← Back to all posts

Called the Number on a Fake Invoice? What to Do Next

If you called the number on a fake bill, hang up and don't call back. If they connected to your computer, turn it off or disconnect it from the internet. If you shared bank or card details or sent money, call your bank using the number on your card right away. Then report it. How much else you need to do depends on what happened on the call.

These numbers come from fake Norton, McAfee, PayPal and Geek Squad renewal notices, sent by email, as PDF attachments, and lately as calendar invitations that skip the Junk folder. The calls follow the same script whichever way the lure arrived.

What happened on the call Start with
You called, got suspicious and hung up without giving anything Step 6: expect follow-up calls
You gave your name, email or address Steps 5 and 6
You installed an app or let them connect to your computer Steps 1, 3, 4 and 6
You entered bank or card details, or logged into your bank while they watched Steps 1 to 4 and 6, starting with your bank
You sent money: gift cards, a wire, crypto, cash, or a payment app Steps 2 to 6, as fast as you can
You shared your Social Security number Steps 4 and 5

What happens on these calls

The script is well documented. The FTC describes it this way: "If you call, the scammers ask for remote access to your computer. They take you to a spoofed website that looks real and tell you to enter your bank or credit card information to process the refund. After you do that, they claim there was an error in the amount entered. They say they refunded you too much money and insist you pay them back with gift cards, a wire transfer, a bank transfer, cryptocurrency, or a payment app" (FTC).

The "overpayment" is staged. Federal prosecutors describe scammers making it look as if a victim was refunded "$10,000 instead of the intended refund amount of $100" because of a typo, then having the victim send back the difference (US Attorney's Office, S.D. Texas). In some cases the "refund" is the victim's own money, moved from savings into checking while the scammer controls the screen (WJLA via Fox Baltimore).

When Norton's researchers called a number from a fake Norton calendar invite, the agent said they were McAfee support, quoted a $587.88 renewal, and walked the caller toward downloading AnyDesk, a legitimate remote-access app, to "cancel" it (Norton). One call center, many brands.

1. End the call and cut off remote access

Hang up. If someone is connected to your computer, turn the computer off or disconnect it from the internet: turn off Wi-Fi or unplug the network cable. AnyDesk's own guidance notes that turning off the device ends a session, and that a remote helper who asks you to log in to your bank is "most likely a scammer" (AnyDesk).

Don't call the number back, even to argue. Don't answer calls from numbers you don't know for the next few days.

2. Call your bank or card company

If you entered card or bank details, logged into your bank during the call, or sent money, call your bank or card issuer now. Use the number on the back of your card or on the bank's website, never a number the caller gave you. Ask them to stop or reverse any payment, watch the account, and issue a new card if needed.

Speed matters. In one case the FTC described, an older adult who called the number in a fake "Norton Security Plan" email had $50,000 wired out of their account. The full amount was frozen after the FTC referred it to the FBI's Recovery Asset Team (FTC).

If you paid with a gift card, wire, crypto, a crypto ATM or a payment app, contact that company too. The FTC's What To Do if You Were Scammed lists what to ask for with each payment method.

3. Clean up the computer

If they had remote access:

  • Uninstall the remote-access app they had you install, such as AnyDesk. Other remote-access tools named in FBI and Microsoft reporting on related callback scams include ScreenConnect, Quick Assist, Zoho Assist and Splashtop.
  • Run a full malware scan before using the computer for anything sensitive. Our guide to what to do after clicking a phishing link covers free options for Windows and Mac.
  • Check for new accounts or apps you didn't create. If you're not confident the computer is clean, get help from someone you trust before using it for banking.

4. Change passwords from a different device

Change the passwords for your email and bank first, then anything else you logged into during the call or that uses the same password. Do it from a phone or another computer, not the one they accessed. Turn on two-step verification for your email and bank.

If you shared your Social Security number, go to IdentityTheft.gov and place a free credit freeze with all three credit bureaus (FTC).

5. Report it

  • File a report at ReportFraud.ftc.gov.
  • File with the FBI at ic3.gov, whatever the amount. The FBI says "time is of the essence" when money has moved (FBI IC3).
  • If you're 60 or older, or helping someone who is, the National Elder Fraud Hotline is 1-833-FRAUD-11 (1-833-372-8311).
  • Tell the company that was impersonated. For fake Norton bills, Norton takes reports at [email protected] (Norton).

You can report on someone else's behalf. About 16% of reports to the FTC about people 80 and older are filed by someone else (FTC).

6. Watch for the second call

People who pay once are often called again by someone new. The FBI calls the pattern the "Phantom Hacker" scam: a fake technician hands you to a fake bank representative, then to a fake government agent, each warning that your money isn't safe and must be moved (FBI IC3). Some victims are told to withdraw cash or buy gold and hand it to a courier who comes to the door (FBI IC3).

None of this is real:

  • Your bank won't ask you to move money to a "safe" account.
  • The FTC says there is no such thing as a "federal safety locker" (FTC).
  • The FBI says legitimate businesses will never ask you to buy gold (FBI IC3).
  • No real company collects payments with gift cards or sends a courier for cash.

If someone calls claiming to be from your bank, hang up and call the number on your card.

Why speed matters

These scams are expensive. People reported $2.13 billion in tech and customer support scam losses to the FBI in 2025, and people 60 and older accounted for about $1.04 billion of it. Victims paid mostly in cryptocurrency (43%), followed by wire or bank transfers (20%), cards (14%), gift cards (12%) and cash (11%) (FBI IC3). The longer money sits with the scammer, the harder it is to recover.

If it happened at work

Tell whoever handles IT immediately, and don't use the affected computer until they've looked at it. Against businesses, the same "call to cancel your subscription" step is used to break in rather than to take a refund. The FBI has warned that the Silent Ransom Group sends fake subscription notices, has callers install remote-access software, and steals data for extortion, and that it has targeted US law firms since spring 2023 (FBI). Our admin guide covers what IT can do.

Frequently asked questions

I called but hung up quickly. Am I okay? Probably. They now know your number works, so expect more calls and texts, and don't engage with any of them. If you gave nothing and installed nothing, there's nothing else to undo.

They had me log into my bank. What could they see? Assume they saw everything on the screen while they were connected. Call your bank, change your banking password from another device, and ask the bank to watch for transfers.

Will I get my money back? It depends on how you paid and how quickly you report it. Call your bank and the payment provider right away and ask; the FTC lists what to ask for with each payment method. Then file at ic3.gov.

How do I stop the fake invoices from coming back? If they arrived as calendar invitations, change the setting that lets them in. Our guide shows how to remove and stop spam calendar invites in Google Calendar, Outlook and iPhone.