A fake insurance cancellation call says an insurance policy in your name is about to renew. Canceling it sounds simple, and the caller even promises to return a large charge.
The conversation becomes dangerous when the supposed cancellation requires access to your bank account.

Overview
The caller invents a policy problem you need to fix
A fake insurance cancellation call claims you bought a policy through an online platform, messaging account, bank, or partner company. The caller says it will renew automatically unless you cancel before a short deadline.
The amount is chosen to provoke concern. It may be high enough to demand attention but still sound possible for annual coverage. If the recipient says the policy is unfamiliar, the scammer treats that reaction as a reason to begin a refund or cancellation process.
Some versions impersonate an insurer directly. Others claim to represent WeChat, Tencent, a consumer protection office, or a financial regulator. The names change, but the request moves in the same direction.
The cancellation becomes a guided banking session
The caller may transfer the victim to a supposed cancellation specialist or government officer. The next person asks for personal details, bank information, one-time codes, or a screen-sharing session to “verify” the account and process the refund.
Once the victim shares the screen, the criminal can watch balances, account numbers, security prompts, and transfer activity. The scammer may then instruct the victim to move money into a “safe” or “verification” account.
A real insurer does not need to watch a customer operate online banking to cancel a policy. Screen sharing is not an identity check. It gives the stranger a view of the exact information the bank is trying to keep private.
Authorities have documented substantial losses
ScamShield’s official guidance says victims in Singapore lost at least S$25.2 million to insurance service scams during 2025. The page was updated in May 2026 and describes unsolicited calls and WhatsApp messages about renewal, cancellation, payment, or verification.
A 2024 police advisory documented at least 443 cases and at least S$9.6 million in losses involving scammers who claimed a WeChat insurance policy required cancellation. This is a confirmed impersonation scheme, not a complaint about a legitimate insurer or messaging service.
Common warning signs include:
- you are contacted about a policy you do not recognize;
- the caller says a large renewal will occur today or tomorrow;
- cancellation supposedly requires a bank transfer or refundable deposit;
- the call is moved to WhatsApp or another messaging app;
- a second person claims to be a regulator or police officer;
- you are asked to share your screen while banking;
- the caller requests a password, PIN, or one-time code;
- you are told to keep the investigation secret from your bank or family.
The Refund Story Is Designed to Keep You on the Call
People often stay because the caller appears to be preventing a charge. The victim is not being offered an investment or prize. The conversation is framed as ordinary customer service, which lowers suspicion.
The criminal usually avoids asking for money in the opening minute. First, the caller confirms a name, invents a policy number, and explains the supposed renewal. Each small detail encourages the victim to participate in the next step.
If the victim denies buying the policy, the scammer does not argue. The caller agrees that something may be wrong and offers help. That cooperative tone makes the fraud feel like a resolution rather than an attack.
A transfer to another “department” adds authority. The second scammer may claim to be from a regulator, bank security unit, or police service. In reality, both voices can be sitting in the same call center.
The supposed official may say the unknown policy reveals identity theft or money laundering. The victim is now worried about a criminal case, not just an insurance charge. That escalation creates a reason to reveal more information and follow unusual instructions.
Screen sharing is especially powerful because the scammer can correct the victim in real time. The caller may tell the person to hide the transfer description from a bank employee, raise a payment limit, or approve a security prompt.
The caller sometimes asks the victim to turn the screen black, place the phone face down, or avoid reading messages. Those instructions do not protect privacy. They prevent the victim from seeing what the criminal is doing.

How the Fake Insurance Cancellation Call Scam Works
Step 1: An unsolicited call announces a renewal
The first caller claims an insurance service was activated through a familiar company or account. A renewal date, policy number, and large annual charge make the warning sound specific.
Caller ID may show a local number or a familiar business name, but caller ID can be spoofed. An incoming label does not establish who controls the call.
Step 2: The scammer turns denial into a cancellation request
When the victim says the policy is unfamiliar, the caller offers to cancel it and issue a refund. The scammer may ask for an identity number, address, or bank name to open the supposed case.
Those questions also reveal which story will work next. The criminal can tailor later instructions to the victim’s bank and local authorities.
Step 3: A second impostor adds official pressure
The call is transferred to a fake regulator, police officer, or bank investigator. This person claims the policy is connected to stolen identity details, unauthorized accounts, or money laundering.
The victim may receive forged identification, case papers, or a link to an official-looking site. Images of badges and documents are easy to create and do not authenticate a caller.
Step 4: The victim is isolated from real help
The supposed officer says the case is confidential and must not be discussed. The victim may be told that calling the bank will alert suspects or interfere with the cancellation.
Secrecy is a control tactic. A legitimate insurer expects customers to verify a call. Police and regulators do not prevent people from contacting their own banks.
Step 5: Screen sharing exposes the bank account
The scammer sends a link or uses a messaging app’s screen-sharing function. The victim is guided to open online banking, where account balances and security details become visible.
The criminal may watch a one-time code arrive, learn login information, or direct the victim to create a new payee. Even without remote control, live instructions can produce the transfer the scammer wants.
Step 6: Money is moved to a supposed safe account
The victim is told to transfer funds for verification, cancellation, or protection. The receiving account may be described as a central bank account, regulator account, evidence account, or temporary vault.
There is no special account that requires a customer to move savings during an unsolicited call. Once sent, the money is under the recipient’s control.
Step 7: The scam continues until the victim stops
A fake balance, processing delay, or failed verification creates reasons for additional transfers. The criminals may keep the victim on calls for hours while moving funds and collecting more information.
After contact ends, another impostor may offer recovery for an advance fee. That person may be part of the same operation and already know the amount lost.
Why the WeChat Insurance Version Keeps Reappearing
The WeChat version gives the scammer a familiar platform to blame for an unfamiliar policy. The caller can claim the coverage was activated by a click, a free trial, or an account setting the user forgot to disable.
Because messaging platforms support calls, chats, files, and screen sharing, the criminal can keep every stage inside one environment. The victim receives documents, sees an official-looking profile, and shares a screen without returning to a verified insurer website.
The named platform may change by country. A similar call can mention a bank benefit, travel policy, shopping membership, health plan, mobile contract, or accidental subscription. The scam does not depend on a real policy existing.
That is why searching only the policy name can miss the issue. The decisive signs are unsolicited contact, urgent cancellation, movement to a second impostor, banking access, and a transfer to an account chosen by the caller.
If you think an insurer may have your details, locate the insurer’s website independently and call its published number. Ask whether the policy number and representative exist. Do not use a number sent during the chat.
A caller may also point to a pending debit that cannot be found in the banking app. The supposed charge is bait, not evidence. Do not create a real transfer to cancel a transaction that never existed.
Legitimate policy disputes leave an ordinary paper trail. You should be able to obtain the contract, effective date, premium schedule, cancellation terms, and licensed insurer details without giving a stranger access to your finances.
If the caller refuses to provide those records unless you remain on the line, the process is not customer service. It is an attempt to keep control of your attention.
Company, Address, and Fulfillment Checks
The insurer must confirm the policy independently
Search your own records for policy documents and charges. Then contact the insurer through a statement, trusted app, or official website. A caller who supplied the policy story cannot also be the only source that verifies it.
If the insurer has no record of the policy, end the process. You do not need to cancel a product that does not exist.
The representative should survive a callback
Ask for the person’s name, department, and case reference, then hang up. Call the company’s main number and request that department. Scammers often resist because the callback breaks their controlled channel.
Do not rely on caller ID, a messaging profile, or a photograph of an employee badge. Each can be copied or spoofed.
The regulator will not operate through a safe account
Government officials do not protect money by asking you to transfer it during a call. They also do not need your banking password, one-time code, or live screen to investigate an insurance issue.
End the call and contact the regulator or police through a published number if an official identity is claimed.
A real cancellation produces records, not secret transfers
A legitimate insurer can explain cancellation terms in writing and update the policy account. Any refund should travel through an established company process and appear in normal records.
A personal bank account, crypto wallet, cash handoff, gift card, or newly supplied QR code is not fulfillment of an insurance cancellation.
What to Do if You Have Fallen Victim to This Scam
- End the call and stop screen sharing. Disconnect any remote-access session and close the messaging link. Do not follow another instruction from the caller.
- Call the bank’s fraud team now. Use the number on your card or official app. Ask the bank to stop transfers, freeze compromised access, and review new payees and limit changes.
- Change online banking credentials. Use a trusted device. Replace passwords and PINs as directed by the bank, and revoke unfamiliar devices or sessions.
- Tell the insurer or platform being impersonated. Contact it independently, confirm that no policy exists, and report the number, profile, and documents.
- Secure the messaging account. Review linked devices, enable strong multifactor authentication, and block the scam profile.
- Protect email and identity accounts. Change any disclosed password, remove unknown recovery methods, and watch for password-reset messages.
- Preserve evidence. Save chat exports, call logs, screenshots, transfer receipts, account details, profile names, files, and URLs before blocking the contact.
- Report the incident. Notify local police and the appropriate national fraud service. US victims can report at ReportFraud.ftc.gov and IC3.gov.
- Remove remote-access software. Uninstall any app the caller requested, revoke accessibility permissions, and check device administration settings.
- Scan the device. Malwarebytes can check for unwanted remote tools or malware after a download. AdGuard can reduce exposure to malicious links and ads, but it cannot reverse a bank transfer.
- Warn trusted contacts. Scammers may use stolen information or messaging access to target family members with a related story.
- Ignore refund agents. Anyone who demands a deposit, tax, or recovery fee before returning money is likely attempting a second theft.
Frequently Asked Questions
Can an insurer call about a real renewal?
Yes, but you can verify the policy and representative by ending the call and using the insurer’s official contact details. A real company should not object to that check.
Is screen sharing ever needed to cancel insurance?
No legitimate insurer needs to watch you operate online banking. Refuse the request and end the call.
What if the caller knows my policy or identity number?
Accurate data can come from breaches, public records, or earlier phishing. It makes the call more persuasive but does not prove the caller’s identity.
Can a government officer ask me to move money for safety?
No. A request to transfer savings into a safe, evidence, or investigation account is a major scam warning.
What if I shared my screen but sent no money?
Contact the bank, change exposed credentials, review account activity, remove remote tools, and secure the device. The scammer may have captured information for later use.
Will paying a cancellation fee stop the renewal?
Not when the policy was invented. Payment rewards the scam and often triggers another demand. Verify any real policy directly with the insurer.
The Bottom Line
The fake insurance cancellation call begins as customer service and ends as a bank-account takeover. The invented renewal gives the scammer a reason to collect identity details, introduce a fake official, and guide the victim through a transfer.
End the call before opening banking or sharing a screen. Verify the policy through the insurer’s published channels. If you already followed the instructions, contact the bank immediately, secure the affected accounts, remove remote access, and report the impersonation.