Updated: August 14, 2026
OPRS may receive compensation when readers open an account through partner links on this page. Our analysis is based on independent research, BBB data, and IRS publications.
Tech support scams are one of the top-loss frauds targeting older Americans, and the Federal Trade Commission and the FBI Internet Crime Complaint Center have tracked them under that label for more than a decade. The pitch keeps mutating. A screaming browser pop-up. A calm caller who says a virus was detected. A friendly refund agent who happens to overpay you and needs the money back. All three are the same fraud with different masks.
This page walks through the mechanics of each variant in plain language, then gives you a step-by-step action block for the moment a scam is happening and a recovery block for the hours after. Nothing here is legal or IT advice. If a scam is in progress right now, jump to the block directly below.
OPRS is a US retirement information service. This is one page in our elder-fraud protection library for readers between 55 and 75. As of 2026, the tactics on this page reflect the current FTC and IC3 alert patterns.
If this is happening to you right now
Stop. Do not follow any instruction on the screen or over the phone. Do not read out any code, card number, or bank balance.
- Power off the computer. Hold the power button for ten seconds. A pop-up that locks the browser cannot survive a full shutdown. Restart only after step five.
- Hang up the phone. Do not argue, do not explain, do not stay on to be polite. A real support agent from a real company will never object to you hanging up and calling back.
- Do not install anything. If a caller asked you to type a web address that ends in a name like AnyDesk, TeamViewer, LogMeIn, UltraViewer, or Supremo, or asked you to type a code, close the browser. Those are legitimate remote-access tools weaponized by scammers.
- Call your bank from the number printed on your debit or credit card. Ask the fraud desk to freeze the account, watch for unusual transfers, and reverse anything that already moved. Speed matters more than any other factor.
- File a report the same day at reportfraud.ftc.gov and ic3.gov. If a courier came to your door or is on the way for cash or gold, call local police.
Print this list. Tape it inside a kitchen cabinet or near the computer. Nobody thinks clearly in the first minute of a fake emergency, and a printed checklist is worth more than trying to recall rules under pressure.
The browser-lock pop-up: how the fake alert works
You open a news article or click a link in an email. Suddenly the browser fills the screen with a red or blue warning. There is a siren sound. A voice repeats that your computer has been infected, that Microsoft is monitoring the breach, that you must call a toll-free number immediately, and that closing the window will damage your files.
None of that is real. The FTC has documented this browser-lock pattern for years in its consumer guidance on tech support scams. The alert is a web page, not an operating system message. Its only purpose is to prevent you from closing the tab so you feel forced to call the number on the screen.
Real security warnings from your operating system or antivirus never include a phone number. They never ask you to call anyone. They live inside a small system window, not full-screen, and they do not read themselves aloud through your speakers.
To close a browser-lock page, ignore the on-screen buttons. On Windows, press Ctrl-Alt-Delete and open Task Manager to end the browser. On a Mac, press Command-Option-Escape to force-quit the browser. When you reopen the browser, decline any prompt to restore the previous session, since that would just reload the fake alert.
If a phone number was displayed and the pop-up read it out loud, do not call it. That number connects directly to a call center run by the scam operation. Once you are on the line, the second act of the script begins.
The cold-call variant: a known brand, said generically
The cold-call version starts with your phone. The caller says they are from the security department of a familiar brand. Common names include Microsoft, Apple, Norton, McAfee, Amazon, and internet service providers. The caller often refuses to give a direct number where you can call them back.
The pitch has three usual openings. Suspicious activity was detected on your account. A software subscription is about to auto-renew for a large amount, and they can cancel it if you help them log in. Or a router has been compromised and your entire home network needs remote inspection.
Real support desks at real companies do not call households unprompted. They do not ask for passwords. They do not ask you to install a remote-access tool. They do not ask for gift cards, wire transfers, or cryptocurrency. The FTC lists all four of these as universal scam signals in its consumer alert on how to avoid a scam.
If a caller mentions a specific product you own by name, that is not proof. Warranty and purchase records leak in data breaches every year. A convincing detail early in the call is a scripted move to make the next request feel routine.
Remote-access software: the point of no return
The pivotal danger moment in almost every tech support scam is the remote-access install. AnyDesk, TeamViewer, LogMeIn, UltraViewer, and Supremo are legitimate business tools. Scammers use them because they are free, easy to install, and hand over full control of a home computer in under a minute.
Once the software is running and you have read out the connection code, the caller has the same access to your machine as if they were sitting at your desk. They can open your bank site. They can move funds. They can copy files. They can install a second hidden program that survives after the call ends. They can watch you type your passwords in real time.
Everything after this moment is theater. The scammer will pretend to run a virus scan while quietly opening your bank account in another window. The scammer will show you a fake screen with fake red warnings while a real transfer processes behind it. Some scripts even blank the screen for a few minutes so you cannot see what is happening.
The single defense against this stage is prevention. Never type a code given to you over the phone into a website you were told to visit. Never install a program on a caller’s instruction. If a genuine tech emergency ever calls for remote support, arrange it through an appointment with a technician you already know.
The refund-overpayment reversal trick, worked through
The refund trap is the most financially damaging tech support scam variant, and it is engineered around a fake bank transfer. It is worth walking through the whole flow because reading it once is often enough to break the script when it happens.
Step one. The caller claims to be a refund agent from a company you may have used, such as an antivirus provider or an online marketplace. They say your subscription is being canceled and a refund of, for example, four hundred dollars is on its way.
Step two. They install remote-access software. They ask you to open your bank site so they can process the refund into your account. From here, the scammer has full control.
Step three. They pretend to type in the refund amount, but they add extra zeros. The screen displays a deposit of forty thousand dollars instead of four hundred. Sometimes the scammer moves your own money between your accounts to fake the deposit. Sometimes they edit the balance display through the browser to fake it entirely.
Step four. The caller panics on the phone. They say they will lose their job if the company sees the mistake. They beg you to send back the overpayment quickly through wire transfer, gift cards, cash by courier, or a cryptocurrency ATM. All of these channels are hard or impossible to reverse.
Step five. You send the money back. There was never a refund. The extra funds you saw were your own money moved between your accounts, or a display trick. The money you sent is now truly gone. The scammer disappears within the hour.
The FBI IC3 Elder Fraud Report has documented this exact reversal pattern under the tech support scam category for several reporting cycles, and losses per victim tend to run in the tens of thousands of dollars. Reading the flow once, out loud with a family member, is often enough to catch it the next time the phone rings.
Bank-impersonation follow-ups: the second act
A common second wave of the tech support script is a call from a person claiming to be your bank’s fraud department. Sometimes it arrives minutes after the first scam call, sometimes days later. The caller ID may even display the real name of your bank because caller ID can be faked.
The pitch shifts. There has been suspicious activity on your account, and to protect the funds, you need to move them into a “safe holding account” the caller will provide. Or you need to read out a one-time code the bank just texted you. Or you need to authorize a small test transaction through your online banking app.
Real banks do not ask you to move money to protect it. They do not ask for one-time codes over the phone. They do not need your password. The FTC has published consumer alerts on bank-impersonation scams and lists these three requests as unmistakable red flags.
The verify-first rule is simple. End the call politely. Look at your debit or credit card. Call the number printed on the card. Ask the bank if there is any real fraud alert on the account. In almost every case the answer is no, which confirms the earlier call was the fraud.
Payment channels the scam always steers you toward
The payment side of any tech support scam is where the loss becomes real. The FTC Consumer Sentinel data has ranked the same channels at the top of imposter fraud for years. Recognizing them by name breaks the script.
- Gift cards read over the phone. Apple, Google Play, Amazon, eBay, Target, Steam. No real refund, no real government office, and no real tech company will ever ask for a gift card as payment. This is documented in the FTC gift card scam guidance.
- Wire transfers. Same-day wires are hard to reverse and often gone within hours. A refund via wire is not how any real company issues a refund.
- Cryptocurrency ATMs. The caller directs you to a specific machine, gives you a QR code, and tells you to feed cash into it. The FTC has warned about cryptocurrency ATM abuse in scam scripts and treats it as an instant red flag.
- Cash courier at the door. A rideshare driver or hired stranger arrives to pick up an envelope. Do not open the door. Close, lock, call local police non-emergency, and then call your bank.
- Mailed cash to a hotel address. A courier or “safe deposit” instruction telling you to overnight cash to a specific address is the same fraud in envelope form.
The channel itself is the tell. If a caller is steering you toward any of these five, the request is fraudulent regardless of the story around it. That is true even if the caller says the word “bank” or “police” or “IRS” or the name of a company you recognize.
Cleaning up after remote access was granted
If a scammer had access to your computer, even for a few minutes, act as if the machine is compromised. Skipping this step is how single-loss victims become repeat-loss victims a week later.
- Disconnect the computer from the internet. Unplug the ethernet cable or turn off Wi-Fi from the router if you can. This prevents any hidden tool from talking to the scammer’s server.
- Uninstall the remote-access program. Look for AnyDesk, TeamViewer, LogMeIn, UltraViewer, Supremo, or anything installed in the last day you did not put there yourself. Remove them through the standard uninstall menu.
- Run a full antivirus scan from a trusted product already installed on the machine. Do not download new “security” software the scammer suggested. If in doubt, take the computer to a local repair shop and explain what happened.
- Change every password used on that computer from a different, uncompromised device. Bank, email, retirement broker, Social Security online account. Prioritize email first, since a stolen email account unlocks the rest.
- Turn on two-factor authentication for every account that supports it, using a phone app or a hardware key. Text-message codes are better than nothing but weaker than an app-based code.
- Freeze credit at all three bureaus. Equifax, Experian, TransUnion. A credit freeze is free, does not affect your existing accounts, and blocks new-account fraud. The FTC guide on what to do if you were scammed walks through the steps.
- Watch bank and retirement statements weekly for three months. Repeat scammers often wait a few weeks so the victim relaxes before the second attempt lands.
Reporting: the six-agency ladder
Reporting is not paperwork for its own sake. Each channel below feeds different investigators and may trigger a rapid recall on your specific case. The IC3 filing in particular has been credited by the FBI with recovering wires when the victim reported within the first 24 to 72 hours.
- Your bank fraud desk, same hour. Ask for a wire recall, ACH reversal, or stop payment. If gift cards were purchased, contact the issuer fraud line printed on the back of the card. Some issuers can freeze unspent balances.
- reportfraud.ftc.gov, same day. The FTC report feeds Consumer Sentinel, the shared database used by federal and state law enforcement across the country.
- ic3.gov, same day. IC3 coordinates wire recalls with domestic banks through its Recovery Asset Team and shares case data with FBI field offices in the state of loss.
- Your state Attorney General consumer protection division. Every state has one, and many run rapid-response elder fraud units. State-level cases often trigger a faster local response than federal channels alone.
- Adult Protective Services, if a vulnerable adult was targeted. APS can open a case and coordinate with other agencies if there is a pattern of repeat calls or in-person visits. Find your state APS through the National Adult Protective Services Association or the federal Eldercare Locator.
- SSA Office of the Inspector General, if the caller mentioned Social Security or asked for your Social Security number. Reports go to oig.ssa.gov and feed a separate investigative track for Social Security impersonation.
AARP’s Fraud Watch Helpline at 1-877-908-3360 is available to any US resident regardless of AARP membership. A trained volunteer can walk through the reporting steps at a slower pace and answer questions in real time. This helpline is often the least stressful first phone call after a scam.
Be alert for a follow-up recovery scam in the weeks after any loss. The most common second-wave pattern is a caller claiming to be a lawyer, federal agent, or private asset-recovery firm who can pull the money back for a fee. The FTC, the FBI, and multiple state AGs have all warned publicly that this second wave targets the same victim list. No real government agency asks for payment to help recover fraud losses.
Family conversation guide, without condescension
Adult children often struggle with tone when they want to protect an older parent from scam calls. The wrong framing lands as “we think you cannot handle this.” The right framing lands as “this happens to everyone your age and we want a shared plan.”
- Open with a specific fact from a government source. “The FTC just published another alert on tech support scams.” Specific facts feel like information, not nagging.
- Suggest a household rule that applies to everyone, not one person. “Nobody in the family installs anything on a caller’s instruction. If a screen locks, power off and call me.”
- Print the mid-crisis checklist and tape it near the computer and the landline. Under pressure, printed text works better than memorized rules.
- Set a “call me first” rule for any request above a set dollar amount, no matter who is calling. Frame the rule as protection for the family, not doubt about one person.
- Practice the response once out loud. Rehearsed sentences survive adrenaline. Cold-recall sentences usually do not.
Falling for a tech support script is not a sign of decline or naivety. The scripts are written and tested by paid teams that run thousands of calls to refine the wording. Anyone who cares about their savings and their family reputation is the target audience by design. Treat this topic the same way you would treat a home fire drill.
FAQ
Will Microsoft or Apple ever call me about my computer?
No. Neither company initiates unsolicited phone calls to home users about viruses, breaches, or software problems. The FTC explicitly warns against this scenario in its tech support scam guidance. Any call claiming otherwise is a scam regardless of what the caller ID shows.
The pop-up locked my browser. Did I get a virus?
Almost never. A browser-lock pop-up is a web page designed to seem like a system alert. Closing the browser through Task Manager or Force Quit ends it. If you had not clicked “install” on anything before the pop-up appeared, the machine is generally clean once the browser is closed.
I gave the caller a remote-access code. What do I do first?
Power off the computer, then follow the cleanup checklist on this page. Change your bank and email passwords from a different device. Call your bank fraud desk immediately, since the scammer may have already tried a transfer. File at reportfraud.ftc.gov and ic3.gov the same day.
Can I get my money back if I already sent gift cards?
Sometimes, if you act inside the first hour. Call the card issuer fraud line printed on the back of the card and ask them to freeze the balance. Some issuers can lock unspent value. Also file at reportfraud.ftc.gov and keep the physical cards and receipts as evidence.
The caller ID showed my bank’s real name. Isn’t that proof?
No. Caller ID spoofing is a known scam technique. Scammers can display any name or number on your screen, including a bank you actually use. Always hang up and call back on the number printed on your card, not the number on the caller ID screen.
Where does this scam intersect with investment fraud?
The manufactured-urgency architecture is the same across many elder fraud scripts: a fake authority, a synthetic emergency, and a fast payment channel that cannot be reversed. If a caller has pushed you toward gold, precious metals, or a “safe haven” purchase with the same pressure, treat it as the same category of fraud. See the OPRS recovery playbook for gold IRA scam victims for the parallel investment-side steps.
Sources cited
- FTC Consumer Advice, How To Spot, Avoid, and Report Tech Support Scams
- FTC Consumer Advice, How To Avoid a Scam
- FTC Consumer Advice, What To Do If You Were Scammed
- FTC Consumer Advice, Avoiding and Reporting Gift Card Scams
- FTC Consumer Advice, What To Know About Cryptocurrency and Scams
- FTC Consumer Advice, How To Recognize and Avoid Phishing Scams
- FTC Pass It On, Impersonator Scams (educational materials)
- FTC Consumer Alerts Archive
- Federal Trade Commission, Report Fraud Portal
- FBI Internet Crime Complaint Center (IC3)
- FBI IC3 Elder Fraud Report (2024)
- FBI IC3 Internet Crime Report (2024)
- Social Security Administration Office of the Inspector General
- SSA OIG, Report Social Security Fraud, Waste, or Abuse
- Consumer Financial Protection Bureau, Fraud and Scams
- US Department of Justice, Elder Justice Initiative
- National Center on Elder Abuse (federally funded, ACL)
- Administration for Community Living, Eldercare Locator
- National Adult Protective Services Association, Find Local APS
- AARP Fraud Watch Helpline (1-877-908-3360)
More on OPRS
- The grandparent scam: emergency-call script decoded
- Social Security impersonation scams: what to know
- Medicare scams during open enrollment
- Recovery-room scams: the second wave after a loss
- How to report elder financial fraud
- Recovery playbook for gold IRA scam victims
