Tech support scams start the same way almost every time: a scary warning appears on screen, or a stranger calls to say your computer is in trouble. The goal is never to help you. It is to get you to pay for fake repairs, hand over remote access, or share passwords. Know the pattern and it becomes easy to spot and easy to hang up on.
The three entry points
Tech support scams reach you in three ways:
- Pop-up warnings. A full-screen alert claims your PC is infected and tells you to call a number. The page may show a fake "scan" with a progress bar — but a web page cannot scan your computer.
- Cold calls. Someone claims to be from Microsoft, Apple, or your internet provider, saying they detected a problem and can fix it for a fee. Real companies never cold-call customers about viruses.
- Fake search results and ads. A scam support number appears at the top of search results for "tech support" or "Microsoft support". The ad is the scam.
What the scammer does once they have you
Whatever the entry point, the playbook is the same:
- Build urgency. "Your computer is at risk", "you will lose your files", "act now".
- Request remote access. The "technician" asks you to install remote access software (AnyDesk, TeamViewer, or a similar tool) so they can "fix" the problem.
- Show fake evidence. Once connected, they run built-in Windows tools that look like diagnostics, and point at "errors" that are normal.
- Ask for payment. The "fix" costs $100–$500, paid by credit card, gift card, or wire transfer. Gift card and wire demands are the signature of a scam.
The rules that defeat every version
- A web page cannot scan your computer. Any pop-up showing a scan progress bar is fake.
- Microsoft, Apple, and ISPs never cold-call about computer problems. If they did, they would not ask you to pay with gift cards.
- No legitimate technician needs to "take control" of your computer to fix a virus you did not confirm exists.
- Never call the number on a warning screen. It reaches the scammer.
What to do if you already gave remote access
If a "technician" has remote access to your computer, act in this order:
- Disconnect from the internet. Unplug the ethernet cable or turn off Wi-Fi. This cuts the remote connection immediately.
- Uninstall the remote access software. Remove AnyDesk, TeamViewer, or whatever was installed.
- Run a full antivirus scan with your real security software (Windows Defender is sufficient).
- Change your passwords from a different device — starting with email, then banking, then social media.
- Enable two-factor authentication on every account that offers it. The two-factor guide covers the setup.
- Contact your bank if you provided payment details, and dispute any charge.
What to do if you paid
If you paid the scammer, contact your card issuer immediately to dispute the charge, or the wire/gift card company if you paid that way. Then report the scam to the FTC at ReportFraud.ftc.gov and the FBI IC3 at ic3.gov.
How to protect yourself going forward
- Use a real antivirus. Windows Defender is free, automatic, and sufficient for most people.
- Block pop-ups in your browser. Most browsers block them by default.
- Get support from the official source. If your computer genuinely has a problem, use Microsoft's official support site or a store you trust — never a number from a pop-up or search ad.
- Use a tool like Scam Guard for real-time protection against scam and phishing websites.
Quick answers
Do real companies cold-call about computer problems? No. Microsoft, Apple, and internet providers never call you about viruses on your computer.
Can a website scan my computer? No. A web page cannot scan your computer. Any pop-up showing a scan finding threats is fake.
What should I do if a scammer has remote access? Disconnect from the internet immediately, uninstall the remote access software, run a security scan, and change your passwords from a different device.
I paid the scammer. Can I get my money back? If you paid by credit card, contact your card issuer to dispute the charge. Gift card and wire payments are much harder to recover, but report them anyway.
Sources and further reading
Written by Hassan Arshad, founder of UsefulOrbit. Last updated August 31, 2026.