No link to click. Just a phone number, a friendly voice, and a few minutes later a stranger is on your screen. Here is the exact script they read to you, three things you can do today, and an hour with me to shut the rest of your doors.
Save My Seat →Thursday, July 9, 2 PM ET. No charge, no pitch.
The problem: A fake "your antivirus is about to auto-renew for $349" email lands in a business inbox. There is no bad link to spot, just a phone number. Someone on your team calls, and a friendly "agent" talks them into handing over a card and remote control of a work computer.
The solution: Once you have heard the script, you can't un-hear it, and it stops working. By the end of this you will know the whole con beat by beat, you will have three things you can do today, and you will see why your antivirus never makes a peep while it happens.
In this article
A reader who runs a small office forwarded me one that is hitting business inboxes hard. The email says the company's antivirus subscription, Norton in this case, is about to auto-renew for three hundred and forty-nine dollars. Did not authorize it? Call this number to cancel.
That is the whole email. No attachment, no link to a fake site, nothing for a spam filter to grab. Just a believable charge nobody remembers agreeing to, and a phone number that feels like the helpful way out. The office manager calls, because of course she does. And that is the moment the hosers have been waiting for, because now they are not fighting your software. They are just talking to a person.
This is not improvised. It is a script, and it runs the same way nearly every time. Knowing the beats is most of the protection.
1. They sound official and confirm the charge. A calm voice pulls up "your account," repeats the $349, and agrees it looks like a mistake. Now you trust them, because they are on your side against the bill.
2. They offer to cancel it and refund you. Relief. You just want the charge gone, and they are making it easy.
3. To "process the refund," they need onto your computer. They walk you to a website and have you download a small helper program, the same kind of remote-access tool a real IT department uses. You click yes. Now they can see and control your screen.
4. Then comes the real play. Usually one of two. They "accidentally" refund you too much and demand you send the difference back in gift cards or a wire. Or, while they keep you talking, they quietly copy files, grab saved passwords, or plant something to come back later. Often both.
5. And the card you gave them at the start is already gone. The number you read out to "verify the refund" was the point all along.
Every beat sounds reasonable in the moment. That is the design. It is built for a busy person trying to do the right thing about a charge they did not make.
Here is the cruel twist. The email had no link and no attachment, so nothing for the filter to flag. The weapon was a phone call, and there is no software that scans a phone call. And the remote-access tool they had you install is a real, legitimate program, so your antivirus has no reason to block it. You invited it in, on purpose, while a nice person on the phone said it was fine.
That is why a business that did everything "right," good filter, paid antivirus, a careful staff, still gets taken. The con was designed to walk around all of it and knock on the one door no software guards: a helpful human in a hurry. And at a company the payoff is bigger, because one work computer is a doorway to the shared drives, the email, and every other machine on the network.
You do not need to buy anything to shut this down. Three steps, all free, all stronger than any gadget.
Nobody gives remote control of a work computer to anyone who called or emailed first. Not ever, not for a refund, not for "support," no exceptions. A real company never needs onto your screen to give you money back. Say it at the next team huddle so the office manager and the bookkeeper have a flat answer ready before the friendly voice ever calls.
Never the number in the message, that just connects you back to the hosers. Look at the real bank or credit-card statement to see if the charge even exists, which it usually does not. If you need to ask, call the number printed on the back of your card. The message is the last place you should get a phone number.
If your office does not use a remote-access tool every single day, it should not be sitting installed and ready on your machines. The fewer of those tools lying around, the less a sweet-talker can do even if someone slips. While you are at it, keep your programs updated, since an unpatched app is one more door that does not need a phone call at all.
Do those three and the script falls apart at every beat. The piece left over is the one you usually can't see for yourself: which doors are already standing open on your machines. That is what I do live.
These calls are scripted to sound helpful and to move fast, and they are aimed at good people trying to fix a problem. Blaming the person who fell for it misses the point. The fix is a clear rule and fewer open doors, not sharper instincts.
I have spent more than thirty-five years in this, FBI InfraGard, zero ransomware on any client I have worked with. And the hosers still got to my own father. He let them onto his computer, and I stopped them remotely just before they reached the spreadsheet with all his bank passwords. We were lucky. That night is the whole reason I made seeing your open doors simple.
The three steps above are yours to do today. Finding the doors you can't see is the part I will walk you through, live, in plain English. No guesswork about how it works, here are the three steps.
✅ No charge, and nothing to buy on the call.
✅ It is not a pitch-fest. You will leave with real steps whether or not you ever buy a thing.
✅ Plain English. No jargon, and no talking down to you.
✅ Come live if you can, that is where I answer your questions. Saved a seat but can't make it? I'll send you the replay.
✅ If your setup is in good shape, I will tell you so. No scare tactics.
✅ Straight talk. I will show you what is "open" and "at risk," never "guaranteed."
Maybe. But you just read how careful the trap is, and it only takes one busy afternoon and one person trying to do the right thing about a charge they did not recognize. The script is built for exactly that moment, and remote access to a single work computer can reach your whole network.
An hour now gives your team the one rule and shows you which doors are already open. If you are buttoned up, you will walk away knowing it.
These scams want onto your computer, and the fewer open doors you leave, the less they can do once they are there. Spend one hour with me, walk away knowing exactly what to close first, and trade that low hum of worry for the quiet confidence of an owner who knows his doors are shut.
Save My Seat →Thursday, July 9, 2 PM ET. No charge, no pitch.
Want this kind of plain-English security news every week? Sign up for Craig's Insider Notes at CraigPeterson.com.
Join thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.
Join 10,000+ cybersecurity professionals