Fake $149.99 Apple/Amazon Charge Popup Scam

Malwarebytes · Medium sophistication
Last updated August 6, 2026

A scam campaign uses full-screen browser popups impersonating Apple Support or Amazon to claim an “unauthorized” $149.99 charge and pressure victims to call a phone number. Callers reach a live scammer posing as support who tries to gain remote access or steal payment/account details, sometimes pushing payment via gift cards or wire transfer.

Key findings

  • Attack uses full-screen popups impersonating Apple Support or Amazon claiming a “$149.99 purchase” and urging an immediate call.
  • The same phone number is reused across the Apple- and Amazon-branded versions, indicating a single scam operation.
  • The lure is engineered for credibility and urgency using a “moderate dollar amount,” “Pre-Authorization” payment jargon, and “Call immediately” language.
  • If victims call, a live scammer poses as support and attempts to get remote access, collect account/payment info, or demand payment (e.g., gift cards or wire transfer).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance/Accounting, IT Helpdesk.
  • Affected industries: Retail / eCommerce, Consumer technology, General public / consumers.
  • Attack channels: website, vishing.
  • Impersonated: Apple Support or Amazon Support.

Awareness takeaways

  • Treat unexpected browser popups about account charges as suspicious, verify by going directly to the company site/app, not by interacting with the popup.
  • Never call a phone number provided by a popup; use known-good contact paths (official site/account dashboard or your card issuer).
  • Be cautious of ‘tech support’ callers asking for remote access or pushing unusual payment methods like gift cards or wire transfers.
  • Recognize the pattern: urgency + specific dollar amount + authoritative branding + phone call demand is a common scam formula.

Red flags to watch for

  • Unexpected full-screen popup while browsing (not from the real account/app)
  • High-pressure urgency like “Call immediately” / “Immediate Action Required”
  • A single phone number presented as the only way to resolve the issue
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re browsing, and suddenly your screen locks up: “Apple ID charged $149.99 – call immediately to stop this payment.” Sometimes it’s Apple, sometimes Amazon, but the script’s identical: a $149.99 “Pre-Authorization,” a big warning icon, and the same phone number as your only option. The popup wants one thing: for you to call. On that line, a fake “support” rep pushes remote access to your computer or payment by gift cards or wire transfer. If you see a $149.99 charge popup, don’t call the number, close the tab and check your Apple, Amazon, or card account directly instead.

Similar attacks

Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
Phishing Hits M365; Deepfake Vishing Targets Funds

Phishing Hits M365; Deepfake Vishing Targets Funds

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be…

August 7, 2026
Revolut Smishing Uses Fake Identity Check

Revolut Smishing Uses Fake Identity Check

Following a Revolut data breach, scammers sent text messages that appeared to come from the same message thread as legitimate Revolut texts. The texts pushed victims to click a link for a fake identity “liveness check,” request camera access, and then capture passwords, information that could be…

September 21, 2026
Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Fake Bitrefill Sites Steal Crypto via Search Results

Fake Bitrefill Sites Steal Crypto via Search Results

Scammers are using lookalike Bitrefill domains that appear in search results to trick people into buying gift cards or top-ups. The fake sites copy Bitrefill’s branding and checkout flow, then display a QR code and crypto address so victims unknowingly pay the scammers instead of Bitrefill. Because…

September 15, 2026
Gambling Goblin Hijacks Gov Sites for Phishing

Gambling Goblin Hijacks Gov Sites for Phishing

Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon)…

September 2, 2026