TL;DR:

  • Tech support scams typically start with a pop-up, cold call, or email claiming your computer or account has a problem — the goal is to get remote access to your device.
  • Once remote access is granted, attackers can install malware, steal banking credentials, transfer money, and access your business accounts and data.
  • If someone has had remote access to a business device, treat it as a full incident: revoke access, change credentials, and check banking.

Tech support scams are not a new problem, but they have become significantly more sophisticated in recent years. What used to be an obvious cold call from “Windows Support” has evolved into targeted attacks that can be convincingly tailored to your specific business, software, and suppliers. Action Fraud receives tens of thousands of reports from UK businesses each year, and the financial losses are often substantial because attackers focus on gaining access to banking portals and payment systems rather than just browsing your files.

Understanding how these attacks work is the best defence.

The Three Starting Points

Tech support scams begin in one of three ways, and each uses a different hook to create urgency:

The browser pop-up. A malicious or compromised website triggers a full-screen pop-up with an alarm sound and a message claiming your computer has a virus, your Windows licence has expired, or your files are being encrypted. A phone number is displayed prominently: “Call Microsoft Security immediately.” The page may appear to freeze your browser. The goal is panic: if you call the number, you reach a fraudulent call centre that will ask you to install remote access software.

The cold call. You receive a call from someone claiming to be from Microsoft, BT, Virgin Media, your broadband provider, or increasingly from specific software vendors your business uses. They say they have detected unusual activity on your connection, that your router has been compromised, or that a security certificate is expiring. They sound technical and may use real company names correctly. They ask to walk you through some steps on your computer — which eventually involves installing remote access software.

The email lure. An email arrives claiming to be from your antivirus software provider, your bank’s fraud department, or HMRC IT support. It says a renewal payment failed, a scan found threats, or your account needs verification. It contains a phone number or a link to a “verification portal.” Both lead to the same outcome: contact with the fraudulent support team.

What Happens When You Call or Click

After the initial hook, the script is largely the same regardless of entry point:

  1. A convincing “technician” answers and takes you through “diagnostic steps” — usually showing you Windows Event Viewer (which always has warning entries, even on a healthy computer) and claiming the errors they can see are serious.

  2. They ask you to download and install a remote access tool, usually AnyDesk, TeamViewer, or Zoho Assist. These are legitimate software products, which is why they pass antivirus checks. Once installed, you are asked to share the session code so the “technician” can connect.

  3. With remote access, they move fast. Common next steps include: opening your browser and directing you to your business banking portal, then asking you to log in while they “check the connection.” They record your credentials or, in some cases, use your own session while you are distracted with an overlay. They may also navigate to PayPal, payment platforms, cloud storage, or email while talking you through something unrelated on screen.

  4. They may then claim to have fixed your problem and attempt to charge a fee, asking you to log into your bank to authorise a payment. Some will initiate a bank transfer themselves using your captured credentials.

The More Targeted Version

The evolved form of this attack is more dangerous because it is harder to dismiss. Attackers research your business using LinkedIn, Companies House, and your website before calling. They may:

  • Reference your actual IT supplier by name (“We’re calling on behalf of [your MSP]”)
  • Know which software you use and claim a specific licence issue
  • Address you or your staff by name
  • Send a spoofed email from a domain that looks like your software vendor’s
  • Claim to be following up on a specific ticket number

If someone calls referencing your actual IT provider’s name and a plausible-sounding issue, it is much harder for a staff member to dismiss. Training staff to always verify by calling the IT provider back on a known number, never on the number provided by the caller, is the key control here.

If Someone Has Already Given Remote Access

If a member of staff has already given a fraudster remote access to a business device, treat it as a security incident:

Immediate steps:

  1. Disconnect the device from the internet immediately — unplug ethernet, disable WiFi. Do this before anything else.
  2. Disconnect the remote access session using the remote access software’s own controls if it is still running.
  3. Do not use that device for anything sensitive until it has been checked by your IT support.

Within the hour: 4. Call your bank’s fraud line — the number on the back of your card or your business banking app. Report that credentials may have been compromised and ask for a hold on transactions if any payments may have been authorised. 5. Change passwords on business email, cloud accounts, and any accounts whose credentials may have been visible on screen — from a different, clean device. 6. Revoke active sessions on Microsoft 365, Google Workspace, or whichever platform you use (this is usually in the account’s active sessions or security settings).

Afterwards: 7. Report to Action Fraud at actionfraud.police.uk or by phone on 0300 123 2040. This creates a record and contributes to intelligence that leads to shutdowns. 8. Have the device professionally cleaned — remote access allows installation of malware, keyloggers, and remote access backdoors. A factory reset or reinstall is the only way to be confident the device is clean.

Prevention: What Actually Works

Pop-up alarm? Close the browser tab. Press Ctrl+W or Cmd+W. If the tab is frozen, force-quit the browser. There is no legitimate scenario where Microsoft, BT, or any software company displays your phone number in a browser pop-up.

Cold call about a computer problem? Hang up. Call the organisation back on a number from their official website. Legitimate support does not cold-call you about security issues without a prior support request.

Train staff on the single rule that matters: Your IT team, your bank, and Microsoft will never call you out of the blue to ask you to install remote access software or give out a session code. If someone asks for this, it is a scam, regardless of what they know about you.

Restrict installation rights. Standard user accounts in Windows and macOS can be prevented from installing software without an administrator password. If staff cannot install AnyDesk without IT approval, the main attack vector is blocked even if they are deceived.

Use managed remote access. If your business genuinely needs remote IT support, agree with your IT provider on which tool they will use (many MSPs use Splashtop, ConnectWise, or N-able) and instruct staff to only allow sessions initiated through that specific provider.

References