Companies
Microsoft scams: how the fake messages work
Microsoft impersonation scams primarily manifest as fraudulent technical support pop-ups, browser lockouts, and phishing emails falsely claiming system virus infections or unauthorized Microsoft 365 subscription charges. Scammers utilize scare tactics and spoofed caller IDs to trick victims into calling toll-free hotlines or granting remote desktop access. Attackers ultimately aim to extract payment fees for nonexistent repairs, harvest credentials, or steal sensitive financial information.
Last reviewed: August 9, 2026 · Drafted with AI assistance. Every figure on this page was checked against the source cited for it. Not yet reviewed by a human editor.
ScamPreventionGuide is an independent consumer-protection resource. We are not affiliated with, endorsed by, or sponsored by Microsoft. Company names and trademarks are the property of their respective owners and are used here only to identify the companies that scammers impersonate.
Is the Microsoft message real?
How the brand actually contacts customers: Microsoft never proactively reaches out to provide unsolicited technical or PC support. Genuine Microsoft error and warning messages never include a phone number. Microsoft does not make unsolicited phone calls or send unsolicited emails requesting personal or financial information, or offering to fix computer problems. Any support interaction must be initiated by the customer.
FTC Impersonation Losses: According to Federal Trade Commission (FTC) data published in May 2024, consumers reported losing a total of $60 million to Microsoft impersonation scams. Source: New FTC Data Shed Light on Companies Most Frequently Impersonated by Scammers.
Which versions are in circulation?
The versions in circulation, and what each one is after:
| Version | How it reaches you | What it wants |
|---|---|---|
| Fake Defender Pop-Up Lockout | Pop-up / Web | Call fake tech support hotline, pay for unneeded removal service or grant remote access [2] [3]. |
| Unsolicited Tech Support Call | Phone | Gain remote access to PC via downloaded utility, extract bank details, or purchase phony tech support contracts [2] [3]. |
| Microsoft 365 / Office Renewal Phishing | Call the toll-free number listed in the invoice to "cancel and get a refund", leading to remote takeover or credential harvesting [4]. | |
| Windows Activation Expiry Scam | Pop-up / Email | Payment for fraudulent product keys or submission of credit card details under the guise of license re-authentication [2]. |
| Malicious Search Engine Ad Redirect | Search / Web | Download bundled malware or adware that locks browser sessions and forces fraudulent support engagement [2]. |
What do the fake messages actually say?
We are not quoting example wording on this page. On 16 August 2026 we checked the quoted messages against the sources they were credited to, and the sources did not contain them — so the quotes were removed rather than reworded. We would rather show you nothing than show you an invented example of a real crime.
The exact wording changes constantly anyway. What does not change is the shape: a message you did not ask for, about a problem you cannot verify, with a link or a phone number supplied for you to use. Do not use either — reach the company the way you normally would.
How can you tell a real message from a fake one?
The differences you can check yourself:
- Error messages with phone numbers: Genuine Microsoft error and warning dialog boxes never contain a telephone number to call.
- Proactive cold outreach: Microsoft never calls, emails, or pops up unprompted to state that your device is infected or requires repair.
- Browser full-screen lockups: Legitimate security software does not trap browsers in unclosable infinite pop-up loops or demand immediate telephone dialing to exit.
- Refund hotlines in receipts: Authentic Microsoft billing emails reference self-service account management at account.microsoft.com rather than asking you to dial an inbound toll-free number for refunds.
- Remote access demands: Genuine Microsoft support personnel will never request remote desktop connection permissions out of the blue to scan hardware.
What should you do in the first hour?
It depends on how far it got. Find your situation:
- If you contacted them but gave nothing: Immediately close the web browser (use Task Manager if frozen) and clear browser cache. Do not dial any numbers or interact further.
- If you gave information (passwords, email, personal details): Immediately go to Microsoft Account Security to change your account password, enable multi-factor authentication (MFA), and terminate active session tokens.
- If you gave remote access to your computer: Disconnect the computer from the internet (unplug Ethernet or disable Wi-Fi) immediately. Uninstall any remote access software (e.g., AnyDesk, TeamViewer, QuickAssist) installed during the call. Run a full offline scan using Windows Defender Antivirus. Consider resetting the PC to factory settings if deep compromise is suspected.
- If you paid or transferred money: Immediately contact your bank or credit card issuer to freeze the account, report fraudulent charges, and request a chargeback. File a formal report at ReportFraud.ftc.gov or IC3.gov. Submit incident details to Microsoft via reportfraud.microsoft.com.
Where do you report it?
Official security/fraud page: Microsoft Support - Avoid and report Microsoft technical support scams
Whatever the brand, two official channels take the report. File with the US Federal Trade Commission at reportfraud.ftc.gov, and — if money was lost or a computer was accessed — with the FBI's Internet Crime Complaint Center at ic3.gov. Reporting rarely recovers money on its own; it is what makes the next person's warning possible.
Sources
- Avoid and report Microsoft technical support scams, 2026-08-07.
- Tech Support Scams - Microsoft Defender for Endpoint, March 18, 2022.
- Avoid and report Microsoft technical support scams (Threat Overview), 2026-08-07.
- Received a “Microsoft Security Alert”, is this a scam?, June 20, 2025.
- New FTC Data Shed Light on Companies Most Frequently Impersonated by Scammers, May 24, 2024.
- 2025 IC3 Annual Report, 2026-08-07.