Refund and remote access scams

Also called: refund scam · overpayment refund · rebate scam · subscription refund scam · remote access scam

A refund scam claims you are owed money — for a cancelled subscription, an overcharge or a closing company. The victim is talked into granting remote access so the "refund" can be processed, shown a doctored account page implying they were overpaid, and asked to return the difference. Nothing was ever sent, and the returned money is real.

Key facts

Category
Tech support & remote access
First documented
2015
Typical loss
$500–$100k USD, per victim
Main channels
email invoice, phone call, browser pop-up, SMS, remote access software
Who is targeted
People over 60, who report the largest losses in this category; Anyone with several subscriptions, where an unexpected renewal notice is plausible; Previous victims of other scams, approached with a refund or recovery story; People who are not confident reading a bank statement on screen under pressure
Documented origins
India, United States, Pakistan, Philippines
Main targets
United States, Canada, United Kingdom, Australia, New Zealand, Ireland
Case files
3 documented cases
Last reviewed
2026-09-06
Anatomy of a refund scamAnatomy of a refund scam. Nobody asks you for money. They give you some, make a mistake, and ask you to be decent. 1. A refund you did not ask for: A renewal you don't recognise, a company closing, an overcharge found. Always with a number. 2. The victim calls: Defences built against cold callers do not fire on a number you dialled yourself. 3. Remote access, to process it: A support tool goes on. The browser, the files and any open banking session go with it. 4. The staged overpayment: $4,000 instead of $400 — an edited page, or your own savings moved to your current account. 5. Distress, not a demand: The agent will be fired. Returning it is simply the decent thing to do. 6. Repayment that cannot be undone: Gift card codes, a transfer, crypto or cash. Never a card refund, which would reverse. 7. Another error, or a recovery offer: Some victims are returned to repeatedly. Others get a recovery approach weeks later. The diagram marks stage 1 as the point where the scheme can still be stopped: Never call a number supplied by the document that alarmed you. If a subscription might really have renewed, check your card statement or log in to the provider directly. The invoice is the bait; the number is the trap.Anatomy of a refund scamNobody asks you for money. They give you some, make a mistake, and ask you to be decent.1A refund you did notask forA renewal you don'trecognise, a companyclosing, an overchargefound. Always with anumber.Minutes2The victim callsDefences built against coldcallers do not fire on anumber you dialledyourself.Minutes3Remote access, toprocess itA support tool goes on. Thebrowser, the files and anyopen banking session gowith it.Minutes4The stagedoverpayment$4,000 instead of $400 — anedited page, or your ownsavings moved to yourcurrent account.Minutes5Distress, not ademandThe agent will be fired.Returning it is simply thedecent thing to do.Minutes6Repayment that cannotbe undoneGift card codes, atransfer, crypto or cash.Never a card refund, whichwould reverse.Hours7Another error, or arecovery offerSome victims are returnedto repeatedly. Others get arecovery approach weekslater.WeeksWhere it can still be stopped — stage 1Never call a number supplied by the document that alarmed you. If a subscription might really have renewed, check your card statement or log in to the providerdirectly. The invoice is the bait; the number is the trap.Stages documented in a May 2025 US Department of Justice indictment and in the Australian National Anti-Scam Centre's 2025 report.howscamswork.com
The stages of the scheme, in order, with the point where it can still be stopped.

What it is

The refund scam is unusual in one respect: it does not ask you for money. It gives you some.

It begins with an unexpected credit. A subscription you do not remember has renewed and been cancelled, and a refund is due. An antivirus company is closing and returning customers’ balances. An overcharge has been identified. The number to call is right there on the invoice.

The person who answers needs to process the refund, and to do that they need to see your screen. Once they have it, something goes wrong: the refund has been entered incorrectly. Instead of $400, they sent $4,000. They will be fired. Would you return the difference?

You look at your account and the money is there. Except it never arrived. Either you are looking at a page the operator edited on your own screen, or they moved your own savings into your current account so that a balance genuinely changed. The refund is a picture. The money you send back is real, comes from your own funds, and goes on a rail that does not reverse.

Australia’s data captures how the pretext has grown: rebate scam reports fell 49.1% in 2025 while losses to the same category rose 170%, from A$1.7 million to A$4.7 million — a rise the National Anti-Scam Centre attributes to high-value cryptocurrency recovery scams using the same framing.

How it actually works

  1. An unexpected refund

    An invoice for a renewal you do not recognise, an email saying a company is closing and returning balances, or a call about an overcharge. Every version supplies a number to call.

    Where it could have stopped

    Never use a phone number supplied by the document that alarmed you. If you think a subscription may really have renewed, check your card statement or log into the provider directly. The invoice is the bait; the number is the trap.

  2. The victim calls

    As with tech support fraud, the inversion matters: defences built against cold callers do not fire on a number you dialled yourself.

  3. Remote access, to “process the refund”

    A support tool is installed. It is presented as routine, and it hands over the browser, the files, the saved passwords and any banking session that is open.

  4. The staged overpayment

    You are asked to log into your bank so the refund can be confirmed. Then the “mistake” — $4,000 instead of $400. What you are shown is either an edited page or a genuine transfer between your own accounts. Nothing came from outside.

  5. Distress, and an obligation

    The agent will lose their job. Their manager is angry. They are apologetic and frightened. The request to return the difference is not a demand; it is an appeal, which is far harder to refuse.

  6. Repayment on an irreversible rail

    Gift card codes read down the phone, a bank transfer, cryptocurrency, or cash to a courier. Any of these is final; a card refund would not be, which is exactly why none is offered.

  7. Repetition

    Some victims are returned to repeatedly with new “errors”. Others are approached later by a recovery scam — the same refund logic, aimed at the loss the first scam created.

Why it works

It reverses the direction of the ask. Every fraud warning people have absorbed is about someone wanting money from them. This one is about someone giving money and making a mistake. The frame does not match the warning, so the warning does not fire.

Guilt is a stronger lever than fear. The victim is not frightened; they are being decent. Keeping money that is not yours is wrong, the agent is in trouble, and returning it is straightforwardly the right thing to do. That is a much harder impulse to argue against than greed.

The evidence is on the victim’s own screen. Not a website they were sent to — their own bank account, in their own browser. Doubting it means doubting something people treat as ground truth, and almost nobody does under pressure.

Remote access removes the ability to check. Once someone else controls the display, what is on it is no longer evidence. Most people have never had to think about that distinction.

The urgency is human rather than institutional. Nobody threatens anything. Someone is going to lose their job because of an error made while helping you.

And the pretext scales. The same “we owe you money” framing works on a $400 subscription and on somebody who has just lost $400,000 to an investment fraud. Australia’s numbers show the operators moving it to wherever the value is.

Where it comes from

Refund fraud is a variant of tech support fraud and shares its production base: organised call centres, with a large documented share aimed at North America run from India, and a domestic layer of couriers and mule accounts.

The overlap is visible in the case record. The Rhode Island prosecution described on this page charges eight defendants over a scheme in which pop-ups lured elderly victims into calling agents who then claimed their financial assets were at risk — around 300 identified victims across 37 states and more than $5 million in known losses. The refund story and the “your assets are at risk” story are two scripts running out of the same room.

The Australian data also shows something useful about disruption. Remote access scams fell on both measures in 2025 — reports down 47.8%, losses down 37.2% — which the National Anti-Scam Centre attributes to detection and disruption by banks and telecommunications companies. Rebate scams moved the opposite way. The same operators, facing pressure on one script, moved to another.

Real cases

US tech support losses more than doubled in two years

2025 US Ongoing $2.1bn

FBI Internet Crime Complaint Center data shows tech support fraud losses in the United States rising from $924.5 million in 2023 to $1.46 billion in 2024 and $2.13 billion in 2025 — a 131% increase in two years. Complaint volume grew far more slowly, from 37,560 to 47,794, meaning the average loss per complaint roughly doubled. Tech support is now the third-largest loss category the FBI tracks.

Read the case file · 2 sources

Pop-ups, live agents and 300 victims across 37 states

2025 US · CA Charged — allegation, not conviction $5.0m

In May 2025 the US Attorney's Office for the District of Rhode Island indicted eight people over a transnational fraud and money laundering scheme aimed at elderly people in the United States and Canada. Pop-up messages on victims' computers made false claims that lured them into calling live agents, who then told them their financial assets were at risk or could be garnished. Investigators identified around 300 victims in at least 37 states with known losses exceeding million.

Read the case file · 1 source

Rebate scams: half the reports, nearly three times the losses

2025 AU Ongoing $3.0m

Australia's National Anti-Scam Centre recorded a 49.1% fall in rebate-scam reports to Scamwatch in 2025 while losses to the same category rose 170%, from A$1.7 million to A$4.7 million. The report attributes the increase to several high-value cryptocurrency recovery scams — the refund pretext being used against people who had already lost money once.

Read the case file · 1 source

Red flags

  • A refund you did not request, for a subscription or service you do not remember buying.
  • An invoice with a phone number to dispute it. Real providers expect you to use your account, not a number on a PDF.
  • Any request to install remote-access software or share your screen to “process” a refund. No refund requires this.
  • Being asked to log into your bank while someone is watching your screen.
  • An overpayment, and a request to return the difference. This is the scam, in one sentence.
  • The agent will be fired, or has to pay it back personally. Emotional pressure in place of a threat.
  • Repayment in gift cards, cryptocurrency, wire transfer or cash to a courier. A genuine overpayment would be reversed by the sender, not repaid by you.
  • You are told not to discuss it with your bank, or to describe the payment as something else.
  • A refund offer arriving after a previous scam. That is a recovery scam.
  • Pressure to stay on the line throughout the transfer.

If it’s happening to you

If someone is on your screen right now. Disconnect from the internet — unplug the cable or turn off Wi-Fi. That ends the session immediately. Do not argue, do not explain.

Then, using a different device:

  1. Change your email password first, then banking, then anything sharing a password. Email controls password resets for everything else.
  2. Call your bank’s fraud line and say someone had remote access to your computer. Ask them to review the account and check for transfers between your own accounts — that is often how the fake overpayment was staged.
  3. Uninstall the remote-access software and anything else added during the session, then run a full scan. Treat any account that was open during the session as compromised regardless of the result.

If you sent money back.

  1. Call your bank immediately. A transfer that has not settled may be recallable.
  2. For gift cards, call the issuer straight away with the card numbers and receipts, and keep the cards.
  3. For cryptocurrency, send the transaction hashes to the receiving exchange.
  4. Report it. See where to report.
  5. Expect a follow-up. People who paid once are contacted again, often with a recovery offer.

Preventing it. One habit covers this whole family: never call a number that came with the thing that alarmed you. Not on an invoice, not in a pop-up, not in a text. If you think it might be real, go to the provider or your bank the way you normally would. That single rule closes the door before any of the rest of it can happen.

Where the money goes

The returned “difference” is the victim’s own money, and it leaves on a rail chosen for finality. Gift card codes are resold within minutes of being read out. Bank transfers go to mule accounts and move on within hours. Cryptocurrency goes to an address the operation controls.

There is a detail worth noticing about the choice. A genuine overpayment would be corrected by the sender reversing it — no action needed from the recipient at all. The insistence that you send money back, by a method that cannot be undone, is the part of the story that makes no sense on inspection, and it is the part the emotional pressure exists to prevent you inspecting.

The other half of this story

Our sibling site Clean on Paper explains how the returned money is moved — the mule accounts, the gift-card resale market, and where the chain becomes visible to a bank.

By the numbers

No agency publishes a line item for most of the schemes on this site, so these charts show the official categories that contain this scheme. Each series is labelled with the agency's own category name. See how the mapping works.

How contact was made, CA, 2025Horizontal bars of reported losses by contact channel in 2025, led by Internet-social network at $2.0m.How contact was made, CA, 2025Reported losses by the channel the scammer used, for the agency categories covering this scheme.Internet-social network$2.0mInternet-social network: $2.0mInternet$1.8mInternet: $1.8mOther/unknown$1.6mOther/unknown: $1.6mDoor to door/in person$1.5mDoor to door/in person: $1.5mDirect call$1.2mDirect call: $1.2mEmail$849,338Email: $849,338Text message$558,314Text message: $558,314Not Available$81,844Not Available: $81,844Video Call$68,033Video Call: $68,033Mail$33,871Mail: $33,871$0$500,000$1.0m$1.5mAggregated across every agency category that maps to this scheme, so it inherits those categories’ breadth.Reported losses only. Every agency here says most fraud is never reported to it, so treat these as a floor, not a total.Sources: Canadian Anti-Fraud Centre / RCMP. Pulled 2026-09-06.
Full dataset, methodology and downloads
Reported losses over timeLine chart of reported losses from 2021 to 2025 for the agency categories that cover this scheme: Tech/Customer Support (US); Remote access (AU); Service (CA); Remote access scams (AU).Reported losses over timeEach line is one agency category that covers this scheme. Agency categories are usually broader than the scheme itself.$0$500m$1.0bn$1.5bn$2.0bnTech/Customer Support (US), 2023: $925mTech/Customer Support (US), 2024: $1.5bnTech/Customer Support (US), 2025: $2.1bnRemote access (AU), 2024: $70mRemote access (AU), 2025: $45mService (CA), 2021: $9.4mService (CA), 2022: $16mService (CA), 2023: $17mService (CA), 2024: $15mService (CA), 2025: $9.7mRemote access scams (AU), 2024: $4.9mRemote access scams (AU), 2025: $3.0m20212022202320242025Tech/Customer Support (US)Remote access (AU)Service (CA)Remote access scams (AU)Categories are the publishers’ own and are broader than this scheme, so these lines bound it rather than measure it exactly. Lines are notcomparable to each other: different countries, different reporting systems.Reported losses only. Every agency here says most fraud is never reported to it, so treat these as a floor, not a total.Sources: Canadian Anti-Fraud Centre / RCMP; FBI Internet Crime Complaint Center (IC3); National Anti-Scam Centre (ACCC), Australia(transcribed from the published report). Pulled 2026-09-06.
Full dataset, methodology and downloads

Sources

Every factual claim above traces to one of these. Statistics are reported losses; see methodology for what that does and does not measure.

  1. Targeting scams: report of the National Anti-Scam Centre on scams data and activity 2025. National Anti-Scam Centre (ACCC), Australia. Accessed 2026-09-06. Supports: Rebate scam reports down 49.1% while losses rose 170% to A$4.7m, attributed to crypto recovery scams; remote access reports down 47.8% and losses down 37.2%.
  2. 2025 Internet Crime Report. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: US tech support and customer support losses of $2.13bn in 2025, and the cryptocurrency share of those transactions.
  3. Justice Department Highlights Enforcement Efforts Protecting Older Americans from Transnational Fraud Schemes in Recognition of 2025 World Elder Abuse Awareness Day. US Department of Justice. Accessed 2026-09-06. Supports: The Rhode Island indictment describing pop-up messages leading to live agents and claims that victims' assets were at risk.
  4. Canadian Anti-Fraud Centre Fraud Reporting System Dataset. Canadian Anti-Fraud Centre / RCMP. Accessed 2026-09-06. Supports: Canadian Service-category reports and losses, which cover refund and remote-access fraud.
  5. Consumer Sentinel Network Data Book 2024. US Federal Trade Commission. Accessed 2026-09-06. Supports: Payment-method distribution of reported US fraud losses, including gift cards and wire transfers.

Common questions

They showed me my own bank account with the refund in it. How was that faked?

It was not necessarily faked in your account — it was faked on your screen. With remote access, the operator can edit what the browser displays, or move money between your own savings and current accounts so a balance genuinely changes. Nothing arrived from outside; you were shown a picture, or your own money.

Why would they send me too much on purpose?

The overpayment is the entire mechanism. It creates an obligation — you have their money, and returning it is the decent thing to do. Your return payment is real, irreversible and comes from your own funds; the overpayment never existed.

I got an invoice for a subscription I never bought. Should I call the number to cancel it?

No. The invoice is the bait and the number is the trap. If you think a real subscription might have renewed, check the account with the actual provider or look at your card statement. Never use contact details supplied by the document that alarmed you.

Can I get the money back?

Sometimes, if you move today. Call your bank's fraud line immediately. Gift card issuers can occasionally freeze a balance if you call fast with the numbers. Cryptocurrency is much harder, but send the transaction hashes to the receiving exchange straight away.

Someone had remote access to my computer. What should I do first?

Disconnect from the internet, then use a different device to change your email password first and banking second. Call your bank and say someone had remote access. Uninstall the software they installed and run a scan — and treat any account that was open during the session as compromised.

Is this the same as a recovery scam?

Increasingly, yes. Australia's National Anti-Scam Centre attributes a 170% rise in rebate-scam losses to high-value cryptocurrency recovery scams. The refund pretext is a wrapper: attached to a small overcharge it is worth a few hundred dollars, attached to someone who has just lost six figures it is worth far more.

Where the "returned difference" goesWhere the "returned difference" goes. A genuine overpayment is corrected by the sender. Being asked to send it back is the part that makes no sense. Where the "returned difference" goesA genuine overpayment is corrected by the sender. Being asked to send it back is the part that makes no sense.The victim's own moneyA rail chosen forfinality, at theinsistence of theperson who calledGift cards, transferor cryptoGift card codes resoldwithin minutes ofbeing read outMule accounts andresellersTransfers move onwithin hours; cryptogoes to an addressthey controlBeyond recallReversibilityA recall is realistically possible only at the first hop, and only in the first hours. After the money is converted it becomes an investigation, not a refund.How the returned money is collected — Clean on Paper, our sibling sitehttps://cleanonpaper.site/techniques/money-mules/The emotional pressure exists to prevent the victim inspecting the one thing that does not hold up: that they are being asked to send the money themselves, irreversibly.howscamswork.com
Where the money goes after it leaves, and where it becomes hard to recover.

Report it

Reporting is what produces the enforcement data on this page. Find the right agency and phone number for your country on the report page. If money moved in the last few hours, call your bank first.