Workforce and access social engineering · Also called BazarCall, fake renewal invoice scam, fake subscription cancellation call, Luna Moth, Silent Ransom Group
Callback phishing (fake subscription renewal)
Callback phishing is a scam email about a subscription charge or renewal that tells you to call a phone number to cancel it. The person who answers poses as customer support and talks you into installing remote access software, giving criminals control of your computer to steal money or company data.
How it works
- An email or text says you have been, or will be, charged for a subscription or renewal, and gives a phone number to dispute or cancel it.
- The victim calls, and the fake support agent directs them to a website or sends a link that downloads remote access software or a malicious file.
- With access to a work computer, the criminals copy data and send a ransom demand threatening to publish or sell it, sometimes calling staff to pressure them.
- On a personal computer, they may install spyware, steal banking logins, or fake a refund and ask for the extra money back in gift cards.
Red flags
- An invoice or renewal notice arrives for a subscription you do not recognise, often for a small amount.
- The only way offered to cancel or dispute it is to call the number in the message, sometimes within 24 hours.
- The support agent asks you to download software or visit a site so they can connect to your computer.
- The agent says you were refunded too much and asks you to send the difference back, for example in gift cards.
If you are targeted
- Stop: hang up, and do not install anything or let anyone connect to your computer.
- If you already gave access to a work computer, disconnect it and tell your IT team; on a personal computer, update your security software, run a scan, and change your passwords.
- Check your bank and card accounts for charges you did not make, and ask your bank to reverse them.
- Report it. Our Report a scam page lists where to report in your country, such as ic3.gov and ReportFraud.ftc.gov in the US.
Prevention
For individuals
- Never call the phone number in an unexpected invoice or renewal message.
- Check any subscription by signing in to your real account or calling the company on a number you know is genuine.
- Never give remote access to your computer to someone you reached through a number in a message.
For organisations
- Train staff to recognise callback phishing and to report fake renewal emails rather than calling them.
- Tell employees how and when IT will contact them and prove who it is.
- Alert on unauthorised downloads of remote access tools such as AnyDesk, Zoho Assist, Splashtop, or Atera.
- Use multi-factor authentication for all employees and keep regular backups of company data.
By the numbers
Figures are for the reporting category this scam falls under, not this scam alone.
| Tech and customer support scam losses reported to the FBI IC3 in 2025 | $2.13B | US, 2025, FBI IC3 |
Real cases
No documented case in the atlas yet. New cases are added as they are sourced.
Delivered through: Email phishing, Voice phishing (vishing)
How official datasets classify it
- FBI IC3
- Tech/Customer Support
- FTC
- Business Imposters
- MITRE ATT&CK
- T1566.004, T1219
Questions
- What is callback phishing?
- It is a phishing email with no malicious link, just a phone number to call about a fake charge. The criminals do the damage on the call, by getting you to install remote access software.
- I got a renewal invoice I do not recognise. Should I call to cancel?
- No. Do not use the number in the message. Check your real account or contact the company on a number you know is genuine, and look for any unauthorised charge on your card.
Related scams
- Email bombing followed by fake IT support
- Tech support pop-up scam
- Fake refund and over-refund scam
- Data theft extortion