Updated October 2026 to our current guidance. The original reporting date is unchanged.
No link to click. Just a phone number, a friendly voice, and a few minutes later a stranger is on your screen. Here is the script they read, the office rule that stops it, and three things you can do today.
Count What’s on Your Computers →See how many programs each Windows PC has, how many are current, and how many need updating. No credit card needed.
In this article
Hey folks! A reader who runs a small office forwarded me one that is landing in business inboxes. It says the company’s antivirus subscription, Norton in this case, is about to auto-renew for $349. Didn’t authorize it? Call this number to cancel.
That is the whole email. No attachment, no link to a fake site, nothing for a spam filter to catch. Just a believable charge nobody remembers agreeing to, and a phone number that looks like the helpful way out. The office manager calls, because that is the responsible thing to do with a charge you didn’t make. From that moment the scammer is talking to a person, and no software is involved.
The call follows a script, and it runs about the same way every time. Once you know the steps, most of the trick stops working.
1. A calm voice pulls up “your account,” repeats the $349, and agrees it looks like a mistake. They are on your side against the bill, so you start to trust them.
2. They offer to cancel it and refund you. You just want the charge gone, and they are making it easy.
3. To “process the refund,” they need to get onto your computer. They walk you to a website and have you download a small helper program, the same kind of remote-access tool a real IT department uses. You click yes, and now they can see and control your screen.
4. Then the real play, usually one of two. They “accidentally” refund too much and ask you to send the difference back in gift cards or a wire. Or, while they keep you talking, they copy files, grab saved passwords, or leave something behind so they can come back. Often both.
5. The card number you read out at the start “to verify the refund” was the point all along.
Every step sounds reasonable in the moment. It is written for a busy person trying to do the right thing about a charge they did not make.
Your filter and your antivirus are doing their jobs here. The email had no link and no attachment, so the filter had nothing to check. The real move happened on a phone call, and no software listens to phone calls. The remote-access program they had you install is a real, legitimate product, so antivirus has no reason to block it. It was installed on purpose, while a friendly voice said it was fine.
So a business with a good filter, paid antivirus, and a careful staff can still be walked through it. The scam goes around the software and straight to a helpful person. At a company, one work computer can also reach the shared drives, the email, and other machines on the network, which is why the rule below matters more at work than at home.
You do not need to buy anything for these.
Nobody gives remote control of a work computer to anyone who called or emailed first. Not for a refund, not for “support,” no exceptions. A real company never needs onto your screen to give you money back. Say it at the next team huddle so the office manager and the bookkeeper have a flat answer ready before the call comes.
Never call the number in the message, because it connects you straight back to them. Look at the real bank or credit-card statement to see whether the charge exists. It usually does not. If you need to ask, call the number printed on the back of your card.
If your office does not use a remote-access program every day, it does not need to sit installed and ready on your machines. The fewer of those programs around, the less a smooth talker can do even if someone slips. The same goes for any old program nobody opens anymore.
These calls are scripted to sound helpful and to move fast, and they are aimed at good people trying to fix a problem. The fix is a clear rule and fewer programs lying around, and sharper instincts are a bonus.
My own father let one of these callers onto his computer. I stopped them remotely before they reached the spreadsheet with his bank passwords.
I have spent 35+ years in cybersecurity. FBI InfraGard trainer. Dozens of managed clients since 1991. None has had ransomware.
Step three assumes you know what is on each machine. Most owners have a rough idea, and Windows keeps itself current. Here is the boundary that matters. Windows Update never touches third-party software. The remote-access tool from three years ago, the PDF reader, and the accounting add-on each update on their own, or not at all. Nobody did anything wrong. That is where Windows Update’s job ends.
So who has been checking the rest?
Before you run anything, guess how many programs are on one of your computers and write the number down. Then run the Reveal Scan on that Windows PC. It counts what is installed and tells you how many programs are current and how many need updating. Then look down the list for anything nobody uses.
If the second number is higher than you guessed, that is common. You don’t have to be able to do this. We’ll do it with you.
Maybe. The script is built for one busy afternoon and one person trying to do the right thing about a charge they don’t recognize. That describes most good employees.
The office rule costs nothing and takes one sentence at the next huddle. Give it to them before they need it.
The Reveal Scan counts what is installed on each Windows PC: how many programs are current and how many need updating. Read-only, no credit card needed.
Count What’s on Your Computers →The scan is on us. If you want step-by-step instructions afterward, that’s a paid report, and you’ll see the price before you decide.
If you run it and never speak to us again, that’s a fine outcome.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
Join the owners who get Craig's Insider Notes every week.