Security Scams: how they work and what to do if you fall for one
Tech support scams: the fake virus warning and the fake refund
How pop-up warnings and cold calls from Microsoft or Apple lead to remote access and drained bank accounts, and how to get out at any stage.
The short answer
- A web page cannot scan your computer, so a full screen virus warning with a phone number is always fake.
- Microsoft, Apple and your internet provider do not call you about a virus, ever.
- The real loss usually happens later, during a staged refund, not during the fake virus repair.
- A browser can be closed safely with Task Manager or Force Quit, no matter what the page says.
- Once remote access software has run, assume passwords typed on that device are known and change them from a different device.
A tech support scam starts with a fake emergency on your screen or a call about a virus you do not have, and it ends, often days later, with money leaving your account. The important thing to know up front is that a web page cannot scan your computer. It has no access to your files, your antivirus or your system status. Any page that shows a countdown, plays an alarm and displays a support number is a picture of a warning, not a warning. If you are in the middle of one right now, skip to the exit instructions below.
The two front doors
The first is the pop-up. You are on an ordinary site, often one with heavy advertising, and a new tab takes over the whole screen. It may play a siren, show a fake scan filling up, imitate a Windows or macOS security dialog, display an error code, and warn that your banking details are being transmitted. Sometimes it locks the keyboard shortcuts you would normally use, or repeats a dialog box every time you click. It always includes a toll free number, because the page has no way to do anything to you. It needs you to make the call.
The second is the cold call. Someone says they are from Microsoft, Apple, your internet provider or "the Windows department", and that suspicious activity has been detected on your connection. There is no such department, and no company monitors home computers this way. The number on your screen often looks local or official, which proves nothing, because caller ID is supplied by whoever places the call.
Both doors lead to the same room: a friendly person on the phone who needs to get onto your machine.
The chain, step by step
Understanding the whole sequence matters, because most people who lose money were not robbed in the first twenty minutes.
Stage one is proof. The caller opens a system tool you have never looked at, usually Event Viewer on Windows, which is full of yellow warning icons from completely ordinary events. They read them out as infections. On a Mac they might use Console. They might run a command that lists network connections and call them hackers.
Stage two is access. You are asked to install a remote support tool. These are real, legitimate products used by real IT departments, which is why your antivirus, which is watching for the usual malware families, does not object. Once it is running, they can see your screen, move your mouse and type.
Stage three is payment, often modest: a few hundred dollars for a support plan or a lifetime license. Many victims stop here, feeling annoyed rather than robbed. If that payment went on a card rather than gift cards, it can sometimes be disputed through your bank, so keep the receipt.
Stage four is where the large losses happen, usually weeks or months later. A second caller says the company is closing and you are owed a refund. You are asked to log into your bank while they watch, and the refund is typed in. Then comes the "mistake": instead of 300 dollars, the screen shows 30,000. It is not real. They have either edited what the page displays on your screen, or moved money between your own accounts, so your checking balance genuinely looks higher while your savings quietly dropped. You are then asked, apologetically and desperately, to send back the difference in gift cards, a wire transfer, cash by courier, or crypto. That part is real, and it is your own money.
Getting out, at whichever stage you are in
- If a full screen warning is on your display, do not call the number and do not click the page. Press Escape or F11 to leave full screen, then close the tab. If clicking does nothing, open Task Manager with Ctrl, Shift and Escape on Windows, or Force Quit with Command, Option and Escape on a Mac, select the browser, and end it. Nothing is lost except open tabs.
- Reopen the browser and decline any offer to restore the previous session, or the same page returns. Then clear the site's notification permission if it has been sending desktop alerts.
- If you are on a call and have installed anything, stop the call and disconnect from the internet: turn off Wi-Fi or unplug the cable. This ends their session immediately.
- Uninstall the remote access tool through Add or remove programs on Windows, or by dragging it to the Trash and emptying it on a Mac. Then restart the computer and make sure it does not reappear.
- Run a full scan with the built in tool: Microsoft Defender on Windows, or your installed security software. The fuller cleanup process, including hidden scheduled tasks and browser hijacking, is in cleaning an infected computer.
- Change passwords from a different device, starting with email, then banking, then anything else you signed into on that machine. Use a phone or another computer, not the one that was accessed.
- Call your bank on the number from your card if you paid anything or if they saw your online banking. Ask for a new card and for the account to be flagged.
- Report it. In the US, reportfraud.ftc.gov and ic3.gov. In the UK, Action Fraud. In Canada, the Canadian Anti-Fraud Centre. In Australia, Scamwatch.
Telling a real warning from a fake one
| Signal | Real system message | Tech support scam |
|---|---|---|
| Where it appears | In the system's own notification area, not a web page | Full screen inside the browser |
| Phone number | Never | Always, usually toll free |
| Sound | Silent | Alarm or a recorded voice |
| Urgency | None, it waits for you | A countdown, or a threat to lock the machine |
| What it asks | Run a scan, restart, update | Call now and allow remote access |
Genuine security software wants you to click a button in the software. It never wants you to phone anyone.
Helping an older relative without making it worse
These scams are aimed at people who are polite, at home during the day, and reluctant to be rude to someone who says they are helping. That is not a character flaw, and treating it as one tends to make the next incident a secret, which is far more expensive than the first.
A few things help more than warnings. Check their computer for remote access software and remove anything they did not knowingly install, and do the same for browser extensions nobody chose. Turn on the phone setting that silences unknown callers. Remove an administrator password from a shared machine only if you are ready to support it. Most of all, agree on a simple no fault rule: nothing computer related gets paid for without one phone call to you first, and there is never any trouble for making that call. More approaches for this are in helping an older relative with technology.
What to do next
If the only thing that happened was a scary pop-up, close it, clear the browser's notification permissions, and carry on. If somebody had remote access, work through the cleanup above today rather than this weekend. If money has moved, the next hour is worth more than the next week, and the actions by payment type are set out in I sent money to a scammer. Repeated fake alerts on the same sites are usually an advertising problem rather than an infection, which is covered in adware and pop-ups.
Common questions
Can a website really detect a virus on my computer?
No. A page in your browser can see your browser type, your screen size and roughly where you are, and nothing about your files or your security software. Every warning that claims otherwise is a picture designed to look like a system alert.
I let them onto my computer but paid nothing, am I fine?
Probably not fine, but recoverable. Remove the remote access tool, run a full scan, and change the passwords of anything you signed into on that machine, using a different device to do it.
They said my bank account is compromised and I must move the money, is that related?
Yes, it is the same chain arriving at the same destination. No bank or support desk moves your money to keep it safe, and any instruction to do so is fraud regardless of who appears to be calling.
My parent keeps getting these calls, what actually helps?
Silencing unknown callers and removing any remote access software from their machine does more than warnings do. Agreeing in advance that they will always call you before paying for anything computer related gives them a way to pause without feeling foolish.