Most scams try to get something out of you — a password, a payment, a click. A tech-support scam is stranger than that. It tries to get you to open your own computer and hand over the keys, while thanking the person taking them.
It is one of the more common things people bring to us, and it catches capable, careful people, because it doesn't ask you to do anything reckless. It asks you to accept help with a problem it just invented.
Nothing is wrong with your computer. The warning is the attack, and the "support" is the attacker.
How it starts
There are two front doors, and they often lead to the same room.
The pop-up. You're browsing normally and the screen fills with an alarming warning — a Windows or Apple logo, sirens, sometimes a robotic voice, a message that your computer is infected or has been locked, and a phone number to call immediately before your files or identity are lost. It can be hard to close, which is deliberate. It is a web page pretending to be your operating system, nothing more.
The cold call. The phone rings and it's "Microsoft," "Apple," your internet provider, or "the security department," saying they've detected a virus or suspicious activity on your machine. Sometimes it follows a pop-up; sometimes it arrives out of nowhere. The caller is calm, technical, and helpful — the opposite of what you expect a scammer to sound like.
Either way, the destination is the same: get you to install a remote-access program so they can "fix" it while you watch.
Why it works when other things don't
This scam runs on trust in the brand and fear of the unknown, and it earns both.
The names are ones you rely on. When a screen says Microsoft or Apple, most people don't think to doubt it — those companies are supposed to be the safe ones. The scam borrows that safety.
The problem sounds real and urgent. Viruses, hackers, and locked accounts are genuine things people worry about, so a warning about them doesn't feel far-fetched. And the fix on offer — let an expert take a look — is exactly what a reasonable person would want.
Then, once someone is remoted in, they manufacture proof. They open a normal Windows tool that lists routine background processes and call them "infections." They run a harmless command and point at ordinary output as "hackers." By the time they ask for payment, you've watched them "find" a problem with your own eyes. Nothing was wrong until they arrived, but it no longer feels that way.
What they're actually after
Once they have remote control, the ask takes one of a few shapes.
A fee for fixing nothing. A few hundred dollars for "support," "a security subscription," or "removing the virus," often paid by card, bank transfer, or gift card. Gift cards especially are a certainty — no real company charges for security in Apple or Google Play cards.
Your accounts, while you watch. With the screen shared, they steer you to log into your bank "to confirm the refund" or "verify your identity," and read or capture the details as you type.
The refund reversal. A favorite with repeat victims: they claim they've refunded you too much by mistake and need you to send the difference back. The "overpayment" is a faked number on a screen they control; the money you send back is real.
A door left open. Sometimes the payment is almost beside the point. The remote-access software they installed stays behind, along with the access it grants, to be used or sold later.
The one move that ends every version
Every form of this scam depends on one thing: unsolicited contact that you didn't start. So the rule is simple and it holds every time.
No real company monitors your personal computer and reaches out about a virus — so any pop-up, call, or message that tells you to call a number about one is a scam, full stop.
- A genuine antivirus alert comes from software you installed and never includes a phone number to call.
- Microsoft, Apple, and your internet provider do not watch your machine and will not call, email, or pop up to warn you about it.
- If you're ever worried something is genuinely wrong, you make contact, using a number or website you find yourself — never one handed to you by the warning.
That last point is the whole game. The scam only works inside a channel it opened. Close that channel — hang up, close the browser, and reach out on your own terms — and there's nothing left of it.
How to shut it down safely
A pop-up you can't close. Don't call the number, and don't click anything inside the box — not even close or cancel, which can be wired to the trap. Close the browser from outside it instead: on Windows, Ctrl-Alt-Delete, open Task Manager, and end the browser task; on a Mac, Command-Option-Escape and force quit the browser. When you reopen, decline to restore the previous tabs.
A call. You don't owe a cold caller a conversation. Hang up. Don't confirm your name, don't answer questions about your computer, and don't "just take a look" at anything they ask you to open. If you want to be sure your machine is fine, that's a separate errand you run yourself, later, calm.
Never install what they ask you to install. Remote-access tools like AnyDesk, TeamViewer, or "support" apps are legitimate software used for the wrong reason here. If a caller or pop-up wants you to download one, that is the scam's turning point — the moment before you lose control of the machine. Stop there.
If you already let them in
If you followed the instructions before the doubt set in, you're not the first and it's recoverable. Move in this order.
- Disconnect. Turn off Wi-Fi or unplug the network cable, then shut the computer down. That cuts their access immediately.
- Change passwords from a different device. Email first, then your bank, then anything else that matters. Turn on two-factor authentication where you can.
- Call your bank if you shared any card or account details, made a payment, or bought gift cards — read the codes to them; some can still be stopped. Say the words fraud and scam so it's handled as one.
- Remove what they installed. Uninstall any remote-access or "support" program. If you're not confident the machine is clean, have a trusted local technician check it before you use it for banking or email again.
- Report it. In the US, file at ic3.gov, the FBI's Internet Crime Complaint Center, and reportfraud.ftc.gov. Outside the US, report to your national fraud reporting service. Reporting quickly can help others and, with payments, sometimes helps recovery.
Gift cards deserve one specific note: if you were told to buy them, call the card's issuer straight away with the receipt and card numbers. Funds are occasionally frozen if the card hasn't been drained yet, and that window is measured in hours.
Summary
- The warning is the attack. A pop-up or call about a virus on your personal computer is the scam, not a sign of one.
- No real company monitors your machine or calls, emails, or pops up to tell you to phone a support line. A genuine antivirus alert never gives you a number.
- The turning point is remote access. Once you install their tool, they control the computer — don't reach that step.
- Close the channel they opened: hang up, close the browser from outside the pop-up, and verify anything yourself using contacts you find independently.
- If you let them in, act in order: disconnect, change passwords from another device, call your bank, remove their software, report it.
Got a pop-up or a call in front of you right now and not sure? Describe it in a free Quick Check with Carmen for a read in seconds, or get help if you've already paid or given someone access.