S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T24.3
CATEGORY Internet Scams
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Tech-Support Scams

Impersonation Fraud · Manufactured-Problem Con · Very Common
Red Flag
How It WorksSEC 01

Tech-support scams manufacture a computer emergency and then sell you the “fix.” An unsolicited pop-up, a cold call, or a fake search-ad helpline convinces you that something is urgently wrong — a virus, a hack, a compromised bank account — and that a helpful “technician” from a trusted brand like Microsoft, Apple, your bank, or your antivirus vendor will resolve it if you cooperate right now. The problem is fictional; the “fix” is the crime.

Three entry vectors dominate: scareware pop-ups (a full-screen “infection” warning, often with an alarm and a “do not restart” instruction, showing a number to call); cold calls and robocalls (“Windows support” reporting a problem you never noticed); and search-ad or SEO-poisoned fake helplines that intercept people looking for a real company’s number. All three funnel to the same sequence — build fear and authority, get you to install remote-access screen-sharing software, stage “proof” of infection, then demand payment in hard-to-reverse forms: gift cards, wire, crypto, or a coached bank transfer.

Its defining signature: the same party invents the problem and sells the cure, and the cure requires you to surrender control, secrecy, or untraceable payment before you can independently check whether anything was ever wrong. Real support strengthens under verification; this scam resists it.

Warning SignsSEC 02
  • Unsolicited "you're infected" contact. A pop-up, call, or ad from a brand you did not contact says your device or account is compromised.
  • A warning with a phone number. A full-screen "virus" alert giving a call-us number and a "do not restart" instruction — real OS and antivirus warnings never do this.
  • A request for remote access. Any push to install screen-sharing software so a "technician" can help.
  • Untraceable payment demands. Gift cards, wire, crypto, or a bank transfer — never how legitimate support is paid.
  • Pressure to stay and stay quiet. "Don't hang up, don't restart, don't tell your family," and act immediately.
  • A refund or overpayment story. A claim they owe you money and need remote access — then ask you to send the "excess" back.
Frequently Paired WithSEC 03
  • Vishing · T14.8
    The voice channel the call rides
  • Relief Exploitation · T7.13
    Invents the problem, sells the cure
  • Malware Delivery · T24.25
    Remote access plants it
  • Account Takeover · T24.10
    A common downstream goal
How the Scam UnfoldsSEC 04
  • Stage 01 · Contact
    An unsolicited pop-up, call, or fake helpline warns that your device is infected or your account is compromised.
  • Stage 02 · Control
    Fear, authority, and urgency get you to install remote-access software while staged "proof" of infection appears on your screen.
  • Stage 03 · Extraction
    Payment is demanded in gift cards, wire, or crypto — or your own money is moved — before you can independently verify anything was wrong.
Counter-ProtocolSEC 05
Defense: The same party invented the problem and is selling the cure — stop before you pay or grant access.
  • Don't call the pop-up number. It's a web page, not your computer — close the browser or force-restart; power the device off if it won't close.
  • Hang up and verify yourself. Reach the vendor only through a number from the box, receipt, or the official site you type — never a searched ad or a number the caller gives you.
  • Never grant remote access, never pay by gift card, wire, or crypto. Those demands are, by themselves, proof of a scam.
  • Set a family rule. "No real company calls out of the blue — check with me first" before any action.
  • If you paid or gave access: disconnect, scan, change passwords from a clean device, call your bank and card issuer, and report to the FTC, IC3, and the vendor.