← Back to Blog

August 21, 2026 · Backgrounder Team

The Call Says Your Computer Is Infected. The Call Is the Infection.

Most scams try to get something out of you — a password, a payment, a click. A tech-support scam is stranger than that. It tries to get you to open your own computer and hand over the keys, while thanking the person taking them.

It is one of the more common things people bring to us, and it catches capable, careful people, because it doesn't ask you to do anything reckless. It asks you to accept help with a problem it just invented.

Nothing is wrong with your computer. The warning is the attack, and the "support" is the attacker.


How it starts

There are two front doors, and they often lead to the same room.

The pop-up. You're browsing normally and the screen fills with an alarming warning — a Windows or Apple logo, sirens, sometimes a robotic voice, a message that your computer is infected or has been locked, and a phone number to call immediately before your files or identity are lost. It can be hard to close, which is deliberate. It is a web page pretending to be your operating system, nothing more.

The cold call. The phone rings and it's "Microsoft," "Apple," your internet provider, or "the security department," saying they've detected a virus or suspicious activity on your machine. Sometimes it follows a pop-up; sometimes it arrives out of nowhere. The caller is calm, technical, and helpful — the opposite of what you expect a scammer to sound like.

Either way, the destination is the same: get you to install a remote-access program so they can "fix" it while you watch.

Why it works when other things don't

This scam runs on trust in the brand and fear of the unknown, and it earns both.

The names are ones you rely on. When a screen says Microsoft or Apple, most people don't think to doubt it — those companies are supposed to be the safe ones. The scam borrows that safety.

The problem sounds real and urgent. Viruses, hackers, and locked accounts are genuine things people worry about, so a warning about them doesn't feel far-fetched. And the fix on offer — let an expert take a look — is exactly what a reasonable person would want.

Then, once someone is remoted in, they manufacture proof. They open a normal Windows tool that lists routine background processes and call them "infections." They run a harmless command and point at ordinary output as "hackers." By the time they ask for payment, you've watched them "find" a problem with your own eyes. Nothing was wrong until they arrived, but it no longer feels that way.

What they're actually after

Once they have remote control, the ask takes one of a few shapes.

A fee for fixing nothing. A few hundred dollars for "support," "a security subscription," or "removing the virus," often paid by card, bank transfer, or gift card. Gift cards especially are a certainty — no real company charges for security in Apple or Google Play cards.

Your accounts, while you watch. With the screen shared, they steer you to log into your bank "to confirm the refund" or "verify your identity," and read or capture the details as you type.

The refund reversal. A favorite with repeat victims: they claim they've refunded you too much by mistake and need you to send the difference back. The "overpayment" is a faked number on a screen they control; the money you send back is real.

A door left open. Sometimes the payment is almost beside the point. The remote-access software they installed stays behind, along with the access it grants, to be used or sold later.

The one move that ends every version

Every form of this scam depends on one thing: unsolicited contact that you didn't start. So the rule is simple and it holds every time.

No real company monitors your personal computer and reaches out about a virus — so any pop-up, call, or message that tells you to call a number about one is a scam, full stop.

  • A genuine antivirus alert comes from software you installed and never includes a phone number to call.
  • Microsoft, Apple, and your internet provider do not watch your machine and will not call, email, or pop up to warn you about it.
  • If you're ever worried something is genuinely wrong, you make contact, using a number or website you find yourself — never one handed to you by the warning.

That last point is the whole game. The scam only works inside a channel it opened. Close that channel — hang up, close the browser, and reach out on your own terms — and there's nothing left of it.

How to shut it down safely

A pop-up you can't close. Don't call the number, and don't click anything inside the box — not even close or cancel, which can be wired to the trap. Close the browser from outside it instead: on Windows, Ctrl-Alt-Delete, open Task Manager, and end the browser task; on a Mac, Command-Option-Escape and force quit the browser. When you reopen, decline to restore the previous tabs.

A call. You don't owe a cold caller a conversation. Hang up. Don't confirm your name, don't answer questions about your computer, and don't "just take a look" at anything they ask you to open. If you want to be sure your machine is fine, that's a separate errand you run yourself, later, calm.

Never install what they ask you to install. Remote-access tools like AnyDesk, TeamViewer, or "support" apps are legitimate software used for the wrong reason here. If a caller or pop-up wants you to download one, that is the scam's turning point — the moment before you lose control of the machine. Stop there.

If you already let them in

If you followed the instructions before the doubt set in, you're not the first and it's recoverable. Move in this order.

  • Disconnect. Turn off Wi-Fi or unplug the network cable, then shut the computer down. That cuts their access immediately.
  • Change passwords from a different device. Email first, then your bank, then anything else that matters. Turn on two-factor authentication where you can.
  • Call your bank if you shared any card or account details, made a payment, or bought gift cards — read the codes to them; some can still be stopped. Say the words fraud and scam so it's handled as one.
  • Remove what they installed. Uninstall any remote-access or "support" program. If you're not confident the machine is clean, have a trusted local technician check it before you use it for banking or email again.
  • Report it. In the US, file at ic3.gov, the FBI's Internet Crime Complaint Center, and reportfraud.ftc.gov. Outside the US, report to your national fraud reporting service. Reporting quickly can help others and, with payments, sometimes helps recovery.

Gift cards deserve one specific note: if you were told to buy them, call the card's issuer straight away with the receipt and card numbers. Funds are occasionally frozen if the card hasn't been drained yet, and that window is measured in hours.


Summary

  • The warning is the attack. A pop-up or call about a virus on your personal computer is the scam, not a sign of one.
  • No real company monitors your machine or calls, emails, or pops up to tell you to phone a support line. A genuine antivirus alert never gives you a number.
  • The turning point is remote access. Once you install their tool, they control the computer — don't reach that step.
  • Close the channel they opened: hang up, close the browser from outside the pop-up, and verify anything yourself using contacts you find independently.
  • If you let them in, act in order: disconnect, change passwords from another device, call your bank, remove their software, report it.

Got a pop-up or a call in front of you right now and not sure? Describe it in a free Quick Check with Carmen for a read in seconds, or get help if you've already paid or given someone access.

Frequently asked questions

What is a tech-support scam?

A tech-support scam is a fraud that convinces you your computer has a virus or a security problem so you will let a stranger fix it. It usually starts with a full-screen pop-up warning and a phone number to call, or an unexpected call claiming to be from Microsoft, Apple, or your internet provider. The goal is to get you to install remote-access software or read out payment details. There is rarely anything actually wrong with your computer until you follow their instructions.

Does Microsoft or Apple ever call you about a virus?

No. Microsoft, Apple, and your internet provider do not monitor your personal computer for viruses and do not call, email, or pop up a warning telling you to phone a support line. A real security alert from your own antivirus software never includes a phone number to call. Any unsolicited contact that names a big tech company and gives you a number to ring is a scam, regardless of how official it looks or sounds.

I let someone remote into my computer. What do I do now?

Disconnect from the internet immediately by turning off Wi-Fi or unplugging the network cable, then shut the computer down. On a separate device, change the passwords for your email and bank first, then anything else important, and turn on two-factor authentication. Call your bank if you shared card or account details or made any payment. Uninstall any remote-access program they had you install, and if you are unsure whether the machine is clean, have a trusted local technician check it before you use it for anything sensitive.

How do I get rid of a scam pop-up that fills my screen?

Do not call the number and do not click anything inside the pop-up, including a close or cancel button, because those can be part of the trap. Instead, close the browser from outside the pop-up. On Windows press Ctrl-Alt-Delete, open Task Manager, and end the browser task. On a Mac press Command-Option-Escape and force quit the browser. If the pop-up returns when you reopen the browser, decline to restore the previous tabs. The alert is a web page designed to look like a system warning, not a real infection.

Stay one step ahead of scams

Spot red flags early and protect yourself, your family, and your business

Try for free