Close It. Don't Call It. The Four-Word Rule That Ends Every Tech Support Scam.

# Close It. Don't Call It. The Four-Word Rule That Ends Every Tech Support Scam.

She was reading the news when it happened. The browser filled the screen with a blue background, a Windows logo, and text in white capital letters: WINDOWS DEFENDER ALERT. YOUR COMPUTER HAS BEEN BLOCKED. DO NOT SHUT DOWN. CALL MICROSOFT SUPPORT NOW: 1-888-XXX-XXXX. A mechanical voice began repeating the warning on a loop. She couldn't close the tab. She couldn't find a way out.

She called the number.

A calm, patient man answered. He said his name was David. He said Microsoft had detected unusual network activity originating from her IP address — hackers, possibly government-linked, possibly using her machine right now. He said he could fix it remotely if she'd install a small program called AnyDesk. She did. He took control of her screen, opened a black command window, ran some lines she couldn't read, then opened a folder full of red warning icons. "This is the evidence," he said. "You can see it yourself."

She saw it. It looked real. She stayed on the call for two hours and forty minutes.

The program he'd run was harmless. The folder of warnings was Windows Event Viewer — a system log every computer generates constantly, flagging nothing unusual. The voice, the lock screen, the command window, the warnings: theater. All of it. She understood this three days later, after her bank called about a wire transfer she hadn't authorized. David had had her banking passwords the moment he touched her screen.


Why this scam works on almost everyone

The tech support scam doesn't exploit ignorance about computers. It exploits something far more universal: a full-screen alarm that seems to be coming from your own machine is genuinely frightening, and the person who answers the phone is trained to sound exactly like the person who should be answering it.

These operations run structured call centers with scripts, quotas, and escalation managers. The agents are coached to sound calm, authoritative, and concerned — the exact tone you'd want from actual tech support. They know which system tools look alarming to a non-expert. They know how to keep you on the phone long enough that hanging up feels like giving up on your own computer.

The scam's single structural weakness is the one thing you can check in under a second: real security warnings from Microsoft, Apple, or any antivirus software never include a phone number. A warning that wants you to call is advertising for a scam. That's the whole tell.


The 6 signs you're looking at a scam

1. The warning includes a phone number

This is the definitive tell, and it applies without exception. Genuine Windows Defender alerts, macOS security warnings, and antivirus notifications appear quietly in your taskbar or notification panel. None of them display a phone number. None. If a warning is asking you to call someone, it's not from your operating system — it's from a webpage designed to look like one.

2. Your browser appears locked or the warning is full-screen

A legitimate OS security alert cannot lock your browser or prevent you from closing it. What looks like a system takeover is almost always a browser tab using full-screen mode and JavaScript to prevent easy exit. Force-quitting the browser (Alt+F4 on Windows, Cmd+Q on Mac, or Ctrl+Alt+Delete to open Task Manager) ends it completely. Your computer is not infected. The page just wants you to believe it is.

3. There's an alarm, a robotic voice, or a countdown

Real security software doesn't scream. It doesn't announce your infection out loud or start a countdown to data loss. These elements exist for one purpose: to stop you from thinking. Fear and urgency are the two mechanisms that override the instinct to pause and verify. The louder and more alarming the warning, the less likely it is to be real.

4. Someone calls you claiming to be Microsoft, Apple, or your antivirus

Microsoft does not proactively monitor personal computers for infections. Apple does not call customers when their devices misbehave. No tech company has a system that detects "signals" from your machine and dispatches a support agent. If someone calls you about your computer, they are not who they say they are. The premise is technically impossible.

5. They ask you to install remote access software

AnyDesk, TeamViewer, UltraViewer, LogMeIn — the moment a stranger asks you to install any of these, the scam has moved from fear to access. Once connected, they control your files, your browser history, your saved passwords, and anything visible on your screen — including your banking portal if you're logged in. Legitimate tech support from your actual ISP or device manufacturer will always walk you through their verified, official channels. They will never ask a stranger to download an app you've never heard of.

6. They show you "evidence" using your own system tools

Event Viewer logs thousands of entries on every Windows machine, constantly — most of them flagged as warnings or errors, all of them completely routine. A scammer who has remote access will open it, highlight the red-and-yellow entries, and narrate them as proof of infection. They'll do the same with the netstat command, showing "foreign connections" that are just normal network traffic. The theater is convincing because the tools are real. The interpretation of them is entirely fabricated.


Three encounters, graded

2 / 10 — LOW: The screaming pop-up

"WINDOWS DEFENDER ALERT: Your PC is infected with 5 viruses! Do not shut down. Call Microsoft Support: 1-888-XXX-XXXX" — delivered full-screen with a blaring siren.

It's a webpage, not Windows. Browser ads can fill a screen and loop audio, but they cannot touch your computer's files or read your passwords. Force-quit the browser and it's gone. The tell is visible even mid-panic: the Windows taskbar is still accessible behind it, and real Defender alerts appear there — silently, with no phone number.

5 / 10 — CAUTION: The unsolicited callback

"This is Michael from Microsoft Windows Support. We're receiving error signals from your computer indicating a network breach. I can help you secure it — are you in front of your machine?"

Calm, professional, patient. The impossible premise is the tell: Microsoft has no system that generates "error signals" from individual personal computers and dispatches outbound calls. No tech company does. But the caller sounds real, which makes the call feel real, and that's exactly the gap this script exploits. Hang up. Don't call back.

8 / 10 — HIGH RISK: The refund trap

An email arrives saying your $399 "PC Shield" subscription has auto-renewed. A friendly refund line walks you through the process over the phone. During the "refund," your online banking is open on screen via remote access — and suddenly $4,000 appears in your account instead of $400. The panicking agent begs you to send back the difference before his manager finds out. The method is gift cards. Or Zelle. Or a wire.

The overpayment was never real — money moved between your own accounts while you watched a manipulated screen. The scam weaponizes your honesty: you're not paying a stranger, in your mind you're correcting an error. The multi-day patience, the live account manipulation, and the emotional scripting make this the version that empties savings accounts. It accounts for some of the largest individual losses in tech support fraud.


If you already called — or let them in

The protocol here is immediate and specific.

If you gave them remote access, treat the machine as compromised until you've confirmed otherwise. Disconnect it from the internet first — unplug the ethernet or turn off Wi-Fi. Then uninstall the remote access software (AnyDesk, TeamViewer, or whichever tool they used). Run a full antivirus scan from a reputable program you already have or download from a trusted source on a different device.

From a separate, trusted device — not the one they touched — change your passwords immediately, starting with email and any financial accounts. Enable two-factor authentication on every account you can.

If they had access while your banking was open, or if they asked for account numbers, call your bank's fraud line now. Monitor statements closely for the next several weeks.

If you transferred money, file a report with the FTC at ReportFraud.ftc.gov and with the FBI's Internet Crime Complaint Center at IC3.gov. These reports feed active investigations even when recovery isn't possible.


When the alarm is still going

Close it. Don't call it. That's the full protocol for any pop-up or browser warning with a phone number — force-quit the browser, and if it resists, restart the computer. Your files are fine. The warning was a webpage.

If someone already called you, or if you're not sure whether what you saw was real, Scamanot's Tech Support Scam Investigator can read the situation in under a minute — describe the warning, the call, or the request, and get a clear verdict before you do anything else.

Investigate This Warning — Free →

The refund version of this scam — the one where an "overpayment" needs to be returned in gift cards or Zelle — is a separate operation layered on top. If a gift card or payment request appeared anywhere in this encounter, the Gift Card Scam Investigator can assess that half of the story.


Common questions

Does Microsoft or Apple ever call people about viruses?

No. Neither company has a system that monitors personal computers for infections and dispatches outbound calls. If someone calls you claiming to be from either company about your computer, they're not.

A warning locked my whole browser with an alarm. Is my computer infected?

Almost certainly not. Browser pages can mimic system alerts and use full-screen mode with audio. They cannot infect your computer or read your files. Force-quit the browser (Ctrl+Alt+Delete on Windows, Cmd+Q on Mac) and it's gone. If the browser reopens to the same page, don't restore the previous session.

What if I already gave someone remote access to my computer?

Treat the machine as compromised. Disconnect from the internet, uninstall the remote access program, run a full antivirus scan, and — from a different device — change your passwords starting with email and banking. If they were viewing your accounts, call your bank's fraud line.

Why do these scams target older adults so heavily?

They don't, exclusively — but the pop-up version tends to reach people who are less familiar with the difference between a browser window and an OS alert. The phone-call version targets anyone with a landline or listed number. The refund version is specifically engineered to exploit trust and honesty, which aren't age-dependent traits at all.


Up to 50 investigations a day. For everyone you protect.

Get Guardian — $9/mo →


Use the tools mentioned in this article: Tech Support Scam Investigator · Gift Card Scam Investigator · Scam Text Investigator

Not sure if something is a scam? Run it through Scamanot — free investigations available, no account required.

Investigate Something Now