Menu+

Fake tech support calls and voucher payments

The warning on your screen cannot see your computer. The evidence the engineer shows you is standard output from tools built into Windows. Here is the whole script, in order.

Published
2026-08-21
Reading
6 min

Three ways the call begins

The pop-up

A browser window fills the screen. There is an alarm tone, sometimes a synthesised voice, a warning that your machine is infected or your IP address has been compromised, an instruction not to restart the computer, and a telephone number in large type. Occasionally there is an animated scan that appears to be finding files.

A web page cannot scan your computer for viruses. It has no access to your files, your antivirus or your system. What it can read is what every website reads: which browser you are using, which operating system, and a rough location from your IP address. That is why the warning "knows" you are on Windows in your city. It is the oldest trick on the page and it does most of the work.

The page may also trap the keyboard in full screen or throw a dialog box each time you try to close it. Force the browser to quit — Task Manager on Windows, Force Quit on a Mac — and reopen it declining to restore the previous session. Nothing has been damaged.

The unsolicited call

"I am calling from Microsoft. Our servers have detected a serious infection on your machine." Microsoft, Apple, Google and internet providers do not telephone individuals about virus infections. They do not monitor your computer and could not identify you from it if they did. The same applies to any caller claiming that your router has been hacked or your licence has expired.

The number you found yourself

This one deserves attention because it feels safe. You search for a company's support line, call the number at the top of the results, and reach a call centre that has bought the advert or seeded the listing. You dialled, so your guard is down. Reach support only by typing the company's own address into the browser and navigating from there.

A close relative of this is the renewal invoice by email: your antivirus subscription has auto-renewed for a large sum, and to cancel it you must call the number below. There is no link and no attachment, which is exactly why it passes the spam filter. The number is the entire payload.

What the engineer does with your screen

The first request is always remote access. You will be walked through installing a remote-support program — AnyDesk, TeamViewer, UltraViewer, LogMeIn, Supremo and similar are ordinary tools used honestly by real technicians, which is why they are chosen — and reading out the connection ID.

Once connected, the demonstration begins. Every item in it is genuine software behaving normally.

  • Event Viewer. Every working computer logs warnings and errors: a driver that started late, a service that timed out. Scrolling through a screen of red and yellow icons is presented as evidence of intrusion.
  • The network connection list. The netstat command prints the connections your machine currently holds. Update servers, cloud storage, the websites open in your browser. Each foreign address is described as a hacker sitting inside your computer.
  • The licence identifier trick. You are asked to run a command that prints file associations, and pointed to a long string in the output — a class identifier. The engineer claims it is your unique licence number and then reads the same string back from "our records" to prove they are Microsoft. That string is identical on every Windows installation on earth.
  • A directory listing at full speed. Thousands of filenames pouring down a black window, described as a deep scan.
  • Disabled services. A configuration screen is opened and a few unticked boxes are shown as proof that your protection has been switched off by an attacker.
  • Notepad as a chat window. Typing messages to you keeps your eyes on the screen, and keeps you reading while other things happen.
  • The blanked screen. "I will hide the display while the repair runs." Nothing legitimate requires you to stop watching your own computer.

The diagnosis follows: your machine is compromised, your bank details are exposed, and a security package, a lifetime firewall licence or a network protection subscription is needed at once.

Why the payment has to be a voucher

No software company charges for support with a Paysafecard PIN. None takes Neosurf, Transcash, PCS, Cashlib or Flexepin. Vendors bill through the account you already hold with them, or take a card and issue a receipt with a company name on it.

The call centre cannot take a card, because a card needs a merchant account, and a merchant account needs a registered company, a bank and an address. What they need instead is something that becomes cash the moment you read it aloud and belongs to nobody afterwards. Prepaid voucher codes work exactly that way, and the brands that are nothing but a PIN on a ticket are the purest example of it.

The refund reversal, which is the costly one

Weeks or months later, a caller says the company is closing and owes you a refund. Or the antivirus invoice email leads to a call in which a cancellation is agreed. Either way, they need remote access to "process" it, and they need you to open your online banking or a form on their screen.

Then something goes wrong. The refund appears on screen as far more than the sum agreed — an extra digit, they will say. The mechanism varies: they move money between two accounts you already own so a balance jumps, they edit the figures displayed in the browser using the developer tools built into it, or they show you a doctored page. Nothing has arrived from anywhere.

What follows is engineered distress. The engineer says the mistake was theirs, that the money came from their personal account, that their manager will dismiss them, that they have a family. Would you please return the difference. Not by transfer, because the audit would show it. In vouchers, from the shop down the road.

Check the balance from a different device, or telephone the bank on the number printed on your card. The overpayment is the trick, and it is the only part of the story that ever needs testing.

If you are on the call now

  • Hang up. Do not let them finish, do not argue, do not warn them first.
  • Disconnect the computer from the internet — unplug the cable or switch off the wireless — which ends their session immediately.
  • Do not answer when they call back, and they will call back, sometimes many times.

Afterwards, in this order

  1. Remove their access. Uninstall the remote-support software they had you install. If you are not confident it is gone, treat the machine as untrusted.
  2. Change passwords from a different device. A phone or another computer. Email first, because it is the key to everything else, then banking, then anything sharing that password. Turn on two-factor authentication where you can.
  3. Telephone your bank if online banking was open during the session, if card details were typed, or if any money moved. Ask them to review the account and reissue the card.
  4. Consider what they had. Someone with full control of a computer for half an hour can install anything and read anything. Where banking or work systems live on that machine, a clean reinstall is the only honest answer. At minimum, run a full scan with security software you obtained yourself.
  5. Report it to the police or your national fraud reporting service, and to your bank's fraud team.
  6. If a code was already read out, follow the steps for a voucher code that has gone without delay.

Expect a second wave. The same details get reused by "the refund department", "the fraud team", a cybercrime unit, or a recovery firm that has heard about your case. Anyone contacting you first about money you have lost is working from a list.

What genuine support never does

  • Telephones you, unprompted, about an infection on your machine.
  • Displays a phone number inside a virus warning.
  • Asks you to install remote-access software you did not go looking for.
  • Asks for payment in prepaid vouchers, in any currency, for any reason. Nobody legitimate does.
  • Asks you to keep the call from your family or your bank.
  • Issues a refund by asking you to send money back.

Any one of those, on its own, is enough to end the call.

If a voucher of yours is involved in something that is happening right now, tell us before you do anything else. Speed is what decides whether funds can still be held.

Contact support