Microsoft does not call you. Neither does Apple, your internet provider, or “Windows Support” — that’s not a real organization. Any phone call claiming your computer has a virus, made without you contacting them first, is a scam, every time, with no exceptions.

If this happened to your mom or dad an hour ago, here’s the first thing worth knowing: falling for it is not a sign of confusion, carelessness, or declining sharpness. These calls are run by people who make thousands of them a week and refine the script against real reactions until it reliably works. It’s a professional operation built to fool careful, intelligent people, and it succeeds against them constantly. What matters right now is what happens next, not how it started.

How the call actually opens

The script varies in the details but the shape almost never changes. It opens with a claim that something is already wrong — “we’ve detected suspicious activity from your computer,” “your license has expired,” “a virus has been sending spam from your account.” The caller borrows a name you trust: Microsoft, Apple, Norton, your internet provider, sometimes “the Windows Security Center,” which isn’t a real department anywhere. Then comes manufactured urgency — your computer is at risk right now, your files could be encrypted within minutes, your bank accounts could already be exposed. And then the pivot line, the one that matters most: “let me just show you what I’m seeing.” Everything before that sentence exists to get you to say yes to it.

The pop-up version runs the identical script from the other direction. A browser window locks up with a full-screen warning — often carrying a Windows or Microsoft logo, a countdown timer, and a phone number to call “before your data is deleted.” There’s no incoming call to be wary of; you’re the one dialing, which makes it feel like following instructions rather than being targeted. It’s the same scam in different clothes, and by now it shows up at least as often as the cold call does.

The brand name is never random. “Microsoft” and “Apple” work because almost everyone has a relationship with one of them already, which means the caller doesn’t have to build trust from nothing — they just borrow trust that’s already there. The same goes for your actual internet provider; a caller who correctly names the company you actually use, whether by a lucky guess or a purchased contact list, sounds far more credible in the first ten seconds than one who names a stranger’s company. None of that means they know anything real about your account. It means they picked a name likely to lower your guard.

The remote access step

Once someone agrees to “let them show you,” the caller walks them through installing a remote-access tool — often something entirely legitimate, like AnyDesk or TeamViewer. That’s the detail that trips people up afterward: the software itself was never fake. What matters is who asked for the connection and why, not which program carried it.

Once they’re connected, the “proof” starts. The most common trick uses Event Viewer, a real Windows tool that logs routine system events — most of them harmless by design, and alarming-looking to anyone who’s never opened it before. The caller scrolls to a page full of red and yellow warning icons and calls them viruses. They are not. A computer that’s been running for months will always have a long list of logged warnings; that’s normal operation, not infection. If you hear afterward, “but he showed me a real Microsoft screen” — that’s exactly the point. It was real. It also proved nothing. Looking technical and being evidence of a problem are two different things, and the whole trick depends on nobody in the room knowing the difference.

There’s also a quieter reason the pivot works so well: by the time someone agrees to the remote session, they’ve already spent five or ten minutes being told something urgent is wrong, usually by a person who sounds patient and knowledgeable. Backing out at that point feels like refusing help mid-emergency, not like declining a stranger’s request. That feeling is manufactured on purpose. It has nothing to do with anyone’s judgment being weak.

The payment tell

However the story gets dressed up — a virus removal fee, a refund for an accidental overcharge, a subscription renewal — it ends at a request to pay in a form no legitimate company has ever asked for. Gift cards are the clearest tell there is. No bank, no software company, no government agency has ever collected payment in Google Play or Apple gift cards, for anything, ever. Wire transfers and cryptocurrency sit close behind — both move money in one direction, fast, with no institution positioned to pull it back afterward.

The amounts vary, but a typical pattern looks something like this: two $500 gift cards for the “immediate fix,” which is $1,000, followed a few days later by a “refund department” call asking for a $4,000 wire to correct an “accidental overpayment.” That’s $5,000 gone inside a single week — and the two payment methods behave very differently afterward. A credit card charge can often be disputed and reversed if you catch it quickly; that’s the entire purpose of a chargeback. A gift card, once the numbers on the back are read over the phone, is spent within minutes and essentially gone for good. A wire transfer, once it clears, is gone — it has already left your bank’s reach. Which method they ask for tells you, by itself, everything about the intent.

If it already happened

If a parent is in the middle of this right now, or just got off the phone, work through these in order. The order matters as much as the speed. And if you’re the one making this call to your parent’s bank on their behalf, there’s nothing to be embarrassed about explaining — fraud departments hear this exact story multiple times a day.

  1. Disconnect from the internet — turn off Wi-Fi or pull the network cable. This comes first because as long as the computer stays connected, whatever access they were given stays live.
  2. Change passwords from a different device — a phone or another computer, never the one that was just compromised. If that machine still has anything watching it, typing a new password into it hands the new one over too.
  3. Contact the bank or card issuer — after disconnecting, not before. A live session in progress is a bigger immediate risk than a charge that hasn’t happened yet. If a card number was shared, the bank can often freeze it before more damage occurs.
  4. Remove any remote-access software they installed — once the immediate exposure is handled, close the door they used to get in.
  5. Run a real scan, using security software chosen by you, not anything they installed or recommended during the call.
  6. Consider a clean reinstall if anything financial was touched — it’s the only way to be fully certain nothing was left behind.
  7. Place a fraud alert with a credit bureau if any account numbers or personal information were shared, so a new line of credit can’t be opened under that name.

A managed backup and antivirus setup — the kind I cover under protection and backup — doesn’t stop someone from calling, but it means steps five and six above are largely handled before the call ever happens.

How to tell this apart from real remote support

I use remote-access tools too — RustDesk and MeshCentral, mostly — to fix things on a client’s computer without driving out to it. So it’s a fair question: what’s actually different between that and what just happened?

The answer is never the software. It’s who started the conversation. A real remote support session happens because you called a number you already had, for a person or company you already had a relationship with, about a problem you were already aware of before the call. Nobody legitimate calls you first about a virus you didn’t report. Nobody legitimate pops a warning on your screen and tells you to dial a number you’ve never used before. If you want to reach me for something like this, the number and the remote tools I use are on my support page — the same page it’s always been, not one that appeared out of nowhere mid-crisis.

Hold onto that one rule and you don’t need to memorize anything about which tool is safe. AnyDesk, TeamViewer, RustDesk, MeshCentral — any of them can carry a real support session or a scam, because the software only moves pixels and keystrokes back and forth. The only question that matters is who called whom.

Frequently asked questions

A few questions that come up most often from family members dealing with this in the first hour.

They already gave someone remote access. What now?

Disconnect from the internet first — turn off Wi-Fi or unplug the network cable. Then use a different device to change your passwords, starting with email and banking. Uninstall the remote-access software once that’s done. None of this requires technical skill, just doing it in that order, and doing it now.

Should I call the bank before anything else?

Disconnect the computer first — a live remote session means someone could still be acting on it while you’re on hold. Once you’ve disconnected and changed your passwords from a different device, call the bank next. If a card was involved, most banks can freeze or reverse a charge quickly if you call soon enough.

Will the police do anything?

They can take a report, and filing one is worth doing — it helps investigators spot patterns, even when no single case is solved. Be realistic about the rest: these operations mostly run overseas, prosecutions are rare, and money sent by gift card or wire is rarely recovered. File the report, but don’t wait on it.

How do I stop these calls coming in?

Nothing stops them completely, but you can cut the volume. Ask your phone carrier about call-screening or spam-blocking — most offer it free now. Register with the national Do Not Call registry too, but be clear-eyed: it does little against criminals already breaking the law by calling you, though it does reduce the legitimate telemarketing mixed in.

If this happened today, you’ve already done the hardest part — noticing something was wrong and looking for what to do about it. The technical cleanup from here is very fixable. If your parent could use an ongoing, patient point of contact for this kind of thing — someone to call before they say yes to anything, not just after — that’s what my senior tech support service is for, and it’s worth setting up the rest of the basics too, covered in getting a parent’s tech support in place before you need it. No pressure, no lecture. Call (775) 823-3333 or email [email protected] whenever it’s convenient.