Security & Privacy

How to Spot a Tech Support Scam

A calm, jargon-free guide to spotting tech support scams, covering unsolicited calls, scary pop-ups, remote access requests, and gift-card payment demands.

A laptop showing a warning pop-up message beside a telephone handset
Photograph via Unsplash

A tech support scam is any unsolicited contact — a phone call, a full-screen pop-up, or an emailed invoice — that claims your device is infected or compromised and pushes you to call a number, install software, or pay to "fix" it. The single fact that unravels every version: real technology companies do not phone you out of the blue, never put a support phone number inside an error message, and never accept payment in gift cards or cryptocurrency.

Everything below is how that lie gets dressed up, and exactly how to see through each layer of it.

Why that one rule holds#

Microsoft, Apple, and Google have all publicly stated that they do not make unsolicited calls about security problems, and that their genuine error messages never contain a phone number. Your computer has no mechanism to broadcast "I have a virus" to a distant call center. Malware detection happens locally, inside software like Microsoft Defender, and the results appear inside that app — not as a browser page with a toll-free number. Once you internalize that, the caller's entire script is exposed as fiction, no matter how technical or polite they sound.

The scam survives because it doesn't need to fool everyone. FTC data has repeatedly ranked tech support fraud among the top scams reported by people aged 60 and over, precisely because it targets those less confident about correcting a self-assured "engineer." That is also why sharing these tells with older relatives protects them more than any antivirus subscription ever will.

How the contact actually reaches you#

The cold call#

Someone claims to be from "Microsoft," the "Windows Technical Department," or your internet provider, and says your machine is "sending out errors" or "infected." Caller ID is worthless here: number spoofing is trivial, so the display can show the real company's name or a familiar local area code. Treat caller ID as decoration, never as evidence.

The pop-up (malvertising)#

You did nothing wrong to trigger these. A single poisoned ad on an otherwise normal website (malvertising), or a mistyped web address, redirects your browser to a page styled to look like "Windows Defender Security Center." It flashes an official-looking error code (something like 0x80070643), plays a looping siren, and often "locks" the browser using a JavaScript dialog loop or the fullscreen API so the window won't close. The phone number on that page is the entire point. A real Windows or Defender alert never appears as a web page and never lists a number to call.

The renewal invoice#

A quieter variant arrives as an emailed receipt for antivirus you never bought — commonly "Geek Squad," "Norton," or "McAfee" — with a number to "cancel the charge." Calling it routes you straight into the scam.

The fake "proof" they show you#

If you stay on the line, the caller directs you to open ordinary Windows tools and misreads normal output as catastrophe. Knowing the specific tricks makes them almost funny:

  • Event Viewer (eventvwr): every healthy PC logs hundreds of yellow "Warning" and red "Error" entries during normal operation. Scammers scroll through them as if each is a hacker.
  • The assoc trick: they have you type assoc in Command Prompt and point to the line ending in {888DCA60-FC0A-11CF-8F0F-00C04FD7D062}, calling this "CLSID" your computer's unique license that only they could possibly know. It is identical on every Windows machine on earth — it is just the file-association ID for zipped folders.
  • netstat: a list of network connections marked "ESTABLISHED" gets narrated as intruders currently inside your machine.
  • The %temp% folder: a directory full of harmless temporary files is presented as a nest of viruses.

None of this shows infection. It is theater built on tools that look alarming to anyone who has never opened them.

The two demands that confirm fraud#

The story is only setup. Two requests reveal the scam completely, and either one should end the interaction on the spot.

1. Remote access#

They ask you to install a remote-desktop program so they can "fix it for you." Legitimate tools are abused here — AnyDesk, TeamViewer, UltraViewer, LogMeIn, and ConnectWise ScreenConnect. Once connected, a stranger sees your screen and controls your mouse; they can open your saved passwords, your email, and your online banking. Some deliberately black out your screen mid-session so you cannot watch what they do. Never grant remote control to anyone who contacted you first.

2. Untraceable payment#

No real company charges for support in gift cards — Google Play, Apple, Amazon, Steam, or Target cards, with the codes read aloud over the phone — or in cryptocurrency fed into a Bitcoin ATM. Those methods are chosen for one reason: once the codes leave your mouth, the money is effectively gone and cannot be reversed.

Watch, too, for the refund and overpayment twist. Months later a "refund department" calls to return your original fee. While screen-sharing, they open your online banking (or a convincing fake copy of it) and appear to deposit, say, $500 instead of $50 — a figure they simply typed, not real money. Then they act panicked and beg you to send back the "extra" in gift cards, or they'll "lose their job." There was never an overpayment; the point is to make you hand over your own money out of guilt.

What to do, step by step#

  1. Hang up or close it. You owe an unsolicited caller nothing. End the call without debate or explanation.
  2. Kill a locked pop-up without calling. Press Ctrl + Shift + Esc to open Task Manager, select your browser, and click End task (on a Mac, Cmd + Option + Esc to Force Quit). When you reopen the browser, choose "Don't restore" so the page does not reload.
  3. If you already let them in: disconnect from the internet, uninstall any remote tool they added (AnyDesk, TeamViewer, and the like), then run a full scan with Microsoft Defender or Malwarebytes. From a different device, change your important passwords starting with email and banking, and turn on two-factor authentication.
  4. If you paid: call your bank immediately. For gift cards, call the issuer using the number on the card — acting within hours occasionally lets them freeze the balance. Keep the card and the receipt.
  5. Report it. In the US, file at reportfraud.ftc.gov, and report the impersonated brand directly to that company. Reporting quickly is what freezes funds and warns the next target.

If you are ever genuinely unsure about your device, you start the contact. Type the address yourself (support.microsoft.com, getsupport.apple.com) or dial the number on your purchase paperwork. The direction of contact is the entire game.

Common mistakes people make#

  • Trusting the caller ID or the company logo. Both are trivially faked and prove nothing.
  • Staying on "just to hear them out." Every extra minute is engineered to raise your fear and lower your judgment. Courtesy is not owed to a con.
  • Calling the pop-up number "to check." That number is the scam; there is nothing to verify.
  • Assuming a virus scan ends it after remote access. Attackers may leave hidden tools behind or have already copied your data. Treat every account they could reach as compromised and reset it.
  • Being too embarrassed to report. Speed is what freezes money and protects others; shame only helps the scammer.

FAQ#

Can a scammer really see my screen if I never installed anything?#

No. Screen viewing and control require a remote-access program running on your device. If you never installed one and never clicked "allow," a random caller cannot see anything. The "we can see your errors right now" line is a pure bluff designed to make you comply.

The pop-up says it is from Microsoft Defender — is it fake?#

Yes, if it is a web page or shows a phone number. Genuine Microsoft Defender alerts appear as Windows notifications and inside the Windows Security app, never as a full-screen browser page urging you to call. Close it with Task Manager and move on.

I called the number but did nothing else — am I in danger?#

Usually not, provided you hung up before installing software or reading out any codes or card numbers. The real damage begins at remote access or payment, not at the call itself. Simply hang up; you do not need to call back, apologize, or explain yourself.

What is the safe way to reach real support?#

Initiate it yourself. Type the company's official web address by hand or use the number printed on your receipt or the back of the device — support.microsoft.com, getsupport.apple.com, or 1-800-MY-APPLE for Apple. Never use contact details supplied by the person or page that alarmed you in the first place.

Theo Vance
Written by
Theo Vance

Theo writes about online safety the way a good friend would — clearly, calmly, and without trying to scare you. He's interested in the simple habits that stop most problems, and he thinks staying private online is a skill anyone can learn.

More from Theo