Scam Types
Tech support scams — how fake support calls and pop-ups work
Someone posing as support tells you there is a problem with your computer, your account or a subscription. There is no problem. What they want is either a payment or a way into your device — and the call is designed so that helping them feels like the sensible thing to do.
Last reviewed: July 25, 2026 · Drafted with AI assistance. Reviewed and edited by a human editor before publication.
What a tech support scam is
A tech support scam is built on a role rather than a story. The criminal poses as support staff — for a software company, an internet provider, a retailer, a bank's fraud team — and reports a problem you cannot easily check yourself. Because the problem is technical, being unsure is normal, and the natural response is to let the expert look. That is the whole design.
The FBI's Internet Crime Complaint Center recorded 47,794 complaints of tech and customer support fraud in 2025, with $2,134,675,818 in reported losses. That is a category that has grown fast: the same figures were $1,464,755,976 in 2024 and $924,512,658 in 2023, so reported losses have more than doubled in two years [1].
How they reach you
There are four common entry points, and they matter because the right response differs depending on who started the conversation.
- The browser pop-up. A full-screen warning claims your device is infected or locked, often with alarm sounds and a countdown, and gives a support number to call. The page may be hard to close. It is a web page — it has no access to your computer and knows nothing about it.
- The cold call. Someone rings claiming to be from a software or telecoms company, sometimes with your name and address already. Caller ID can be forged, so a number that looks local or official proves nothing.
- The search result. You go looking for a helpline and reach a paid advert or a lookalike site placed above the real one. This is the dangerous one, because you initiated contact and your guard is down.
- The invoice email. A receipt arrives for a subscription renewal you do not recognise, with a number to call to cancel. There is no charge and no subscription. The invoice exists to make you dial.
Note on the numbers you may have read
You will see tech support fraud reported as "more than 80,000 complaints and over $2.9 billion" in 2025. That figure is correct but it is not tech support alone — the FBI uses it for the two categories of call-centre fraud together, tech and customer support plus government impersonation. Tech and customer support on its own was 47,794 complaints and $2,134,675,818 [1]. Both numbers are real; they measure different things.
What they actually do once they are in
The usual first step is to get you to install a remote access tool. These tools are legitimate and widely used by real IT departments, which is exactly why they are chosen — nothing your antivirus sees will look wrong. Once connected, the caller can see your screen and control the machine.
What follows is theatre with a purpose. They open a system log and present ordinary warnings as evidence of infection. They run a command that lists files and call it a scan. Sometimes they briefly black out your screen and describe it as the virus acting up. The aim is to convert your uncertainty into consent for the next step, which is payment, or a look at your online banking while they have control.
Payment is rarely by card, because card payments can be disputed. Expect requests for bank transfer, gift cards, cryptocurrency, or — increasingly — cash or precious metals handed to a courier who comes to your door. The FBI recorded roughly 725 complaints of these courier collections in 2025, with $311.8 million in losses, tied to tech support and government impersonation calls [1].
If you have already given someone remote access, the crisis steps are set out in I let a scammer into my computer.
The main variants
The subscription renewal invoice
An email confirms that an antivirus or software subscription has auto-renewed for a few hundred, with a helpline to call if you did not authorise it. Antivirus brands are favoured because a security product is plausible to have forgotten about. Nothing has been charged.
What makes it different: it makes you the caller, which removes the suspicion that an incoming call would raise.
The refund that goes wrong on purpose
You are offered a refund and asked to log in to your bank while they watch. They edit what is displayed on your screen so it appears they sent far too much — say £5,000 instead of £500 — then ask you to return the difference. Your balance never changed; only the page you were looking at did. The money you send back is real.
What makes it different: it recruits your sense of fairness. You are not being robbed, you are correcting someone else's mistake.
The handover to the "bank fraud team"
The support call escalates: your account is compromised, and you are transferred to someone presented as your bank's fraud department or a government investigator. You are told to move your savings to a "safe account", or to withdraw cash or buy gold and hand it to a courier for safekeeping. Secrecy is requested because there is supposedly an investigation.
What makes it different: it turns a technical problem into an authority instruction, and the secrecy request is what stops anyone talking you out of it.
Who it hits hardest
Tech support fraud is unusually concentrated by age. Of the $2,134,675,818 reported lost in 2025, $1,040,730,043 was lost by people aged 60 and over — close to half the category total, from 21,333 complaints. For that age group, tech and customer support was the second-largest source of losses after investment fraud [1].
That is worth knowing if you are reading this on behalf of a parent rather than for yourself. The useful intervention is rarely a warning about viruses. It is an agreement made in advance: that nobody legitimate will ever ask them to install something during a phone call, and that they can hang up and check with you first without it being rude or embarrassing. If someone you know is in this now, helping a relative who has been scammed covers how to approach it.
One newer wrinkle: some of these calls now use synthetic voices. The FBI logged $19,457,078 of tech and customer support losses in 2025 in complaints that mentioned an artificial intelligence element [1]. It is a small share of the category so far, but it removes the accent and script cues people were told to listen for.
What real companies do not do
This list is more useful than a list of scam signs, because it does not require you to judge how convincing someone is.
- They do not phone you unprompted to say your computer has a virus.
- They do not put a phone number in a browser warning. Real security software reports problems inside the software.
- They do not ask for remote access on a call that they started.
- They do not ask for payment in gift cards, cryptocurrency, cash by courier, or gold.
- They do not ask you to move money to a "safe account". No bank or police force does this.
- They do not ask you to keep the conversation secret from your family or your bank.
- They do not need your password or a one-time code. Support staff can help without either.
- They do not set deadlines measured in minutes.
Key Takeaway
Hanging up on a real support agent costs you five minutes. Staying on the line with a fake one can cost your savings. When the two are hard to tell apart, the cheaper mistake is to hang up and call back on a number you looked up yourself.
How to report it
If money has moved, contact your bank before anything else — they have the shortest window to act. Then report it. Reporting a call where you lost nothing still has value, because the phone numbers and payment accounts are what get shut down.
- United States — the FBI's Internet Crime Complaint Center at ic3.gov, and the FTC at reportfraud.ftc.gov.
- United Kingdom — Action Fraud at actionfraud.police.uk.
- Australia — Scamwatch at scamwatch.gov.au.
- Canada — the Canadian Anti-Fraud Centre at antifraudcentre-centreantifraude.ca.
- Denmark — report to the police at politi.dk and contact your bank, which you can reach securely using MitID.
- Elsewhere in Europe — report to your national police and to your bank.
Sources
- Federal Bureau of Investigation, Internet Crime Complaint Center — 2025 IC3 Annual Report. ic3.gov. Accessed July 2026. Cited for tech and customer support complaint counts and losses for 2023–2025, losses among complainants aged 60 and over, the combined call-centre fraud figure, courier collection complaints and losses, and losses in complaints with an artificial intelligence element.
Reviewed by Anton Hoelstad, founder and editor of ScamPreventionGuide.com. We are not lawyers or financial advisers, and we cannot recover money for you. What we can do is tell you what the reporting routes are and what the people on the other end of them will ask for.
Last reviewed: July 25, 2026 · Next review due: January 25, 2027 · Drafted with AI assistance. Reviewed and edited by a human editor before publication.