Anatomy of a scam: the tech-support phone call, line by line
A pop-up tells you to call "Windows Support", and a calm professional answers. We take the tech-support scam call apart line by line — and mark the exact sentence where you should hang up.
This is the latest in our series taking a single scam apart line by line. The earlier ones were silent — a text on a lock screen, an email to an accounts team. This one has a voice. It is the tech-support scam call, and it is unusual among scams for one reason: the victim places the call. A frightening pop-up does the scaring; you do the dialing; and a calm, professional voice does the rest.
The conversation below is invented, but every beat matches what the FBI’s Internet Crime Complaint Center (IC3) and Microsoft describe. We pick it up the moment a full-screen pop-up — “Windows Defender Security Warning: your computer has been blocked. Call Microsoft Support now: 1-800-###-####” — has frozen the screen, and a worried person has dialed the number.
The opener: a calm professional, and a case number
“Support”: Thank you for calling Windows Support, this is David, technician ID 4471. I can see your machine has flagged a critical alert — don’t worry, you’ve reached the right place. Can I start by giving you your case reference?
Everything here is engineered to make you exhale. A name, a technician ID, a case reference — the furniture of a real support desk. But notice what just happened: the pop-up handed you a number, you dialed it, and now a stranger is “the right place.” The premise is already false. Microsoft states plainly that its “error and warning messages never include phone numbers,” and that “real error messages in Windows never ask you to call a tech support number.” A security alert that gives you a number to call is the scam — full stop.
The hinge: “I’ll just need to connect to your computer”
“Support”: To diagnose this properly I’ll need to run a remote scan. Go to your browser and type in this address — it’ll let me see your screen and run the diagnostic. It’s completely standard.
This is the single most important line in the call, and it is where the damage begins. The “diagnostic tool” is ordinary remote-access software, and granting that access hands a stranger full control of your computer. The FBI describes the move exactly: scammers “request that the victim grant full control access to the computer to provide efficient technical support.” Their first rule in response is just as blunt: “Do not grant remote access to your computer to unknown persons.” Once you click, they can see your files, your browser, and anything you log into.
The proof: alarming screens that mean nothing
“Support”: Okay, I’m in. Oh… this isn’t good. See all these red entries? Those are foreign IP addresses inside your network. Someone in another country has been accessing your accounts. How long has this been happening?
Now in control of your screen, the “technician” opens a normal system log — the Event Viewer, or a list of network connections — and narrates the harmless lines as catastrophe. Every computer has “red entries” and routine connections; none of it means you have been hacked. But you cannot tell that, and the performance is designed to convert the vague dread of the pop-up into a specific, urgent emergency: strangers are in your bank accounts right now. The fear is the product.
The handoff: “I’m connecting you to your bank’s fraud team”
“Support”: This is beyond what I can fix from here — your money is actively at risk. For your protection I’m going to connect you with the fraud department at your bank. Stay on the line, do not hang up.
This is the pivot from “your computer” to “your money,” and often the point where a second scammer joins, playing your bank or a government officer. (When the chain runs to a fake bank and a fake government official, it has its own name — see the “Phantom Hacker” scam.) The handoff lends borrowed authority: you are no longer talking to tech support, you are talking to “the fraud team,” and the stakes have just been raised to your life savings.
The ask: “move your money somewhere safe”
“Bank fraud team”: To protect your funds while we secure the breach, we need you to move your balance to a safe account we’ve set up in your name. And please don’t mention this to the teller — we believe the hackers may have someone on the inside.
Here is the whole point of the call. Every previous step existed to get you to this instruction: move your money. The FBI documents these calls ending in “a victim-initiated wire transfer,” often “to foreign banks” because those are hardest to reverse, and warns: “Do not conduct banking activity while providing remote access,” and “do not send wire transfers… at the instructions of someone you have only spoken to online or via phone.” The secrecy request — don’t tell the teller — exists to strip away the one human who might stop you. No real bank or agency ever asks you to move money to a “safe account” or to hide the reason from staff.
How to spot it
The spine of the con is short: a pop-up or call hands you a number → a “technician” wants remote access → harmless screens become “proof” you’re hacked → you’re told to move money to stay safe. Each step launders the last: the case ID makes the call feel official, the remote access makes the “proof” feel real, the “proof” makes the money move feel urgent. Pull any single link and the chain falls apart — and the easiest one to pull is the very first.
What to do instead
The free move comes first, and it is the whole defense: Go Direct. A phone number that arrives in a pop-up, an email, or an unexpected call is never the company — so don’t use it. If you’re genuinely worried, hang up and reach Microsoft, Apple, or your bank through a channel you find: an address you type by hand, a number from your card or the back of the box. If someone calls you claiming to be Microsoft, Microsoft’s own advice is to hang up — they “do not make these kinds of calls.” For the trigger that starts it all, see the “your computer is infected” pop-up; for the refund-flavored version, see the tech-support refund scam. And test yourself with the 60-second quiz or browse all our defense moves.
- A pop-up, email, or call gives you a phone number to "fix" a problem you did not report — and a real Microsoft or Apple message never includes a support number.
- Whoever answers wants remote access to your computer "to run a diagnostic", then shows you alarming-looking screens as "proof" you have been hacked.
- The call ends at your money: you are told to move funds to a "safe" account, wire them, or buy gift cards to protect yourself from the very hackers they invented.
- A phone number handed to you by a pop-up, email, or unexpected caller is never the company — it is the scam. Do not dial it, and if someone calls you claiming to be Microsoft or your bank, hang up.
- Never give remote control of your computer to someone who contacted you. That single click is the hinge the whole con turns on.
- If you are worried something is real, reach the company yourself — type its address by hand or use a number from your card, your statement, or the box. Never use the contact path the message gave you.
- No real company or agency ever asks you to move money to a "safe account", wire funds overseas, or buy gift cards to keep them secure.
What unsettles me about this one is that the victim does the dialing. Every other scam has to reach in and grab your attention; this one waits for a scary pop-up to do that, then lets you call them — and the instant you do, you have reframed a stranger as the help you went looking for. From there every request sounds reasonable, because you asked for assistance and assistance is what you think you are getting. So the line I'd underline for anyone is brutally simple: a phone number that finds you is never the company. The company is the one you have to go and find.
Sources
Frequently asked
The pop-up looked exactly like a Windows security alert and had a Microsoft logo. How is that fake?
Logos and official-looking design are trivial to copy, and the pop-up is just a web page a scammer built. The reliable tell is the phone number itself. Microsoft is explicit: its "error and warning messages never include phone numbers," and "real error messages in Windows never ask you to call a tech support number." So the moment an alert tells you to call someone, you already know it is a scam — no matter how real it looks.
They called me — I did not call them. Doesn't that make it more likely to be the real Microsoft?
It makes it less likely, not more. Microsoft says it "will never proactively reach out to you to provide unsolicited PC or technical support," and "does not make unsolicited phone calls." An unsolicited call from "Microsoft Support" is the scam announcing itself. Microsoft's own advice is the right move: hang up.
I let them connect to my computer and may have moved money. What do I do now?
Act fast. Disconnect the computer from the internet, then call your bank on the number from your card or statement (not any number the caller gave you) to flag the transfers and accounts. The FBI warns scammers often push wire transfers "to foreign banks" precisely because they are hard to recall, so speed matters. Change passwords from a different, clean device, and report it at ic3.gov. If you let them install software, have the machine checked before banking on it again.