Run a contracting, freelance, or gig business? Try Roadfolio·Mileage, invoices, expenses & AI voice assistant in one app·iOS & Android
Help/Security/How to spot a tech support scam

How to Spot a Tech Support Scam (And What to Do If You Got Tricked)

By Isaac Farris·Updated May 22, 2026·8 minute read

I get calls every week from clients who almost got scammed, or who did get scammed and are now trying to undo the damage. Tech support scams target everyone, but seniors get hit the hardest because the scammers know how to push the right emotional buttons. Fear, urgency, authority.

This article covers two things: how to spot the scam before you fall for it, and exactly what to do if you already did.

The single most important rule

Microsoft does not call you. Apple does not call you. Norton, McAfee, your internet company, Amazon. None of them call you to warn about computer problems. If someone calls claiming to be from any tech company about a virus, hack, or computer error, it is always a scam. Always. There is no exception. Hang up.

The four most common tech support scams (right now)

1. The fake virus popup

You're browsing the web. Suddenly your screen fills with a flashing warning: "WARNING: Your computer is infected! Trojans detected! Call Microsoft Support immediately: 1-800-XXX-XXXX." Sometimes a robotic voice reads the warning aloud. The popup won't close. The browser is frozen.

It is not real. Microsoft does not display popups with phone numbers. Real antivirus software does not either. The popup is a website you accidentally landed on (often from a malicious ad on an otherwise normal site).

What to do: Don't call the number. Don't click anything in the popup. Close the browser entirely (right-click its taskbar icon and pick "Close window," or use Ctrl + Shift + Esc to open Task Manager and end the browser process). Restart your computer if it's stuck. Your computer is not actually infected.

2. The cold call from "Microsoft"

The phone rings. An accented voice (often, but not always, with a thick Indian or Eastern European accent) says they're from Microsoft Technical Support. They've detected viruses on your computer. They need to fix it before your data is stolen. They sound professional, calm, almost helpful.

It is not real. Microsoft does not have your phone number. They do not monitor your computer. They have never called anyone, ever, about a virus.

The scammer will try to get you to:

What to do: Hang up. Block the number. If they call back from a different number, hang up again. Don't engage, don't ask questions. Just hang up.

3. The "your subscription is expiring" email

An email arrives that looks exactly like it's from Geek Squad, Norton, McAfee, or PayPal. It says your subscription is about to auto-renew for $399 to $599. To cancel, call this number.

It is not real. The email isn't from the real company. The phone number connects to a scammer who will try to "process your refund" by remoting into your computer.

What to do: Don't call. If you actually have a subscription with the company, log in to your account directly (type their website into your browser, don't click the email). Confirm or cancel from inside your account. Delete the email.

4. The fake refund or fake invoice

Similar to above but more sophisticated. The scammer convinces you that a refund was sent to your account by mistake (often "too much" was refunded), and now they need to take the extra back. They ask you to log in to your bank account while they're on the call. They transfer money around to make it look like an error happened. Then they ask you to send the "extra" back via gift cards.

What to do: No legitimate company resolves refund issues by asking you to send gift cards. None. Hang up immediately and call your bank from a number on the back of your actual bank card.

Universal red flags (if you see any of these, it's a scam)

What to do if you already let them in

If you already gave a scammer access to your computer, here is the action list. Do these in order, today:

Step 1: Disconnect from the internet immediately

Unplug the ethernet cable, or turn off Wi-Fi. This kicks them out and stops anything else from being uploaded or downloaded.

Step 2: From a different device (phone, tablet, friend's computer), call your bank

If you gave them ANY payment information, gave them remote access while logged in to banking, or sent money in any form, your bank needs to know within 24 hours. Tell them you've been victimized by a tech support scam and want to freeze accounts and review recent activity. Most banks can help.

Step 3: Change critical passwords

From your phone or another device (not the compromised computer), change:

Step 4: Get the computer cleaned

Don't trust the computer. The scammer likely installed remote access tools, keyloggers, or other malware. Either:

A "scan and clean" with antivirus alone is not enough. Sophisticated scammer tools often survive that.

Step 5: Report it

Help others. File a report at:

You probably won't get your money back, but reporting helps law enforcement track these operations and warn others.

How to prevent it next time

Worried you got hit?

If you just had a sketchy popup or call and you're not sure what happened, that's exactly the kind of thing to send us a quick email about. We'd rather take a free five-minute look than have you stress about it.

Did this article help a family member?

If this kept someone from getting scammed, that's the best possible thanks. Tips also welcome.

Buy me a coffee