Knowledge · Guides & Articles · Guide

Fake Tech-Support Pop-Ups and Calls: What to Do (and Not Do)

A blaring browser pop-up says your PC is infected and gives you a number to call — or someone calls claiming to be Microsoft. Here's how to tell it's fake and shut it down safely.

Cybersecurity 5 min read Updated 2026-07-22

Fake Tech-Support Pop-Ups and Calls: What to Do (and Not Do)

Two versions of the same scam show up constantly: a full-screen browser pop-up that locks up your screen with a siren sound and a warning that your computer is infected, giving you a phone number to call — or a phone call out of nowhere from someone claiming to be “Microsoft,” “Windows Support,” or your internet provider, saying they’ve detected a problem with your PC. Both are trying to do the same thing: scare you into handing over remote access to your computer, your money, or both. Neither Microsoft, Apple, nor your internet provider will ever contact you first about a problem with your device, and no legitimate security software locks your screen and demands a phone call.

How to recognize it

What real companies actually do

Microsoft, Apple, your internet or cable provider, and legitimate antivirus companies do not cold-call you about a virus on your computer, and they do not put a phone number in a browser pop-up. If your real antivirus software has something to tell you, it shows up as a normal notification inside the program you already have installed — not a full-screen browser takeover with a phone number.

If you get the pop-up

  1. Do not call the number. Do not click anything inside the pop-up, including buttons that say “Cancel” or “Close” — on some of these, even the X can trigger something. It’s just a web page dressed up to look scary.
  2. Close the browser the hard way. On Windows, press Ctrl + Shift + Esc to open Task Manager, find your browser (Chrome, Edge, Firefox), and click End Task. On a Mac, press Cmd + Option + Esc, select the browser, and choose Force Quit.
  3. Reopen the browser without restoring your tabs. If it asks to reopen your previous session, decline — that pop-up tab is what you’re leaving behind.
  4. Nothing was actually installed just from seeing the page. A pop-up alone doesn’t infect your computer. You’re safe once the browser is closed, as long as you didn’t call, click through, or download anything from it.

If you already called the number or let someone connect

This is the part that matters most, and there’s no shame in it — these are professionally run scams designed to work on smart, careful people. Move through this in order:

  1. Disconnect the device from the internet (turn off Wi-Fi, or unplug the network cable) to cut off any active remote connection right away.
  2. Uninstall any remote-access software they had you install (AnyDesk, TeamViewer, etc.) through your normal Settings/Control Panel apps list.
  3. Change your passwords — starting with email and banking — from a different, clean device, not the one that was connected. If you reused that password anywhere else, change it there too.
  4. Check your bank and card statements for any charge you didn’t expect, and call your bank directly (the number on the back of your card, never one given to you during the call) if you see one or if you gave out card details.
  5. If you gave them remote control of the machine, treat it as compromised. Don’t just run a quick scan and call it done — have the device professionally checked before you trust it again with anything sensitive.
  6. Turn on two-factor authentication on your important accounts if it isn’t on already, so a stolen password alone isn’t enough to get in.

Protecting yourself going forward

If you’re ever unsure whether something you saw or clicked was real, our Scam Check tool can give you a quick read on a suspicious message, or just call us — checking is free, and it’s a lot cheaper than finding out the hard way.

⚠ Safety note: Never call a phone number from a pop-up, and never let someone you didn't contact first install remote-access software on your computer. If you already did, treat the device as compromised — see the recovery steps below, and call a shop you already trust.

← Back to the Knowledge hub