“Microsoft Tech Support” Phone Call: What’s Really Happening and How to Recover
A real Microsoft tech support call is one of the most successful scams in 2026. Here is what is actually happening, what to do if you fell for it, and how to lock down your accounts in the next hour.
Prefer to see how it works first? Visit our Tech Support help page for pricing, expert credentials, and answers to common questions.
Microsoft Does Not Make Unsolicited Calls
A core fact you can use to identify any scam call instantly: Microsoft, Apple, your bank, and the IRS all NEVER call you out of the blue. Real customer support is reactive — you contact them when you have a problem. Any unsolicited call claiming to be from a tech company saying "we detected a virus on your computer" is a scam. The script is consistent because it works on roughly 5-10% of recipients: fear, urgency, then access. The caller talks fast, insists immediate action is required, and asks you to install software so they can "fix" the issue. The software (AnyDesk, TeamViewer, LogMeIn, or similar) gives them complete control of your computer.
What They Did While Connected
Once they have remote access, the scammer follows a sequence: install a backdoor (so they can reconnect later), search for saved passwords in your browser (Chrome, Edge, Firefox all store them in retrievable formats), check your email for password reset links to your bank, log into your accounts and either drain them immediately or note credentials for later, and copy your contact list (to scam your contacts next). Some sophisticated operations install ransomware as a separate payload. The window during which they have access is typically 15-90 minutes — enough to do significant damage but limited by their need to move on to the next victim.
Hour 1: Immediate Damage Control
Disconnect from the internet immediately (unplug the ethernet cable or turn off WiFi). This severs the remote connection and stops any in-progress damage. From a different device (phone, tablet, another computer): change passwords on your most critical accounts in this order — primary email account first (because it controls password resets for everything else), banking and brokerage second, credit cards third, then any account containing financial info or personal documents. Use unique strong passwords for each. If you reused passwords, assume every account with that password is compromised.
Hour 2-4: Lock Down and Investigate
Enable two-factor authentication on every important account. Call your bank and credit card companies and tell them what happened — they may flag your accounts for unusual activity or issue new card numbers. Check your accounts for: new outgoing wire transfers, new credit cards opened in your name, login activity from unrecognized devices, password changes you did not make, email forwarding rules you did not set, and unfamiliar charges. Check your email "sent" folder for messages you did not send. Pull a credit report from all three bureaus (free at AnnualCreditReport.com) and place a fraud alert.
Day 2-7: Clean the Computer and Report
Assume the computer is compromised even if it looks fine. The most reliable cleanup is a full factory reset of Windows or macOS — back up your essential files first (documents, photos), reset to factory, and restore only your essential files (not applications, which may have been backdoored). Less thorough but easier: run Malwarebytes (free version) and Microsoft Defender Offline scan, uninstall any remote-access software they installed (AnyDesk, TeamViewer, LogMeIn), and delete recently-installed unknown programs. Report the scam to the FTC at ReportFraud.ftc.gov and the FBI at IC3.gov. If you sent money or gift cards, file a police report — your local police may not investigate, but the report supports an insurance or bank claim.
Pro Tips
Frequently Asked Questions
How can I tell if my computer is still compromised?
Common signs: programs starting on their own, mouse cursor moving without your input, unusual hard drive activity when you are not using the computer, programs you did not install, browser homepage changes, slow performance with no obvious cause, and antivirus software disabled. A full Malwarebytes scan and Microsoft Defender Offline scan will catch most known threats. Persistent symptoms after scanning indicate factory reset is needed.
Will the police actually investigate?
For most individual scam cases, no — the perpetrators are typically overseas and not within US jurisdiction. However, file a report anyway. The FBI and FTC compile reports and use the data for larger investigations. Your bank or credit card company may require a police report number to process fraud claims.
Can I recover money I sent the scammers?
Wire transfers and gift cards are usually unrecoverable. Bank transfers under $50,000 may be recoverable if you contact the bank within 24-48 hours. Credit card charges can be disputed and usually reversed (zero liability for unauthorized charges, federal law). Bitcoin or cryptocurrency transfers are essentially never recoverable.
Should I just buy a new computer?
A factory reset is usually sufficient and free. Buying a new computer is overkill unless the existing one was already aging out. If you do replace, do NOT transfer files via direct disk copy from the old machine — that can carry over malware. Manually copy only essential documents and photos.
Still stuck? Talk to an expert.
Get personalized tech support help for your specific situation — just $1.
Chat with an expert — $1 →