named company, moving home, changing tariffs or waiting for an adjustment.

Conversely, the wrong supplier name does not establish that your account is current. In many markets, the energy retailer and network operator are different organizations. Identify the company on your agreement first, then check the balance in a known customer portal or on a recent bill.

Verify three elements separately:

  • the balance — whether the amount actually appears on your customer account;
  • the sender — whether the contact came from an organization you use;
  • the payment route — whether the account and site match the official channel.

One matching element does not confirm the others. A real amount can be quoted in a fake link, and a genuine logo can sit above a scammer’s payment account.

Do not tap the link, button or QR code. Do not reply or call the number in the message. Capture the complete text or email so the sender, time, wording and visible link are preserved without opening it.

Then:

  1. Open the provider’s app from its icon or type the customer-portal address you already know.
  2. Review the balance, payment history, invoice numbers and notices on the account.
  3. Compare the payment account with a genuine earlier bill, not with the text message.
  4. If uncertainty remains, call the number on the bill, agreement or official app.
  5. Ask specifically about the amount, due date and agreement status rather than merely asking an agent to judge the suspicious link.

If you have no app or bill, type the company’s site address yourself. Watch for paid search adverts impersonating customer service. Compare the domain with earlier documents and correspondence.

Why a small amount is not a small risk

A token balance lowers your guard. The fake page may display the correct 6.42, but its form captures complete card details, a password or authorization code. In another version, the banking screen presents a different amount or permission to add a recipient, device or service.

Do not approve an operation based on what the merchant page displayed. Read the bank’s own message: the amount, recipient and type of permission. A text-message code does not “confirm customer identity”; it authorizes exactly what the bank message describes.

If the form rejects payment, do not try another card. The “error” may be intentional: the attacker already received the first details and wants a second set. Close the page and contact the bank if you entered financial information.

Warning signs that should stop the payment

  • disconnection is supposedly happening within hours or the next day;
  • the message names a tiny uneven balance and includes a shortened link;
  • the sender insists on an instant-payment code, gift card, payment app, cryptocurrency or fast transfer through its page;
  • a caller tells you not to hang up or claims ordinary support cannot see the case;
  • you must provide a username, password, complete card number or text code to “cancel the shutoff”;
  • the payment account differs from the one on your bill;
  • the site uses a lookalike rather than the provider’s exact domain;
  • it names the network operator even though you pay a different retailer;
  • someone visits the premises and demands cash without allowing independent confirmation;
  • a second “reconnection fee” or “deposit” appears after payment.

Professional language, correct spelling and a sender name instead of a number do not remove the risk. Caller and message identifiers can be spoofed, and a fraudulent text may appear in an existing message thread.

If the overdue balance is genuine

Do not use the suspicious message merely because the amount matches. Pay through the official portal or with the account information on a verified bill. If you cannot pay the full amount, contact the provider using a known number and ask about options available in your location. A scammer exploits fear and embarrassment; a real account issue requires a conversation with the real company.

Request a case number and written confirmation through the customer portal or post. Do not accept a payment plan from the person who called from the message number. If the agreement is held by a landlord, relative or company, verify together without sharing passwords.

Distinguish planned network maintenance from service action related to billing. An outage or scheduled engineering work is checked through the network operator’s official map, while the balance is checked with the retailer. A fraudulent message may deliberately blur those issues.

When an employee, receptionist or tenant receives the threat

A restaurant, shop, clinic or workshop cannot easily tolerate loss of power. Fraudsters therefore call at the busiest time, when an employee wants to protect the business quickly. They may know the premises address and owner’s name from public sources.

The employee should not pay with a personal card or buy a code to “save the business.” They should record the contact, hang up and reach the person responsible for the agreement. The organization needs an accessible record of its provider, customer reference, official contact route and authorized payment approvers.

A tenant may feel similar pressure. Do not send money to new details in a supposed landlord message. Verify with the landlord using a known number, request the document and, where the agreement permits, confirm status directly with the provider.

If you clicked but entered nothing

Close the page. Do not download an app, profile, certificate or file offered as a “secure payment” tool. Review downloads and remove an unexecuted suspicious file. If you installed an app or granted permissions, stop using the device for banking and contact both your bank and trusted technical support.

Opening a page alone does not automatically mean the account was stolen, but do not continue testing the link. Report the text, site or sender through the national reporting route available where you live.

If you disclosed details or paid

Call the bank immediately using the number on your card or official app. Explain what you entered, approved and when. Ask the bank to protect the card or online banking and investigate whether the payment can be stopped. Change a potentially exposed password on the bank’s real site and end unknown sessions.

Then contact the genuine utility to confirm the message was false and report misuse of its name. Preserve the message, page address, payment receipts and call history. Report the matter to law enforcement if money or sensitive information was taken. Do not pay a second person who promises to recover the loss for a fee.

A simple rule for households and organizations

Agree on one sentence: we check and pay bills from our own app or invoice, never from a reminder link. The decision no longer depends on recognizing a particular domain, logo or new text-message variation.

Organizations can add a second rule: a service-disconnection threat goes to the agreement owner and another approver before anyone pays. At home, tell older relatives they can call you without embarrassment even after clicking. Fast response matters more than blame.

What the sources confirm, and what Breachroad recommends

Polish utility Energa warns about overdue-balance and disconnection messages and explains on its current support page that its notices do not contain random payment accounts or links and do not request passwords or card details. The US Federal Trade Commission describes the same impersonation pattern involving electricity, gas and water providers, and recommends calling the provider through a bill or independently reached official site.

The three-question model, five-minute process, household phrase and business escalation route are Breachroad recommendations. Exact billing and disconnection rules depend on the contract, provider and applicable law. When looking for a payment site, remember that the first search result can impersonate the company you intend to pay. Teams practise these scenarios in our employee cybersecurity training.

SHARE / COPY