Also called: tech support scam · pop-up scam · Microsoft scam · remote access scam · virus scam
A tech support scam starts with a fake warning that your computer is infected or compromised, along with a phone number to call. The person who answers asks to connect to your machine, stages evidence of a problem, and escalates from a support fee to draining accounts. US reported losses reached $2.13 billion in 2025, more than double two years earlier.
People over 60, who account for the large majority of reported losses in this category; Anyone unsure whether a security warning is genuine — which is most people; Users of shared or older computers, where an unexpected pop-up seems plausible; People who searched for a support number rather than using one they already had
Documented origins
India, United States, Canada, Pakistan, Philippines
Main targets
United States, Canada, United Kingdom, Australia, New Zealand, Ireland, Germany, Netherlands
Case files
7 documented cases
Last reviewed
2026-09-06
The stages of the scheme, in order, with the point where it can still be stopped.
What it is
A tech support scam begins with a problem that does not exist and ends, increasingly often, with
somebody’s retirement savings.
The opening is familiar: a browser fills with a warning, sometimes with an alarm sound, saying the
machine is infected, or that a licence has expired, or that a bank login has been compromised. It
cannot be closed. It supplies a phone number. That number is the entire point of the exercise —
nothing has been installed, nothing has been stolen, and the “warning” is a web page.
What happens after the call is what has changed. Ten years ago the scheme sold a fake cleanup for a
few hundred dollars. Now the phone call is an introduction. The agent takes remote control, shows
staged evidence of an intrusion, and escalates: your identity has been stolen, your accounts are being
drained, we have to move your money somewhere safe, there is a federal investigation.
The numbers follow that escalation. US reported losses rose from $924.5 million in 2023 to $2.13
billion in 2025 — a 131% increase — while complaint counts rose only 27%. Losses per victim roughly
doubled. Tech support now sits behind only investment fraud and business email compromise in reported
US losses.
How it actually works
The warning appears
A pop-up while browsing, an advert at the top of search results for “printer support”, a fake
invoice email for a subscription you never bought, or a cold call. Every route ends the same way:
a phone number in front of a worried person.
Where it could have stopped
A genuine problem with your computer never arrives with a phone number attached. Microsoft, Apple, your bank and your antivirus do not put support numbers in warnings, and they do not call you. If the alert supplies the number, the alert is the scam. Force-quit the browser and it is over.
A calm, competent person answers
Not a shouty scammer — a polite agent with a script and a queue. The tone is deliberate. The
whole scheme depends on the victim feeling helped rather than pressured.
Remote access is requested
AnyDesk, TeamViewer, or something branded to look like a support tool. It is framed as normal,
because it is: real IT departments use these. Granting it hands over everything at once —
email, files, saved passwords, and any banking session that is open.
Evidence is staged
Event Viewer, full of ordinary warnings, presented as an infection log. netstat, listing normal
connections, presented as intruders. Nothing here is faked — real tools, real output, false
interpretation. That is why it is convincing.
A fee, then an escalation
First a support charge. Then, on the call, the story grows: your identity has been stolen, your
accounts are compromised, your bank has been notified, there is an investigation. The remote
session is used to show doctored account pages the victim believes are their own.
Money is moved on an irreversible rail
Cryptocurrency at an ATM or exchange, gift card codes read aloud, a wire transfer, or gold and
cash handed to a courier at the door. In 2025, 43% of reported tech support transactions went by
cryptocurrency and a further 20% by wire or ACH.
Secrecy is imposed
Do not tell the bank what it is for. Do not discuss it with family, because they may be involved.
The investigation is confidential. This step is what keeps the loss growing.
Why it works
Uncertainty is the raw material. Most people genuinely cannot tell a real security warning from a
fake one — and they are right not to be sure, because real ones do exist and do look alarming. The
scam does not exploit stupidity; it exploits a legitimately confusing environment.
The victim makes the call. That inversion matters enormously. Everyone is on guard against a
stranger who rings them. Almost nobody is on guard against a number they dialled themselves, and the
scheme is built entirely around that asymmetry.
Remote access is a single decision with unlimited consequences. Most security choices are
incremental. This one is not: it is one click, after which everything on the machine belongs to
someone else, including whatever bank page happens to be open.
The evidence is real. Event logs, network connections, running processes — all genuine, all
normal, all meaningless. Nobody can refute a demonstration they do not have the background to
interpret, and being talked through it by a patient expert makes disbelief feel rude.
The escalation arrives after trust is established. By the time the conversation turns to bank
accounts, the victim has been on the phone for an hour with someone who has been helping. The person
delivering the frightening news is now the ally.
And secrecy is built in. “Don’t tell the bank what the transfer is for” is the instruction that
converts a $400 loss into a $200,000 one, because the bank clerk asking why is the last line of
defence and the scheme knows it.
Where it comes from
The enforcement record on this category is unusually detailed, because the money touches US and
Canadian banks and the call centres have been prosecuted directly.
A substantial share of tech support fraud aimed at North America has been documented running from
call centres in India, particularly around Ahmedabad, and the Justice Department has run repeated
joint enforcement actions with Indian authorities against them. These operations are structured like
businesses — shifts, scripts, quotas, floor managers, escalation to a “supervisor” when a target
hesitates. The Delaware guilty plea documented on this page involved an Indian national and at least
$2.1 million in losses.
The domestic layer is equally important and equally documented: US-based couriers, mule accounts, and
gold buyers. The Rhode Island indictment charged eight people over a scheme that reached roughly 300
victims across 37 states.
Two qualifications. This is a statement about identified criminal operations and where they have been
prosecuted, not about a country or its people — India also hosts the legitimate support industry these
operations imitate, which is part of why the imitation works. And the geography moves: enforcement
pressure has pushed parts of this trade toward other jurisdictions, and the Canadian data shows the
category’s shape changing rather than the crime ending.
The FTC reported in August 2025 that combined losses from older adults who lost more than $100,000 to impersonation scams rose eightfold, from $55 million in 2020 to $445 million in 2024. The payment instructions in those cases are physical: cash into Bitcoin ATMs, and stacks of cash or gold handed to couriers.
FBI Internet Crime Complaint Center data shows tech support fraud losses in the United States rising from $924.5 million in 2023 to $1.46 billion in 2024 and $2.13 billion in 2025 — a 131% increase in two years. Complaint volume grew far more slowly, from 37,560 to 47,794, meaning the average loss per complaint roughly doubled. Tech support is now the third-largest loss category the FBI tracks.
2025US · CACharged — allegation, not conviction$5.0m
In May 2025 the US Attorney's Office for the District of Rhode Island indicted eight people over a transnational fraud and money laundering scheme aimed at elderly people in the United States and Canada. Pop-up messages on victims' computers made false claims that lured them into calling live agents, who then told them their financial assets were at risk or could be garnished. Investigators identified around 300 victims in at least 37 states with known losses exceeding million.
In May 2025 the US Attorney's Office for the District of Delaware announced that Rakeshkumar Patel, an Indian national, had pleaded guilty to one count of wire fraud conspiracy over an elder fraud scheme targeting Americans. Victims were called by fraudsters posing as federal agents who convinced them their identities had been stolen and that they were themselves under federal investigation. The scheme involved at least .1 million in losses.
In May 2025 a grand jury in the Northern District of Florida charged Atharva "Andy" Sathawane with conspiracy to commit wire fraud and conspiracy to commit money laundering over a scheme that defrauded elderly victims across the United States into handing over money and gold in response to fraudulent phone calls and messages. The FBI recorded roughly 725 complaints and .8 million in losses to gold-courier schemes in 2025 — an average loss per complaint of over ,000.
The FTC's September 2024 analysis found reported losses at Bitcoin ATMs rising nearly tenfold from 2020 to over $110 million in 2023, and topping $65 million in the first half of 2024 alone. The median loss was $10,000, people over 60 were three times as likely to lose money at one, and the losses come overwhelmingly from impersonation scams.
US consumers reported losing $212 million on gift or reload cards across 41,120 reports in 2024 — the sixth-largest payment method by losses, well behind bank transfers at $2.09 billion. The gap is the point: gift cards are used for the scams that take hundreds, and they are the method most likely to go unreported entirely.
A warning with a phone number in it. The single clearest tell in this category. Genuine software never does this.
A pop-up you cannot close, possibly with an alarm sound. It is a web page. Force-quit the browser.
An unsolicited call about your computer, from “Microsoft”, “Apple”, your internet provider or your antivirus.
A request to install remote-access software or share your screen. Nobody legitimate who called you needs this.
You are asked to open your banking while they are connected — to “check for fraudulent transactions” or “confirm your refund”.
An invoice for a subscription you do not recognise, with a number to call and dispute it. The invoice is the bait.
Payment in gift cards, cryptocurrency, wire transfer, or cash to a courier. There is no legitimate version of any of these.
The story escalates beyond the computer — identity theft, an investigation, your accounts being emptied right now.
You are told not to tell your bank what the money is for, or not to tell your family.
A refund is “accidentally” too large and you are asked to send back the difference. See refund scams.
The support number came from a search result or an advert rather than from the back of a device or a company’s own site.
If it’s happening to you
A pop-up is on screen and you have not called. Force-quit the browser: Ctrl+Shift+Esc on Windows,
Cmd+Option+Esc on macOS. Restart if you need to. When you reopen the browser, do not restore the
previous session. Nothing has happened to your computer.
You called, but did not install anything or pay. Hang up. Nothing is wrong with the machine.
Expect a callback — numbers that engage get called again, sometimes for months.
You gave someone remote access.
Disconnect from the internet — unplug the cable or turn off Wi-Fi. This ends the session.
Using a different device, change your email password first, then banking, then anything that
shares a password. Email comes first because it controls password resets for everything else.
Call your bank’s fraud line and say someone had remote access to your computer. Ask them to
review recent activity and flag the account.
Uninstall the remote-access software, check for anything else installed during the session, and
run a full scan. If financial accounts were open while they were connected, treat them as
compromised regardless of what the scan says.
Turn on two-factor authentication where you can — and never read a code out to anyone.
Money has gone. Call your bank immediately; the first hours are when a transfer can still be
recalled. For gift cards, call the issuer with the card numbers — occasionally funds are still
recoverable. For cryptocurrency, send the transaction hashes to the receiving exchange straight away.
Then report it, and expect a
recovery approach afterwards.
Helping an older relative. The most useful framing is not “don’t fall for pop-ups”. It is: the
pop-up is not the crime, the phone call is. Agree now that any alarming computer message means
calling you first, and that this is never an imposition. It is a much easier rule to follow than
telling real warnings from fake ones — which nobody can reliably do.
Where the money goes
Small payments go straight onto card processors that will be abandoned within weeks. The larger sums —
the ones that arrive after the escalation — go the way all irreversible money goes: cryptocurrency
bought at an ATM or exchange, gift card codes read down the phone, wires to mule accounts, and
increasingly gold and cash collected by a courier at the door.
That courier route is worth noting as an adaptation. Banks got better at interrupting transfers, so
the schemes moved to a rail banks cannot see at all. The FBI recorded roughly 725 gold courier
complaints and $311.8 million in losses in 2025, an average above $400,000 per complaint, and links
them specifically to tech support and government impersonation victims.
No agency publishes a line item for most of the schemes on this site, so these charts show the
official categories that contain this scheme. Each series is labelled with the agency's
own category name. See how the mapping works.
Every factual claim above traces to one of these. Statistics are reported losses; see
methodology for what that does and does not measure.
2025 Internet Crime Report.
FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: $2,134,675,818 in 2025 tech support losses from 47,794 complaints; the 43% cryptocurrency payment share; gold courier figures.
2024 Internet Crime Report.
FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: The 2023 and 2024 tech support comparison figures.
Consumer Sentinel Network Data Book 2024.
US Federal Trade Commission. Accessed 2026-09-06. Supports: 69,221 US tech support scam reports in 2024 under the Imposter Scams category.
Canadian Anti-Fraud Centre Fraud Reporting System Dataset.
Canadian Anti-Fraud Centre / RCMP. Accessed 2026-09-06. Supports: Canadian Service-category reports, victims and losses by year, where the CAFC files tech support fraud.
A full-screen warning says my computer is locked and I cannot close it. What do I do?
Nothing is locked. It is a web page using a browser trick, and the alarm is the product. Force-quit the browser — Ctrl+Shift+Esc on Windows, Cmd+Option+Esc on a Mac — or restart the machine. Do not call the number, and when you reopen the browser, decline to restore the previous session.
Will Microsoft or Apple ever call me about a virus?
No. Neither company monitors individual consumer machines for infections, and neither makes unsolicited support calls. Nor do they put phone numbers in pop-up warnings. A warning that supplies the number to call is telling you what it is.
I let someone connect to my computer. What now?
Disconnect from the internet, then use a different device to change the passwords for your email and banking — email first, because it controls password resets everywhere else. Call your bank and say someone had remote access. Uninstall any remote-access software they installed, run a scan, and if financial accounts were open during the session, treat them as compromised.
Why do they ask for gift cards or cryptocurrency?
Because those rails cannot be reversed. A credit card payment can be charged back and a bank transfer can sometimes be recalled; a gift card code read out over the phone cannot be. The payment method is the single most reliable tell in this whole category.
They showed me error logs and network connections proving I was hacked. Weren't those real?
They were real Windows tools showing normal output. Event Viewer always lists warnings and errors; netstat always shows connections. Presenting ordinary output as evidence of an intrusion is the standard demonstration, and it is convincing precisely because nothing was faked — only the interpretation.
It started as tech support but ended with someone talking about my bank accounts. Is that the same scam?
Yes, and it is the most damaging version. The computer problem is the introduction; once there is a live phone call, the pretext escalates to compromised accounts, a federal investigation, or money that must be moved somewhere safe. That is where six-figure losses come from.
Where the money goes after it leaves, and where it becomes hard to recover.
Reporting is what produces the enforcement data on this page. Find the right agency and phone
number for your country on the report page. If money moved in the last
few hours, call your bank first.