Money that never actually arrived can still empty a real bank account. That paradox is the heart of the refund-overpayment scam, a con that hands the target a screen showing thousands of dollars deposited by mistake and then asks, apologetically, for the extra amount back. The refund is a stage prop. The money sent in return is the victim’s own savings, walking out the door.
The fake overpayment that starts it all
The setup usually opens with an unexpected message: a subscription is being canceled, a company is going out of business, or a tech-support charge is being reversed, and a refund is owed. The caller offers to process it and asks for remote access to the target’s computer or bank login “to complete the transfer.” From there, the numbers on the screen become a puppet show the scammer controls.
With that access, the fraudster moves money between the target’s own accounts, or simply edits what the browser displays, so it looks as though far too much has been refunded. A promised $300 appears as $30,000. The caller then acts flustered, claims the extra was a typo that will get them fired, and pleads for the difference to be returned right away.
The Federal Trade Commission lays out this exact sequence in its guidance on how to spot, avoid, and report tech-support scams: the “overpayment” is manufactured, and the money a target wires or sends back is real money drawn from their own balance. Once it leaves in an untraceable form, it is effectively gone.
Free retirement updates: Scam calls targeting retirees change every week. Our free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.
Why the “send back the difference” step is the trap
The entire con hinges on one emotional lever: guilt. The caller frames the return as a favor to a nervous employee who made an honest error, turning a stranger’s problem into the target’s responsibility. That framing is designed to bypass the obvious question of why a legitimate company would ever need a customer to manually correct its own accounting.
The requested method of return gives the scheme away. Gift cards read aloud over the phone, cash mailed in a package, a wire transfer, or cryptocurrency all share the same trait: the funds cannot be clawed back once they land. A real business that genuinely overpaid would reverse the transaction on its own end, not ask a customer to buy gift cards or drive cash to a courier.
Because the display balance was faked, the target believes the extra thousands are sitting there and freely sends “their” money back, not realizing the returned amount comes straight out of true savings. The deposit that seemed to justify the whole exchange was never a deposit at all.
The remote-access request that should stop everything
A single demand marks the moment to end the call: any request to install screen-sharing software or to grant control of a computer or phone in order to receive a refund. No legitimate refund requires a company to see or steer a customer’s device. That access is what lets the scammer stage the phantom overpayment in the first place.
The same caution applies to handing over online-banking credentials or reading back one-time security codes. Impersonators often pose as well-known retailers, antivirus brands, or payment platforms, and they rely on official-sounding names and spoofed numbers to lower a target’s guard. The polish of the pitch is not evidence that it is real.
Verifying a refund the safe way
A genuine refund can always be confirmed independently. The protective move is to refuse remote access, hang up, and contact the company directly through a number or account page the customer already trusts, not one the caller provided. A quick look at the actual bank statement, reached through the bank’s own app or site, will show whether any real deposit occurred.
When the numbers do not match the story, they never do, the exchange is a scam, and no money should be returned. Suspected refund and tech-support scams can be reported to the FTC at its fraud reporting site, and a bank should be alerted immediately if account access or credentials were shared. Speed matters, because a wire or gift-card transfer caught within hours occasionally can be halted.
The tell is consistent across every version of this scam. A real refund adds money and asks for nothing back. A refund that overpays and then needs the difference returned is not a refund; it is a withdrawal from the target’s own account, disguised as a favor.
Why the deposit looks real when it is not
The illusion is convincing because the numbers on the screen genuinely change. With remote access, a scammer can shuffle a target’s own money from a savings account into checking, making it appear that a large sum just arrived from outside, when in truth the balance was only moved from one pocket to another. In other cases the fraudster simply alters what the web page displays, editing the figure so a modest refund reads as a five-figure windfall that never existed at all.
Either way, the target is looking at a number the scammer manufactured, which is why the request to “send back the difference” can feel reasonable in the moment. The defense is to trust the bank’s own record rather than the screen the caller helped arrange: logging in fresh, on a device with no remote-sharing software running, shows what actually happened to the account, and it rarely matches the story the caller told.
This article was researched and drafted with AI assistance and reviewed against the linked primary sources.
More Financial Reading
- How many CDs can you park at 1 bank? FDIC rules you must know
- The ideal retirement withdrawal rate so your savings actually last



