Can We Trust It?Can We Trust It?← All guides

Is that McAfee or antivirus renewal email a scam?

Fake antivirus renewal emails — most commonly impersonating McAfee, but also TotalAV, PC Protect, Avast, and Norton — are a parallel operation to the Geek Squad scam. The email is an invoice for an annual security subscription renewal: typically $299 to $449. A bold phone number is provided to 'cancel the renewal and request a refund'.

When you call, a fake support agent explains that they need remote access to your computer to 'process the refund'. Once they have access, they either install malware, steal credentials, or stage a fake bank portal that shows a 'refund' of a far larger amount — then claim the overpayment needs to be returned via gift cards.

McAfee, NortonLifeLock, and other major security vendors have all issued public warnings about these emails. The emails have no connection to the companies they impersonate.

🚩 Red flags to watch for

  • You have no active McAfee, TotalAV, or other antivirus subscription — or you're not sure, which is exactly the ambiguity these scams exploit.
  • The email's only action is to call a phone number — there is no account login link, no website portal, no real company infrastructure.
  • The sender address is not from the genuine vendor's domain (@mcafee.com, @totalav.com, @avast.com).
  • The invoice amount is between $200 and $500 — alarming, but not so large as to seem implausible for a security subscription.
  • No purchase confirmation from when the subscription allegedly started a year ago.

✅ What to do

  1. 1Do not call the number. The phone call is the entire scam mechanism — calling is where the fraud happens.
  2. 2If you have a genuine McAfee account, log in directly at mcafee.com to check your subscription status. Do not use any link or number from the email.
  3. 3Delete and block the sender.
  4. 4If you already called and gave remote access: disconnect from the internet, run a full malware scan (Malwarebytes free edition is reliable), and change passwords for your email and banking accounts from a different device.
  5. 5Report to the FTC (reportfraud.ftc.gov) or Action Fraud (UK).

📣 Where to report (by country)

🇺🇸 United States

🇬🇧 United Kingdom

🇦🇺 Australia

🇨🇦 Canada

🌍 Everywhere else

  • Contact your local police and your bank immediately
  • If money was sent, ask your bank about a recall request — act within hours

Got a suspicious message right now?

Paste it into our free AI checker for an instant pattern analysis

No account needed · Free to try · Privacy-first

Check your message free →

No tool is a guarantee. AI pattern detection is a guide, not a verdict — always use your own judgment.

Common questions

How do I know if I actually have a McAfee subscription?

Log in to your McAfee account directly at mcafee.com. If you don't have an account or can't find a matching subscription, the email is fake. You can also check your credit/debit card statements for any recurring McAfee charges.

I called and the agent had remote access for several minutes. What should I do now?

Treat this as a full account compromise. Immediately: disconnect from the internet, run a malware scan, change all important passwords from a different device, check bank accounts for unauthorised transactions, and contact your bank if any financial information was visible during the session.

Geek Squad / Norton renewal scamFake invoice / BEC scamFake tech support pop-up