Tech Support Scams UK: Remote Access and Fake Alerts

Fake support calls, virus pop-ups and remote-access requests: how UK tech support scams work, how to shut one down, and what to do if you granted access.

Tech scams may seek direct payment, remote control, credentials or access to accounts. A pop-up announces that your PC is infected. A caller reports a fault on your line. A sticker on a parking meter sends you to a payment page that is not the operator's. A voice on the phone sounds exactly like your daughter. In every version the criminal is borrowing something you already trust — a brand, a network name, a familiar voice.

Technology companies do contact their customers, so the channel settles nothing. The request is what gives it away: remote access to your device, a payment to fix a problem you never reported, a security code read aloud, or credentials typed into a page you did not navigate to yourself. Not sure about a pop-up, call or message? Paste it into our free AI scam checker for an automated second opinion. It is a fallible assessment, not a verdict, so still verify the contact independently.

Four routes a tech scam takes

The unsolicited support call. A caller claims a virus, a fault or a refund and works towards remote access or a payment. Microsoft says it does not make unsolicited calls or send unsolicited messages to provide technical support, and that genuine Microsoft error and warning messages do not include telephone numbers — the basis of our Microsoft support scam guide. HP says it does not provide unsolicited technical support, covered in our printer support scam guide. Broadband and phone providers are impersonated the same way, as our guide to BT, Sky, Virgin Media and Openreach impersonation calls explains. Do not stretch those company statements into a belief that no technology company ever telephones anyone — many do, for genuine reasons.

The browser pop-up. A full-screen warning, often with an alarm sound and a number to ring, appears while you are browsing. Apple's guidance is to treat such browser alerts as fraudulent; our Apple tech support scam guide covers what to do instead of calling. A number displayed in a warning is a number the attacker chose, so dialling it is not the same as contacting the company.

The environmental trick. Here the attacker changes something in the world rather than contacting you: a code sticker placed over a genuine one, explained in our QR code 'quishing' guide, or a wireless network that copies a venue's name, covered in our fake Wi-Fi hotspot guide.

The attack on your identity rather than your device. Criminals take over your mobile number to intercept security codes — see SIM swap fraud warning signs — or use AI to imitate someone you know, in voice cloning scams and in sextortion using AI-generated images or video. Cifas recorded a 38% rise in unauthorised SIM swaps in its Fraudscape 2026 report, which also logged a record 444,993 cases filed by its members during 2025; more dated figures are in our UK scam statistics research.

Remote access: genuine tools, unverified control

AnyDesk, TeamViewer, Quick Assist and Chrome Remote Desktop are legitimate products, used every day by real IT departments and by trusted family, friends and workplace IT. Installing one is not inherently a scam. Remote-access tools are legitimate; the danger is granting control to a person or service you have not independently authenticated. An unsolicited call is a major warning, but so is a support number taken from a pop-up, message or search advert. Start from the vendor's official site or an existing trusted support channel.

The exposure is the whole point. Google says a person given Chrome Remote Desktop support access can have full access to apps, files, emails, documents and history. Microsoft's Quick Assist warning is specifically about someone claiming to be Microsoft Support: allow that helper in only if you started the contact with Microsoft Support yourself. TeamViewer says it does not provide remote-support services itself, so a caller presenting themselves as 'TeamViewer support' deserves immediate suspicion. Our remote access scam guide sets out what to do the moment you realise access has been granted.

Decision tree: is this contact genuine?

  • Where did the number or link come from? A contact route you found on the vendor's official site, or an existing trusted support channel, is not the same as one supplied by a pop-up, a message or a search advert — even when you were the one who dialled. Treat anything that followed an unverified route as unauthenticated, including anything the helper appears to know about you.
  • Is there a phone number in the warning? Microsoft says its genuine error and warning messages do not include telephone numbers, and Apple's guidance is to treat browser alerts claiming an infection as fraudulent. A pop-up that hands you a support number to ring is advertising at best.
  • Does it require remote control before anything else? Pause there. Remote access can be reasonable once you have authenticated the helper through a route you chose and described the problem yourself; the safety issue is unverified control, not remote access as such.
  • Is payment part of the fix? Be especially wary of gift cards, cryptocurrency, a bank transfer, or a 'refund' that requires you to sign in to online banking while the caller listens.
  • Did the page arrive from a code, link or network you did not choose? Inspect the destination without opening it where your device offers a preview or long-press option — some devices show a preview, others open straight after a tap, and a shortened or redirected address is not conclusive either way. Confirm the exact network name with venue staff before connecting.
  • Does it sound like someone you know, in an emergency, asking for money? A familiar voice is not sufficient evidence of identity on its own, especially when it is paired with an emergency and an urgent payment. End the call, ring the person back on the number you already have, and consider agreeing a family codeword in advance.

How to shut it down, and what to do afterwards

  • End the contact. Hang up, or close the tab; if a pop-up will not close, restart the device. You do not need to interact with the warning to be rid of it.
  • If you granted access: end the session, disconnect the device from the network, remove or disable the remote-access application, update the operating system and security software, and run a security scan. A scan that finds nothing is reassuring but is not evidence that the device is clean.
  • Secure the accounts, not just the device. From a different, trusted device, change your email password first — it is the reset route for everything else — then banking and shopping, and turn on two-step verification. Revoke unfamiliar sign-in sessions, app passwords and connected applications, and check your email forwarding, filter and account-recovery settings, because a rule or recovery address added during the session keeps working after a password change.
  • Review bank and card activity from another trusted device, and if money or banking was involved contact your bank immediately on the number on your card or by dialling 159.
  • If the helper had administrative access, installed software you cannot identify, disabled security controls, or if access seems to persist, seek trusted technical help and consider a full reset or rebuild rather than assuming the clean-up worked.
  • If your phone lost signal without explanation, contact your mobile network from another device straight away. A sudden, total loss of service can indicate a SIM swap, though activation delays and network faults look similar.
  • If you are being threatened with intimate images or video, including AI-generated material: stop replying, do not pay, keep the messages and any evidence, and report the account to the platform. Contact the police on 101 about a suspected offence, or 999 if the threat is immediate. Adults in the UK can contact the Revenge Porn Helpline on 0345 6000 459. StopNCII can be used by an adult who is depicted in an eligible image or video, was 18 or older when it was created, and still holds the file. It creates a hash on the person's device for use by participating platforms; it does not upload the image itself. If the image was taken when the person was under 18, use the child-protection routes signposted by police, Childline, CEOP or Report Remove rather than an adult service. Our guide to AI-generated sextortion walks through it.
  • Work through our scam recovery checklist for the full order of operations.

How to report a tech scam in the UK

Send suspicious emails to report@phishing.gov.uk, and a suspicious SMS text can be forwarded to 7726 free of charge. Report money lost or details shared to Report Fraud (formerly Action Fraud) at reportfraud.police.uk or 0300 123 2040 in England, Wales or Northern Ireland, or Police Scotland on 101 in Scotland. Tell the impersonated company through its official website, and report a tampered physical code to whoever owns the site, such as the council or car park operator. For consumer-rights help, use the service for your nation: Citizens Advice in England and Wales on 0808 223 1133, Advice Direct Scotland in Scotland on 0808 800 9060, or Consumerline in Northern Ireland on 0300 123 6262.

All tech support scams guides

Tech Support Scams

QR Code Scam UK: Spot a Fake 'Quishing' Code

A QR code sticker looks slightly different from the one next to it? That mismatch is the clearest sign of a tampered parking or payment code.

Updated

Tech Support Scams

Apple Tech Support Scam UK: Spot a Fake Pop-up

Got a pop-up or call saying your iPhone or Mac is infected and Apple support needs access? How to spot an Apple tech support scam and report it.

Updated

Tech Support Scams

Printer Support Scam UK: Spot a Fake HP Contact

An unsolicited caller or pop-up claims a printer fault and asks for remote access or payment. HP says it does not provide unsolicited technical support.

Updated

Common questions

Does Microsoft or Apple ever ring you about a virus?

Microsoft says it does not make unsolicited calls or send unsolicited messages to provide technical support, and that its genuine error and warning messages do not include telephone numbers. Apple's guidance is to treat browser alerts claiming your device is infected as fraudulent. That does not mean no technology company ever telephones a customer, so judge any contact by what it asks for — remote access, a payment or a security code are the warning signs, whatever name is used. A number from a pop-up or search advert is no safer just because you dialled it, and an official app is no safer if an unexpected caller is directing what you approve in it.

Is AnyDesk, TeamViewer or Quick Assist a scam app?

No. They are legitimate remote-access tools, used routinely by genuine IT support teams and by trusted family, friends and workplace IT. The danger is granting control to a person or service you have not independently authenticated — which includes a helper reached on a number from a pop-up, message or search advert, not only an unsolicited caller. Microsoft's Quick Assist warning is specifically about someone claiming to be Microsoft Support: allow that helper in only if you started the contact with Microsoft Support yourself. TeamViewer says it does not provide remote-support services itself, so a caller presenting themselves as 'TeamViewer support' deserves immediate suspicion.

I let someone remote into my computer — what should I do now?

End the session and disconnect the device from the network, then remove or disable the remote-access application, update the operating system and security software, and run a security scan. From a different, trusted device, change your email password first, then banking and shopping, turn on two-step verification, revoke unfamiliar sign-in sessions, app passwords and connected applications, and check your email forwarding and account-recovery settings. Review bank and card activity from that trusted device, and contact your bank on the number on your card or by dialling 159 if money may be exposed. If the helper had administrative access, installed software you cannot identify, or access seems to persist, get trusted technical help and consider a full reset. Then report it to Report Fraud at reportfraud.police.uk or 0300 123 2040 in England, Wales or Northern Ireland, or Police Scotland on 101 in Scotland.

Can a QR code or public Wi-Fi really take my details?

Indirectly, yes. A code sticker placed over a genuine one can send you to a convincing but fraudulent payment page. An evil-twin hotspot copies a trusted network name: it can steer users towards phishing and expose unencrypted traffic or connection metadata, while HTTPS limits direct reading of protected page content. Inspect a code's destination without opening it where your device offers a preview or long-press option, ask venue staff to confirm the exact network name, prefer mobile data for sensitive tasks, and do not treat a VPN as protection from a fraudulent site.

A call sounded exactly like my son asking for money — was it real?

Treat it as unverified. AI can clone a recognisable voice from recordings of that person speaking, so a familiar voice is not sufficient evidence of identity on its own, particularly when the call combines an emergency with an urgent payment. Hang up and ring the person back on the number you already have saved, or check with another family member. Agreeing a private family codeword in advance gives you a quick way to confirm a genuine call later.

Check a message Start recovery