Fake $149.99 Apple/Amazon Charge Popup Scam

Malwarebytes · Medium sophistication
Last updated August 6, 2026

A scam campaign uses full-screen browser popups impersonating Apple Support or Amazon to claim an “unauthorized” $149.99 charge and pressure victims to call a phone number. Callers reach a live scammer posing as support who tries to gain remote access or steal payment/account details, sometimes pushing payment via gift cards or wire transfer.

Key findings

  • Attack uses full-screen popups impersonating Apple Support or Amazon claiming a “$149.99 purchase” and urging an immediate call.
  • The same phone number is reused across the Apple- and Amazon-branded versions, indicating a single scam operation.
  • The lure is engineered for credibility and urgency using a “moderate dollar amount,” “Pre-Authorization” payment jargon, and “Call immediately” language.
  • If victims call, a live scammer poses as support and attempts to get remote access, collect account/payment info, or demand payment (e.g., gift cards or wire transfer).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance/Accounting, IT Helpdesk.
  • Affected industries: Retail / eCommerce, Consumer technology, General public / consumers.
  • Attack channels: website, vishing.
  • Impersonated: Apple Support or Amazon Support.

Awareness takeaways

  • Treat unexpected browser popups about account charges as suspicious, verify by going directly to the company site/app, not by interacting with the popup.
  • Never call a phone number provided by a popup; use known-good contact paths (official site/account dashboard or your card issuer).
  • Be cautious of ‘tech support’ callers asking for remote access or pushing unusual payment methods like gift cards or wire transfers.
  • Recognize the pattern: urgency + specific dollar amount + authoritative branding + phone call demand is a common scam formula.

Red flags to watch for

  • Unexpected full-screen popup while browsing (not from the real account/app)
  • High-pressure urgency like “Call immediately” / “Immediate Action Required”
  • A single phone number presented as the only way to resolve the issue
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re browsing, and suddenly your screen locks up: “Apple ID charged $149.99 – call immediately to stop this payment.” Sometimes it’s Apple, sometimes Amazon, but the script’s identical: a $149.99 “Pre-Authorization,” a big warning icon, and the same phone number as your only option. The popup wants one thing: for you to call. On that line, a fake “support” rep pushes remote access to your computer or payment by gift cards or wire transfer. If you see a $149.99 charge popup, don’t call the number, close the tab and check your Apple, Amazon, or card account directly instead.

Similar attacks

Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
Phishing Hits M365; Deepfake Vishing Targets Funds

Phishing Hits M365; Deepfake Vishing Targets Funds

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be…

August 7, 2026
Gambling Goblin Hijacks Gov Sites for Phishing

Gambling Goblin Hijacks Gov Sites for Phishing

Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon)…

September 2, 2026
Teams Helpdesk Vishing Pushes Remote Control Tools

Teams Helpdesk Vishing Pushes Remote Control Tools

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or…

August 31, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026