What Is a Refund Scam?
A refund scam is a social engineering attack in which a criminal impersonates a trusted company or government agency, convinces the target they are owed money back, and then manipulates them into surrendering funds or account access.
The pretext of money owed lowers the target's guard: a person expecting a refund treats a request for bank access as part of the process rather than a warning sign.
How refund scams work
The attack opens with an impersonation lure. Scammers make contact through phone calls, emails, texts, or pop-up windows (opens in new tab), typically claiming that a subscription from Microsoft, Norton, or Geek Squad has auto-renewed for several hundred dollars and instructing the victim to call within 24 hours (opens in new tab) to dispute the charge.
The message often carries only a phone number, with no malicious link or attachment, which lets it slip past filters (opens in new tab) that scan payloads.
On the call, the scammer walks the victim through installing remote access software such as AnyDesk, TeamViewer, or ScreenConnect to "process the refund," a malicious RMM abuse (opens in new tab) of legitimate tools. The victim then logs into online banking while the scammer watches.
To fabricate an overpayment, the scammer either shuffles the victim's own money between their checking, savings, and retirement accounts to simulate a deposit (opens in new tab), or simply edits the HTML (opens in new tab) of the transaction page so a fake refund appears on screen.
In the double zero variant (opens in new tab), the scammer claims to have accidentally added two zeros to the refund amount and begs the victim to return the difference. The refund is fictitious, while the money the victim wires, loads onto gift cards, or deposits at a cryptocurrency ATM is real, chosen because victims struggle to reverse it.
Attackers also reuse infrastructure across channels: one callback number (opens in new tab) has appeared in both PayPal and Norton LifeLock lures, routing every caller to the same call center.
Why refund scams matter
The impersonated brand absorbs the damage even though scammers never breached its systems. Customers associate the scam with the company whose name it used, so that company pays for takedowns and legal work and carries a heavier customer-service load.
Fraudulent refund messages aimed at airline passengers pushed Etihad Airways and Abu Dhabi Police to issue joint public alerts (opens in new tab) in March 2026, and JetBlue has publicly described the legal and customer-service work (opens in new tab) of removing fake support accounts set up to defraud its customers.
Regulators impose separate consequences on impersonators and payment providers. Impersonation scams hurt the reputation (opens in new tab) of legitimate businesses, and the FTC's Government and Business Impersonation Rule (opens in new tab), effective April 1, 2024, lets the agency pursue civil penalties against impersonators.
In the UK, the Payment Systems Regulator's reimbursement requirement (opens in new tab), effective October 7, 2024, makes banks financially liable when authorized push payment fraud victimizes customers, a category that explicitly includes impersonation scams.
Types of refund scams
Refund scams cluster into recurring variants based on the brand scammers impersonate and the channel they use.
- Tech support and subscription renewal scams. Fake renewal invoices impersonate Geek Squad, Norton, McAfee, Microsoft, and PayPal, each carrying a callback number instead of a link. In the multi-step version, scammers call victims back offering refunds (opens in new tab), falsely claim they refunded too much, and induce payment via gift cards.
- Retail and delivery smishing. Texts impersonating Amazon claim the retailer recalled an item and offer a refund, linking to sites that steal login credentials and payment data, a recurring trend (opens in new tab) Amazon tracks on its own shopping-safety pages.
- Government and tax refund impersonation. Phishing and SMS smishing sit at the top of the 2026 Dirty Dozen (opens in new tab) list of tax scams. Texts and emails claim authorities have "processed" or "approved" a refund pending identity verification. Scammers also impersonate the FTC's own "Refund Department."
- Airline customer service impersonation. Scammers plant fake support numbers in search results and run fake social accounts that intercept public complaints (opens in new tab) from stranded travelers to harvest booking confirmations and bank details.
- Bank fraud-department impersonation. Fake security alerts push victims to move money to "protect" it, or harvest the verification codes (opens in new tab) that legitimate bank representatives never ask customers to read aloud.
- Recovery scams. Scammers buy victim lists and contact prior fraud victims, offering to recover lost money for a fee. Some pose as FBI personnel (opens in new tab) who handle IC3 complaints, then revictimize people who already reported fraud.
How to defend against refund scams
Because the scammer impersonates the brand on channels the brand does not control, defense requires authentication and monitoring, with training supporting both.
- Enforce email authentication. Publishing a DMARC policy (opens in new tab) lowers the chance of spoofed email from your own domains, but SPF and DKIM must be configured first.
- Monitor and take down lookalike infrastructure. Watch new domain registrations and certificate transparency logs for brand variants, and defensively register (opens in new tab) high-risk combinations of your brand with terms like "login" or "account."
- Harden the voice channel. Confirm carriers are STIR/SHAKEN compliant (opens in new tab), and require callback verification on registered numbers for any sensitive phone request.
- Train customer-facing teams. Contact-center agents should hold to verification scripts no matter how insistent a caller becomes, with simulated fraud calls as hands-on practice.
- Warn customers on verified channels. When impersonation surfaces, warn customers quickly (opens in new tab) by mail, email, or social media, and send email warnings without hyperlinks so the alert itself does not resemble phishing.
- Triage customer impersonation reports as intelligence. Banks piloting a shared intake framework (opens in new tab) for abuse mailboxes and intelligence sharing saw impersonation abuse volumes fall.
How Doppel helps
Doppel is the AI-native Social Engineering Defense (SED) platform that unifies Digital Risk Protection and Human Risk Management to detect and dismantle refund-scam impersonation across email, SMS, social media, search ads, and voice.
The Doppel Threat Graph connects spoofed domains, fake support profiles, and reused callback numbers into a single campaign view, so a refund campaign is dismantled as one operation rather than one asset at a time.
The platform's agentic AI prioritizes and executes takedowns across registrars, hosts, social platforms, ad networks, and telecom providers at machine speed. Brand AbuseBox turns customer-reported refund lures into validated takedowns that feed the Threat Graph, so inbound reports become enforcement instead of a backlog. Coordinated action across every channel makes the refund campaign too costly to run.
Request a demo to see the refund campaigns impersonating your brand and the takedowns that dismantled them.
Frequently asked questions about refund scams
What is a refund scam?
A refund scam is a confidence trick in which a scammer impersonates a company or government agency and convinces the victim that they are owed money back. After fabricating an overpayment, often by gaining remote access to the victim's computer and altering what appears on the banking screen, the scammer pressures the victim to return the "excess" by wire transfer, gift cards, or cryptocurrency. No refund was ever issued, and the victim sends real money that is difficult to recover.
What is a refund scam in cybersecurity?
In cybersecurity, security teams classify a refund scam as a social engineering attack built on pretexting: the scammer impersonates a legitimate company and fabricates account data to establish trust. Refund scams abuse legitimate remote monitoring and management (RMM) tools such as ScreenConnect and AnyDesk to reach victims' machines and falsify bank-account summaries. Because the initial email frequently contains only a phone number and no malicious payload, it evades filters that catch links and attachments.
What is the difference between a refund scam and refund fraud?
A refund scam targets a consumer: the scammer impersonates a brand and tricks the victim into sending their own money. Refund fraud targets a merchant: the fraudster exploits a retailer's return policy through false claims such as item-not-received or empty-box reports, sometimes through organized refund-as-a-service groups that charge clients a fee for fraudulent refunds. Chargeback fraud, also called friendly fraud, is a third distinct pattern in which a cardholder disputes a legitimate purchase through their bank. The three harm different victims and require different controls.
What is an example of a refund scam?
A common example begins with an email claiming a tech-support or antivirus subscription, supposedly from Geek Squad or Norton, has renewed for several hundred dollars, with a phone number to call for a refund. The "agent" has the caller install remote access software, then moves money between the caller's own accounts to stage a fake overpayment and pressures them to return the difference through gift cards, wire transfer, or cryptocurrency. In documented cases, victims drained savings and retirement accounts before anyone interrupted the sequence.


