Fake tech support

Also called: tech support scam · pop-up scam · Microsoft scam · remote access scam · virus scam

A tech support scam starts with a fake warning that your computer is infected or compromised, along with a phone number to call. The person who answers asks to connect to your machine, stages evidence of a problem, and escalates from a support fee to draining accounts. US reported losses reached $2.13 billion in 2025, more than double two years earlier.

Key facts

Category
Tech support & remote access
First documented
2008
Typical loss
$300–$200k USD, per victim
Main channels
browser pop-up, search advert, phone call, email, SMS, fake invoice
Who is targeted
People over 60, who account for the large majority of reported losses in this category; Anyone unsure whether a security warning is genuine — which is most people; Users of shared or older computers, where an unexpected pop-up seems plausible; People who searched for a support number rather than using one they already had
Documented origins
India, United States, Canada, Pakistan, Philippines
Main targets
United States, Canada, United Kingdom, Australia, New Zealand, Ireland, Germany, Netherlands
Case files
7 documented cases
Last reviewed
2026-09-06
Anatomy of a tech support scamAnatomy of a tech support scam. The pop-up is not the crime. It exists to make you dial a number. 1. A warning with a number: A pop-up, a search advert, a fake invoice or a cold call. All end in a number to dial. 2. The victim makes the call: Defences built against strangers who ring you do not fire on a number you dialled. 3. Remote access, framed as routine: A support tool is installed. Email, files, passwords and open banking sessions go with it. 4. Real tools, false reading: Event logs and network connections shown as proof of intrusion. Nothing is faked but the meaning. 5. The story leaves the computer: Identity theft, an investigation, accounts being emptied now. A support fee becomes a rescue. 6. Payment on a rail with no reversal: Crypto, gift card codes, a wire — or gold and cash handed to a courier at the door. 7. Secrecy, then repetition: Do not tell the bank what it is for. Numbers that engaged once are called again. The diagram marks stage 1 as the point where the scheme can still be stopped: A genuine problem with your computer never arrives with a phone number attached. Microsoft, Apple, your bank and your antivirus never put support numbers in warnings and never call you. If the alert supplies the number, force-quit the browser — nothing has happened to your machine.Anatomy of a tech support scamThe pop-up is not the crime. It exists to make you dial a number.1A warning with anumberA pop-up, a search advert,a fake invoice or a coldcall. All end in a numberto dial.Minutes2The victim makes thecallDefences built againststrangers who ring you donot fire on a number youdialled.Minutes3Remote access, framedas routineA support tool isinstalled. Email, files,passwords and open bankingsessions go with it.Minutes4Real tools, falsereadingEvent logs and networkconnections shown as proofof intrusion. Nothing isfaked but the meaning.20 minutes5The story leaves thecomputerIdentity theft, aninvestigation, accountsbeing emptied now. Asupport fee becomes arescue.The same call6Payment on a railwith no reversalCrypto, gift card codes, awire — or gold and cashhanded to a courier at thedoor.Hours to days7Secrecy, thenrepetitionDo not tell the bank whatit is for. Numbers thatengaged once are calledagain.WeeksWhere it can still be stopped — stage 1A genuine problem with your computer never arrives with a phone number attached. Microsoft, Apple, your bank and your antivirus never put support numbers inwarnings and never call you. If the alert supplies the number, force-quit the browser — nothing has happened to your machine.Stages documented in US Department of Justice prosecutions, May 2025, and FBI IC3 annual reporting for 2023 to 2025.howscamswork.com
The stages of the scheme, in order, with the point where it can still be stopped.

What it is

A tech support scam begins with a problem that does not exist and ends, increasingly often, with somebody’s retirement savings.

The opening is familiar: a browser fills with a warning, sometimes with an alarm sound, saying the machine is infected, or that a licence has expired, or that a bank login has been compromised. It cannot be closed. It supplies a phone number. That number is the entire point of the exercise — nothing has been installed, nothing has been stolen, and the “warning” is a web page.

What happens after the call is what has changed. Ten years ago the scheme sold a fake cleanup for a few hundred dollars. Now the phone call is an introduction. The agent takes remote control, shows staged evidence of an intrusion, and escalates: your identity has been stolen, your accounts are being drained, we have to move your money somewhere safe, there is a federal investigation.

The numbers follow that escalation. US reported losses rose from $924.5 million in 2023 to $2.13 billion in 2025 — a 131% increase — while complaint counts rose only 27%. Losses per victim roughly doubled. Tech support now sits behind only investment fraud and business email compromise in reported US losses.

How it actually works

  1. The warning appears

    A pop-up while browsing, an advert at the top of search results for “printer support”, a fake invoice email for a subscription you never bought, or a cold call. Every route ends the same way: a phone number in front of a worried person.

    Where it could have stopped

    A genuine problem with your computer never arrives with a phone number attached. Microsoft, Apple, your bank and your antivirus do not put support numbers in warnings, and they do not call you. If the alert supplies the number, the alert is the scam. Force-quit the browser and it is over.

  2. A calm, competent person answers

    Not a shouty scammer — a polite agent with a script and a queue. The tone is deliberate. The whole scheme depends on the victim feeling helped rather than pressured.

  3. Remote access is requested

    AnyDesk, TeamViewer, or something branded to look like a support tool. It is framed as normal, because it is: real IT departments use these. Granting it hands over everything at once — email, files, saved passwords, and any banking session that is open.

  4. Evidence is staged

    Event Viewer, full of ordinary warnings, presented as an infection log. netstat, listing normal connections, presented as intruders. Nothing here is faked — real tools, real output, false interpretation. That is why it is convincing.

  5. A fee, then an escalation

    First a support charge. Then, on the call, the story grows: your identity has been stolen, your accounts are compromised, your bank has been notified, there is an investigation. The remote session is used to show doctored account pages the victim believes are their own.

  6. Money is moved on an irreversible rail

    Cryptocurrency at an ATM or exchange, gift card codes read aloud, a wire transfer, or gold and cash handed to a courier at the door. In 2025, 43% of reported tech support transactions went by cryptocurrency and a further 20% by wire or ACH.

  7. Secrecy is imposed

    Do not tell the bank what it is for. Do not discuss it with family, because they may be involved. The investigation is confidential. This step is what keeps the loss growing.

Why it works

Uncertainty is the raw material. Most people genuinely cannot tell a real security warning from a fake one — and they are right not to be sure, because real ones do exist and do look alarming. The scam does not exploit stupidity; it exploits a legitimately confusing environment.

The victim makes the call. That inversion matters enormously. Everyone is on guard against a stranger who rings them. Almost nobody is on guard against a number they dialled themselves, and the scheme is built entirely around that asymmetry.

Remote access is a single decision with unlimited consequences. Most security choices are incremental. This one is not: it is one click, after which everything on the machine belongs to someone else, including whatever bank page happens to be open.

The evidence is real. Event logs, network connections, running processes — all genuine, all normal, all meaningless. Nobody can refute a demonstration they do not have the background to interpret, and being talked through it by a patient expert makes disbelief feel rude.

The escalation arrives after trust is established. By the time the conversation turns to bank accounts, the victim has been on the phone for an hour with someone who has been helping. The person delivering the frightening news is now the ally.

And secrecy is built in. “Don’t tell the bank what the transfer is for” is the instruction that converts a $400 loss into a $200,000 one, because the bank clerk asking why is the last line of defence and the scheme knows it.

Where it comes from

The enforcement record on this category is unusually detailed, because the money touches US and Canadian banks and the call centres have been prosecuted directly.

A substantial share of tech support fraud aimed at North America has been documented running from call centres in India, particularly around Ahmedabad, and the Justice Department has run repeated joint enforcement actions with Indian authorities against them. These operations are structured like businesses — shifts, scripts, quotas, floor managers, escalation to a “supervisor” when a target hesitates. The Delaware guilty plea documented on this page involved an Indian national and at least $2.1 million in losses.

The domestic layer is equally important and equally documented: US-based couriers, mule accounts, and gold buyers. The Rhode Island indictment charged eight people over a scheme that reached roughly 300 victims across 37 states.

Two qualifications. This is a statement about identified criminal operations and where they have been prosecuted, not about a country or its people — India also hosts the legitimate support industry these operations imitate, which is part of why the imitation works. And the geography moves: enforcement pressure has pushed parts of this trade toward other jurisdictions, and the Canadian data shows the category’s shape changing rather than the crime ending.

Real cases

Older adults losing six figures to impersonation scams rose eightfold

2025 US Ongoing $445.0m

The FTC reported in August 2025 that combined losses from older adults who lost more than $100,000 to impersonation scams rose eightfold, from $55 million in 2020 to $445 million in 2024. The payment instructions in those cases are physical: cash into Bitcoin ATMs, and stacks of cash or gold handed to couriers.

Read the case file · 3 sources

US tech support losses more than doubled in two years

2025 US Ongoing $2.1bn

FBI Internet Crime Complaint Center data shows tech support fraud losses in the United States rising from $924.5 million in 2023 to $1.46 billion in 2024 and $2.13 billion in 2025 — a 131% increase in two years. Complaint volume grew far more slowly, from 37,560 to 47,794, meaning the average loss per complaint roughly doubled. Tech support is now the third-largest loss category the FBI tracks.

Read the case file · 2 sources

Pop-ups, live agents and 300 victims across 37 states

2025 US · CA Charged — allegation, not conviction $5.0m

In May 2025 the US Attorney's Office for the District of Rhode Island indicted eight people over a transnational fraud and money laundering scheme aimed at elderly people in the United States and Canada. Pop-up messages on victims' computers made false claims that lured them into calling live agents, who then told them their financial assets were at risk or could be garnished. Investigators identified around 300 victims in at least 37 states with known losses exceeding million.

Read the case file · 1 source

Posing as federal agents: $2.1 million from people told they were under investigation

2025 US · IN Convicted $2.1m

In May 2025 the US Attorney's Office for the District of Delaware announced that Rakeshkumar Patel, an Indian national, had pleaded guilty to one count of wire fraud conspiracy over an elder fraud scheme targeting Americans. Victims were called by fraudsters posing as federal agents who convinced them their identities had been stolen and that they were themselves under federal investigation. The scheme involved at least .1 million in losses.

Read the case file · 1 source

Gold couriers: collecting precious metals from the door

2025 US Charged — allegation, not conviction $311.8m

In May 2025 a grand jury in the Northern District of Florida charged Atharva "Andy" Sathawane with conspiracy to commit wire fraud and conspiracy to commit money laundering over a scheme that defrauded elderly victims across the United States into handing over money and gold in response to fraudulent phone calls and messages. The FBI recorded roughly 725 complaints and .8 million in losses to gold-courier schemes in 2025 — an average loss per complaint of over ,000.

Read the case file · 2 sources

Losses at Bitcoin ATMs rose nearly tenfold in three years

2024 US Ongoing $110.0m

The FTC's September 2024 analysis found reported losses at Bitcoin ATMs rising nearly tenfold from 2020 to over $110 million in 2023, and topping $65 million in the first half of 2024 alone. The median loss was $10,000, people over 60 were three times as likely to lose money at one, and the losses come overwhelmingly from impersonation scams.

Read the case file · 2 sources

$212m on gift cards, and the reason that number is small

2024 US Ongoing $212.0m

US consumers reported losing $212 million on gift or reload cards across 41,120 reports in 2024 — the sixth-largest payment method by losses, well behind bank transfers at $2.09 billion. The gap is the point: gift cards are used for the scams that take hundreds, and they are the method most likely to go unreported entirely.

Read the case file · 2 sources

Red flags

  • A warning with a phone number in it. The single clearest tell in this category. Genuine software never does this.
  • A pop-up you cannot close, possibly with an alarm sound. It is a web page. Force-quit the browser.
  • An unsolicited call about your computer, from “Microsoft”, “Apple”, your internet provider or your antivirus.
  • A request to install remote-access software or share your screen. Nobody legitimate who called you needs this.
  • You are asked to open your banking while they are connected — to “check for fraudulent transactions” or “confirm your refund”.
  • An invoice for a subscription you do not recognise, with a number to call and dispute it. The invoice is the bait.
  • Payment in gift cards, cryptocurrency, wire transfer, or cash to a courier. There is no legitimate version of any of these.
  • The story escalates beyond the computer — identity theft, an investigation, your accounts being emptied right now.
  • You are told not to tell your bank what the money is for, or not to tell your family.
  • A refund is “accidentally” too large and you are asked to send back the difference. See refund scams.
  • The support number came from a search result or an advert rather than from the back of a device or a company’s own site.

If it’s happening to you

A pop-up is on screen and you have not called. Force-quit the browser: Ctrl+Shift+Esc on Windows, Cmd+Option+Esc on macOS. Restart if you need to. When you reopen the browser, do not restore the previous session. Nothing has happened to your computer.

You called, but did not install anything or pay. Hang up. Nothing is wrong with the machine. Expect a callback — numbers that engage get called again, sometimes for months.

You gave someone remote access.

  1. Disconnect from the internet — unplug the cable or turn off Wi-Fi. This ends the session.
  2. Using a different device, change your email password first, then banking, then anything that shares a password. Email comes first because it controls password resets for everything else.
  3. Call your bank’s fraud line and say someone had remote access to your computer. Ask them to review recent activity and flag the account.
  4. Uninstall the remote-access software, check for anything else installed during the session, and run a full scan. If financial accounts were open while they were connected, treat them as compromised regardless of what the scan says.
  5. Turn on two-factor authentication where you can — and never read a code out to anyone.

Money has gone. Call your bank immediately; the first hours are when a transfer can still be recalled. For gift cards, call the issuer with the card numbers — occasionally funds are still recoverable. For cryptocurrency, send the transaction hashes to the receiving exchange straight away. Then report it, and expect a recovery approach afterwards.

Helping an older relative. The most useful framing is not “don’t fall for pop-ups”. It is: the pop-up is not the crime, the phone call is. Agree now that any alarming computer message means calling you first, and that this is never an imposition. It is a much easier rule to follow than telling real warnings from fake ones — which nobody can reliably do.

Where the money goes

Small payments go straight onto card processors that will be abandoned within weeks. The larger sums — the ones that arrive after the escalation — go the way all irreversible money goes: cryptocurrency bought at an ATM or exchange, gift card codes read down the phone, wires to mule accounts, and increasingly gold and cash collected by a courier at the door.

That courier route is worth noting as an adaptation. Banks got better at interrupting transfers, so the schemes moved to a rail banks cannot see at all. The FBI recorded roughly 725 gold courier complaints and $311.8 million in losses in 2025, an average above $400,000 per complaint, and links them specifically to tech support and government impersonation victims.

The other half of this story

Our sibling site Clean on Paper explains how the collected funds are moved — the mule accounts, the gift-card resale market, and why gold is such an attractive intermediate step.

By the numbers

No agency publishes a line item for most of the schemes on this site, so these charts show the official categories that contain this scheme. Each series is labelled with the agency's own category name. See how the mapping works.

How contact was made, CA, 2025Horizontal bars of reported losses by contact channel in 2025, led by Internet-social network at $2.0m.How contact was made, CA, 2025Reported losses by the channel the scammer used, for the agency categories covering this scheme.Internet-social network$2.0mInternet-social network: $2.0mInternet$1.8mInternet: $1.8mOther/unknown$1.6mOther/unknown: $1.6mDoor to door/in person$1.5mDoor to door/in person: $1.5mDirect call$1.2mDirect call: $1.2mEmail$849,338Email: $849,338Text message$558,314Text message: $558,314Not Available$81,844Not Available: $81,844Video Call$68,033Video Call: $68,033Mail$33,871Mail: $33,871$0$500,000$1.0m$1.5mAggregated across every agency category that maps to this scheme, so it inherits those categories’ breadth.Reported losses only. Every agency here says most fraud is never reported to it, so treat these as a floor, not a total.Sources: Canadian Anti-Fraud Centre / RCMP. Pulled 2026-09-06.
Full dataset, methodology and downloads
Reported losses over timeLine chart of reported losses from 2021 to 2025 for the agency categories that cover this scheme: Imposter Scams (US); Tech/Customer Support (US); Internet Services (US); Remote access (AU).Reported losses over timeEach line is one agency category that covers this scheme. Agency categories are usually broader than the scheme itself.$0$1.0bn$2.0bn$3.0bnImposter Scams (US), 2024: $3.0bnTech/Customer Support (US), 2023: $925mTech/Customer Support (US), 2024: $1.5bnTech/Customer Support (US), 2025: $2.1bnInternet Services (US), 2024: $164mRemote access (AU), 2024: $70mRemote access (AU), 2025: $45m20212022202320242025Imposter Scams (US)Tech/Customer Support (US)Internet Services (US)Remote access (AU)Categories are the publishers’ own and are broader than this scheme, so these lines bound it rather than measure it exactly. Lines are notcomparable to each other: different countries, different reporting systems.Reported losses only. Every agency here says most fraud is never reported to it, so treat these as a floor, not a total.Sources: Federal Trade Commission (US); Canadian Anti-Fraud Centre / RCMP; FBI Internet Crime Complaint Center (IC3); National Anti-ScamCentre (ACCC), Australia (transcribed from the published report). Pulled 2026-09-06.
Full dataset, methodology and downloads

Sources

Every factual claim above traces to one of these. Statistics are reported losses; see methodology for what that does and does not measure.

  1. 2025 Internet Crime Report. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: $2,134,675,818 in 2025 tech support losses from 47,794 complaints; the 43% cryptocurrency payment share; gold courier figures.
  2. 2024 Internet Crime Report. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: The 2023 and 2024 tech support comparison figures.
  3. Justice Department Highlights Enforcement Efforts Protecting Older Americans from Transnational Fraud Schemes in Recognition of 2025 World Elder Abuse Awareness Day. US Department of Justice. Accessed 2026-09-06. Supports: The Rhode Island pop-up indictment, the 300 victims across 37 states, and the DOJ definition of tech support fraud.
  4. Consumer Sentinel Network Data Book 2024. US Federal Trade Commission. Accessed 2026-09-06. Supports: 69,221 US tech support scam reports in 2024 under the Imposter Scams category.
  5. Canadian Anti-Fraud Centre Fraud Reporting System Dataset. Canadian Anti-Fraud Centre / RCMP. Accessed 2026-09-06. Supports: Canadian Service-category reports, victims and losses by year, where the CAFC files tech support fraud.
  6. Targeting scams: report of the National Anti-Scam Centre on scams data and activity 2025. National Anti-Scam Centre (ACCC), Australia. Accessed 2026-09-06. Supports: Australian remote access losses falling 34.1% to A$69.9m in 2025.

Common questions

A full-screen warning says my computer is locked and I cannot close it. What do I do?

Nothing is locked. It is a web page using a browser trick, and the alarm is the product. Force-quit the browser — Ctrl+Shift+Esc on Windows, Cmd+Option+Esc on a Mac — or restart the machine. Do not call the number, and when you reopen the browser, decline to restore the previous session.

Will Microsoft or Apple ever call me about a virus?

No. Neither company monitors individual consumer machines for infections, and neither makes unsolicited support calls. Nor do they put phone numbers in pop-up warnings. A warning that supplies the number to call is telling you what it is.

I let someone connect to my computer. What now?

Disconnect from the internet, then use a different device to change the passwords for your email and banking — email first, because it controls password resets everywhere else. Call your bank and say someone had remote access. Uninstall any remote-access software they installed, run a scan, and if financial accounts were open during the session, treat them as compromised.

Why do they ask for gift cards or cryptocurrency?

Because those rails cannot be reversed. A credit card payment can be charged back and a bank transfer can sometimes be recalled; a gift card code read out over the phone cannot be. The payment method is the single most reliable tell in this whole category.

They showed me error logs and network connections proving I was hacked. Weren't those real?

They were real Windows tools showing normal output. Event Viewer always lists warnings and errors; netstat always shows connections. Presenting ordinary output as evidence of an intrusion is the standard demonstration, and it is convincing precisely because nothing was faked — only the interpretation.

It started as tech support but ended with someone talking about my bank accounts. Is that the same scam?

Yes, and it is the most damaging version. The computer problem is the introduction; once there is a live phone call, the pretext escalates to compromised accounts, a federal investigation, or money that must be moved somewhere safe. That is where six-figure losses come from.

Where tech support money goesWhere tech support money goes. Banks got better at interrupting transfers, so the schemes moved to rails banks cannot see. Where tech support money goesBanks got better at interrupting transfers, so the schemes moved to rails banks cannot see.Victim's savingsWithdrawn orconverted, oninstructionCrypto ATM, giftcards, wire — or goldCollected at the dooror received in-accountCourier or muleaccountConsolidated and sentonCall-centre operatorsabroadReversibilityA recall is realistically possible only at the first hop, and only in the first hours. After the money is converted it becomes an investigation, not a refund.How the collected funds are moved — Clean on Paper, our sibling sitehttps://cleanonpaper.site/techniques/money-mules/Rails documented in the FBI's 2025 Internet Crime Report: 43% of tech support transactions by cryptocurrency, plus 725 gold courier complaints totalling $311.8 million.howscamswork.com
Where the money goes after it leaves, and where it becomes hard to recover.

Report it

Reporting is what produces the enforcement data on this page. Find the right agency and phone number for your country on the report page. If money moved in the last few hours, call your bank first.