A fake Google Play billing phishing email (or SMS) claims you were charged for a movie, game, subscription, or “Play Protect premium,” then pushes Cancel order / Refund / Confirm payment links to steal Google passwords or payment data. Do not use those buttons. Check real Play purchases in the Play Store app → profile → Payments & subscriptions (or pay.google.com) you open yourself. This guide is Google Play billing phishing—not fake App Store receipt phishing, not third-party app access review, and not Enhanced Safe Browsing alone.
1. What this scam looks like
Branded headers, order IDs, and prices that look plausible. Domains misspell play.google.com or use “play-store-support” hosts. Some attach HTML receipts. Pressure language: “dispute within 15 minutes or charge is final.” Real Google purchase emails can exist—still verify inside the Play Store or Google Pay UI.
Play Protect is Google’s on-device app scanning—not a surprise premium invoice you must “activate” via email. Anything selling “Play Protect Pro” refunds through a random site is a lure.
2. Legitimate vs scam cues
| Cue | Likely legitimate | Likely scam |
|---|---|---|
| Where you manage the order | Play Store app / pay.google.com you navigate to | Only via email/SMS button |
| Domain | Google domains after careful check | Hyphenated look-alikes, odd TLDs |
| Credential ask | Sign-in inside official app/site flows | Password + card + SMS code on a rushed page |
| Threats | Calm receipt details | Legal action, account wipe timers |
3. What to do if contacted
- Do not tap the message links. Do not “confirm” a purchase you do not recognize through email.
- Open the Google Play Store app → profile icon → Payments & subscriptions / purchase history. On the web, use https://pay.google.com or Play order history from a typed address.
- Cancel unwanted subscriptions inside those official screens. Request refunds through Google’s documented Play refund flows when eligible.
- Report phishing to Google when the product provides a report path; also use ReportFraud.ftc.gov for clear fraud.
- Delete the message; tell household members on Family Link / shared payment methods.
4. If you already entered your Google password
- Change the password; check devices and sign out unknowns at myaccount.google.com.
- Revoke third-party app access you do not recognize.
- Review bank/card statements; contact the issuer if payment details were typed.
- Turn on Enhanced Safe Browsing in Chrome for extra link warnings going forward.
- Scan PCs with Norton or Bitdefender; keep one primary product (TotalAV, McAfee, Avast on-site).
FAQ
Does Google email Play receipts?
Google can send purchase notifications. Unexpected “refund now” pressure is still a reason to open the Play Store yourself instead of the email button.
How is this different from App Store receipt phishing?
Same social engineering, different stores and review paths—Apple’s flow is in iPhone Settings / reportaproblem; Google’s is Play Store / pay.google.com.
Family member bought a game and I got mail.
Confirm inside Play family/purchase settings. Do not use a forwarded “dispute” link from a relative’s phishing copy.
Will Enhanced Safe Browsing auto-stop these emails?
It may warn when you open bad links in Chrome; it does not filter Gmail by itself. Still treat billing panic emails as hostile.
If you still want a paid suite
Avoiding how to spot a fake Google Play billing phishing email does not require paid antivirus. Careful habits and official support paths are a valid buy-nothing stack. If you want multi-device paid protection later, use only these on-site paid links: TotalAV (paid link), Norton (paid link), Bitdefender (paid link), McAfee (paid link), Avast (paid link).