Microsoft and tech support impersonation scams
Last verified:
Tech support scams often begin with fake virus warnings in pop-ups or unsolicited calls claiming to be from Microsoft or another well-known company. Scammers may request remote access, payment for unnecessary repairs, or bank details for fake refunds. FTC and Microsoft guidance note that well-known tech companies generally do not make unsolicited calls about computer problems.
- Impersonated brand
- Microsoft and other technology brands
- Scam type
- Brand impersonation
- Common delivery methods
- Phone call, Website, Email
How this scam works
A browser pop-up may claim your computer is infected and display a phone number to call. Alternatively, you may receive a cold call from someone claiming to be Microsoft or Windows support. The scammer may ask for remote access to your computer, run fake scans, and claim to find malware. They may then charge for removal or trick you into entering payment details for a refund that does not arrive — sometimes claiming they “over-refunded” and demanding repayment via gift cards or wire transfer.
Warning signs
- Pop-up warnings with phone numbers — legitimate security software generally does not ask you to call a number shown in a pop-up.
- Unsolicited calls about viruses or hacked accounts.
- Requests to install remote-access software such as AnyDesk or TeamViewer from an unknown caller.
- Demands for gift cards, wire transfers, or cryptocurrency to fix a computer issue.
- Claims that Microsoft detected a problem without you contacting them first.
- Pressure to act within minutes.
How to verify safely
- Close suspicious pop-ups using task manager if needed — do not call the number shown.
- Update your device security software and run a scan from software you installed yourself.
- Contact Microsoft support only through official microsoft.com paths if you need help.
- Never grant remote access to someone who contacted you unexpectedly.
If you received this message
- Hang up on unsolicited tech support calls.
- Do not pay for services pushed through urgent or threatening pop-ups.
- Uninstall remote-access tools if you already installed them at a scammer’s direction.
- Change passwords for accounts accessed on the affected device if remote access was granted.
If you already clicked or paid
- Contact your bank or card issuer if you paid by card.
- Report gift card or wire payments to the issuer immediately — recovery is often limited.
- Report to ReportFraud.ftc.gov and ic3.gov.
- Consider a professional device check if remote access was allowed.
Official reporting guidance
- Report to ReportFraud.ftc.gov.
- Report Microsoft impersonation through Microsoft’s official scam reporting channels.
- File with ic3.gov if you paid or granted remote access.
Check a suspicious link
Paste a URL into Fraudly’s free checker for a structured trust review. Results are informational — not a guarantee.
Open free checkerAuthoritative sources
Fraudly resources
Related local alerts
- ActiveSMS phishing (smishing)
USPS smishing scam
Criminals send texts or emails claiming a USPS package could not be delivered, an address is incomplete, or a fee is owed. The messages are typically designed to steal payment details or personal information through fake tracking links. U.S. Postal Inspection Service guidance warns that unexpected delivery problem messages with links are a common smishing pattern — verify through usps.com rather than the message.
Impersonated brand: United States Postal Service (USPS)
Last verified:
- ActiveSMS phishing (smishing)
Toll road text scam
Scammers send texts claiming you owe unpaid tolls through programs such as E-ZPass, FasTrak, or SunPass. Messages may threaten late fees or registration suspension and link to phishing sites. FCC consumer guidance warns that legitimate toll agencies generally do not demand immediate payment through unsolicited text links.
Impersonated brand: E-ZPass, FasTrak, SunPass, and other U.S. toll programs
Last verified:
- ActiveGovernment impersonation
IRS impersonation scam
Scammers impersonate the IRS through email, text, social media messages, and phone calls. They may claim you owe tax, must verify an account, or are due a refund — often with links or QR codes to fake IRS sites. According to IRS guidance, the IRS does not initiate contact by email, text, or social media to demand payment or sensitive information.
Impersonated brand: Internal Revenue Service (IRS)
Last verified:
Microsoft and other vendors provide legitimate paid support when you initiate contact. This alert describes criminal impersonation and coerced remote access. Fraudly cannot diagnose your device.
Related Fraudly resources
- Stay Safe OnlineClear answers on website trust, phishing, fake shops, and safer payments—tied to Fraudly’s checkers.
- Website scam checkerRun a free URL check for trust signals, scam patterns, and plain-language risk context.
- Latest checksBrowse recent public website trust snapshots from the Fraudly community feed.
- Intelligence HubEditorial guides on fake webshops, phishing, and warning signs before you pay or log in.