LIVE: New phishing campaigns targeting mobile users —View latest threats →

Back to Threats
High💸 Scam

Fake Tech Support Scam (Microsoft & Apple Pop-ups)

Fake Microsoft or Apple browser pop-ups claim your PC is infected and push you to call a scam number — leading to remote access theft and financial fraud.

Published: 5 March 2026Last updated: 20 January 2026

What Is This Threat?

Fake tech support scams use alarming browser pop-ups — often styled as official Microsoft or Apple security alerts — to trick people into calling a fake helpline. Once on the call, "technicians" convince victims to install remote access software (AnyDesk, TeamViewer, QuickAssist), then steal banking credentials, drain accounts, or charge hundreds of euros for fake "repairs."

The FBI's Internet Crime Complaint Center (IC3) reported $924 million in losses from tech support fraud in 2023 alone, making it one of the most lucrative scam categories in the world.

How It Works

  • You visit a website — often via a misleading ad or malicious redirect — and a full-screen pop-up appears with flashing warnings: "VIRUS ALERT — Your computer is infected! Call Microsoft Support immediately: +1-800-XXX-XXXX." In some cases, your browser speakers blare an alarm sound.
  • The pop-up may lock your browser so it appears impossible to close (hold Alt+F4 or Cmd+Q to exit).
  • You call the number. A fluent English-speaker answers as "Microsoft Support" or "Apple Care."
  • They instruct you to install a remote access tool (AnyDesk, TeamViewer, Windows Quick Assist).
  • Once connected, they "show" you fake virus infections (e.g., Event Viewer error logs that are harmless but look alarming).
  • They demand €200–€500 for a "security package," ask for your banking credentials to process a "refund," or transfer money directly from your open bank account.
  • In a variation called the overpayment scam, they pretend to accidentally send you a €3,000 refund and beg you to wire the difference back — the initial transfer is fraudulent.
  • Real Examples

  • Microsoft's Digital Crimes Unit reported taking down over 600 fake tech support domains in 2023 and 2024.
  • Austrian consumer protection agency AK Österreich recorded hundreds of complaints per year, with average losses of €400–€1,500 per victim.
  • macOS users are not safe: scammers increasingly run Apple-branded versions of the same pop-up, targeting Safari users.
  • In 2025–2026, scammers use AI-generated voices to sound more convincing and bypass suspicion.
  • Red Flags

  • Microsoft and Apple never display your phone number in a browser alert — real security warnings come from the OS, not a website.
  • Legitimate companies never cold-call you about viruses, and they never ask you to install remote access software.
  • Urgency tactics: "If you close this window, your files will be permanently deleted in 5 minutes."
  • Requests for gift cards (Amazon, Google Play, iTunes) as payment — no legitimate company accepts these.
  • A caller who "accidentally" overpays and asks you to wire back the difference.
  • How to Protect Yourself

    • Close pop-up alerts immediately with Alt+F4 (Windows) or Cmd+Q (Mac) — a real virus never announces itself via a browser pop-up
    • Never call a phone number displayed in a browser security alert — look up official support numbers from the company's official website
    • Never install remote access software (AnyDesk, TeamViewer, QuickAssist) at someone else's request unless you initiated the support request yourself
    • Know that Microsoft and Apple never proactively call you about viruses on your computer
    • Use a reputable ad blocker (uBlock Origin) to prevent the malicious ads and redirects that trigger these pop-ups

    What to Do If Affected

    1. 1.Force-close your browser (Alt+F4 / Cmd+Q / Task Manager) — do not interact with the pop-up
    2. 2.If you allowed remote access, disconnect immediately (unplug ethernet, disable Wi-Fi) and then uninstall the remote tool
    3. 3.If you paid or gave banking details, call your bank immediately to freeze the account and dispute the charges
    4. 4.Run a reputable antivirus scan (Windows Defender, Malwarebytes) to check for any malware installed during the session
    5. 5.Report the incident to your national cybercrime authority (Austria: bundeskriminalamt.at, Germany: bsi.de, Ukraine: cyberpolice.gov.ua)
    #tech support#Microsoft#Apple#remote access#pop-up#AnyDesk#TeamViewer