A callback scam, meaning a fraudulent text message written to make the recipient call a number the attacker controls, recently reached a Washington, D.C., resident named Paul C. with a claim that Apple Pay had already charged him $8,250 and would charge him $8,250 more within 35 minutes. Paul did not call. He sent the message to Kurt "CyberGuy" Knutsson for review instead.

What the text actually said

The message opened with "$8,250.00 APPLE PAY - 35-MINUTE DEADLINE" and described the situation using words like "hemorrhaged," "catastrophic fraud event," and "verbally kill the pending charge." Legitimate fraud alerts use plain terms: charged, declined, frozen, pending. They do not describe accounts as hemorrhaging money.

The text cited case number CA-3321 and provided an 855 toll-free callback number. It arrived from a phone number carrying a +44 prefix, the international calling code for the United Kingdom. A genuine Apple Pay notification would not route a U.S. recipient through a United Kingdom sender to a separate callback line.

The two supposed merchants named in the message were "an agricultural processing surplus in Stockton, CA" and "a payday lending chain in Modesto." Neither is an actual merchant name. Real transaction alerts show the merchant's name, not a vague industry description with a city attached.

The text also claimed Paul's contactless spending limit had been "crushed to $0" while simultaneously warning that another $8,250 charge would auto-approve in 35 minutes. A limit of zero and a pending approval cannot coexist. The contradiction reveals a message written to manufacture panic, not to describe an actual account problem.

Why the 35-minute window is the mechanism

The deadline was not accidental. Thirty-five minutes is long enough to place a call and short enough to stop Paul from opening Wallet, checking his bank's app, or asking someone nearby what to make of it. That window is where the scam operates.

Once a target calls back, the FTC warns, a fake support agent may ask for card numbers, request a verification code framed as a cancellation step, or instruct the caller to install a remote-access application. CyberGuy previously reported a separate Apple Pay scam that nearly produced a $15,000 loss after a caller kept the target on the phone while she drove to her bank.

How to verify a charge without following the scammer's script

Apple Pay questions belong in Wallet, the bank or card issuer's official app, or the number printed on the back of the card. Apple states that Wallet may not show a complete transaction history for every card, so the bank remains the authoritative source. Contact information supplied inside an unexpected message should not be used.

Suspicious texts impersonating Apple can be reported by emailing a screenshot to [email protected]. Forwarding the message to 7726, which spells SPAM, alerts your carrier as well.

The message Paul received contained no link, so security software would not have detected the threat. The pressure came entirely from the words on the screen and the stranger waiting at the other end of that 855 number.