Tech Support Scams: How They Work and What to Do If You’re Targeted

Tech support scams rely on a specific emotional trigger — sudden fear that your computer is broken, infected, or about to lose your data — to short-circuit normal caution. Understanding the mechanics of how these scams actually run makes them much easier to recognise in the moment, which is exactly when recognising them matters most.

How the scam typically starts

There are two common entry points. The first is a fake pop-up warning appearing while browsing, styled to look like it’s from a well-known company (often invoking Microsoft, Apple, or a security software brand), claiming your device is infected and urging you to call a phone number immediately. The second is a direct, unsolicited phone call, where the caller claims to be from tech support, sometimes using fake caller ID information designed to look like a trusted or local number.

What happens once they have you on the phone

The scammer’s core goal is to get one of two things: remote access to your device, or a direct payment. A typical sequence looks like:

  • They ask you to install remote access software (sometimes legitimate software, like a real remote-support tool, used for an illegitimate purpose) so they can “diagnose the problem.”
  • Once connected, they run a fake scan — sometimes just opening a normal system log or process list and pointing at completely ordinary entries as if they were evidence of infection — to manufacture a sense of crisis.
  • They then offer to “fix” the fabricated problem for a fee, often pushing for payment via gift cards, a wire transfer, cryptocurrency, or a payment app specifically because these are hard to trace or reverse once sent.
  • In some cases, once they have remote access, they use it directly to access banking apps, saved passwords, or personal files on the device, going well beyond the amount initially agreed for the “fix.”

Warning signs to treat as a hard stop

  • An unsolicited call or pop-up claiming to have detected a problem with your device that you didn’t report
  • Any request to install remote access software from someone who contacted you first, rather than someone you contacted
  • Urgency and fear-based language (“your data will be lost,” “your bank account is at risk”) pushing you to act immediately
  • A request for payment via gift cards, cryptocurrency, or wire transfer specifically — legitimate tech companies do not request payment this way
  • Being asked to keep the call or the “fix” secret from family members or bank staff

What genuine tech support actually looks like

Real technology companies don’t proactively call or pop up a warning demanding you phone a number to fix a problem they’ve supposedly detected remotely. If you have a genuine concern about your device, the safe route is to contact the manufacturer or your antivirus provider directly, through contact details you look up independently — never a number given to you in a pop-up or unsolicited call.

If you’ve already granted remote access or made a payment

  • Disconnect the device from the internet immediately to cut off ongoing remote access.
  • Change your important passwords (banking, email) from a different, unaffected device, since the compromised device itself may no longer be trustworthy for this.
  • Contact your bank immediately if you shared card details, made a payment, or believe banking access may have been exposed.
  • Run a full security scan with reputable antivirus software, or get the device professionally checked, since remote access sessions can be used to install further malicious software.
  • Report it to Action Fraud (actionfraud.police.uk) and, if the initial contact was via email or text, forward the original message to the NCSC’s reporting addresses.

It’s worth saying directly: falling for one of these is not a sign of being careless or unintelligent — these scams are specifically engineered around inducing panic, and they succeed against people who are otherwise entirely careful with technology. The important thing is acting quickly once you realise, not how it happened.

Sources