Social Engineering & FraudMANIPULATIVE

Tech Support Scam

What it is

A fraud in which the target is convinced their device is infected or compromised and that a fake "support" agent must be given remote access or payment to fix it.

How it works

The scam manufactures a technical crisis the victim cannot independently assess, then supplies the only person who can calm it. A full-screen browser warning with a siren and a phone number, or an unsolicited call claiming "we detected a virus on your Windows computer," creates alarm in someone who already feels out of their depth with technology. The agent restores a sense of control by taking charge, and asks for remote access to "show" the problem, using ordinary system logs and harmless error messages as fabricated proof of infection. Once inside, they can install real malware, open the victim's bank site, or simply charge for a nonexistent repair. Miramirkhani and colleagues' large-scale study documented the call-center infrastructure and the reliance on scare pages; Microsoft's multi-country survey found a majority of people encounter these scams and a minority are drawn in, skewing costly among those who engage. The FBI ranks tech-support fraud the top crime type reported by Americans over 60.

Real-world examples

  • A browser page freezes with a loud "Windows Defender Alert" and a toll-free number; the page is just a web pop-up, but it drives frightened users to call.
  • A caller claiming to be from a well-known software company asks the victim to open the Windows Event Viewer, then points to routine warnings as "evidence" of infection.
  • After gaining remote access, a scammer opens the victim's online banking, moves money between the victim's own accounts to fake a mistaken "refund," then demands the difference back in gift cards.
  • Refund variants revisit prior victims months later, claiming the "support company" is closing and owes a refund, restarting the cycle with people already known to comply.

Historical case studies

Office Depot's "PC Health Check"

2009–2016FTC Enforcement

Office Depot and OfficeMax stores offered customers a free computer check-up using software from Support.com. According to the Federal Trade Commission, the program reported that it had found "malware symptoms" whenever the customer had answered yes to any of four opening questions, such as whether the computer had been running slowly, regardless of what the scan itself found. Staff then sold repair services costing up to $300. The companies paid a combined $35 million in 2019. The case shows the fake-diagnosis technique used by a national retailer with a trusted name, not only by overseas call centres.

Source →

FTC data: older adults and tech-support scams

2019Consumer Protection Data

Analysing its 2018 complaint data, the Federal Trade Commission found that people aged 60 and over were about five times more likely than younger adults to report losing money to a tech-support scam, the reverse of the pattern for most fraud types, where younger people report losses more often. The typical approach was a pop-up warning styled as a message from a well-known technology company, with a phone number to call; the "technician" then asked for remote access, showed routine system messages as proof of infection, and charged for the repair.

Source →

Ethical guidelines

  • Fabricating an infection to sell a fix or gain access is fraud and unauthorized computer access; there is no honest version.
  • Legitimate vendors do not cold-call about viruses or place scare pop-ups with phone numbers; adopting those tactics is itself a red flag.
  • Remote-access tools are legitimate, but inviting their use through a manufactured emergency is abuse of a trusted technology.

How to defend against it

  • No real company detects a virus on your personal computer and calls you unprompted; treat any such call or pop-up as a scam and end it.
  • Never grant remote access or type a code from someone who contacted you; close a scare pop-up with the task manager or by restarting, not by calling the number.
  • If you have already given access, disconnect from the internet, run a scan or seek reputable local help, change passwords from a clean device, and watch your accounts.
  • For older relatives, set up a family rule in advance: any "tech emergency" call gets paused so they can check with you first.
  • Report attempts to reportfraud.ftc.gov and, for those over 60, the FBI's IC3; documented reports drive takedowns of the call centers.

From the Defense Playbook

Bring a Second Personminutes

Insist on having a trusted third party present, on the call, or copied in before a significant decision, because a single ally breaks the isolation that most high-pressure and fraudulent persuasion depends on.

Out-of-Band Verificationminutes

Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.

The Callback Ruleminutes

When anyone contacts you claiming to be your bank, a government agency, a utility, or a company you deal with, hang up and call back on the number printed on your card, statement, or the organization's official website, never the number they gave you.

Never Pay (or Move Money) to Protect Moneyseconds

No bank, agency, or company will ever ask you to move, withdraw, convert, or hand over your money to keep it safe, so any such request identifies the person making it as the threat.

Gift Cards Mean Scamseconds

Treat any demand to pay a debt, fine, fee, bail, or "security deposit" with gift cards, cryptocurrency, a wire to a stranger, a payment app, or cash handed to a courier as proof of fraud, because no legitimate institution collects money that way.

Tell Someone Before You Send Moneyminutes

Before sending money or sharing account details in response to any unexpected request, describe the situation out loud to one person who is not involved, because scams depend on the target deciding alone.

Verify, Then Trust (for Authority Claims)minutes

Separate the symbols of authority (a title, a uniform, a badge, a confident tone, an official-looking letterhead) from the fact of authority, and check the fact through a source the claimant does not control before you comply.

Multi-Factor Authentication and Passkeysminutes

Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Miramirkhani, N., Starov, O., & Nikiforakis, N. (2017). Dial One for Scam: A Large-Scale Analysis of Technical Support Scams. Proceedings of the 24th Network and Distributed System Security Symposium (NDSS 2017) · link
    Systematic study of technical-support-scam infrastructure, scare pages, and call-center operations.
  2. Microsoft (2021). 2021 Global Tech Support Scam Research. Microsoft / YouGov survey of 16 countries · link
    Cross-country survey finding a majority encounter tech-support scams and a minority are drawn in to continue.
  3. Federal Bureau of Investigation, Internet Crime Complaint Center (2024). 2023 IC3 Elder Fraud Report. FBI IC3 · link
    Tech-support fraud as the most-reported crime type among victims over 60, with nearly 18,000 complaints.
Last reviewed
Suggest a correction

Detect Tech Support Scam in any text

Paste any message, email, or article into our free Manipulation Detector to see if Tech Support Scam or other techniques are being used on you.

Related Articles