Fake Microsoft Support Calls: How the Scam Works in 2026
The phone rings just after lunch. The screen shows a local number, so you answer.
"Hello, this is Kevin from Microsoft Security. We have detected unusual activity on your computer."
The voice is calm and professional. And in that moment, a decision gets made that costs Americans over 60 more than $159 million a year.
This guide walks through the entire script these callers use, start to finish, so you can recognise it at line one instead of line forty. It also covers what to do if you already let someone into your computer, because that situation needs different steps.
Read next: Who calls from (805) 637-7243? 22 people have reported it
Why this scam works so well on older adults
The Federal Trade Commission's report to Congress found that adults aged 60 and over are more than five times as likely as adults aged 18 to 59 to report losing money to a tech support scam. Reported losses came to more than $159 million in 2024.
The usual explanation is that older people do not understand computers. That is wrong, and it matters, because believing it makes you less careful rather than more.
The real reasons are simpler:
- Older adults answer the phone. Younger people let unknown numbers ring out. Answering is the entire first step of the scam.
- Older adults are polite. Hanging up mid sentence on someone who sounds helpful feels rude, and scammers count on that hesitation.
- A phone call used to mean something. Businesses called customers. Doctors called patients. That instinct to take a call seriously is being used as a weapon.
- The pop-up version and what it costs
None of that is about intelligence. It is about habits formed in a time when the phone was trustworthy.
Read next: Rental Scams in 2026: $275 Million Lost and How to Spot One
The two ways the scam reaches you
The cold call
Someone rings claiming to be from Microsoft, Apple, Norton, McAfee, Geek Squad, Windows Security, or your internet provider. They say your computer has been sending security alerts.
Microsoft does not do this. The company states plainly on its own security page that it never makes unsolicited phone calls or sends unsolicited emails asking for personal or financial information, and never proactively reaches out about computer problems.
The pop-up you called yourself
This version is now more common, and it is more dangerous because you dial them. A full screen warning appears while you are browsing. It may beep. It may say your computer is locked. It gives a support number to call.
Because you made the call, it does not feel like a scam. That is exactly the point. The FTC took this seriously enough that in late 2024 it amended the Telemarketing Sales Rule to cover inbound tech support calls, specifically because of this tactic.
Read next: Is ShopVSB.com Legit? Vitamin Sea Boutique Review 2026
A real error message never gives you a phone number to call. Not one. If a number appears on your screen, the message is fake.
The script, step by step
These calls follow a fixed order. Knowing the order is what lets you spot it early.
- The friendly opening. A name, a company, a calm tone. No threats yet. They introduce themselves like a real support agent, because they have practised doing exactly that.
- The scary claim. Hackers on your network. Someone accessing your online banking. Your Social Security information exposed. Statements you cannot immediately verify, delivered without a pause.
- "Are you near your computer?" This question is the turning point. Everything before it was setup. Everything after it is the theft.
- The remote access request. They ask you to visit a website and enter a code. The names sound legitimate because they usually are: AnyDesk, TeamViewer, LogMeIn, UltraViewer. These are real business tools being misused.
- The fake proof. Once inside, they open the Windows Event Viewer, or run a command that prints harmless technical text. Every computer shows warnings in Event Viewer. They present these as evidence of infection.
- The bill. A few hundred dollars for a security package, or a multi year plan for more. Sometimes they claim to give you a refund and then say they accidentally sent too much, and ask you to return the difference.
The payment demand gives it away every time
Watch what happens when money comes up. A real company takes a card, sends a receipt, and can be called back.
A scammer asks for one of these instead:
- Gift cards, read out over the phone while you stay on the line
- A wire transfer
- Cryptocurrency, often through an ATM they direct you to
- A payment app such as Zelle or Cash App
- Cash sent by courier or mail
- The pop-up version and what it costs
All of these share one feature: once sent, the money is gone and cannot be reversed. That is the only reason they are used. No legitimate technology company has ever accepted a gift card as payment for support.
Caller ID proves nothing
Years ago you could judge a call by the number. That stopped being true.
Caller ID spoofing lets a scammer display almost any number they choose. It might show your own area code. It might show a local business. It can show the genuine Microsoft number.
Judge the conversation, never the screen. If you want to check a number that called you, look it up here first and see whether other people have reported it.
The three sentences that end the call
You do not need technical knowledge. You need three responses.
"I will call the company myself." Then hang up and find the number independently, from your own paperwork or by typing the company's address into your browser. A genuine caller will not object. A scammer will get urgent, and that urgency is your confirmation.
"I do not install anything during an incoming call." Make this a fixed rule with no exceptions. If it is fixed, you never have to judge each situation in the moment.
"No." Complete sentence. You owe a stranger who called you nothing at all, including politeness.
If you already gave them access
Act in this order. Speed matters most in the first two steps.
- Disconnect from the internet. Unplug the network cable or switch off Wi-Fi. This cuts their session immediately.
- Call your bank or card issuer on the number printed on your card, from a different phone if you can. Tell them a remote access scam occurred and ask them to review recent activity.
- Change your passwords from a different device. Email first, then banking. Your email is the master key to everything else, so it goes first.
- Remove the remote access software. Uninstall AnyDesk, TeamViewer, or whatever they had you install. If you are unsure how, take the machine to a technician you found yourself.
- Report it to the FTC at reportfraud.ftc.gov. If money was lost, also file with the FBI at ic3.gov.
Our page on what to do after a scam covers the first 48 hours in more detail, including what to say to your bank.
How they got your number
People often assume being called means being hacked. Almost always, it does not.
Your number may have been in a data breach years ago. It may have been sold on a marketing list, or collected from public records. Many operations simply dial thousands of numbers a day until somebody picks up.
Knowing your name and number is not evidence they can see your computer. It is evidence your details exist somewhere online, which is true for nearly everyone.
Talking to a parent about this
The most useful thing is not a warning. It is permission.
Tell them directly that hanging up on a stranger is allowed, and that you would rather they hang up on a real company by mistake than stay polite with a scammer. Most people hesitate because being rude feels worse than being cautious.
Then agree on one habit: any call about a computer problem gets ended, and you get called instead. No judgement, no questions about whether it was really a scam. Just call.
Shame is what keeps these losses hidden. The FTC has said repeatedly that most fraud goes unreported, which is why its own loss figures are only a fraction of the real total.
Related reading
- Tech support scams: what every senior should know, a plain language version of this guide
- Tech support scams now target your bank account, on the newer refund variant
- The pop-up version and what it costs
Sources
- Federal Trade Commission, Protecting Older Consumers 2024 to 2025 report to Congress, December 2025
- Federal Trade Commission, Telemarketing Sales Rule amendment covering inbound tech support calls, November 2024
- Microsoft, Protect yourself from tech support scams
- FTC Consumer Advice, How to spot, avoid and report tech support scams
- The pop-up version and what it costs
What Do You Think?
No one has commented yet. If this happened to you as well, say so below. Knowing that other people had the same call makes it far easier for the next person to trust their instincts.
Add Your Comment
Every comment is read by a person before it appears, so it will not show up straight away. Never post your phone number, address, or bank details here.