Home Articles Get your free assessmentComing soon

Tag: subscriptions

  • “Your Subscription Renewed for $499.” There’s No Link — That’s the Point.

    “Your Subscription Renewed for $499.” There’s No Link — That’s the Point.

    The email lands at 8:20 on a Tuesday, near the top of the administrator’s inbox, between a facilities quote and a note about the flowers.

    Order Confirmation — Auto-Renewal Processed Thank you. Your annual subscription has been renewed. The charge will appear on your statement within 24–48 hours. Plan: Total Device Security — 5 devices Amount: $499.00 USD Order ID: 7734-2210-9861 If you did not authorize this renewal, you must cancel within 24 hours to receive a full refund. Call our billing department at (888) 555-0142.

    There is no link to click. Nothing to download. No misspelled sender name, no urgent all-caps subject line, none of the things anyone has ever been trained to look for.

    And the administrator’s first honest reaction is not suspicion. It’s: do we pay for that?

    She’s worked here three years. There are maybe forty things the church pays for. The last administrator set most of them up — some on the church card, some on the pastor’s card, some auto-drafting from checking. She genuinely does not know whether the church subscribes to Total Device Security, and $499 is real money out of a tight budget.

    So she calls. That was the entire objective of the email.

    Callback phishing, decoded

    Callback phishing is a scam that uses an email to make you dial a phone number, where the actual attack happens. You may also see it called TOAD, for telephone-oriented attack delivery — the same thing in acronym form.

    The name describes the structure precisely. The email is not the attack. It’s bait for a phone call, and the attack is a person talking to you.

    That inversion is why it defeats a decade of security training. Everything your staff has been told about email — don’t click the link, don’t open the attachment — is about a message that contains something dangerous. This message contains nothing dangerous at all. It’s an invoice with a phone number on it, which describes roughly half the legitimate mail your office receives.

    Why your spam filter waves it through

    Spam filters catch things. A malicious attachment, a link to a known-bad domain, a login page pretending to be Microsoft, a sender whose address doesn’t match the domain it claims — a filter can inspect all of that and score it. A plain-text invoice with a phone number offers nothing to inspect.

    The State of Wyoming’s technology agency puts the mechanics plainly in its guidance on this scam: since these emails “do not contain malicious links or attachments, they can bypass email spam filters.” No payload to detonate, no URL to check against a blocklist. The message is just words and ten digits, sent from an address that hasn’t done anything wrong yet.

    Say this to your staff plainly. The assumption underneath most office email habits is that the filter is a wall. It isn’t — it catches what can be caught, and this message is built specifically not to be one of those things.

    The FTC has documented the exact template: “scammers send notices about automatic renewals for tech support subscriptions. You might get an email or text message that says you were charged hundreds of dollars to renew your tech support subscription.”

    What happens on the call

    The person who answers is pleasant, unhurried, and competent. There is no pressure in the first two minutes — the opposite, in fact. He is sorry about the confusion. He can absolutely cancel that and process the refund. It’ll take just a moment.

    Then, gently, comes the ask. To process the refund he needs to connect to the computer — so the credit lands on the right device, or so the software can be removed. He gives her a website to visit and a short code to type in.

    That’s a remote access tool — software that lets someone else see and control your computer as if they were sitting at it. There are entirely legitimate versions; your real IT provider probably uses one. In this call, it’s the whole objective. The FTC describes the pattern directly: “they ask for remote access to your computer and pretend to scan it for viruses.”

    From there it goes one of two ways.

    He takes the machine. With control of the computer he installs something that keeps his access after the call ends, harvests saved passwords from the browser, and looks for anything worth having — banking access, the donor database, the mailbox. Some of these are the front door for a ransomware attack weeks later.

    He fakes an overpayment. This is the version that takes money the same day. The FTC describes it step by step: “They take you to a spoofed website that looks real and tell you to enter your bank or credit card information to process the refund. After you do that, they claim there was an error in the amount entered. They say they refunded you too much money and insist you pay them back with gift cards, a wire transfer, a bank transfer, cryptocurrency, or a payment app.”

    With remote control of the screen, he can make the numbers appear to move. A refund of $499 seems to arrive as $4,990. He is distraught — his mistake, he’ll lose his job, can she please just send back the difference? The balance she is looking at was edited in front of her. Nothing was ever refunded, and the money she sends is entirely real.

    The sympathy is engineered. He has spent fifteen minutes being helpful, and now he needs help. Most people, especially people who work at a church, find that very hard to refuse.

    The church-shaped version

    Every element of this lands harder in a small ministry office, and none of it is because anyone was careless.

    Nobody knows the full list of subscriptions. This is the real vulnerability, and it is almost universal. Software was set up by a departed staff member, a volunteer, or a contractor. Renewals auto-draft. The bookkeeper sees a charge and assumes someone approved it. The scam works because “do we pay for that?” is a genuinely open question.

    There’s no IT helpdesk to check with. At a company, this call gets forwarded to the technology team in thirty seconds. In a church office, the administrator is the technology team, and she has a bulletin to finish.

    Payment cards are shared. When the pastor’s card, the church card, and a reimbursement arrangement are all in play, an unrecognized charge doesn’t read as fraud. It reads as something somebody else did.

    The instinct is to be helpful. Front desk coverage rotates, and church offices are staffed by people whose actual job is to be kind to whoever is on the phone.

    None of this is negligence. It’s what a five-person organization looks like, and it can be closed with about an hour of work.

    The rule, and the list

    One sentence, and it covers the entire category:

    Nobody at this organization installs software or grants remote access to a computer because of an incoming email or an incoming call. Ever, for any reason.

    Every legitimate remote support session starts with a relationship you initiated — your IT provider, whom you called, at a number you already had. No refund requires access to your computer. No cancellation requires it. No bank requires it. If someone on a call needs to see your screen and you did not start that relationship, the answer is no.

    The second half is what makes the rule easy to follow: write down what you actually pay for.

    One page or one spreadsheet. Four columns: the service, what it’s for, roughly what it costs and when it renews, and — most importantly — who owns it. Include everything: Microsoft 365 or Google Workspace, the church management system, the giving platform, the website host, the domain registration, the streaming service, accounting software, online backup, alarm monitoring, the copier contract. Pull the last three months of bank and card statements and work through the recurring charges line by line. That is the whole exercise, and it takes an hour the first time.

    Two things come out of it. The security control: when a renewal notice arrives, “do we pay for that?” takes eight seconds instead of being unanswerable. And the money — nearly every organization that does this finds something it’s been paying for and hasn’t used in two years.

    Then one habit on top, which also covers the versions that arrive by text or voicemail: never verify a charge using contact details supplied by the message telling you about the charge. Open your bank or card account the way you normally do — your own bookmark, your own app — and look at the actual transactions. If the charge isn’t there, there’s nothing to cancel. If it is, call the number printed on the back of your card.

    That’s the same money rule that runs through the rest of this blog — verified by voice, on a number you already had — pointed at a different target. The direction of contact is the control.

    And give your staff explicit permission to be unhelpful. Say it out loud: you will never be in trouble for hanging up, or for saying “I’ll have to check on that and call you back.” Without that permission, a polite person facing a polite stranger will stay on the line.

    If it already happened

    If someone granted access or sent money, move today. This is recoverable more often than people expect, and much less often after a week.

    Disconnect that computer from the network — unplug the cable, turn off the Wi-Fi. Do not wipe it, and do not “just reinstall.” Someone technical needs to see what was installed before it goes back into use, and wiping destroys the only record of what happened.

    Call the bank immediately if money moved or if banking details were entered during the call. Say the words fraud and unauthorized, and ask about recalling the transfer. If a card was involved, cancel it.

    Change the passwords for anything that computer could reach — email, the giving platform, the church management system, the accounting software — from a different device, and sign out all active sessions. Turn on multi-factor authentication anywhere it isn’t already on, and check the mailbox for forwarding rules nobody remembers creating. The FTC’s guidance is the same: if you gave a username and password to a tech support scammer, change your password right away.

    Report it. File with the FBI at ic3.gov. If money moved, go to ic3.gov first and quickly — the FBI’s Recovery Asset Team froze $507,042,623 across 3,574 domestic cases in 2025, and that process depends almost entirely on speed.

    And tell someone in the office immediately. The pattern that turns a contained mistake into a serious loss is always the same: someone embarrassed, waiting until Monday.

    What to do this week

    Build the subscription list. Pull three months of statements, write down every recurring charge with an owner’s name beside it, and put the file where the administrator and the treasurer can both reach it. That’s the hour, and it’s the only part of this that takes real time.

    Then send one sentence to everyone who answers the phone or the office email: we never install software or allow remote access because someone contacted us — if you’re asked to, hang up and tell me, and you will never be in trouble for it.

    For a wider look at where a determined caller could get traction, MissionDefend’s free assessment asks plain-English questions about how your organization handles email, payments, vendor accounts, and member data, then returns a baseline score and a ranked list of what to fix first — including the gaps, like an unmanaged pile of subscriptions, that don’t look like security problems until they are.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: Federal Trade Commission, How To Spot, Avoid, and Report Tech Support Scams; State of Wyoming Enterprise Technology Services, Callback Phishing; FBI Internet Crime Complaint Center, 2025 Internet Crime Report.