“Card on file” is convenient—until scammers exploit it. Criminals are sending emails and texts that look like real notices from familiar brands, telling you to update the payment method they keep on file. The brand names, logos, and account details may look perfect. In some cases, the message references a real subscription you have. This guide explains how these scams work, the specific red flags to look for, how to verify safely without clicking, and what to do if you already interacted with a suspicious request.
Why these scams are convincing now
Fraudsters increasingly blend leaked personal data with polished design to impersonate legitimate merchants. If your email, phone number, and partial billing details were exposed in a data breach or found on data broker sites, criminals can craft messages that feel tailored to you. That realism reduces your guard and pushes you to “fix” a supposed payment issue quickly.
How a card‑on‑file update scam typically works
- Pretext: You receive an email or SMS claiming your payment method failed, your card is expiring, or a new policy requires confirmation.
- Impersonation: The message uses the real merchant’s name, logo, and support-sounding language. It may include your name, partial address, or a last‑4 that looks believable.
- Urgency hook: It threatens account suspension, delivery delays, or fees within 24–48 hours if you don’t act.
- Link to a fake page: The “Update card” button opens a convincing but fraudulent site that collects your card number, CVV, and sometimes your login credentials or one‑time passcode.
- Monetization: Stolen details are used for purchases, account takeover, or sold to other criminals.
Authenticity checks you can do in under 30 seconds
- Sender address/domain: Expand the sender in the email. A real merchant uses its true domain (e.g., @merchant.com), not lookalikes like @merch-support.com or free mail domains.
- Link destination: Hover on desktop or long‑press to preview on mobile. The domain should match the merchant’s official site exactly, not a misspelling, subdomain trap (merchant.com.secure‑pay[.]info), or URL shortener.
- Sign‑in flow: Legitimate notices typically ask you to sign in on the app or website first. If the link opens a bare card form with no login, it’s a red flag.
- Grammar and tone: Many scams are polished, but odd phrasing, mixed fonts, or inconsistent capitalization still expose fakes.
- Out‑of‑band verify: Don’t click. Independently open the merchant’s app or type their URL you already know. Check for billing alerts in your account.
Specific red flags for emails and texts
Email red flags
- Display name trick: The “From” name shows the brand, but the actual email domain is unrelated.
- Unusual personalization: Your name is correct but the account number format is off, or the message references a location you’ve never used.
- Attachment requests: Legit merchants rarely use attachments (.html, .pdf) for billing updates.
- DMARC/branding inconsistencies: Missing brand icons in your inbox, or warnings like “This message seems dangerous.”
SMS (smishing) red flags
- Shortened links: Bitly/tiny links hide the true domain.
- Unknown sender IDs: Real brands often use verified sender IDs or in‑app notifications.
- OTP harvesting: A text asks for one‑time codes for “verification.” Your bank or merchant never asks you to share OTPs via text or email.
Real merchant behaviors you can rely on
- They route you to authenticate first: Most merchants require you to log in before changing billing details.
- They notify in‑app: Many brands place the same alert inside your account messages or app notifications. If it’s real, you’ll see it there.
- No rush to a card form: Urgency plus a direct payment link is rarely legitimate.
- They don’t ask for full card + CVV by email: Any request to share complete card details or photos of your card is suspect.
Safe ways to verify without risk
- Go direct: Ignore the message links. Open the merchant’s app or type their official URL from your bookmarks or a search result you independently verify.
- Check account billing: Review “Payment methods,” “Billing,” or “Subscriptions.” If action is required, it will be shown there.
- Contact support using official channels: Use the phone number or chat listed on the merchant’s website. Quote the message and ask if it’s genuine.
- Check your recent statements: Look for actual failed charges or messages from your card issuer.
Examples of lookalike domains and tricks
- Typosquats: merchanr.com, rnerchant.com (r and n together look like m), merchánt.com (accented characters).
- Subdomain traps: update.merchant.com.billing‑verify[.]net (real brand as a subdomain of a fake parent domain).
- Homograph attacks: Domains using visually similar Unicode characters. If something looks off, retype the URL manually.
If you clicked or entered details: do this now
- Secure the account: Immediately change the password of the impersonated merchant account and any other accounts using the same password. Enable two‑factor authentication.
- Contact your card issuer: Report that your card may be compromised. Request a new card number and monitor for unauthorized charges.
- Review statements and alerts: Set transaction alerts and watch for small “test” charges.
- Scan email rules: In your email settings, check for unexpected forwarding or auto‑delete rules added by attackers to hide future alerts.
- Run device checks: If you downloaded an attachment or installed anything, run your device’s security scan and remove suspicious apps or profiles.
- Report the phishing: Forward phishing emails to the impersonated merchant’s abuse or security address if available, and report SMS to your carrier’s spam number (often 7726 in the U.S.).
How scammers get your info in the first place
- Data breaches: Exposed emails, phone numbers, and partial billing info improve phishing realism.
- Data brokers and people‑search sites: They compile contact details, addresses, and relationships that scammers can mine.
- Public footprints: Old resumes, social posts, and forum accounts reveal services you use and timing (e.g., a gym membership or streaming trial).
Reducing your exposed data shrinks the material scammers can use to personalize attacks. Regularly removing broker listings and tightening privacy settings on major accounts makes impersonation less convincing.
Preventive steps you can take today
- Use unique passwords and a password manager: Prevents one breach from unlocking multiple accounts.
- Turn on two‑factor authentication: Prefer app‑based or hardware keys over SMS where possible.
- Create a “bill‑pay routine”: Once a month, sign in directly to your subscriptions and merchants to review payment methods and invoices. This reduces the urge to react to messages.
- Enable account and transaction alerts: Real‑time alerts from your bank and card can help you catch fraud quickly.
- Harden your inbox: Use spam filters, disable remote image loading, and consider separate emails for shopping and banking.
- Reduce your digital footprint: Opt out of data brokers and keep your contact info private when possible.
When monitoring and identity protection help
If criminals capture your card or personal details, early detection is critical. Credit and identity monitoring can alert you to new account applications, changes to your credit, and other risky activity linked to your identity. For a practical way to keep an eye on credit changes and identity‑related alerts, consider tools like SmartCredit for privacy, credit monitoring, and identity protection. Monitoring complements—not replaces—good security habits and careful verification.
Quick checklist: is this message safe?
- Does the link go to the exact official domain, and does it require sign‑in first?
- Can you see the same alert inside your account or app when you log in directly?
- Is there any pressure to act immediately or risk suspension/fees?
- Is the sender domain authentic, and are there no URL shorteners or odd subdomains?
- Is the message asking for full card details, photos, or one‑time codes?
Frequently asked questions
If my card is truly expiring, how will I know?
Your bank or card issuer typically notifies you directly and mails a replacement. Many merchants update card details automatically through your issuer’s updater services. You can confirm inside your merchant account without clicking any message link.
The message includes my correct subscription tier and last payment date. Is it real?
Not necessarily. That information can leak from breaches or emails in your inbox. Always verify by signing in directly on the merchant’s official site or app.
Can a real merchant ever send a direct card form link?
Some smaller services might, but it’s uncommon. When in doubt, avoid the link and navigate directly to your account settings.
Conclusion
Scam “card‑on‑file update” requests work because they borrow trust from real merchant names and your genuine subscriptions. Slow the process down: verify independently, require a proper sign‑in flow, and never enter full card details through unsolicited links. If you slip, act quickly—secure your accounts, replace your card, and monitor for unusual activity. With a short monthly review routine and careful link hygiene, you can keep the convenience of saved payment methods without giving scammers a shortcut to your wallet.
Good to Know
Legitimate merchants almost never send a link that directly opens a card-entry form; they point you to sign in on their site or app first. If a message skips sign-in, treat it as suspicious.