Hang up. Microsoft, Apple, Google, your ISP, and the FTC do not cold-call a U.S. household to say a virus was found and then ask for remote access, gift cards, a wire, or crypto. Microsoft says it does not make unsolicited support calls, and real Microsoft error messages never include a phone number. The FTC says legitimate tech companies will not contact you by phone, email, or text to report a computer problem, and real security pop-ups never ask you to call a number. If you already let someone in, unplug Ethernet or turn off Wi-Fi, uninstall the remote-access app they had you install, change email and bank passwords from a different device, and run a full Windows Security scan. Elders should call a trusted family member before calling any number on a pop-up. This is a phone-and-remote-access scam, not ransomware.
Hang up on unsolicited Microsoft, Apple, and ISP virus calls
A real support team does not dial your landline or cell to announce a virus, then walk you into AnyDesk, TeamViewer, or Quick Assist.
- End the call. Do not press a keypad number to “speak to an agent.”
- Do not call back a number from caller ID, a pop-up, or a text. Caller ID is easy to spoof.
- If a full-screen “Windows locked” page will not close, hold the power button or use Task Manager. Then close the browser. That page is not Windows.
- Tell the household rule out loud: nobody here grants remote access to a stranger who called us.
- If a parent or grandparent is still on the line, walk over or call them on a second phone and ask them to hang up.
Microsoft’s own warning is blunt: if you receive an unsolicited call from someone claiming to be Microsoft Support, hang up. The FTC adds a second tell: scammers often demand gift cards, a wire, a bank transfer, cryptocurrency, or a payment app because those are hard to reverse.
What to do if you already gave remote access
Disconnect first. Closing the chat window is not enough if they installed a tool that can reconnect.
- Unplug the Ethernet cable or turn off Wi-Fi so the session dies.
- Uninstall every app the caller had you download. Microsoft’s recovery note starts here: remove the applications scammers asked you to install.
- From a phone or a different computer, change the email password first, then banking, Apple or Google, and any reused passwords. Turn on multi-factor authentication.
- Call the bank or card issuer using the number on the card if you typed a password, read a code, or paid. Ask them to watch wires, Zelle, and new payees.
- Reconnect, update Windows, and run a full scan in Windows Security. Defender is enough for this pass — see Is Microsoft Defender enough?.
- If fake error loops will not stop, use Windows recovery or a reset. Microsoft says a reset can be the cleanest option after a remote-access “fix.”
- If you need a wipe checklist after malware, use 9 steps to clean a virus-infected Windows PC. Do not run Malwarebytes real-time protection at the same time as Defender real-time.
A later caller who already knows your name, the tool they used, or the amount you paid is the same crew. Hang up again.
Real support vs a tech-support scam
Use this table when a parent asks “but they knew my name.”
| Signal | Real support you asked for | Scam cold call or pop-up |
|---|---|---|
| Who started it | You opened the official site or app and requested help | They called you, or a web page told you to call |
| Phone number in an error | Microsoft error and warning messages never include a phone number | A lock screen or “virus found” page shows a toll-free number |
| Remote access | Only after you started the case on a site you typed yourself | They rush you to install a remote tool “to scan for viruses” |
| Payment | A receipt inside an account you already have | Gift cards, wire, crypto, or a “refund” they need you to send back |
| Government handoff | Does not happen | They “transfer you to the FTC / FBI” and tell you to move money to protect it |
The FTC is explicit: it will never threaten you, say you must transfer money to “protect it,” or tell you to withdraw cash or buy gold and give it to someone. Badge numbers and case numbers on that call are fake. Fake “Geek Squad / Norton / McAfee subscription renewal” texts that demand you call in 24 hours are the same family of scam — check the real statement, then call the company from a number you already have. For pop-up forensics, see 8 ways to tell a virus warning popup is fake.
After you paid or shared a password
Change the password on a clean device, then report the contact even if you feel embarrassed.
- Change every password you typed or reused, starting with email.
- If you paid by card, call the issuer and contest the charge. Microsoft tells people to do exactly that and to replace the card.
- If you paid with gift cards, wire, or crypto, tell the issuer or the gift-card company anyway. Recovery is harder; still report it.
- Report the call at ReportFraud.ftc.gov and, if they claimed to be Microsoft, at microsoft.com/reportascam.
- Watch for a “refund department” follow-up. That is a second scam.
Talk through how to spot a phishing email with anyone in the house who almost stayed on the line.
FAQ
What should I do if I get a Microsoft tech support scam call?
Hang up. Microsoft does not make unsolicited calls to fix your PC. Do not install remote-access software or read a one-time code to the caller.
Is a pop-up that says call Microsoft about a virus real?
No. Microsoft says error and warning messages never include a phone number. Close the browser or restart the PC. See 8 ways to tell a virus warning popup is fake.
What if I already let them remote into my computer?
Disconnect from the internet, uninstall the remote tool, change email and bank passwords from another device, run a full Defender scan, and call your bank if you typed financial information.
Do I need to buy new antivirus after a tech support scam?
Not automatically. Microsoft’s steps are uninstall their apps, consider a reset, and run Windows Security. Paid extra software is optional and never something the caller sells you.
If you want extra scanning after a real intrusion
Buy-nothing is valid. If the PC was actually remote-controlled and you want a second on-demand scan after Defender, use only these on-site pages: TotalAV, Norton, or Bitdefender. Do not run a second real-time antivirus next to Defender. Skip cold-call “McAfee renewal” and “Avast support” numbers; if you already use those brands, the on-site pages are McAfee and Avast.