Tech Support Scam
A tech support scam impersonates IT or vendor support to gain remote access or payment, often via fake virus pop-ups, cold calls, or search ads.
A tech support scam is a fraud in which the attacker impersonates technical support — Microsoft, Apple, a bank's "security department," or the victim's own IT help desk — to obtain remote access to a device, harvest credentials, or extract payment for fixing a problem that never existed. It is one of the most consistently reported fraud categories in the FBI's IC3 annual data, and it disproportionately targets older victims, though corporate employees are increasingly in scope.
How it works
The entry point varies. Scareware pop-ups announce an infection and display a toll-free number; SEO poisoning and paid search ads plant fake support numbers above the real ones; cold calls simply claim "we've detected a problem with your computer." Some campaigns invert the flow with callback phishing: an email invoice for a subscription the victim never bought, with a support number to call for a refund.
Once on the phone, the "technician" directs the victim to install a legitimate remote-access tool (AnyDesk, TeamViewer, Quick Assist) and hands control of the machine to the attacker. From there the playbook branches: fake malware scans that justify a service fee, a staged "refund" in which the scammer pretends to overpay and pressures the victim to wire back the difference, or quiet installation of credential stealers. In corporate settings the same pretext — "IT support needs to fix your account" — is used to capture credentials and MFA approvals, which is exactly the help-desk impersonation tradecraft groups like Scattered Spider use against enterprises.
How to defend against it
- Teach the direction of trust. Real vendors and IT teams do not cold-call about infections, and legitimate security warnings never include a phone number to call. Support conversations should only happen on channels the employee initiated through a known-good directory.
- Control remote-access tooling. Allowlist the remote support tools your organization actually uses and alert on installations of the rest — the scammer's session tool is often the first hard artifact.
- Rehearse the pretext. Include IT-impersonation scenarios in security awareness training and phone-based simulations, and make sure your incident response runbook treats "I gave someone remote access" as a report to reward, not punish.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo