Skip to main content

That “Microsoft Support” Call Is a Scam — Here’s the Playbook They Use

Media That “Microsoft Support” Call Is a Scam — Here’s the Playbook They Use

The caller sounds calm, professional and concerned.

They know your name, claim to represent Microsoft and warn that your computer is sending error messages, spreading viruses or allowing criminals onto your network.

They may even display a local-looking telephone number on your screen.

Then comes the offer:

“Do not worry. I can fix it for you now.”

The call is not from Microsoft.

Microsoft states that it does not make unsolicited calls offering technical support. Genuine Microsoft warnings do not include a telephone number for you to call, and Microsoft will not unexpectedly contact you to repair your computer. 

The caller’s objective is usually to convince you to:

  • Install remote-access software
  • Reveal passwords or financial information
  • Pay for a non-existent repair
  • Sign in to online banking
  • Transfer money
  • Buy gift cards or cryptocurrency
  • Allow malware or persistent access to be installed

Report Fraud advises that genuine service providers, banks and police will not call unexpectedly and ask you to transfer money, disclose financial information or hand over remote control of your computer. 

The scam works because it follows a rehearsed psychological and technical playbook.

Understanding that playbook makes it much easier to recognise.

The One Rule That Stops Most Microsoft Support Scams

Use this rule:

Microsoft does not know that your individual computer has a problem and then telephone you unexpectedly to fix it.

If somebody calls out of the blue claiming that your Windows PC:

  • Has been hacked
  • Is sending virus warnings
  • Has an expired licence
  • Has a compromised IP address
  • Is attacking Microsoft’s servers
  • Needs an urgent security certificate
  • Must be repaired remotely

hang up.

Do not debate with the caller. Do not press a number to speak to an agent. Do not call them back using the number shown on your screen.

Caller ID can be spoofed so that a call appears to come from a genuine company, bank, police force or local number. The number displayed on your phone is therefore not proof of identity. 

The Scam Can Begin Without a Telephone Call

The traditional version starts with an unsolicited call, but criminals use several ways to bring victims into the same process.

A frightening browser pop-up

A web page may suddenly display:

  • Microsoft Security Alert
  • Your computer has been blocked
  • Trojan detected
  • Do not restart your computer
  • Call support immediately
  • Your files may be deleted

It may play an alarm, speak through the computer’s speakers or repeatedly reopen when you try to close it.

A pop-up displaying a telephone number is not a legitimate Microsoft security warning. Microsoft specifically advises users not to call telephone numbers shown in pop-ups or error messages. 

The pop-up itself does not necessarily mean the PC has already been infected. It may simply be a malicious or misleading webpage designed to frighten you into making the call.

A fake invoice or renewal email

You may receive an invoice claiming that you have purchased or renewed:

  • Microsoft Defender
  • Geek Squad support
  • Norton or McAfee
  • Amazon Prime
  • PayPal protection
  • A computer-maintenance subscription

The message tells you to telephone immediately if you did not authorise the payment.

The supposed charge is the bait. The criminal wants you to call the number, after which the conversation turns into a remote-access or refund scam. The FTC warns that fake renewal and invoice messages commonly direct people to fraudulent support agents who then request remote access. 

A fake search result

You search online for Microsoft, printer, antivirus or email support and telephone a number shown in an advertisement or unofficial result.

The person answers using the correct company name and may already know which product you need help with.

That does not prove they work for the company.

Use the support option built into the product or navigate independently to the organisation’s official website. Do not trust a telephone number simply because it appeared prominently in a search result. 

The Microsoft Support Scam Playbook

Researchers analysing scam-bait calls have found recognisable stages and scripts, including deliberate use of emotion and pressure to move victims through the fraud. The wording changes, but the underlying progression is often remarkably consistent. 

Stage One: Borrow Authority

The caller claims to represent an organisation you recognise.

Common identities include:

  • Microsoft
  • Windows Support
  • Your internet provider
  • Your bank
  • Amazon
  • Apple
  • A security company
  • The police
  • The National Cyber Security Centre

They may use official-sounding department names such as:

  • Microsoft Global Security Department
  • Windows Licence Division
  • Network Protection Team
  • Cybercrime Investigation Unit
  • Refund Department

The department name may not exist.

They may provide:

  • A fake employee number
  • A case reference
  • A licence ID
  • An IP address
  • A telephone number to call back
  • A website designed to resemble the real company

These details are props intended to make the conversation feel formal.

The NCSC warns that criminals also impersonate its staff and confirms that genuine NCSC representatives will not ask for remote access, login details or passwords. 

Stage Two: Create Fear and Urgency

The caller tells you that something serious is already happening.

They might claim:

  • Hackers are inside your computer.
  • Your identity is being stolen.
  • Your internet connection will be disconnected.
  • Your bank account is being attacked.
  • Your Windows licence will be cancelled.
  • Illegal activity is coming from your IP address.
  • Your photographs and documents are about to be deleted.
  • You must act before the computer crashes.

The aim is to prevent calm consideration.

The NCSC identifies threatening language, false offers of help and pressure to act as common signs of scam communications. 

A genuine technical problem rarely becomes more dangerous because you took ten minutes to verify who called.

When somebody says that you must act immediately, treat that urgency as evidence against them.

Stage Three: Isolate You From Other Advice

The caller may say:

  • Do not tell your bank.
  • Do not speak to your family.
  • Do not call your normal IT company.
  • Stay on the telephone.
  • Do not close the support window.
  • Do not turn off the computer.
  • Do not use another device.
  • This is a confidential investigation.

This is not normal support behaviour.

The scammer needs to control the information you receive. Another person may immediately recognise the fraud, so the caller tries to prevent you from checking.

A legitimate organisation will allow you to end the call and contact it independently.

Stage Four: “Prove” the Computer Is Infected

The scammer directs you to ordinary Windows tools and misrepresents normal information as evidence of infection.

Event Viewer

They may ask you to press:

Windows key + R

and enter:

eventvwr

Event Viewer records application, service, driver and Windows activity. Even a healthy computer will contain warnings and errors caused by temporary network failures, application crashes, interrupted services and events Windows subsequently recovered from.

The scammer points at red and yellow entries and declares:

“These are all viruses.”

They are not.

Microsoft has specifically documented scammers using ordinary Event Viewer errors to frighten victims into believing that the PC is damaged. 

Netstat

The caller may ask you to open Command Prompt and run:

netstat

The command lists network connections and listening services.

A computer connected to the internet normally communicates with numerous remote systems, including:

  • Microsoft services
  • Websites
  • Cloud applications
  • Email services
  • Content-delivery networks
  • Security platforms

The scammer may point to a “foreign address” and claim it is a foreign hacker.

In networking terminology, a foreign address simply means the remote end of a connection. Microsoft has identified misuse of netstat as another common tech-support scam tactic. 

Command Prompt theatre

The scammer may run commands that:

  • Display directory listings
  • Show Windows configuration
  • List network sessions
  • Print meaningless warning text
  • Produce normal access-denied messages
  • Display a tree of folders

The speed and technical appearance are intended to overwhelm you.

A command window containing unfamiliar text is not proof that the computer is infected.

Normal service states

The scammer may show services that are:

  • Stopped
  • Manual
  • Trigger-started
  • Not currently required

They claim every stopped service is evidence that hackers disabled Windows.

Many Windows services are designed to run only when needed.

Stage Five: Request Remote Access

Once you are worried, the caller offers to fix the problem.

They ask you to:

  1. Open a browser.
  2. Visit a website.
  3. Download a remote-support program.
  4. Read a session code.
  5. Approve screen sharing or control.
  6. Accept an administrator prompt.

The application itself may be a legitimate remote-support product.

The problem is not necessarily the software—it is the stranger you are allowing to control it.

Microsoft warns that tech-support scammers routinely ask victims to install remote-administration applications, after which the criminal can control the computer, alter settings, install unwanted software or steal information. 

Report Fraud advises that remote access should never be granted because of an unsolicited call, pop-up or text message. 

What remote access may allow them to do

Depending on the permissions you approve, the caller may be able to:

  • Move the mouse and type
  • View files
  • Open email
  • Read browser information
  • Install applications
  • Change security settings
  • Watch you enter passwords
  • Create unattended access
  • Access cloud services already signed in
  • Copy personal or business data

A professional support engineer may also require remote access—but only after you have independently contacted and verified the provider.

The critical difference is who initiated the support relationship.

Stage Six: Sell the Non-Existent Repair

The scammer now announces that the problem can be repaired for a fee.

The offer may include:

  • Lifetime Microsoft support
  • A five-year security licence
  • Firewall protection
  • Identity-theft monitoring
  • Network cleaning
  • Antivirus software
  • A Windows warranty
  • A refund-protection plan

The “service” may cost anything from a modest amount to thousands of pounds.

At best, you are paying for unnecessary work. At worst, the payment process is the beginning of a larger financial theft.

The FTC states that tech-support scammers commonly sell useless services, steal payment information or use remote access to install malware and obtain account credentials. 

Stage Seven: Move From Tech Support to Banking Fraud

Some scams do not ask for a simple support fee.

Instead, the caller says:

  • You are owed a refund.
  • Microsoft accidentally charged too much.
  • A support subscription must be cancelled.
  • The refund form can only be completed through online banking.
  • Money was deposited into your account by mistake.
  • You must return the excess amount.

They ask you to sign in to your bank while they still control or view the computer.

The criminal may then use manipulation, altered screen content or transfers between your own accounts to make it appear that too much money has been refunded.

You are told to return the supposed overpayment by:

  • Bank transfer
  • Cash
  • Gift cards
  • Cryptocurrency
  • A money-transfer service

No legitimate support provider needs access to your online bank to issue a refund.

Report Fraud’s guidance is unambiguous: a genuine provider, bank or police officer will not call and ask you to transfer money, disclose financial details or hand over remote control. 

Stage Eight: Keep You on the Line

The caller may remain connected for hours.

This gives them time to:

  • Build trust
  • Wear down resistance
  • Prevent you calling somebody else
  • Wait for financial transactions
  • Pressure you into further payments
  • Gather additional personal information

Scammers can alternate between kindness, authority, anger and panic.

If you hesitate, they may accuse you of:

  • Breaking the law
  • Losing the company’s money
  • Refusing to protect your family
  • Interfering with an investigation

These emotional changes are deliberate.

The goal is compliance—not technical support.

Stage Nine: Create Future Access

Even after the call ends, the criminal may try to preserve access.

They may have:

  • Configured the remote tool to start automatically
  • Enabled unattended access
  • Created a new Windows user
  • Installed another remote application
  • Added browser extensions
  • Changed recovery contact details
  • Stolen active account sessions
  • Installed malware

This is why simply closing or uninstalling the visible remote-support program may not be sufficient after meaningful remote access.

Stage Ten: Call Again Under a Different Identity

Victims are frequently targeted again.

The next caller may claim to be:

  • Your bank’s fraud team
  • The police
  • Microsoft’s refund department
  • Report Fraud
  • A recovery specialist
  • A different cyber-security company

They may know details from the first incident, making the second call sound convincing.

Treat unexpected offers to recover money as another potential scam. Contact the organisation independently using a number you already know to be correct.

Red-Flag Phrases

Hang up when an unexpected caller says:

“We have detected errors from your computer.”

“Your IP address has been compromised.”

“Your Windows licence is sending warnings.”

“Press Windows and R.”

“Open Event Viewer.”

“The red errors are viruses.”

“Install this support application.”

“Read me the code on your screen.”

“Do not tell your bank.”

“Log in so I can process the refund.”

“We accidentally refunded too much.”

“Buy gift cards to return the money.”

“Transfer it to a secure account.”

“Do not disconnect or your computer will stop working.”

One phrase alone may not prove fraud, but this combination follows the established support-scam pattern.

What Genuine Microsoft Support Looks Like

Legitimate Microsoft support normally begins because you requested assistance through an official Microsoft channel.

A genuine support agent should not unexpectedly:

  • Telephone to report viruses
  • Ask you to call a number shown in a browser warning
  • Demand access to online banking
  • Ask you to buy gift cards
  • Tell you to move money
  • Prevent you verifying their identity
  • Demand secrecy
  • Threaten to cancel Windows
  • Claim that normal Event Viewer entries prove infection

Microsoft advises that communications about technical support are initiated by the customer, not through unsolicited calls. 

How to Verify a Support Call

When somebody claims to represent Microsoft or another provider:

  1. End the call.
  2. Do not use a telephone number they supplied.
  3. Do not use a link from their email or pop-up.
  4. Open the organisation’s official application or website independently.
  5. Contact support through the official service.
  6. Explain what the caller claimed.
  7. Ask whether a genuine case exists.

A real organisation will not object to you ending the call and verifying it.

What to Do When the Pop-Up Will Not Close

Do not call the displayed number.

Try:

  1. Pressing Alt + F4
  2. Closing the browser through Task Manager
  3. Restarting the computer if the browser remains trapped
  4. Reopening the browser without restoring the suspicious tabs
  5. Clearing the browser’s site permissions and notifications
  6. Running a Windows Security scan

Do not click buttons inside the warning—even ones labelled Cancel, Close or Scan—because the webpage controls what those buttons do.

If the same warning immediately returns, the browser may be reopening the previous session or allowing a malicious site to send notifications.

What to Do During a Scam Call

Use a simple response:

“I do not accept unsolicited support calls. I will contact Microsoft independently.”

Then hang up.

Do not:

  • Confirm your name
  • Confirm which computer you own
  • Read information from the screen
  • Install anything
  • Visit a website
  • Give the caller a code
  • Argue with them
  • Try to discover who they are
  • Call them back

Report Fraud advises people who feel suspicious or pressured to hang up and take time to verify the contact independently. 

What to Do If You Installed the Program but Did Not Grant Access

Disconnect from the internet and close the application.

Then:

  1. Uninstall the remote-support software.
  2. Check Startup apps.
  3. Check installed browser extensions.
  4. Run a full Microsoft Defender scan.
  5. Review whether any passwords were entered.
  6. Restart and confirm the program has not returned.

When no session code was shared and no access was approved, the risk may be lower—but you should still check what was installed and whether it was configured to run automatically.

What to Do If You Granted Remote Access

Treat the device as potentially compromised.

Immediately:

  1. Disconnect Wi-Fi and Ethernet.
  2. End the telephone call.
  3. Do not use the affected PC for banking or password changes.
  4. Use another trusted device.
  5. Contact your bank when financial information was exposed.
  6. Change your email password first.
  7. Change banking and other important passwords.
  8. Sign out other active account sessions.
  9. Enable or review multi-factor authentication.
  10. Contact your IT provider.

When you believe somebody is trying to manipulate you into making a payment, Stop Scams UK recommends stopping the conversation, hanging up and calling 159 to connect safely to a participating bank. 

A meaningful remote-access session may justify resetting or clean-installing Windows, especially where the scammer had administrator rights, security software was disabled or business data was accessible.

Report the Scam

You can report somebody misusing Microsoft’s name through Microsoft’s official technical-support scam reporting service. 

In the UK, fraud and cybercrime can be reported through Report Fraud. Reports can be submitted online or by telephone on 0300 123 2040. 

The NCSC also provides services for reporting:

  • Suspicious telephone calls
  • Scam websites
  • Phishing messages
  • Fraudulent adverts 

Preserve:

  • The caller’s number
  • Call time
  • Claimed identity
  • Remote software used
  • Websites visited
  • Email messages
  • Payment details
  • Screenshots
  • Session codes
  • Bank references

Do not contact the scammer again to gather more evidence.

Scam-Baiting YouTubers: What Their Calls Reveal

Scam baiters deliberately engage criminals to waste their time, expose their scripts and educate viewers.

Their videos can be useful because they allow you to hear how the same persuasion techniques are repeated across many calls.

Kitboga

Kitboga is known for long, character-driven calls in which he keeps scammers occupied and exposes how their stories change when the victim does not behave as expected. His content focuses heavily on phone fraud and the emotional manipulation behind it. 

Useful lessons from his videos include:

  • Scammers may stay on a call for hours.
  • They frequently switch between friendliness and anger.
  • The technical explanation changes whenever the victim asks difficult questions.
  • The fraud often evolves from “computer repair” into a fake refund or banking emergency.

Scammer Payback

Scammer Payback, also known as Pierogi, produces scam-baiting content intended to raise awareness through humour and confrontation. The channel covers technical-support, refund and other telephone-based scams. 

The videos often illustrate:

  • How organised scam call centres follow scripts
  • How callers transfer victims between supposed departments
  • How criminals react when their real objective is exposed
  • How personal information is used to create credibility

Jim Browning

Jim Browning’s verified channel describes its purpose as tracking and identifying scammers who telephone, arrive through pop-ups or target people through other methods. His work has a more investigative focus and frequently explains the technology and infrastructure behind fraudulent call centres. 

His videos are particularly useful for understanding:

  • How scam operations are structured
  • How remote-access sessions are used
  • How callers monitor and transfer victims
  • How technical tools can be misrepresented

Pleasant Green

Pleasant Green’s channel explores and exposes internet scams, including technical-support, advance-fee, employment, payment and identity-based fraud. 

His content demonstrates that the same social-engineering principles appear in many different scams:

  • A believable identity
  • A fabricated problem
  • An urgent request
  • A financial demand
  • Pressure to continue communicating

Trilogy Media

Trilogy Media combines scam-bait calls with investigations, stings and direct attempts to interrupt fraud in progress. Its channel features scam busts and live calls alongside collaborations with other anti-scam creators. 

Their videos show that support scams can extend beyond call centres into:

  • Cash collection
  • Money mules
  • Courier fraud
  • In-person handovers
  • Wider organised networks

Watch Scam Baiters—Do Not Try to Become One

Professional scam-baiting content is entertaining and educational, but ordinary users should not imitate it.

Do not call scammers back, invite them onto your PC or attempt to access their systems.

Engaging them can:

  • Confirm that your number is active
  • Expose personal details
  • Increase future targeting
  • Lead to threats or harassment
  • Put your real computer and accounts at risk
  • Interfere with investigations
  • Cross legal or ethical boundaries

Recent cyber-security reporting has warned that replying to scam messages or attempting amateur scam bait can make you a more valuable target. The safer approach for most people is to ignore, block and report the contact. 

Established creators generally use controlled environments, separate identities, specialist technical knowledge and precautions that are not visible in the finished video.

Learn the script. Do not join the call.

Why Intelligent People Fall for These Calls

Support scams do not succeed because victims are unintelligent.

They succeed because criminals:

  • Create urgency
  • Pretend to possess authority
  • Use technical language
  • Show genuine Windows tools
  • Prevent independent verification
  • Continue until the victim is tired
  • Exploit fear of financial loss
  • Gradually increase the size of each request

The victim is not asked to hand over everything at once.

The process may begin with something small:

  1. Press two keys.
  2. Open a program.
  3. Read a number.
  4. Install a tool.
  5. Approve access.
  6. Sign in.
  7. Make a payment.

Each completed step makes the next one feel slightly more reasonable.

Protecting a Business From Support Scams

A scammer calling a business may target:

  • Reception
  • Finance
  • Remote workers
  • Senior management
  • New employees
  • Staff with local administrator rights
  • Employees who regularly speak to external IT suppliers

Businesses should establish a clear rule:

No employee grants remote access following an unsolicited call.

Publish the approved support process

Employees should know:

  • Who provides IT support
  • What telephone number to use
  • Which remote-support tool is approved
  • How engineers identify themselves
  • Whether a ticket number is required
  • Who can authorise software installation
  • What to do after a suspicious call

Remove unnecessary administrator rights

A user without local administrator rights may be less able to install persistent remote-access tools or disable security controls.

This does not eliminate the scam, but it can reduce its impact.

Control remote-access software

Businesses should inventory and restrict remote-control applications.

Security teams should be able to identify:

  • Approved products
  • Unapproved installations
  • Newly created services
  • Unattended-access settings
  • Unexpected remote sessions

Train staff using the real script

Generic advice such as “be careful online” is not enough.

Training should demonstrate:

  • The Event Viewer trick
  • Fake refund calls
  • Browser-locking pop-ups
  • Remote-access requests
  • Caller-ID spoofing
  • Requests for secrecy
  • Gift-card and “safe account” demands

Listening to carefully selected scam-bait videos can help employees recognise the tone, pacing and pressure used during real calls.

A Practical Microsoft Support Scam Checklist

When somebody claims to be from Microsoft:

  1. Ask whether you contacted Microsoft first.
  2. If not, assume the call is fraudulent.
  3. Do not trust caller ID.
  4. Do not call a number displayed in a pop-up.
  5. Do not open Event Viewer for the caller.
  6. Do not run commands they dictate.
  7. Do not visit their website.
  8. Do not install remote-access software.
  9. Do not provide a session code.
  10. Do not disclose passwords or verification codes.
  11. Do not sign in to online banking.
  12. Do not buy gift cards or cryptocurrency.
  13. Do not move money to a “safe account.”
  14. End the call.
  15. Verify through an independent official channel.
  16. Report the call.
  17. Contact your bank immediately if money or banking access was involved.
  18. Disconnect and professionally assess the PC if remote access was granted.

How Hamilton Group Can Help

A Microsoft support scam can move from an irritating telephone call to a serious security incident in minutes.

Hamilton Group’s experienced IT team can help businesses and individuals determine what happened and return affected systems to a trusted state.

Immediate Scam Assessment

We can establish:

  • Whether remote access was actually granted
  • Which software was installed
  • Whether administrator permission was approved
  • Which accounts were open
  • Whether the scammer configured unattended access
  • What information may have been exposed

Remote-Access Removal

Hamilton Group can inspect:

  • Installed applications
  • Windows services
  • Startup programs
  • Scheduled tasks
  • Browser extensions
  • Local users
  • Remote-support configuration
  • Security exclusions

Account and Microsoft 365 Protection

For business customers, we can:

  • Reset compromised credentials
  • Revoke active sessions
  • Review multi-factor authentication
  • Check mailbox rules and forwarding
  • Examine sign-in logs
  • Review SharePoint and OneDrive access
  • Remove unauthorised application permissions

Secure Recovery

Depending on the level of access, we can:

  • Perform malware scans
  • Restore Windows security settings
  • Remove unauthorised tools
  • Reset the PC
  • Complete a clean Windows installation
  • Restore verified data
  • Reinstall trusted applications

Staff Awareness Training

Hamilton Group can teach employees to recognise:

  • Fake Microsoft calls
  • Refund scams
  • Remote-access requests
  • Fake browser warnings
  • Invoice and renewal scams
  • Bank impersonation
  • Requests for secrecy or urgent payment

Hamilton Group aims to make first contact on IT support requests within 15 minutes, helping businesses contain potential compromise before it develops into financial loss or a wider data breach.

Microsoft Is Not Calling to Fix Your PC

The most important fact is also the simplest:

Microsoft does not unexpectedly telephone you because your computer has errors or viruses.

The Event Viewer entries are not proof. The foreign network addresses are not proof. The caller ID is not proof. The employee number is not proof.

The scammer’s real proof comes when you install their software and give them control.

Hang up, contact the organisation independently and never grant remote access because of an unsolicited call, message or browser pop-up.

Call 0330 043 0069, book a meeting with one of our experts or visit hgmssp.com for help verifying suspicious support calls, securing compromised devices and protecting your business from remote-access scams.