It arrives the same way every time. Your screen fills with a warning in Microsoft or Apple colours, an alarm noise starts, and a phone number appears with instructions to call immediately. Sometimes it shows your real IP address or browser name to look convincing.
None of it is real. The page has not scanned anything and has not found anything. But it is built to panic you, and it does its best to stop you leaving — so the way out is worth knowing cold.
The one rule that settles it
A genuine Microsoft or Apple error message never contains a phone number. Not ever. If there is a number on the screen, the screen is lying to you. Neither company will contact you unprompted about a problem with your computer either.
What to do right now
- Do not call the number. That is the entire attack. Everything else is theatre designed to get you to dial.
- Get out of full screen. These pages use the browser's own full-screen mode to hide your close buttons and taskbar, which is what makes the machine feel taken over. Press and hold Esc for a few seconds, or press F11 on Windows, Cmd+Ctrl+F on a Mac. When the toolbar reappears, close the tab with Ctrl+W (Cmd+W).
- If the page still will not let go, force the browser to quit: Ctrl+Shift+Esc on Windows and end the browser task, or Cmd+Option+Esc on a Mac and force quit it.
- Reopen the browser and decline to restore tabs. Restoring brings the scam page straight back.
- Clear the browser's cache and history so the page cannot reappear later from a half-typed address.
For most people that is the whole event. Nothing was installed and nothing was scanned; your computer is as healthy as it was ten minutes ago. If you want certainty anyway, work through the virus checklist.
How the page reached your screen
These pop-ups are ordinary web pages, and mostly they arrive through advertising. Scammers buy ad space like any other advertiser, show the ad network a harmless page during review, then swap in the scam for real visitors — the trade calls it cloaking. That is why the warning can appear while you are on a perfectly legitimate site: the site sold an ad slot, and the ad slot sold you. Mistyped addresses and links in junk email are the other common doors — the same instincts as spotting a phishing email apply.
The personal details on the page — your IP address, browser, sometimes your town — are visible to every website you visit. Showing them proves nothing.
What happens if you dial
The people who answer are practised, calm and patient, and the script barely varies:
- They ask to connect to your computer to "diagnose the problem", using a remote access tool such as TeamViewer, AnyDesk or LogMeIn.
- They open ordinary Windows screens — Event Viewer, a folder of temporary files — and read the routine entries out as infections and foreign intrusions.
- Then comes payment, and here is the tell: they want gift cards, a wire transfer or cryptocurrency, because those cannot be pulled back. Victims are kept on the phone while they drive to a store, told to buy Apple or Google Play cards, and coached to lie to the cashier — "say they're for a grandchild's birthday" — because cashiers are trained to ask.
- A common variation is the fake refund: they "deposit" too much into your account — a bank page edited live in your own browser — then insist, with mounting distress, that you return the difference. The extra money never existed. Yours does.
None of it means anything. No legitimate company takes payment in gift cards — one sentence that ends this scam and several of its cousins.
If you already called
Not hopeless. Work through it in order:
- If you let them connect, disconnect the computer from the internet now. The remote tool they installed is still there after they hang up and lets them return at will. Uninstall it — Settings, then Apps on Windows; the Applications folder on a Mac — and check the installed-programs list and startup items for anything added that day. If you are not sure you found everything, treat the machine as compromised and have it properly swept rather than hoping.
- If you paid, call your bank or card issuer now — the fraud number printed on the back of the card, never a number from an email. The script: "I was the victim of a tech support scam. I authorised a payment under false pretences on this date. I want to dispute the charge, cancel the card and have it reissued." Card payments are often reversible, transfers sometimes if you are quick. Gift cards and crypto rarely come back — report them to the issuing company anyway; occasionally a card is frozen before it is drained.
- If you typed a password while they were connected, change it from a different device, starting with your email — email is the master key to everything else. If they had time in your inbox, follow the first-hour checklist for a hacked email account.
- Turn on two-factor authentication for email and banking. It is what makes a stolen password nearly worthless.
- If they saw your Social Security number or bank details, freeze your credit. Freezes are free by federal law at all three bureaus — Equifax, Experian and TransUnion, each placed separately — and they stop new accounts being opened in your name. Lifting one later takes minutes.
Report it, even if you lost nothing
Tell the FTC at reportfraud.ftc.gov — it takes a few minutes. A single report feels pointless; in aggregate they are how these operations get traced and shut down. If money moved, the report also gives your bank's fraud team something official to attach to the case.
If it landed on a parent's screen
These operations aim squarely at older adults, and it works: in the FTC's December 2025 report to Congress, people over 60 reported $159 million lost to tech support scams in 2024, and the agency's 2022 age analysis found them about five times more likely than younger adults to report losing money to one. That is not because older people are foolish. The scam imitates how real support worked for decades — a phone call, and a patient, technical-sounding man talking you through screens.
So if a parent met one of these pages, skip every version of "how could you fall for that". Shame is the scammer's best friend — it is the main reason this goes unreported. What helps: the one rule above, an agreement that they call you before calling any number a screen shows them, and turning on their browser's pop-up and notification blocking to close the doors it usually arrives through.
When you want the machine checked by someone real
If the pop-up was the whole event, you need nothing more. If someone connected to your computer, an hour of expert time is worth it — remote tools removed, startup checked, passwords sorted. Post what happened, free and in your own words, at Koadi's post-a-problem page; set a fixed price or take bids, and a vetted, identity-verified technician picks it up — remotely anywhere in the US, evenings and weekends included, or on-site through a local tech. Payment sits in escrow until you approve the work, and you watch everything the technician does. After this particular scam, that is exactly the arrangement you want.