Cys Infotech

Smarter sites, safer businesses — no strings attached.

Home / Blog

What Are Tech Support Scams, and How Do They Actually Work?

Short answer: Tech support scams use a scary pop-up or a cold call claiming your computer is infected, to get you to grant remote access or pay for a fake repair. No website can actually scan your computer for viruses, so any pop-up or call claiming it found one is lying.

Like invoice fraud, a tech support scam needs no hacking at all — just a scary message and a phone number to call. It's built entirely around convincing someone their computer is broken right now, before they've had a moment to stop and think about it.

What's actually happening

It usually starts one of two ways:

Here's the one rule that exposes this every time: a website has no way to scan the files on your computer. A browser pop-up cannot detect a virus on your device — that's not a security gap, it's just not technically possible for a webpage to do. Any pop-up claiming to have found an infection on your computer is lying, by definition, every single time. The same goes for cold calls — legitimate companies do not phone customers out of the blue to say they've detected a problem on their device.

Once someone calls the number or stays on the line, the scammer talks them into installing remote-access software — often a real, legitimate tool (the kind IT support actually uses), misused because a stranger is now controlling the computer. From there, a common move is opening a normal system log (like Windows Event Viewer) full of routine, harmless entries every computer has, and pointing at them as "proof" of infection — a well-documented trick that works because the logs look technical and alarming to someone who's never seen them before. The call usually ends with a demand for payment — for a "repair," a "support subscription," or a fake "refund" that requires logging into online banking, handing the scammer either your money or your banking credentials directly.

No website can scan your computer — any pop-up that claims to is lying

A local business scenario

(A composite, illustrative pattern — not one specific business's story.)

A shop owner's office printer starts acting up, so they search online for the manufacturer's support number. The number they call — from a sponsored search ad that looked official — actually reaches a scam call center with no connection to the real manufacturer at all. The "technician" asks for remote access to "diagnose the printer driver," gets it, then pivots: opens a system log full of routine warnings, points at them as proof of a serious infection unrelated to the printer, and offers to fix it for a few hundred dollars, payable immediately by gift card.

The owner, now worried about a computer that seemed fine an hour ago, buys the gift cards and reads the codes over the phone. The "technician" says the issue is resolved. Nothing was ever actually wrong with the computer — the entire infection was invented from routine logs, and the only real damage is the money already spent on gift cards, which are essentially untraceable and unrecoverable once the codes are handed over.

Best practices

  1. Close the pop-up without calling the number. If the browser is locked in fullscreen, use your task manager (Ctrl+Alt+Delete on Windows, Cmd+Option+Esc on a Mac) to force-quit it rather than following any on-screen instructions.
  2. No legitimate company cold-calls to report a problem they detected on your device. Treat any such call as fraudulent by default and hang up — this is true whether they claim to be Microsoft, Apple, your ISP, or anyone else.
  3. Only grant remote access to a company you contacted first. If someone reaches out to you — pop-up, cold call, unsolicited chat — unsolicited contact is the red flag itself, regardless of how convincing the rest of the call sounds.
  4. Gift cards, wire transfers, and cryptocurrency for "computer repair" are always a scam signal. No legitimate company asks to be paid that way, for anything.
  5. If you already gave access or paid, act right away: disconnect the computer from the internet, run a legitimate, already-installed antivirus scan, change your passwords from a separate, clean device, and report it (see the resource below) — the sooner, the more options are still open.

Helpful, free resources

A note on what this is and isn't: this post is general security education, not a personalized risk assessment of your specific business or systems. If you want a free, automated starting point for your own site, we offer a Security Health Check — free for any business, no obligation.