No link. No attachment. Just a phone number.
An email lands in your inbox on a Thursday. Subject line is something like Order Confirmation, and the body says your antivirus subscription auto-renewed for $479.99. There’s an order number, a date, and a line at the bottom: if you did not authorize this charge, call our billing department at this number to cancel within 24 hours.
No link to click. No attachment to open. Nothing for your email filter to flag, because there’s nothing malicious in the message at all. Just a number and a deadline.
That’s the point. The attack doesn’t start until you pick up the phone.
Why this is spreading fast
Every email security product on the market is built to hunt for bad links and bad files. A message that contains neither sails right through. The criminals figured this out and rebuilt the whole scam around a phone call.
It also flips the psychology. Normal phishing needs you to trust a stranger who contacted you. This one makes you the one initiating contact, which feels safer. You called them. You looked up nothing, you clicked nothing, you made the decision. By the time somebody picks up, you’ve already handed over a chunk of your skepticism.
And the trigger is money leaving your account, which is one of the few things that makes a busy business owner drop everything and act immediately.
What happens on the call
The person who answers is polite and competent-sounding. There’s call center noise in the background. They pull up your order, apologize for the confusion, and confirm they can process a refund right away.
Then comes the pivot: to process the refund, they need to connect to your computer. They’ll walk you to a website to install a remote support tool. AnyDesk, or something with a name you’ve vaguely heard of. This is presented as completely routine, because in the real world, it kind of is. Legitimate support does this every day.
Once they’re connected, one of two things happens.
The refund con. They open what looks like your online banking (often it’s a fake page, sometimes they’ve edited what’s displayed on your real one) and show you a refund of $4,799 instead of $479. Oh no, they typed an extra digit, and now they’re going to lose their job over it. Can you please send back the difference? Panicked, apologetic, urgent. People wire the money. It’s gone.
The quiet version. They keep you on the phone talking while they install something that gives them permanent access, then thank you and hang up. You think the problem is solved. They come back in three weeks with ransomware or start reading your email looking for a wire transfer to hijack.
The invoice variant that hits businesses harder
The consumer version uses fake antivirus or fake Geek Squad renewals. The business version is nastier. It arrives as a PDF invoice from a vendor name that sounds plausible for your industry, with a support number in the footer, sent to accounts payable.
Your bookkeeper doesn’t recognize the charge, calls the number to sort it out, and now a criminal is on the phone with the person who has access to your payment systems. That’s a much better outcome for them than getting a receptionist.
How to spot it before the call
- You don’t have that subscription. Sounds obvious, but urgency makes people skip this. Check before you dial.
- The amount is uncomfortable but not absurd. Around $300 to $600 is the sweet spot. Big enough to demand action, small enough to be believable.
- There’s a deadline. Cancel within 24 hours. Real companies don’t work that way.
- The only way to respond is a phone number. No account portal, no link to your order history, no support email.
- The sender address doesn’t match the brand. Often a free mail domain or something random.
- The invoice is a PDF image. Text as a picture beats text scanners.
The one rule that stops all of it
Never call a number that came in the message. Ever.
If you think a charge might be real, go to the vendor’s actual website by typing the address yourself, or look at your bank statement, or check your credit card app. Real charges show up in real places. A charge that only exists inside an email you received is not a charge, it’s bait.
Same rule for text messages and voicemails. The contact information in the suspicious message is part of the attack.
Train your team on the second half too
Most security training stops at spot the phish. Add this: nobody at this company installs remote access software because a person on the phone asked them to. Not for a refund, not for support, not for anything. If somebody needs remote access to a work machine, it goes through your IT provider, and your provider should already have a tool in place that doesn’t require an on-the-spot install.
Make it a stated policy. Written down, said out loud in a staff meeting. It removes the awkward moment where an employee feels rude for saying no to a friendly voice.
If somebody already got connected
Move fast, in this order.
- Disconnect that computer from the network. Unplug the cable, turn off Wi-Fi.
- Uninstall whatever remote tool got installed, but assume other things were installed too.
- From a different machine, change the passwords for email, banking, and anything else that was open in the browser during the call.
- Call your bank’s fraud line, using the number on the back of your card.
- Get the machine properly examined before it goes back on the network. A reload is often the right call.
- Report it at the FBI’s IC3 site. Takes ten minutes and it helps.
The short version
The message with no link is not safer. It’s a different attack. If an email tells you to call a number about money, the number is the threat.
Want your team trained on this stuff with real examples instead of a boring slideshow? That’s part of what we do for businesses from Delray Beach to West Palm Beach. Get in touch and let’s set it up. Always happy to troubleshoot.