Tech Support Scams in 2025–2026: Don’t Let a Fake Alert Take Control

Tech Support Scams in 2025–2026: Don’t Let a Fake Alert Take Control
Spidanest Team — October 05, 2026
A loud browser warning says your computer is infected. A caller claiming to represent Microsoft, Apple, Google, or another familiar company says your account has been compromised. The supposed technician offers to fix everything—if you call immediately or let them control your device.
That sequence is the foundation of a tech support scam. The warning may look professional, but its purpose is to move you from alarm to remote access before you can verify the story.
How the Scam Usually Begins
Fake browser pop-ups may imitate security software or a trusted technology company. Some take over the full screen, play alarming audio, or make the browser difficult to close, creating the impression that the entire device has been locked.
The message commonly claims that malware, a security breach, or a critical system failure has been detected. It then provides a phone number for “support.” According to the FTC, genuine security pop-ups do not tell consumers to call a phone number for help.
Other scams start with an unexpected call, email, or text. The person may claim to be a technician from a software provider, internet company, or security business and use technical language to make an invented problem sound credible.
The Remote-Access Progression
Once contact begins, the scammer typically asks the victim to install remote desktop or screen-sharing software. Scamwatch has identified tools such as AnyDesk, TeamViewer, and Zoho among the legitimate applications misused in remote-access scams.
The scammer may open ordinary system files, run a fake diagnostic, or display harmless technical information as “proof” of an infection. With remote control, the criminal can view files, observe activity, capture financial information, install malicious software, or manipulate what appears on the screen.
The final demand may be a fee for a worthless repair, security subscription, or unnecessary software. In more serious cases, the scammer directs the victim to open online banking or claims that money must be transferred to protect it from hackers.
Refunds, Renewals, and Other Current Variations
Not every tech support scam begins with a virus warning. Some messages claim that an antivirus product, software subscription, or support plan is about to renew. The victim is invited to call if the charge is incorrect, connecting directly to the scammers.
In a fake-refund variation, the caller says the victim is owed money for a previous service. After obtaining remote access, the scammer alters what the victim sees in online banking to make it appear that too much money was refunded. The victim is then pressured to “return” the difference.
The FBI has also warned about layered schemes in which supposed technicians are followed by people impersonating financial institutions or officials. The story escalates from a device problem to a claim that the victim’s savings are in danger, with instructions to move money into supposedly secure accounts.
The Scale of the Threat
The FBI’s IC3 reported 36,002 tech support scam complaints in 2024, with reported losses of $1,464,755,976. Across all internet crime categories, IC3 received 859,532 complaints and recorded $16.6 billion in reported losses that year.
Those figures represent reports made to the FBI and should not be treated as a complete count of every incident. FTC data uses a different consumer-reporting system, so figures from the two agencies measure different reporting populations rather than providing directly interchangeable totals.
Regulators have also responded to the way these scams generate incoming calls. In November 2024, the FTC finalized amendments extending Telemarketing Sales Rule protections to inbound calls for technical support services.
Older Adults and Small Businesses Face Particular Risks
The FBI says call-center fraud, including tech support fraud, disproportionately targets older adults. Persistent callers may exploit uncertainty about unfamiliar technical messages and then escalate toward retirement accounts, cryptocurrency, cash, or precious metals.
Family members can help without taking away someone’s independence. Agree in advance that unexpected technical warnings, remote-access requests, and instructions to move money will be checked with a trusted person before action is taken.
Small businesses face a related operational risk. A remote session on a work computer can expose email, financial accounts, customer information, and business files. Owners and employees should know which support providers are authorized and refuse unexpected access requests, even when a caller knows the company’s name.
Red Flags That Mean “Stop”
- A pop-up displays a phone number and demands an immediate call.
- An unexpected caller claims to have detected a virus or account problem.
- Someone asks you to install remote-control or screen-sharing software.
- The “technician” wants you to sign in to online banking while connected.
- A caller claims a subscription renewed and offers an immediate refund.
- You are told to move money to a “safe” or “secure” account.
- Payment is requested through gift cards, cryptocurrency, wire transfer, cash, or precious metals.
- The caller becomes threatening or says you must keep the situation secret.
How to Protect Your Home or Business
Do not call a number shown in an unexpected pop-up, and do not click its buttons. If the browser will not close normally, use Windows Task Manager or Mac Activity Monitor to force it to quit, or restart the device.
Hang up on unsolicited technical-support calls. If you are concerned about a real problem, contact a trusted technician or find the company’s support details independently rather than using information supplied by the caller or warning.
Keep operating systems and security software updated, and use multi-factor authentication where available. Small businesses should make their authorized support process clear to every employee, including who may approve remote access.
What to Do After Granting Access
Act quickly, but do not continue following the caller’s instructions.
- Disconnect the affected device from the internet to end the remote session.
- Remove any remote-access software you were instructed to install.
- Use trusted security software to scan the device.
- From another trusted device, change passwords for email, banking, business, government, and social accounts.
- Contact your bank or card provider immediately if information was exposed or money moved.
- Report the incident to the FTC and the FBI’s IC3, including phone numbers, websites, payment details, and transaction records.
Do not be embarrassed into remaining silent. Reporting attempted scams as well as completed losses helps authorities identify patterns and warn other potential victims.
Paste any suspicious message into Spidanest.ai for a free instant AI scam check.
Sources
View all references
- Federal Bureau of Investigation, Internet Crime Complaint Center. Internet Crime Report 2024.
- Federal Trade Commission. How to Spot, Avoid, and Report Tech Support Scams.
- Federal Trade Commission. FTC Finalizes Amendments to Telemarketing Sales Rule Extending Protections to Consumers in Inbound Telemarketing Calls for Technical Support Services.
- Australian Competition and Consumer Commission, Scamwatch. Remote Access Scams.
Not sure if a message is a scam?
Paste a suspicious link, text, or email into Spidanest and get an instant AI threat assessment — free.
Scan it now