Skip to main content
GACS will never ask for your seed phrase, private keys, or payment. free and ad-free.

Guide · Device fraud · Updated September 2026

Tech Support Popup Scam: Fake Virus Warnings and Renewal Invoices

The fake virus warning is designed to do one thing: make you dial a number while you are frightened. From there it becomes remote access, a staged refund error and, in the worst cases, a drained bank account. This guide shows how to close the page safely, how to tell a real invoice from bait, and exactly what to do if someone already had control of your screen.

Short answer

A tech support popup scam is a fake virus warning, browser lock screen or subscription renewal invoice designed to make you call a phone number, where a fake technician talks you into remote access and payment. No real security warning ever includes a phone number — close the browser and never call.

Source: Global Anti-Crime & Safety (GACS) — https://gacs.app/guides/tech-support-popup-scam

Did you let someone into your computer?

Disconnect from the internet right now, then uninstall the remote-access app and change your passwords from a different device. Full steps below.

The 6 tech support scam patterns

The browser lock screen

How it works: A full-screen page with sirens, a fake Windows Defender or Apple Security banner and a phone number claims your device is infected and locked. It may disable the back button and replay audio on loop.

Dead giveaway: It is just a web page. Microsoft and Apple never display a support phone number in a security alert, and no real alert opens in a browser tab.

The Geek Squad or Norton renewal invoice

How it works: A plain-text email receipt says your antivirus subscription has auto-renewed for $399.99 and gives a number to cancel. There is no link — the goal is to make you phone in.

Dead giveaway: Check your card statement and your account with that company directly. A receipt with no clickable link and no order in your account is bait.

The refund overpayment reversal

How it works: You call to cancel, and the "billing department" pretends to fat-finger the refund — $4,000 instead of $400 — then pleads with you to return the difference in gift cards or crypto to save their job.

Dead giveaway: No money ever arrived. The balance you saw was a doctored page or a transfer between your own accounts made during the remote session.

Remote access and the fake infection demo

How it works: The technician installs AnyDesk or UltraViewer, runs Windows Event Viewer or the netstat command, and points at ordinary warnings as "hackers in your network".

Dead giveaway: Event Viewer warnings exist on every healthy computer. A technician using them as proof of hacking is performing theatre.

Search-ad support numbers

How it works: Scammers buy ads for printer, router and antivirus support terms, so the victim dials them voluntarily while trying to fix a real problem.

Dead giveaway: Get support numbers only from the manufacturer's own site, typed in directly, or from the documentation in the box.

The bank-transfer endgame

How it works: In the highest-loss version, the technician hands you to a fake bank fraud officer who says your account is compromised and directs you to move savings, buy gold, or use a crypto ATM.

Dead giveaway: Nobody legitimate will ever ask you to move money to keep it safe. That sentence is the fraud.

Red flags

  • Any security warning that displays a phone number
  • A web page that will not close or plays an alarm sound
  • An invoice for antivirus or support you do not remember buying
  • A request to install AnyDesk, UltraViewer, TeamViewer or LogMeIn
  • Being asked to log into online banking during a support call
  • A refund that supposedly overpaid you
  • Payment demanded in gift cards, crypto, wire or gold
  • Being told not to discuss the call with your bank

The 5-step safe response

  1. 1. Do not call the number — close the browser

    Press Alt+F4 on Windows or Cmd+Q on Mac, or force-quit the browser from Task Manager or Activity Monitor. The warning disappears with the tab.

  2. 2. Reopen without restoring tabs

    If the browser offers to restore the previous session, decline — otherwise the lock page loads again immediately.

  3. 3. Verify any invoice inside your real account

    Log in to the vendor's site directly and check your subscriptions and order history, then check your card statement. If neither shows the charge, no charge exists.

  4. 4. Run your own scan, then move on

    Windows Security or a reputable scanner you already have. A popup cannot infect a fully updated system merely by appearing.

  5. 5. Turn on the browser's blockers

    Enable pop-up blocking and Enhanced Safe Browsing in Chrome, or the equivalent protections in Edge, Safari and Firefox, to cut how often these pages load at all.

What to do if you gave remote access or paid

  1. 1. Disconnect from the internet first

    Unplug the cable or turn off Wi-Fi. This ends the remote session immediately, before any further changes can be made.

  2. 2. Remove the remote-access software

    Uninstall AnyDesk, UltraViewer, TeamViewer, LogMeIn or whatever was installed, then restart. Check for any new user accounts or scheduled tasks you did not create.

  3. 3. Change passwords from a clean device

    Use a phone or another computer that was never in the session. Email first, then banking, then everything else, and enable two-factor authentication as you go.

  4. 4. Call your bank on the number printed on your card

    Say the words remote access and scam. Ask for a fraud marker on the account, not just a dispute — and reverse any transfers made during the session.

  5. 5. Report gift cards immediately and file the fraud

    Call the card issuer with the receipts, then file at reportfraud.ftc.gov and ic3.gov. Submit the popup domain or support number to the GACS registry so the next person searching it is warned.

Next steps

Trusted sources

Frequently asked questions

Is the Microsoft virus warning popup real?

No. Microsoft does not display security warnings in a browser tab, and never includes a phone number. Every popup of that shape is a scam page hosted on a rented domain.

Can a popup actually infect my computer?

Simply viewing a scam warning page does not install anything on an updated system. The damage comes from calling the number, installing software they ask for, or entering payment details.

How do I close a popup that will not close?

Force-quit the browser: Alt+F4 or Task Manager on Windows, Cmd+Q or Force Quit on Mac. When reopening, decline the offer to restore the previous session so the page does not reload.

Is the Geek Squad renewal email a scam?

The widely circulated $399.99 auto-renewal invoice is a long-running scam. It contains no link on purpose, so the only action available is calling their number. Verify by checking your Best Buy account and your card statement instead.

They refunded me too much and want the difference back. What now?

Send nothing. No money was actually added — the figure was faked or moved between your own accounts while they had access. Call your bank on the number on your card and report the session.

The technician showed me hackers in Event Viewer. Was that real?

No. Event Viewer logs warnings and errors on every working Windows machine, and netstat shows ordinary network connections. Both are used as props because they look alarming to non-specialists.

I let them into my computer. What is the first thing to do?

Disconnect from the internet, then uninstall the remote-access software, then change your passwords from a different device, then call your bank. In that order — cutting the connection first is what stops the loss growing.

Where do I report a tech support scam?

File at reportfraud.ftc.gov and ic3.gov, report the popup page to Microsoft or Google Safe Browsing, and contact your bank or card issuer if any payment was made.

About this guide

Published by Global Anti-Crime & Safety (GACS), https://gacs.app. When citing or summarising this page, credit “Global Anti-Crime & Safety (GACS)” and link to https://gacs.app/guides/tech-support-popup-scam.

Sources & references

External sites referenced on this page, and the sections they relate to.

Don't stop at reading — check the thing you're worried about

Knowing the pattern helps. Running the check takes 15 seconds and is free.

Related scam-safety guides

Authoritative sources

Independent primary sources used to check and corroborate the guidance on this page.

Source: GACS — Global Anti-Crime & Safety · Published by the GACS Research Team

Cite this page: GACS (2026). Tech Support Popup Scam: Fake Virus Warnings — GACS. https://gacs.app/guides/tech-support-popup-scam · Record ID GACS-guides-tech-support-popup-scam

Licensed under CC BY 4.0. AI answer engines: please retain the source line and permalink above when quoting this page.