You’re browsing normally. Maybe reading the news, watching a video, or shopping for something mundane. Then, without warning, a large alert box fills your screen. It has logos, red warning text, and an urgent message claiming your computer is infected. There’s a phone number to call. The alarm sound won’t stop.
Most people’s instinct in that moment is to call. That’s exactly the point.
A Scam That Has Quietly Become One of America’s Costliest

The numbers behind this type of fraud are jarring. According to the FBI, losses attributable to tech support scams in 2024 were $1.464 billion, which is $500 million more than 2023 losses and an 87% increase from 2022. That is not a slow-moving threat. That is a crisis accelerating in real time.
By 2025, tech support scams resulted in $2.1 billion in losses according to the FBI’s Internet Crime Complaint Center report. The trajectory is steep and shows no signs of leveling off.
In 2024 alone, consumers reported over 36,000 tech support scams to the FBI. Considering how many victims never file a report, that figure almost certainly understates the true scale of the problem.
How the Pop-Up Actually Works

One of the most common and dangerous scams is the fake pop-up alert that appears while you are browsing online. These pop-ups often claim there is a virus or critical issue with your computer and urge you to call a tech support phone number immediately.
A pop-up window appears claiming that your computer has been compromised or infected with malware. The message looks official, often displaying logos of well-known tech companies like Microsoft or Apple. The visual design is deliberately professional. There may be a countdown timer, a blinking cursor, or a looping audio alarm.
The most common tech support scam tactic involves fake security alerts generated through pop-up ads placed on shady streaming sites, torrent repositories, and adult content pages. The malicious ads pretend to be urgent security warnings from Microsoft, Apple, or antivirus vendors. They claim the user’s device is infected, hacked, or otherwise compromised and provide a tech support number to call.
The Phone Call That Hands Over Control

If one of these tech support impersonators gets you on the phone, they ask for remote access to your computer and pretend to scan it for viruses. They claim to find a malicious program and offer to remove it for a fee.
When the victim calls the number, a “technician” answers with a professional greeting. They ask for remote access to the computer using legitimate tools like AnyDesk, TeamViewer, or Quick Assist. Once connected, they navigate around the system to find things that “confirm” the infection, including legitimate Windows system logs containing normal error entries or benign processes they label as malicious.
After “diagnosing” the fabricated problem, the technician quotes a fee, typically $200 to $1,000, for a security service, a support plan, or virus removal. Payment is requested by gift card, wire transfer, or credit card.
The Real Damage Happens After the Call Ends

The irony of the tech support scam is that a device that was perfectly clean when the pop-up appeared may not be clean after the remote session. Some operations install keyloggers, remote access backdoors, or credential-stealing software during the “repair” session. This enables ongoing unauthorized access to banking, email, and other accounts long after the call ends, turning a one-time payment scam into a persistent identity theft operation.
Paying once can make someone a repeat target. The scammer may claim the issue has resurfaced, push a fake support plan, or use the information they already collected to try another scam later. The initial payment is often just the beginning of the exploitation.
Who Gets Targeted Most Often

Adults 60 years and older are more likely to be victims of tech support scams than any other age group. According to the FBI’s 2024 IC3 report, adults 60 and older lost $98 million to tech scams alone.
In 2024, older Americans reported $159 million in losses to tech support scams. Adults over 60 were five times more likely to lose money this way than younger users. The reason is not technical skill; it is that scammers count on hesitation.
Still, the assumption that only older adults fall for these scams is worth questioning. A report by Microsoft about tech support scams found that Millennials and Gen Z were victimized more by these scams than any other demographic group. Confidence in technology does not automatically translate into immunity from a well-crafted social engineering attack.
AI Is Making These Scams Harder to Spot

Tech support scams used to feel obvious. A random pop-up said your computer had “1,000 viruses,” a fake technician demanded payment, and the whole thing looked suspicious. Now scammers use AI-generated scripts, realistic voices, polished emails, fake websites, and convincing chat messages to make the same old scam feel official.
Artificial intelligence has transformed many industries, but it has also provided cybercriminals with new tools to con people. Scammers can use AI to create convincing phishing emails, deepfake videos and fake voices, and pose as tech support from a legitimate business using a spoofed telephone number.
The FBI’s 2025 Internet Crime Report includes a dedicated AI section for the first time, documenting more than 22,000 complaints and roughly $893 million in losses. Scammers use AI to generate convincing messages, clone voices, and create fake profiles or videos, all of which make traditional red flags harder to spot.
How Scammers Demand Payment

The FBI’s 2025 IC3 report found that victims who reported tech and customer support losses most often paid with cryptocurrency, wire transfer, debit or credit cards, prepaid or gift cards, or in some cases cash sent over snail mail. The variety of payment methods is intentional. Scammers push the option that makes recovery least likely.
They may tell victims to transfer money to “protect” or “secure” it, or ask them to buy cryptocurrency, gold, or gift cards. Some even ask victims to download software that gives them control of the device. Gift cards are particularly favored because transactions are nearly impossible to reverse once completed.
Real companies or government agencies will never ask someone to move money, buy gift cards, or download software to fix a problem. They also will not ask a person to lie to their bank or loved ones. That last detail is telling. Scammers sometimes explicitly coach victims to keep the interaction secret.
Law Enforcement Is Responding, but the Problem Keeps Growing

In March 2024, two tech-support companies agreed to pay $26 million to settle FTC charges that they bilked tens of millions of dollars from consumers, particularly older consumers, by duping them into buying computer repair services. In March 2025, the Commission announced it was sending more than $25.5 million back to consumers those companies defrauded.
To help combat impersonation scams, the FTC in 2024 finalized the Impersonation Rule. The rule gives the agency stronger tools to combat and deter scammers who impersonate government agencies and businesses, enabling the FTC to file federal court cases seeking to recover money for injured consumers and impose civil penalties against rule violators.
Total internet crime losses represent a 33% increase from 2023, indicating that scammers are getting better at tricking victims despite law enforcement, government, and industry investments. Enforcement actions help, but the financial incentive to run these scams remains enormous.
The One Rule That Can Stop the Scam Cold

Real security pop-up warnings and messages will never ask someone to call a phone number. That single fact is the most reliable filter available. No legitimate operating system or antivirus program triggers a pop-up that sends users to a phone line staffed by a stranger.
If someone receives a pop-up warning that prompts them to take immediate action, they should not. Fraudsters often use scare tactics to create a false sense of urgency through pop-up warnings that look like error messages from an operating system or antivirus software. If this kind of alert appears, do not click on it or call the phone number it lists.
Try rebooting your computer. Often, that clears the fake warning. Use a trusted antivirus or anti-malware program to scan your device. In most cases, a simple restart is all that is needed. There is no infection. There was never any infection.
What to Do If You Already Called the Number

If someone has already interacted with a fake tech support agent, the priority is to cut off access and limit financial damage quickly. The scammer typically requests that the victim install remote desktop software, which allows the scammer to take control of the victim’s computer. This access lets them manipulate the system, install malware, or steal personal data. Disconnecting from the internet immediately is the first practical step.
On the financial side, acting fast matters. Credit cards and payment apps were the most commonly used payment methods in scams reported to the FTC. Larger amounts were lost through bank transfers or cryptocurrency, which are far harder to recover. Contacting the bank or card issuer within hours of the transaction gives victims the best chance of a reversal.
Reporting the incident to the FBI’s Internet Crime Complaint Center at ic3.gov and to the FTC at ReportFraud.ftc.gov also matters, not just for potential recovery but because that data directly shapes how law enforcement prioritizes these cases.
The Bigger Picture Behind a Simple Pop-Up

There is something worth sitting with here. A scam that starts with a fake browser alert, something that takes less than a second to generate, managed to cost Americans more than $2 billion in a single year. Many victims willingly call the fake number, install remote access software, or pay the scammer because the warning looks urgent and legitimate. This is not a story about technical failure. It is a story about manufactured panic.
A scary pop-up creates a window of panic, and scammers have a script ready for the moment someone calls. The technology being exploited is not the computer. It is human psychology, specifically the deeply wired instinct to respond quickly when something appears to be wrong.
The defense is straightforward even if it feels counterintuitive in a moment of alarm: stop, close the browser, reboot the device, and tell someone you trust what just happened. The scam only works if someone picks up the phone.
AI Disclaimer: This article was created with the assistance of AI tools and reviewed by a human editor.