Bkav CA’s pricing page includes a “Warning about USB ToKen renewal scams” in its “Warnings/Impersonation” section, while also listing contacts for digital signature purchases and technical support. For businesses using digital signatures, this is a reminder to verify renewal requests before paying or allowing someone else to access the device.
The supplied content does not indicate when the warning was posted or describe a specific incident. The presence of this section is therefore not enough to conclude that there is a new wave of scams or determine how much the risk has increased.
The warning appears directly on the page where buyers check prices
According to Bkav CA’s official pricing page, the bottom of the page contains contact information, usage instructions and the warning section mentioned above. Two phone numbers are listed for separate purposes:
Digital signature purchases: 1900 54 54 14.
Technical support: 1900 18 54.
The page also lists the email address [email protected]. Anyone receiving a call or message requesting renewal can independently check these contacts on the website, rather than relying solely on the contact number supplied by the sender.
Notably, the price list and warning appear on the same page. Buyers therefore need to check not only the amount, but also the party requesting payment and the details of the service being offered.
Subscription prices are not the same as renewal fees
The business price list on the page states that it takes effect on 1 July 2025, with VAT-inclusive payment totals of VND 1,792,800 for one year, VND 2,694,600 for two years and VND 3,056,400 for three years.
For the one- and two-year plans, the Token device costs an additional VND 540,000; the three-year plan states that the device is included in the package price. This separate charge is explained in the article on Bkav CA pricing and Token costs for businesses.
However, the page also has a separate section titled “Digital signature renewal and reissuance price list”. The service purchase prices above therefore should not automatically be treated as renewal quotes. If you receive a payment request, you need to ask whether it is for a subscription renewal, certificate reissuance or device purchase.
Renewal requests need to be checked independently
In day-to-day use, the digital certificate’s validity period and device information need to be checked before deciding to renew. A phone notification does not replace checking the certificate currently in use or confirming with the provider.
The person responsible should avoid sharing the Token PIN, login credentials or control of the computer simply because a caller claims to be a support employee. If remote support is needed, verify the contact and the scope of the work first, following principles similar to those in the article on using Remote Desktop safely.
For businesses where several people are involved in purchasing and operating the service, clearly documenting who can approve payments, who manages the Token and which channel receives incident reports helps reduce confusion. Support provisions also need to be checked in the service agreement, as described in the guide to reading an SLA before subscribing to business software.
The source content currently confirms only the title of the warning section and the publicly listed contact channels; it does not provide details of tactics, losses or a list of impersonators. This page provides no basis for labeling a particular phone number or organization as fraudulent.
Frequently asked questions
Should you transfer money immediately after receiving a notice that your digital signature is about to expire?
Do not rely solely on a call or message. Check the validity period of the certificate you are using, verify the provider through an independent channel and request a quote that clearly states the service, term and payment recipient.
Does the warning section on the pricing page prove that a new scam has occurred?
No. The source content only shows that the warning section exists; it does not provide a publication date or details of an incident. Additional verified documentation is needed to establish the timing, tactics or parties involved.
