The Refund Scam Explained
This scam is a common type of technical support or impersonation fraud designed to steal money by manipulating victims into believing they need to “return” an accidental over-refund.
Here’s the typical scam progression:
Initial Contact: The scammer initiates contact, often through:
- A fake security alert pop-up on the victim’s computer claiming there’s a virus or malware.
- An unsolicited phone call or email pretending to be from a well-known tech company (like Microsoft, Apple, Norton), bank, or retailer (like Amazon).
- They might claim the victim’s account has been hacked, there’s been suspicious activity, or the victim is owed a refund for a previous purchase or subscription (e.g., “Your Geek Squad subscription is renewing,” or “We owe you a refund for Norton”).
Gaining Trust and Remote Access
The scammer builds rapport and convinces the victim there’s a legitimate problem or a refund due. To “fix” the issue or “process” the refund, they insist they need remote access to the victim’s computer. They guide the victim to download and install legitimate remote access software (like TeamViewer, AnyDesk, LogMeIn, Zoho Assist, etc.), assuring them it’s standard procedure.
The Fake Refund
Once connected, the scammer asks the victim to log in to their online bank account so the “refund” can be processed. While the victim is watching (but often distracted by the scammer talking), the scammer uses the remote access to manipulate the bank account page. They don’t actually transfer money. Instead, they often use the web browser’s developer tools (inspect element) to temporarily change the numbers displayed on the screen, making it appear as though a large sum of money (e.g., $5,000 instead of the promised $500) has been deposited.
The “Overpayment” Panic
The scammer then pretends to panic, claiming they made a huge mistake and accidentally refunded far too much money. They’ll plead with the victim, saying they’ll lose their job if the “extra” money isn’t returned immediately before their company or the bank notices. They create a sense of urgency and often play on the victim’s sympathy or fear of being involved in wrongdoing.
The Gift Card Solution
The scammer insists that the quickest and most discreet way to “fix” their mistake and return the excess funds is by purchasing gift cards. They claim traditional bank transfers are too slow or traceable. They instruct the victim to:
- Go immediately to specific stores (like Target, Walmart, Best Buy, CVS, Walgreens).
- Purchase specific types of gift cards (often Apple, Google Play, Steam, eBay, or general store gift cards).
- Buy multiple cards totaling the “over-refunded” amount.
- Stay on the phone with the scammer during the purchase process.
Stealing the Money
Once the victim has the physical gift cards, the scammer instructs them to scratch off the protective layer on the back and read the card numbers and PINs over the phone, or sometimes type them into a chat window or fake website. As soon as the scammer has these codes, they can drain the value from the cards almost instantly. The funds become virtually untraceable and unrecoverable for the victim.
Key Red Flags
- Unsolicited tech support calls, emails, or pop-ups.
- Requests for remote access to your computer to fix a problem you weren’t aware of or to process a refund.
- Anyone asking you to log into your bank account while they have remote access.
Claims of accidental over-refunds. - ANY request to pay for something or return money using gift cards. Legitimate companies and government agencies will never demand payment or refunds via gift cards.
This scam relies heavily on social engineering, creating panic, and exploiting the victim’s trust or desire to help.
