Tech Support Scam
What it is
A fraud in which the target is convinced their device is infected or compromised and that a fake "support" agent must be given remote access or payment to fix it.
How it works
Real-world examples
- •A browser page freezes with a loud "Windows Defender Alert" and a toll-free number; the page is just a web pop-up, but it drives frightened users to call.
- •A caller claiming to be from a well-known software company asks the victim to open the Windows Event Viewer, then points to routine warnings as "evidence" of infection.
- •After gaining remote access, a scammer opens the victim's online banking, moves money between the victim's own accounts to fake a mistaken "refund," then demands the difference back in gift cards.
- •Refund variants revisit prior victims months later, claiming the "support company" is closing and owes a refund, restarting the cycle with people already known to comply.
Historical case studies
Ethical guidelines
- ●Fabricating an infection to sell a fix or gain access is fraud and unauthorized computer access; there is no honest version.
- ●Legitimate vendors do not cold-call about viruses or place scare pop-ups with phone numbers; adopting those tactics is itself a red flag.
- ●Remote-access tools are legitimate, but inviting their use through a manufactured emergency is abuse of a trusted technology.
How to defend against it
- ►No real company detects a virus on your personal computer and calls you unprompted; treat any such call or pop-up as a scam and end it.
- ►Never grant remote access or type a code from someone who contacted you; close a scare pop-up with the task manager or by restarting, not by calling the number.
- ►If you have already given access, disconnect from the internet, run a scan or seek reputable local help, change passwords from a clean device, and watch your accounts.
- ►For older relatives, set up a family rule in advance: any "tech emergency" call gets paused so they can check with you first.
- ►Report attempts to reportfraud.ftc.gov and, for those over 60, the FBI's IC3; documented reports drive takedowns of the call centers.
From the Defense Playbook
Insist on having a trusted third party present, on the call, or copied in before a significant decision, because a single ally breaks the isolation that most high-pressure and fraudulent persuasion depends on.
Confirm any request that arrives through one channel (email, text, chat, a phone call) by reaching the supposed sender through a different channel you already trusted before the request existed.
When anyone contacts you claiming to be your bank, a government agency, a utility, or a company you deal with, hang up and call back on the number printed on your card, statement, or the organization's official website, never the number they gave you.
No bank, agency, or company will ever ask you to move, withdraw, convert, or hand over your money to keep it safe, so any such request identifies the person making it as the threat.
Treat any demand to pay a debt, fine, fee, bail, or "security deposit" with gift cards, cryptocurrency, a wire to a stranger, a payment app, or cash handed to a courier as proof of fraud, because no legitimate institution collects money that way.
Before sending money or sharing account details in response to any unexpected request, describe the situation out loud to one person who is not involved, because scams depend on the target deciding alone.
Separate the symbols of authority (a title, a uniform, a badge, a confident tone, an official-looking letterhead) from the fact of authority, and check the fact through a source the claimant does not control before you comply.
Turn on a second factor for every account that matters and prefer phishing-resistant forms (passkeys or hardware security keys), so that a password typed into a fake page or talked out of you on the phone is not enough to take the account.
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Miramirkhani, N., Starov, O., & Nikiforakis, N. (2017). Dial One for Scam: A Large-Scale Analysis of Technical Support Scams. Proceedings of the 24th Network and Distributed System Security Symposium (NDSS 2017) · linkSystematic study of technical-support-scam infrastructure, scare pages, and call-center operations.
- Microsoft (2021). 2021 Global Tech Support Scam Research. Microsoft / YouGov survey of 16 countries · linkCross-country survey finding a majority encounter tech-support scams and a minority are drawn in to continue.
- Federal Bureau of Investigation, Internet Crime Complaint Center (2024). 2023 IC3 Elder Fraud Report. FBI IC3 · linkTech-support fraud as the most-reported crime type among victims over 60, with nearly 18,000 complaints.
Related Articles
Social Engineering: Why Smart People Fall for It
Social engineering does not target stupidity. It targets helpfulness, deference, and time pressure, which are the same habits that make people good at their jobs. Here is how the attacks are built and which procedures actually stop them.
The Disinformation Playbook: How Campaigns Are Built and Where They Break
Disinformation campaigns follow a recognizable sequence: seed, launder, amplify, and let real people carry it the rest of the way. A field guide to the stages, drawn from the research, with the defences that work at each one.