Fake Tech Support Scams in 2026: How to Spot Them Before You Share a Code or Install an App
A familiar logo or convincing caller can hide a support scam. Learn how to verify the request, protect your accounts, and respond if you already gave access.
Information checked on:

Key takeaways
- Pause when support contacts you unexpectedly.
- A browser warning demanding a phone call deserves independent checking.
- Legitimate remote-access software can be misused.
- Keep login codes private; reject sign-ins you did not initiate.
- Requests for gift cards, crypto, cash, or urgent transfers are warning signs.
- A familiar caller ID does not establish identity.
- Find support through a channel you choose independently.
- If access or money was shared, secure accounts and contact the payment provider promptly.
- Save existing evidence and report the incident without continuing the conversation. [1–4,6,11,13,17]
What is a fake tech-support scam?
A criminal poses as a technology company, security provider, retailer, bank, or another trusted service and offers to solve a supposed problem. The objective may be money, account credentials, personal information, or control of a device—not necessarily all four. [1]
The FBI’s examples extend beyond computers to printers, utilities, internet providers, GPS services, and cryptocurrency exchanges. IC3 says call-center fraud heavily targets older adults; that describes criminal targeting, not a failure of judgment by victims. [1,2]
How tech-support scams usually start
Illustrative examples from FBI and FTC guidance: [1,3,7]
| Contact method | Typical claim | Safe response |
|---|---|---|
| Phone call | Your device or account is compromised | Hang up; contact support independently |
| Text | An account problem needs immediate action | Open the official app yourself |
| A subscription renewed or an unexpected charge occurred | Check billing through your account | |
| Browser pop-up | A virus was found; call for help | Do not call; close the page |
| Search result/ad | Immediate help from a familiar brand | Check the official domain before contacting anyone |
| Fake support website | A representative can restore access | Leave; use the service’s built-in help |
Red flag #1: They contacted you first
Microsoft says it does not make unsolicited calls offering technical support. Knowing your name does not authenticate a caller. [10]
An expected callback is different. If uncertain, contact the official support channel to confirm it.
Red flag #2: A pop-up tells you to call a phone number
Microsoft says its error and warning messages do not include phone numbers. A webpage can imitate a system alert. [10]
Avoid buttons inside the warning; close the tab or quit the browser using its normal controls. Genuine apps also display alerts; check the relevant app directly. Apple also warns about deceptive security pop-ups. [13]
Red flag #3: They want remote access
Remote-support software can be legitimate. Depending on the tool and permissions, the other person may see your screen, control the keyboard and mouse, open files, change settings, or observe signed-in activity. [11,12]
The key question is who receives that access. Microsoft has documented criminals abusing genuine remote assistance. An official-store download does not authenticate the caller. [12]
Red flag #4: They ask for a verification code
One-time passwords (OTPs), authenticator codes, backup codes, and login approvals can authorize access. Do not give authentication secrets to an unsolicited caller or approve a sign-in you did not initiate. [15,16,17]
Apple says it does not request your Apple Account password or verification codes to provide support. Google says it will not call to ask you to verify a code. Automated code delivery for your requested sign-in is different. [13,15]
There are legitimate support-specific codes: Apple documents a temporary Support PIN, for example. Verify the interaction and what the code authorizes. [14]
Red flag #5: They tell you to move or “protect” money
A demand for a bank transfer, wire, gift card, cryptocurrency, cash, or courier pickup should stop the conversation. A support agent has no troubleshooting reason to move your savings into a supposedly safe account or make you hide a transaction from your bank. [3,6,8]
The FBI’s September 17, 2026 government-impersonation alert describes secrecy demands and payments involving couriers, bank wires, prepaid cards, and crypto. Its older tech-support-specific warning also documents cash and precious-metal collections. These tactics predate 2026. [6,8]
The fake refund or subscription-renewal scam
An email claims you were charged for a subscription and supplies a number to cancel. The supposed refund then involves remote access, banking information, or a claim that too much money was returned and must be repaid. [3]
Check the actual subscription and bank statement independently. Do not trust refund screens shown during remote access.
Caller ID can be spoofed
The displayed name or number is not identity verification. The FBI’s 2026 warning describes impersonators using authentic-looking contact details and credentials. [6]
Hang up, stop replying, and open the official app or known website yourself. Use the contact information there—not a number or link provided in the suspicious conversation. [13]
Fake support websites and search results
IC3 warns that customer-support searches can lead to misleading sponsored results. A June 18, 2026 FBI alert also describes fraudulent ads and redirections to fake login pages; that alert concerns broader online fraud, not only tech support. [2,9]
Type a known official domain, check its spelling, or use support inside the genuine app. Treat search placement and familiar branding as insufficient evidence. For related shopping checks, see DECODISTA’s AI shopping agents and scam risk guide.
AI-generated impersonation in 2026
On July 20, 2026, the FBI warned about people impersonating IC3 personnel, including AI-generated promotional videos and spoofed complaint websites used to target previous fraud victims. Its September alert also describes AI-assisted impersonation on video calls. [5,6]
This does not implicate every support scam or any specific technology company. Verify identity through an independently chosen channel; a convincing voice or video is not enough. DECODISTA’s Pixel Scam Detection explainer covers another layer of protection and its limits.
A real company may use remote support—so how do you verify it?
Microsoft documents genuine remote assistance. Use this practical verification sequence: [11]
- End the unsolicited interaction.
- Open the company’s official app or website yourself.
- Start support from there.
- Ask the independently reached service to confirm any existing case.
- Decide whether remote help is necessary and whether you understand the permissions.
A case number supplied by the original caller is not proof; scammers can invent one. [3]
Before you install any support app
Ask yourself:
- Who initiated contact?
- Did I reach support through an official channel?
- Can that channel confirm my case, if one exists?
- What permissions will this app receive?
- Why is remote control needed?
- Am I being rushed or discouraged from checking?
- Am I being asked to open online banking while connected?
If answers are unclear, stop and verify. [7,12]
Never share these through an unsolicited support interaction
- Passwords or device passcodes
- OTPs and authenticator codes
- Backup or recovery codes
- Authenticator setup QR codes or secret keys
- Account recovery keys
- Session tokens or session cookies
- API keys
- Full payment credentials, such as card details plus security codes
Keep these out of chats, screenshots, and shared screens. These credentials have different permissions but all deserve protection. Apple and Google document protections for account secrets; setup secrets, session tokens, and API credentials also need protection. [12,14–16,20–22]
What to do if you installed remote-access software for a scammer
- Stop access. End the remote session. As a containment precaution, disconnect the affected device from Wi-Fi, Ethernet, and mobile data if access may continue.
- Use a trusted device for urgent action. Contact your bank if financial information was exposed, and secure important accounts from a device the stranger did not control.
- Remove the installed app and check the device. Microsoft advises uninstalling scammer-requested applications, applying security updates, and running a full Windows Security scan. For other systems, use the manufacturer’s security guidance.
- Get trusted help if uncertain. Microsoft says a reset may be appropriate; the FBI recommends considering professional cleaning. [1,10,12]
Remote access does not prove malware was installed. Equally, uninstalling one app or receiving a clean scan does not establish that nothing else changed. Keep the device offline if persistent access remains uncertain.
What to do if you shared a password or code
From a trusted device, change the affected password and any reused copies. Review recent security events, signed-in devices, recovery contacts, and connected access; remove what you do not recognize. Use official account recovery if locked out. [18]
Secure email early because its inbox can receive password-reset links for other accounts. Review forwarding rules and sign out other sessions using the provider’s controls. [19]
If recovery codes were exposed, replace them; Google says generating a new set invalidates the previous set. If an authenticator setup secret was exposed, use the affected service’s official process to replace that factor, retaining a safe recovery method. Do not assume an expired OTP reverses a sign-in already approved. [16,17,21]
What to do if you sent money
Contact the bank, card issuer, or payment provider immediately. Explain the scam and ask whether it can stop, recall, or reverse the payment. Options depend on the payment method and circumstances; reimbursement is not guaranteed. [4]
- Wire or bank transfer: Contact the bank or transfer company.
- Payment app: Report through its official fraud process.
- Gift card: Contact the issuer; keep the card and receipt.
- Crypto: Contact the exchange or operator promptly; recovery can be difficult.
- Mailed cash: Contact the delivery service immediately about interception.
- Courier pickup: Report promptly to police; do not arrange another meeting. [4,8]
Save records without delaying your report.
What if you gave access to online banking?
Stop remote access before doing anything else in banking. Contact your financial institution using its official app or the number on your card, from a trusted device or phone. Explain that someone could view or control your banking session. [4,7]
Ask the fraud team about protecting access and stopping transactions. Review transfers and payees, and replace affected credentials securely. A password change alone does not cancel a payment already initiated. Do not log back in while the stranger remains connected. [7,18]
What evidence should you save?
Keep existing messages, emails, screenshots, caller numbers, names or aliases, dates and times, receipts, transaction references, and the remote-access app’s name. Record what you shared and what happened. [2,8]
Give sensitive records directly to the bank or official reporting channel. Do not keep engaging, reopen suspicious links, or restore remote access to gather more evidence.
How to report a tech-support scam in the U.S.
- FBI: Submit an internet-crime complaint at IC3.gov.
- FTC: Report the scam at ReportFraud.ftc.gov.
- Impersonated company: Use its official support or security-reporting channel. [4,13,23]
Reporting does not guarantee a response or financial recovery. Outside the U.S., contact your financial institution and local fraud-reporting authority.
Be alert to follow-up recovery offers. IC3 says it does not directly contact individuals or charge to recover money; legitimate follow-up may come from an FBI field office or another law-enforcement agency. Verify that contact independently too. [5,23]
What legitimate tech support usually looks like
These signals are not an infallible test. [2,6,11,14]
| Signal | More consistent with legitimate support | Common scam red flag |
|---|---|---|
| First contact | You requested help or an expected callback | Unexpected diagnosis and pressure |
| Channel | You independently opened official support | Caller-supplied link or lookalike site |
| Remote access | Explained permissions and a relevant purpose | Immediate demand for control |
| Codes | Clearly identified support-only verification | Request for account login secrets |
| Payment | Expected, documented service charge | Gift cards, crypto, or cash collection |
| Urgency | Time to verify the request | Threats or enforced secrecy |
| Banking | Financial issues handled directly with your bank | Opening banking during remote control |
| Pop-up | Alert checked inside the genuine app | Warning insists you call its number |
| Identity | Confirmed through an independent channel | Logo, badge, or caller ID offered as proof |
Five-minute safety checklist
Stop. Do not click or call the supplied contact. Open official support independently. Keep authentication codes private. Do not grant an unverified person remote access or move money at their direction. If unsure, ask someone you trust before continuing. [7,13,15]
FAQ
What is a tech-support scam?
An impersonator offers supposed technical or customer assistance to obtain money, information, or access. [1]
Does Microsoft call people about viruses?
Microsoft says it does not make unsolicited technical-support calls. An unexpected virus-fix offer should be rejected. [10]
Are pop-up virus warnings real?
Some genuine software displays alerts. A webpage urging you to call an unknown number is a warning sign; check the security app independently. [13]
Can caller ID be faked?
Yes. A displayed number or agency name does not establish who is calling. [6]
Is remote-support software itself dangerous?
It can serve legitimate purposes. Risk depends on who receives access and what permissions you grant. [11]
Should I give a support agent my verification code?
Do not disclose account authentication codes in unsolicited contact. A verified service’s support PIN is a separate mechanism. [14–16]
Why do scammers ask for remote access?
It can expose information or let them act on the device; permissions determine their capabilities. [12]
Why do scammers ask for gift cards or crypto?
These payment methods can make it difficult to retrieve the money. [3]
What should I do if a scammer controlled my computer?
End access, secure accounts using a trusted device, and obtain appropriate security checks or professional help. [7,12]
Should I change passwords after a tech-support scam?
Yes if credentials or device access were exposed. Prioritize email and financial accounts and replace reused passwords. [18,19]
What if I logged into my bank while connected?
End access and call the bank’s fraud team independently. Explain the exposure and review transactions. [7]
Can I get my money back?
Possibly, depending on the transaction. Contact the provider immediately; no refund is guaranteed. [4]
Where do I report a tech-support scam?
U.S. readers can report to IC3 and the FTC using the official links above. [4,23]
Can scammers contact previous victims again?
Yes. The FBI’s July 2026 alert describes repeat targeting through supposed help recovering lost funds. [5]
Are AI-generated videos being used in scams?
Yes, including the documented IC3-impersonation scheme. This does not mean every suspicious video or support scam uses AI. [5]
Sources & Verification
Documentation verified: October 3, 2026. Documentation-based reporting; no scam engagement conducted, no malware executed, no scam phone numbers called, and no remote-access session tested.
Official U.S. government sources
- [1] FBI: Tech Support Scams.
- [2] IC3: Support and government impersonation overview.
- [3] FTC: Spotting and reporting support scams, September 2025.
- [4] FTC: Actions after being scammed, June 2026.
- [5] IC3: Impersonation of IC3, July 20, 2026.
- [6] IC3: Government and law-enforcement impersonation, September 17, 2026.
- [7] IC3: Technical and customer-support fraud, March 16, 2022.
- [8] IC3: Cash and precious-metal couriers, January 29, 2024.
- [9] IC3: Fraudulent website redirections, June 18, 2026.
- [19] FTC: Recovering hacked email and social accounts.
- [23] IC3: Official reporting homepage.
Official company security guidance
- [10] Microsoft: Protection against support scams.
- [11] Microsoft: Quick Assist and trusted remote help.
- [12] Microsoft Security: Remote-assistance abuse, May 15, 2024; June update.
- [13] Apple: Social engineering and phishing precautions.
- [14] Apple: Account security and support verification.
- [15] Google: Google Account Security Scam via Phone Call.
- [16] Google: Backup codes.
- [17] Google: Sign-in prompts.
- [18] Google: Securing a compromised account.
- [20] Google: API-key security.
- [21] Google Firebase: Authenticator enrollment secrets.
- [22] Google: Authenticator codes and transfers.
No independent reporting used.

