Tech Support Scams

Overview

Tech support scams use a false or exaggerated computer problem to obtain money, account information, or remote access to a device. The scammer may pretend to represent Microsoft, Apple, an internet service provider, a security company, a bank, a government agency, a familiar local business, or a university support office.

The contact may begin with a pop-up, unsolicited phone call, email, text message, online advertisement, fake invoice, search result, or message claiming that an account or device has been compromised. The warning may look technical and urgent, but the goal is to make you contact the scammer or follow instructions before you verify the claim.

Legitimate support may use remote-access tools when you initiate a verified support session and understand what access is being granted. The risk comes from allowing an unverified person to control the device or from trusting support contact information supplied by the same unexpected warning.

How It Works

A tech support scam may follow these steps:

  1. The scammer creates a problem. A pop-up, caller, or message claims that the device has a virus, an account was hacked, a subscription renewed, or illegal activity was detected.
  2. You are directed to contact “support.” The warning provides a phone number, link, chat window, QR code, or reply address controlled by the scammer.
  3. The scammer requests access. You may be told to install remote-access software, visit a website, read a code, open a system tool, or change security settings.
  4. Normal computer information is presented as evidence. The scammer may show routine logs, services, network connections, or harmless error messages and claim they prove an infection.
  5. The scammer demands payment or information. Requests may involve a card, bank transfer, payment application, cryptocurrency, gift card, cash, account credentials, or identity information.
  6. The scam may continue. After gaining access, the scammer may install malware, steal files, open financial accounts, create a false refund, or transfer the victim to another person posing as a bank or government official.

Some refund scams use remote access to make it appear that too much money was returned to you. The scammer then pressures you to “repay” the difference even though no real overpayment occurred. Other versions claim that your money must be moved to a “safe” or “protected” account. Moving money at an unexpected caller's direction does not protect it.

Warning Signs

Be cautious when:

  • A pop-up says your computer is infected and provides a phone number to call.
  • An unexpected caller claims to have detected a problem on your computer or account.
  • A warning prevents normal browser use, plays an alarm, uses full-screen mode, or threatens data loss unless you act immediately.
  • A supposed technician asks you to install remote-access software or provide a session code before you have verified the organization.
  • Someone asks for your password, MFA code, recovery code, Social Security number, bank login, or payment-card information.
  • The technician tells you to disable antivirus, ignore a browser warning, change security settings, or run an unfamiliar command.
  • You are instructed to open your bank account while the person can view or control the computer.
  • Payment is requested by gift card, cryptocurrency, wire transfer, cash, payment application, or another difficult-to-recover method.
  • The person claims a refund was too large and asks you to return money.
  • You are told to move money to protect it from hackers, fraud, or government seizure.
  • The caller demands secrecy or tells you not to contact your bank, family, law enforcement, UM, or another trusted support provider.
  • A support number appears only in a pop-up, unsolicited message, advertisement, or sponsored search result.
  • The person claims that several unrelated organizations are working together and transfers you among supposed technicians, bank employees, and government agents.

A logo, caller ID, employee name, technical term, or familiar company name can be copied or spoofed. Verify support through a contact method you find independently.

How to Protect Yourself

  • Do not call a number in an unexpected pop-up. Close the tab or browser and contact support through an official website, application, device documentation, or known phone number.
  • Hang up on unsolicited support calls. A caller's knowledge of your name, device, provider, or recent activity does not prove legitimacy.
  • Initiate support yourself. Use the UM support channel, manufacturer, operating-system provider, service provider, or trusted local support organization you intended to contact.
  • Verify search results. Sponsored advertisements and look-alike websites can impersonate legitimate support. Confirm the domain before calling or downloading anything.
  • Do not grant remote access to an unverified person. Remote-control software can give the other person broad access to the device and information displayed on it.
  • Never share passwords or MFA codes. Legitimate support should use an approved identity-verification process rather than ask you to disclose a password or approve an unrelated sign-in.
  • Do not open financial accounts during a remote session. End the session before accessing banking, payment, tax, medical, or other sensitive services.
  • Do not move money to “protect” it. Contact the financial institution through a trusted number if someone claims an account is at risk.
  • Do not pay by gift card, cryptocurrency, wire transfer, or cash because a technician demands it. These payment methods are commonly used to make recovery difficult.
  • Keep software updated. Use current operating-system, browser, application, and security updates.
  • Use reputable security software. Do not install a cleanup tool recommended by the same pop-up or caller that reported the problem.
  • Talk to someone you trust. A second person can help evaluate a frightening or technically confusing claim.

What You Should Do at UM

If a tech support warning, call, message, or pop-up appears on a UM device or refers to a UM account:

  1. Do not call the number, click the support link, install software, or grant remote access.
  2. Close the message, tab, or browser window when possible.
  3. Contact the UM IT Helpdesk through an approved UM support channel.
  4. Contact the UM Information Security Office when the interaction may involve fraud, credentials, malware, university data, or unauthorized access.

If someone currently has remote access to a UM device, end the session or disconnect the device from the network if you can do so safely, then contact UM support from another device. Do not erase, reset, reimage, or continue troubleshooting the computer unless UM support directs you to do so.

If you interacted with the scam:

  • Installed software or granted remote access: Stop using the device for sensitive work and contact the UM IT Helpdesk or UM Information Security Office immediately.
  • Ran a command: Tell UM support exactly what command window or instructions were used. Do not attempt to reverse the command on your own.
  • Entered your UM password or shared an MFA code: Change your UM password through the normal UM account-management process from a trusted device, deny further prompts, and contact UM support.
  • Shared university information: Contact the UM Information Security Office and the appropriate data owner or UM office.
  • Sent money or exposed financial information: Contact the financial institution or payment provider immediately through a trusted number and contact the appropriate UM financial office when university funds or processes are involved.

If the scam arrived by email in your UM mailbox, use Outlook's Report Message tool and report it as phishing. Delete the message after reporting it. The Report Message tool may remove it automatically.

For a personal device that does not involve UM, end unauthorized remote access and contact the device manufacturer, operating-system provider, internet service provider, security-software provider, or another trusted technical-support service through independently verified contact information. Secure potentially exposed accounts from a separate trusted device.

Additional Questions

For a tech support scam involving a UM device, UM account, university information, or a UM business process, contact the UM IT Helpdesk and the UM Information Security Office. Involve the appropriate UM financial or business office when university funds or transactions are involved.

For a personal tech support scam:

  • Contact the device manufacturer, operating-system provider, internet service provider, security-software provider, or another trusted technical-support service through an official channel.
  • Contact the relevant account provider if credentials or account-recovery information may have been exposed.
  • Contact your bank, credit union, card issuer, or payment provider immediately if money or financial information was involved.
  • Report the scam to the Federal Trade Commission. Internet-enabled fraud can also be reported to the FBI's Internet Crime Complaint Center.

Additional Resources

Was this helpful?
0 reviews