Skip to content
ScamSniff
← Back to Home

Phone Scams

Tech Support Scam Calls: How to Spot Them and What to Do If You Already Let Them In

10 min read min readBy ClearShield Team

Last updated: 2026-07-04

The bottom line upfront: A tech support scam usually starts one of two ways — a scary pop-up on your screen telling you to call a number "immediately," or a phone call from someone claiming to be from Microsoft, Apple, or your internet provider who says they've detected a virus on your computer. Neither one is real. Real tech companies do not monitor your computer for problems and do not call you out of the blue. If you're on a call like this right now, hang up. If you already let someone remotely access your computer or paid them, this article walks you through exactly what to do next — in order.


What a Tech Support Scam Call Actually Sounds Like

It usually starts with urgency. The caller says your computer is "sending out viruses" or that your internet provider detected "suspicious activity" on your network. Sometimes it starts differently — you're browsing normally and a loud pop-up fills your screen with a warning sound, a fake Microsoft or Apple logo, and a phone number to call "before your files are deleted."

Either way, the goal is the same: get you on the phone, get you scared, and get you to let a stranger control your computer.

Once you call the number, a "technician" walks you through installing a remote access program — often something legitimate like AnyDesk or TeamViewer, which is what makes this scam so effective. The software itself isn't malicious. What happens next is the problem: the person on the other end can now see your screen, move your mouse, open your files, and in many cases, watch you log into your bank account.

From there, the scam usually goes one of two directions. Either they ask you to pay a "repair fee" — often by gift card, wire transfer, or a fake refund process where they claim to have overpaid you and ask you to send money back — or they quietly look for banking information, account numbers, and passwords while you believe they're "fixing" your computer.

Why These Calls Work So Well

This isn't a scam that targets people who don't understand computers. It targets anyone who is momentarily worried their computer is broken, because that worry short-circuits the normal instinct to slow down and verify.

A few things make it especially convincing:

It uses real company names. Hearing "Microsoft" or "Windows Support" feels official, even though Microsoft has confirmed publicly that it never makes unsolicited calls about your computer.

The pop-ups look authentic. Scammers copy real logos, real color schemes, and even fake "scanning" animations that appear to find viruses in real time. Some pop-ups even lock your browser in full-screen mode so it feels impossible to close, which adds to the panic.

They sound calm and professional. Many of these call centers are run like real businesses, with scripts, hold music, and "supervisors" who can be transferred to if you push back. That professionalism is designed to override your skepticism.

They create urgency without giving you time to think. "Your computer is actively sending your passwords right now" is a sentence built to make you act instead of pause.

The Warning Signs — Read This Before You Ever Pick Up

Keep these in mind, because the scam changes its details constantly but the pattern almost never does:

  • A phone number appeared on your screen, and you're told to call it. No legitimate error message from Windows, Apple, or your internet provider includes a phone number.
  • The caller says they proactively noticed a problem with your computer. Companies do not monitor individual computers for viruses and call you about it.
  • You're asked to download remote access software. This is the single biggest red flag in the entire scam. There is almost no legitimate reason for an unsolicited caller to ask for control of your screen.
  • Payment is requested by gift card, wire transfer, or cryptocurrency. No real technical support department accepts payment this way, ever.
  • You're told not to hang up or tell anyone, "or the virus will spread." This kind of pressure and isolation is a tactic, not a technical reality.
  • A "refund" requires you to log into your bank account while they watch. This is one of the most damaging versions of the scam, because it hands over live banking access.

What to Do If You're on the Phone Right Now

If you're reading this because a call is happening or just happened, here's the order of operations:

Hang up immediately. You don't owe the caller an explanation, a goodbye, or a reason. Simply end the call.

Do not call any number that appeared on a pop-up. If you're worried about a real problem, look up your device manufacturer's support number independently — through the company's official website that you type in yourself, not a link or number from the pop-up.

Close the browser using Task Manager (Windows) or Force Quit (Mac) if a pop-up won't close normally. On Windows, press Ctrl + Alt + Delete and select Task Manager, then end the browser task. On a Mac, press Command + Option + Esc to force quit. This avoids clicking anything inside the pop-up itself, including an "X," which on some fake alerts can trigger a download.

Do not grant remote access, and if you already did, move to the next section now.

What to Do If You Already Gave Them Access or Paid Them

This is the part that matters most, and there's no need for embarrassment — this scam is convincing by design, and it happens to smart, careful people every day. Work through these steps in order.

1. Disconnect from the internet. Turn off Wi-Fi or unplug the ethernet cable. This cuts off the scammer's remote access immediately.

2. Uninstall the remote access software. Go to your list of installed programs (Settings > Apps on Windows, or Applications folder on Mac) and remove any remote access tool you didn't install yourself, such as AnyDesk, TeamViewer, or LogMeIn.

3. Change your passwords from a different, uncompromised device. Start with email and banking, since those unlock everything else. Use a phone or a family member's computer, not the one that was just accessed.

4. Call your bank and credit card companies directly, using the number on the back of your card. Tell them your computer was accessed by a scammer and ask them to flag your account and watch for unauthorized transactions. If you shared account numbers or made a payment, ask about reversing the charge and issuing new card numbers.

5. If you paid by gift card, call the retailer immediately. Companies like Target, Walmart, and Apple have fraud departments that can sometimes freeze the card balance if you act within hours. Keep the receipt and the card itself.

6. If you paid by wire transfer, contact your bank's fraud department the same day. Wire transfers are hard to reverse, but banks can sometimes intercept a transfer that hasn't been fully processed yet.

7. Report the scam. File a report with the FTC at reportfraud.ftc.gov and with the FBI's Internet Crime Complaint Center at ic3.gov. This helps investigators track patterns even when individual recovery isn't possible. Our guide on how to report a phishing email to the FTC, FBI, and IC3 walks through the reporting process in more detail — the same agencies handle both.

8. Have your computer professionally checked. A local, trusted repair shop can confirm no malware or spyware was installed during the remote session. If you noticed other symptoms first, our guide on signs your computer has been hacked explains what to look for.

Protecting Yourself Going Forward

The steps above handle the immediate damage. These habits make it much harder for it to happen again.

Assume monitoring for identity misuse, not just malware. If a scammer had access to your screen, there's a real chance they saw account numbers, saved passwords, or personal documents even if they never technically "hacked" anything. Aura monitors your identity, bank accounts, and credit file around the clock and alerts you the moment something looks wrong — a new account opened in your name, your Social Security number appearing on the dark web, or unusual account activity. If you've been through a remote access scam, this kind of ongoing monitoring catches the slow-moving damage that isn't obvious right away, and Aura backs its service with a $1 million identity theft insurance policy.

Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.

Set a household rule about tech support calls. Agree with family members that no one will install remote access software or make a payment based on an unsolicited call, full stop — even if it sounds official. If a real problem exists, you can always call the manufacturer back using a number you looked up yourself.

Turn on two-factor authentication everywhere you can. Even if a password is exposed, two-factor authentication requires a second code to log in, which stops most account takeovers cold. Our two-factor authentication setup guide walks through it step by step for your most important accounts.

A Final Word

The single most useful thing to remember is this: legitimate companies do not call you first about a computer problem, and they never ask you to pay with a gift card. If you keep that one fact in mind, you will recognize this scam within the first ten seconds of the call, no matter how official it sounds or how convincing the person on the other end is.

If it already happened to you, you are not alone, and acting quickly — disconnecting, changing passwords, calling your bank, and reporting it — puts you back in control faster than you might expect.


Get Our Free Weekly Security Tips

Join our newsletter for the latest updates.

tech support scamphone scamsremote access scamcomputer securityidentity theftseniors