Blog post: Online security

A message announces a tax, energy, insurance or administrative fee refund, with an amount that seems to be waiting for its beneficiary.
The promise seems advantageous, sometimes even credible when it includes a name, an address or a partial reference.
Yet the trap is not in the amount announced, but in the action requested to receive it. In just a few clicks, the victim can transmit information that will be used for immediate fraud or later identity theft.
The fake refund scam relies on a simple idea: making people believe that an organisation owes them money and that the person contacted must complete a formality to obtain it. The message may mention a public authority, an energy supplier, an insurer, a telecommunications service, a subscription, an adjustment or an overpayment. The wording used varies, but the logic remains the same: a sum is supposedly available, provided that a form is completed, an account is confirmed or a step is validated.
This fraud differs from messages that threaten a fine, a cut-off or a debt. Here, the reaction sought is positive: the person feels lucky, relieved or simply curious to recover money. This promise can reduce vigilance, especially when the amount seems plausible and the procedure appears quick.
Scammers rarely try to convince at length. They prefer to create an impression of obviousness: a refund has been calculated, an adjustment is ready, compensation is awaiting confirmation. The message then pushes the person to act before taking the time to verify through another channel.
Fake refunds can appear in many forms. A message may mention taxes, energy bills, insurance, telephony, a public service, cancellation, compensation or administrative fees. The chosen area mainly depends on what seems familiar to the victim and common enough not to immediately arouse suspicion.
The fraud works all the better because real refunds exist in everyday life. A bill can be adjusted, an overpayment can be returned, a contract can lead to a correction. Scammers exploit this plausibility to introduce an unusual request into the middle of a scenario that seems ordinary.
You should therefore not judge a message only by the subject it addresses. A refund announced in a credible sector can still be used to collect sensitive data. The decisive point is the nature of the action requested and the way it is imposed.
The contact can arrive by email, SMS, instant messaging, phone call or digital letter. The message often announces that a refund has been identified and that information must be confirmed in order to receive it. The request may take the form of a link, a form to complete, a QR code to scan or an invitation to call someone back.
Some messages add a deadline presented as limited. This pressure is useful to fraudsters, because it reduces the likelihood that the person will check their official account, contact the organisation concerned or ask for an outside opinion. The refund then becomes an opportunity not to be missed, rather than information to verify.
The style may be polished or clumsy. A mistake, a strange address or unusual wording remain interesting signals, but the absence of visible errors is not enough to make the message reliable. The most credible campaigns can imitate an official layout and use personal information already known.
The link or QR code may lead to an imitation of an administrative portal, customer account area or refund page. The colours, logos, sections and visual organisation can create an impression of seriousness. Once on the page, the victim is guided step by step, which makes the collection of information less abrupt and more acceptable.
The form sometimes begins with standard elements, such as name, address or email. It may then ask for more sensitive information: date of birth, phone number, contract reference, login details, bank details, full card data or confirmation codes. This gradual progression is designed to prevent the request from immediately appearing excessive.
Not all the information collected has the same usefulness, but it can be combined. An email address, phone number and date of birth can facilitate an attempt to take over an account. Bank data or validation codes can open the way to more direct financial fraud.
The QR code gives the process a modern and practical appearance. It also hides the real destination until it has been scanned, unlike a link that can sometimes be examined before clicking. The person generally has to use their phone, which makes the full website address less visible and harder to check.
This move to the smartphone can benefit the fraudster. On a smaller screen, the details of the address, subdomains or suspicious elements are less readable. Navigation is also faster, more tactile, and the person may be tempted to continue without taking the time to analyse the page.
A QR code is not a sign of reliability. It can simply replace a classic fraudulent link and lead to the same fake website imitation. Before scanning or opening the page, you should ask why the organisation does not direct you to the usual account area accessible directly from its website or app.
The theft is not always immediate. Some campaigns first seek to build an exploitable file on the victim. The information obtained may be used to personalise new messages, bypass certain checks, attempt to access accounts or prepare identity theft.
This approach explains why a fraudulent form may ask for a lot of information without immediately requesting payment. Each piece of data adds credibility to a future attempt. A scammer who already knows an address, phone number or partial reference can appear much more convincing during a second contact.
The presence of accurate information in a message therefore does not prove that the sender is legitimate. These elements may come from data already compromised or recovered elsewhere. The more personalised the message seems, the more important independent verification becomes.
In the most directly financial scenarios, the fake refund is used to obtain card data or bank details. The victim may believe they are providing the means to receive the money, when in fact they are transmitting information that can be used to exploit a payment method. A legitimate refund generally does not require you to provide all the data needed to use a bank card.
Another method consists of presenting a validation as a simple verification. The person thinks they are confirming their identity, account or eligibility, but they may actually be authorising a sensitive operation. It may be a login, a payment, the addition of a device or an action that the message does not clearly describe.
The fraudster may sometimes accompany the victim by phone during this step. This guidance limits thinking time and diverts attention from what is really being validated. When someone insists that a code be given, a notification accepted or a banking operation confirmed, the risk becomes particularly high.
A large fake refund may be preceded by a very small payment request. The pretext varies: administrative fees, banking verification, account validation or mandatory step before payment. The low amount makes the request less worrying, but it may be enough to collect card data or prepare further debits.
The reasoning to keep in mind is simple: you should not have to pay to receive a refund that is genuinely due. A sum presented as symbolic can be a test, a gateway or a way to make the victim more committed to the procedure. Once the payment is accepted, scammers often have additional information and may try to continue.
This request must be examined with the same caution as a large payment. The amount is not the only risk criterion. What matters is the consistency of the procedure and the ability to verify the information through an independent channel.
An unexpected refund always deserves a pause. The message may be professional, include a precise amount and use a presentation close to a known service. Even so, several signs should lead you to suspend any action and verify elsewhere.
These signs do not necessarily all appear together. A single sensitive element can be enough to make the process suspicious, especially when it concerns login details, codes or banking data. Caution means assessing the request, not just the appearance of the message.
The following points should attract attention when they accompany a refund promise:

The right verification begins outside the message. It is better not to click the link, scan the QR code or call back a number provided in the suspicious notification. Access should be through the usual website, the official app already installed or contact details known independently.
If a refund really exists, it should be possible to find it in the official account area of the organisation concerned. The absence of information in that space should lead you to treat the message as suspicious. It is better to spend a few minutes checking than to provide data that is difficult to recover afterwards.
This method also protects against very convincing imitations. A fake site may look like an official portal, but it cannot replace verification carried out from an access point you have chosen yourself. The practical rule is therefore to leave the message and regain control of the verification path.
Fraudsters often present sensitive data as necessary elements for the refund. They may talk about security, confirmation, an incomplete file or mandatory verification. Yet some information should not be transmitted in this type of process, especially when it comes from an unexpected message.
Be wary of requests that make it possible to log in to an account, reset access or validate an operation. A code received by SMS or generated by an app can authorise an action that the victim does not always understand at the moment they share it. A password given to a third party can also open access to other services if the same password has been reused.
The following elements must remain strictly protected:
The response depends on the information transmitted. If banking data has been entered, you must quickly contact the financial institution concerned and monitor transactions. If a password has been shared, it must be changed immediately, as well as on accounts where the same password may have been used.
When a banking validation or operation has been carried out, you need to check precisely what was authorised. The wording, amount, possible beneficiary and nature of the action can help understand the risk. You should not rely only on what the fraudster announced during the procedure.
Evidence must be kept, even if no sum has yet been debited. It can be useful to explain the situation, report the attempt or follow the development of the case. It is advisable to keep the message received, the website address, screenshots, the number used and information linked to any transactions.
Fake refund fraud does not always stop with the first message. After obtaining some data, scammers may get back in touch claiming that a problem has occurred. They then have personal information that allows them to create an impression of continuity and credibility.
The next step may take the form of a new validation, a code to share, a banking operation to confirm or software to install. The victim may think they are resolving an incident linked to the refund, when they are being drawn into a multi-step fraud. The more information already transmitted, the more personalised the speech may seem.
Vigilance must therefore continue for several weeks or months after personal data has been shared. Future messages mentioning the refund, an incomplete file or an error correction must be verified with the same caution. A first mistake must not lead to greater trust in the following contacts.
The fake refund diverts apparently good news in order to trigger a risky action. The main danger is not the announced sum, but the link opened, the QR code scanned, the form filled in or the validation accepted. When a message promises unexpected money, the safest response is to validate nothing from that message and check directly with the official source through independent access.
To strengthen your reflexes, you can consult our practical advice to avoid common scams or test a suspicious address with our dubious link assessment tool. If information has already been transmitted, our support path for fraud victims can help organise the first steps without wasting time.